{"_id":{"$oid":"69184e3f0999409cf96ec55a"},"file_info":{"path":"/home/apogean/projects/malware/windows/samples/dll_sample.dll","name":"dll_sample.dll","size":"52224 bytes","analysis_date":"2025-11-13 12:35:21"},"hashes":{"md5":"40784dca35fa06d4c4cb932e101e56ab","sha1":"b105724b5bee4ad43b23cf35d8d29ff231f94aec","sha256":"cf9cdd5d26283d31c43eb4df35a0dfc867da74441e5363890a84b988d8514c62"},"metadata":{"md5":"40784dca35fa06d4c4cb932e101e56ab","sha1":"b105724b5bee4ad43b23cf35d8d29ff231f94aec","sha256":"cf9cdd5d26283d31c43eb4df35a0dfc867da74441e5363890a84b988d8514c62","analysis":"static","os":"windows","format":"pe","arch":"i386","path":"/home/apogean/projects/malware/windows/samples/dll_sample.dll"},"attack_tactics":[{"tactic":"DEFENSE EVASION","technique":"Obfuscated Files or Information","id":"T1027"},{"tactic":"DISCOVERY","technique":"File and Directory Discovery","id":"T1083"},{"tactic":"EXECUTION","technique":"Shared Modules","id":"T1129"}],"maec_categories":[{"category":"malware-category","value":"launcher"}],"mbc_behaviors":[{"objective":"DATA","behavior":"Encode Data::XOR","code":"C0026.002"},{"objective":"DEFENSE EVASION","behavior":"Obfuscated Files or Information::Encoding-Standard Algorithm","code":"E1027.m02"},{"objective":"DISCOVERY","behavior":"Code Discovery::Enumerate PE Sections","code":"B0046.001"},{"objective":"DISCOVERY","behavior":"File and Directory Discovery","code":"E1083"},{"objective":"FILE SYSTEM","behavior":"Create Directory","code":"C0046"},{"objective":"FILE SYSTEM","behavior":"Delete File","code":"C0047"},{"objective":"FILE SYSTEM","behavior":"Get File Attributes","code":"C0049"},{"objective":"FILE SYSTEM","behavior":"Read File","code":"C0051"},{"objective":"FILE SYSTEM","behavior":"Writes File","code":"C0052"},{"objective":"PROCESS","behavior":"Create Process","code":"C0017"},{"objective":"PROCESS","behavior":"Terminate Process","code":"C0018"}],"capabilities":[{"capability":"encode data using XOR","namespace":"data-manipulation/encoding/xor"},{"capability":"contains PDB path","namespace":"executable/pe/pdb"},{"capability":"create directory","namespace":"host-interaction/file-system/create"},{"capability":"delete file","namespace":"host-interaction/file-system/delete"},{"capability":"check if file exists","namespace":"host-interaction/file-system/exists"},{"capability":"get file attributes (2 matches)","namespace":"host-interaction/file-system/meta"},{"capability":"read file on Windows","namespace":"host-interaction/file-system/read"},{"capability":"write file on Windows (4 matches)","namespace":"host-interaction/file-system/write"},{"capability":"create process on Windows (3 matches)","namespace":"host-interaction/process/create"},{"capability":"terminate process","namespace":"host-interaction/process/terminate"},{"capability":"enumerate PE sections","namespace":"load-code/pe"},{"capability":"parse PE header","namespace":"load-code/pe"},{"capability":"resolve function by parsing PE exports","namespace":"load-code/pe"}]}
{"_id":{"$oid":"693183ff21f7c0a343defdc6"},"file_info":{"path":"/home/apogean/projects/malware/windows/all_runs/360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f1585432b28f.exe","name":"360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f1585432b28f.exe","size":"228352 bytes","analysis_date":"2025-12-04 12:52:06"},"hashes":{"md5":"9a5ff998dbf0f6923d0b454d89800fb4","sha1":"4f4fa23e9c503b941a5e91584d6ecc3813962ba1","sha256":"360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f1585432b28f"},"metadata":{"md5":"9a5ff998dbf0f6923d0b454d89800fb4","sha1":"4f4fa23e9c503b941a5e91584d6ecc3813962ba1","sha256":"360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f1585432b28f","analysis":"static","os":"any","format":"dotnet","arch":"any","path":"/home/apogean/projects/malware/windows/all_runs/360e6f2288b6c836…"},"attack_tactics":[{"tactic":"COLLECTION","technique":"Clipboard Data","id":"T1115"},{"tactic":"","technique":"Data from Information Repositories","id":"T1213"},{"tactic":"","technique":"Input Capture::Keylogging","id":"T1056.001"},{"tactic":"","technique":"Screen Capture","id":"T1113"},{"tactic":"","technique":"Web Browsers","id":"T1555.003"},{"tactic":"DEFENSE EVASION","technique":"Deobfuscate/Decode Files or Information","id":"T1140"},{"tactic":"","technique":"File and Directory Permissions Modification","id":"T1222"},{"tactic":"","technique":"Hide Artifacts","id":"T1564"},{"tactic":"","technique":"Hide Artifacts::Hidden Window","id":"T1564.003"},{"tactic":"","technique":"Impair Defenses::Disable or Modify Tools","id":"T1562.001"},{"tactic":"","technique":"Indicator Removal::File Deletion","id":"T1070.004"},{"tactic":"","technique":"Modify Registry","id":"T1112"},{"tactic":"","technique":"Obfuscated Files or Information","id":"T1027"},{"tactic":"","technique":"Delivery","id":"T1027.004"},{"tactic":"","technique":"Reflective Code Loading","id":"T1620"},{"tactic":"DISCOVERY","technique":"Account Discovery","id":"T1087"},{"tactic":"","technique":"Application Window Discovery","id":"T1010"},{"tactic":"","technique":"File and Directory Discovery","id":"T1083"},{"tactic":"","technique":"Process Discovery","id":"T1057"},{"tactic":"","technique":"Query Registry","id":"T1012"},{"tactic":"","technique":"Software Discovery","id":"T1518"},{"tactic":"","technique":"System Information Discovery","id":"T1082"},{"tactic":"","technique":"System Location Discovery","id":"T1614"},{"tactic":"","technique":"System Network Configuration Discovery","id":"T1016"},{"tactic":"","technique":"System Owner/User Discovery","id":"T1033"},{"tactic":"EXECUTION","technique":"Windows Management Instrumentation","id":"T1047"},{"tactic":"IMPACT","technique":"Resource Hijacking","id":"T1496"},{"tactic":"","technique":"/ Startup Folder","id":"T1547.001"},{"tactic":"","technique":"Association","id":"T1546.001"},{"tactic":"","technique":"Scheduled Task/Job::Scheduled Task","id":"T1053.005"},{"tactic":"PRIVILEGE ESCALATION","technique":"Access Token Manipulation","id":"T1134"}],"maec_categories":[{"category":"malware-category","value":"launcher"}],"mbc_behaviors":[{"objective":"COLLECTION","behavior":"Keylogging::Application Hook","code":"F0002.001"},{"objective":"COLLECTION","behavior":"Keylogging::Polling","code":"F0002.002"},{"objective":"COLLECTION","behavior":"Screen Capture::WinAPI","code":"E1113.m01"},{"objective":"COMMAND AND CONTROL","behavior":"C2 Communication::Receive Data","code":"B0030.002"},{"objective":"COMMAND AND CONTROL","behavior":"C2 Communication::Send Data","code":"B0030.001"},{"objective":"COMMUNICATION","behavior":"HTTP Communication","code":"C0002"},{"objective":"COMMUNICATION","behavior":"HTTP Communication::Create Request","code":"C0002.012"},{"objective":"COMMUNICATION","behavior":"HTTP Communication::Get Response","code":"C0002.017"},{"objective":"COMMUNICATION","behavior":"HTTP Communication::Read Header","code":"C0002.014"},{"objective":"COMMUNICATION","behavior":"HTTP Communication::Send Request","code":"C0002.003"},{"objective":"COMMUNICATION","behavior":"Socket Communication::Create TCP Socket","code":"C0001.011"},{"objective":"COMMUNICATION","behavior":"Socket Communication::TCP Client","code":"C0001.008"},{"objective":"CRYPTOGRAPHY","behavior":"Decrypt Data","code":"C0031"},{"objective":"CRYPTOGRAPHY","behavior":"Encrypt Data","code":"C0027"},{"objective":"CRYPTOGRAPHY","behavior":"Generate Pseudo-random Sequence::Use API","code":"C0021.003"},{"objective":"DATA","behavior":"Check String","code":"C0019"},{"objective":"DATA","behavior":"Decode Data::Base64","code":"C0053.001"},{"objective":"DATA","behavior":"Encode Data::Base64","code":"C0026.001"},{"objective":"DEFENSE EVASION","behavior":"Disable or Evade Security Tools","code":"F0004"},{"objective":"DEFENSE EVASION","behavior":"Self Deletion::COMSPEC Environment Variable","code":""},{"objective":"DEFENSE EVASION","behavior":"[F0007.001]","code":""},{"objective":"DISCOVERY","behavior":"File and Directory Discovery","code":"E1083"},{"objective":"DISCOVERY","behavior":"System Information Discovery","code":"E1082"},{"objective":"DISCOVERY","behavior":"Taskbar Discovery","code":"B0043"},{"objective":"FILE SYSTEM","behavior":"Copy File","code":"C0045"},{"objective":"FILE SYSTEM","behavior":"Create Directory","code":"C0046"},{"objective":"FILE SYSTEM","behavior":"Delete Directory","code":"C0048"},{"objective":"FILE SYSTEM","behavior":"Delete File","code":"C0047"},{"objective":"FILE SYSTEM","behavior":"Get File Attributes","code":"C0049"},{"objective":"FILE SYSTEM","behavior":"Move File","code":"C0063"},{"objective":"FILE SYSTEM","behavior":"Read File","code":"C0051"},{"objective":"FILE SYSTEM","behavior":"Set File Attributes","code":"C0050"},{"objective":"FILE SYSTEM","behavior":"Writes File","code":"C0052"},{"objective":"OPERATING SYSTEM","behavior":"Console","code":"C0033"},{"objective":"OPERATING SYSTEM","behavior":"Registry::Delete Registry Key","code":"C0036.002"},{"objective":"OPERATING SYSTEM","behavior":"Registry::Delete Registry Value","code":"C0036.007"},{"objective":"OPERATING SYSTEM","behavior":"Registry::Query Registry Key","code":"C0036.005"},{"objective":"OPERATING SYSTEM","behavior":"Registry::Query Registry Value","code":"C0036.006"},{"objective":"OPERATING SYSTEM","behavior":"Registry::Set Registry Key","code":"C0036.001"},{"objective":"OPERATING SYSTEM","behavior":"Wallpaper","code":"C0035"},{"objective":"PERSISTENCE","behavior":"Registry Run Keys / Startup Folder","code":"F0012"},{"objective":"PROCESS","behavior":"Create Mutex","code":"C0042"},{"objective":"PROCESS","behavior":"Create Process","code":"C0017"},{"objective":"PROCESS","behavior":"Create Thread","code":"C0038"},{"objective":"PROCESS","behavior":"Suspend Thread","code":"C0055"},{"objective":"PROCESS","behavior":"Terminate Process","code":"C0018"}],"capabilities":[{"capability":"self delete (3 matches)","namespace":"anti-analysis/anti-forensic/self-de…"},{"capability":"get geographical location","namespace":"collection"},{"capability":"save image in .NET","namespace":"collection"},{"capability":"gather firefox profile information","namespace":"collection/browser"},{"capability":"reference SQL statements (2 matches)","namespace":"collection/database/sql"},{"capability":"reference WMI statements","namespace":"collection/database/wmi"},{"capability":"log keystrokes (2 matches)","namespace":"collection/keylog"},{"capability":"log keystrokes via application hook","namespace":"collection/keylog"},{"capability":"log keystrokes via polling (2","namespace":"collection/keylog"},{"capability":"matches)","namespace":"│"},{"capability":"collection/network","namespace":"│ capture screenshot"},{"capability":"│ receive data","namespace":"communication"},{"capability":"send data","namespace":"communication"},{"capability":"manipulate network credentials in","namespace":"communication/authentication"},{"capability":".NET","namespace":"│"},{"capability":"communication/http","namespace":"│ reference HTTP User-Agent string"},{"capability":"│ create HTTP request","namespace":"communication/http/client"},{"capability":"receive HTTP response","namespace":"communication/http/client"},{"capability":"create TCP socket (3 matches)","namespace":"communication/socket/tcp"},{"capability":"act as TCP client","namespace":"communication/tcp/client"},{"capability":"create zip archive in .NET (3","namespace":"data-manipulation/compression"},{"capability":"matches)","namespace":"│"},{"capability":"data-manipulation/encoding/base64","namespace":"│ decode data using Base64 via WinAPI"},{"capability":"│ reference Base64 string","namespace":"data-manipulation/encoding/base64"},{"capability":"encrypt or decrypt data via BCrypt (2","namespace":"data-manipulation/encryption"},{"capability":"matches)","namespace":"│"},{"capability":"data-manipulation/encryption/dpapi","namespace":"│ generate random numbers in .NET"},{"capability":"│ contains PDB path","namespace":"executable/pe/pdb"},{"capability":"extract resource via kernel32","namespace":"executable/resource"},{"capability":"functions","namespace":"│"},{"capability":"host-interaction/clipboard","namespace":"│ monitor clipboard content"},{"capability":"│ read clipboard data (2 matches)","namespace":"host-interaction/clipboard"},{"capability":"manipulate console buffer (8 matches)","namespace":"host-interaction/console"},{"capability":"query environment variable (3","namespace":"host-interaction/environment-variab…"},{"capability":"matches)","namespace":"│"},{"capability":"host-interaction/file-system","namespace":"│ get common file path (7 matches)"},{"capability":"│ copy file (7 matches)","namespace":"host-interaction/file-system/copy"},{"capability":"create directory (8 matches)","namespace":"host-interaction/file-system/create"},{"capability":"delete directory (2 matches)","namespace":"host-interaction/file-system/delete"},{"capability":"delete file (12 matches)","namespace":"host-interaction/file-system/delete"},{"capability":"check if directory exists (15","namespace":"host-interaction/file-system/exists"},{"capability":"matches)","namespace":"│"},{"capability":"host-interaction/file-system/exists","namespace":"│ enumerate files in .NET (6 matches)"},{"capability":"│ get file attributes","namespace":"host-interaction/file-system/meta"},{"capability":"get file size (5 matches)","namespace":"host-interaction/file-system/meta"},{"capability":"set file attributes (2 matches)","namespace":"host-interaction/file-system/meta"},{"capability":"move file (2 matches)","namespace":"host-interaction/file-system/move"},{"capability":"read file on Windows (7 matches)","namespace":"host-interaction/file-system/read"},{"capability":"write file on Windows (11 matches)","namespace":"host-interaction/file-system/write"},{"capability":"enumerate gui resources (2 matches)","namespace":"host-interaction/gui"},{"capability":"change the wallpaper","namespace":"host-interaction/gui/session"},{"capability":"hide the Windows taskbar","namespace":"host-interaction/gui/taskbar/hide"},{"capability":"get disk information","namespace":"host-interaction/hardware/storage"},{"capability":"get disk size","namespace":"host-interaction/hardware/storage"},{"capability":"allocate unmanaged memory in .NET (3","namespace":"host-interaction/memory"},{"capability":"matches)","namespace":"│"},{"capability":"host-interaction/memory","namespace":"│ (14 matches)"},{"capability":"│ create or open mutex on Windows","namespace":"host-interaction/mutex"},{"capability":"get networking interfaces","namespace":"host-interaction/network/interface"},{"capability":"get hostname (2 matches)","namespace":"host-interaction/os/hostname"},{"capability":"get OS version in .NET","namespace":"host-interaction/os/version"},{"capability":"get process image filename (5","namespace":"host-interaction/process"},{"capability":"matches)","namespace":"│"},{"capability":"host-interaction/process/create","namespace":"│ handles and window (14 matches)"},{"capability":"│ create process on Windows (22","namespace":"host-interaction/process/create"},{"capability":"matches)","namespace":"│"},{"capability":"host-interaction/process/list","namespace":"│ find process by PID (2 matches)"},{"capability":"│ find process by name","namespace":"host-interaction/process/list"},{"capability":"acquire debug privileges","namespace":"host-interaction/process/modify"},{"capability":"terminate process (14 matches)","namespace":"host-interaction/process/terminate"},{"capability":"query or enumerate registry key (7","namespace":"host-interaction/registry"},{"capability":"matches)","namespace":"│"},{"capability":"host-interaction/registry","namespace":"│ matches)"},{"capability":"│ delete registry key","namespace":"host-interaction/registry/delete"},{"capability":"delete registry value (2 matches)","namespace":"host-interaction/registry/delete"},{"capability":"get session integrity level (3","namespace":"host-interaction/session"},{"capability":"matches)","namespace":"│"},{"capability":"host-interaction/session","namespace":"│ create thread (3 matches)"},{"capability":"│ suspend thread (9 matches)","namespace":"host-interaction/thread/suspend"},{"capability":"access WMI data in .NET","namespace":"host-interaction/wmi"},{"capability":"reference cryptocurrency strings","namespace":"impact/cryptocurrency"},{"capability":"disable system features via registry","namespace":"impact/features"},{"capability":"on Windows","namespace":"│"},{"capability":"load-code/dotnet","namespace":"│ matches)"},{"capability":"│ load .NET assembly","namespace":"load-code/dotnet"},{"capability":"compile CSharp in .NET","namespace":"load-code/dotnet/csharp"},{"capability":"persist via default file association","namespace":"persistence/registry"},{"capability":"registry key (2 matches)","namespace":"│"},{"capability":"persistence/registry/run","namespace":"│ schedule task via schtasks (2"},{"capability":"│ matches)","namespace":"│"},{"capability":"runtime","namespace":"│ compiled to the .NET platform"}]}
{"_id":{"$oid":"697dd9b63d04a01d9782709c"},"file_info":{},"hashes":{},"metadata":{"md5":"9a5ff998dbf0f6923d0b454d89800fb4","sha1":"4f4fa23e9c503b941a5e91584d6ecc3813962ba1","sha256":"360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f1585432b28f","analysis":"static","os":"any","format":"dotnet","arch":"any","path":"/home/apogean/projects/malware/windows/all_runs/360e6f2288b6c836…"},"attack_tactics":[{"tactic":"COLLECTION","technique":"Clipboard Data","id":"T1115"},{"tactic":"","technique":"Data from Information Repositories","id":"T1213"},{"tactic":"","technique":"Input Capture::Keylogging","id":"T1056.001"},{"tactic":"","technique":"Screen Capture","id":"T1113"},{"tactic":"","technique":"Web Browsers","id":"T1555.003"},{"tactic":"DEFENSE EVASION","technique":"Deobfuscate/Decode Files or Information","id":"T1140"},{"tactic":"","technique":"File and Directory Permissions Modification","id":"T1222"},{"tactic":"","technique":"Hide Artifacts","id":"T1564"},{"tactic":"","technique":"Hide Artifacts::Hidden Window","id":"T1564.003"},{"tactic":"","technique":"Impair Defenses::Disable or Modify Tools","id":"T1562.001"},{"tactic":"","technique":"Indicator Removal::File Deletion","id":"T1070.004"},{"tactic":"","technique":"Modify Registry","id":"T1112"},{"tactic":"","technique":"Obfuscated Files or Information","id":"T1027"},{"tactic":"","technique":"Delivery","id":"T1027.004"},{"tactic":"","technique":"Reflective Code Loading","id":"T1620"},{"tactic":"DISCOVERY","technique":"Account Discovery","id":"T1087"},{"tactic":"","technique":"Application Window Discovery","id":"T1010"},{"tactic":"","technique":"File and Directory Discovery","id":"T1083"},{"tactic":"","technique":"Process Discovery","id":"T1057"},{"tactic":"","technique":"Query Registry","id":"T1012"},{"tactic":"","technique":"Software Discovery","id":"T1518"},{"tactic":"","technique":"System Information Discovery","id":"T1082"},{"tactic":"","technique":"System Location Discovery","id":"T1614"},{"tactic":"","technique":"System Network Configuration Discovery","id":"T1016"},{"tactic":"","technique":"System Owner/User Discovery","id":"T1033"},{"tactic":"EXECUTION","technique":"Windows Management Instrumentation","id":"T1047"},{"tactic":"IMPACT","technique":"Resource Hijacking","id":"T1496"},{"tactic":"","technique":"/ Startup Folder","id":"T1547.001"},{"tactic":"","technique":"Association","id":"T1546.001"},{"tactic":"","technique":"Scheduled Task/Job::Scheduled Task","id":"T1053.005"},{"tactic":"PRIVILEGE ESCALATION","technique":"Access Token Manipulation","id":"T1134"}],"maec_categories":[{"category":"malware-category","value":"launcher"}],"mbc_behaviors":[{"objective":"COLLECTION","behavior":"Keylogging::Application Hook","code":"F0002.001"},{"objective":"COLLECTION","behavior":"Keylogging::Polling","code":"F0002.002"},{"objective":"COLLECTION","behavior":"Screen Capture::WinAPI","code":"E1113.m01"},{"objective":"COMMAND AND CONTROL","behavior":"C2 Communication::Receive Data","code":"B0030.002"},{"objective":"COMMAND AND CONTROL","behavior":"C2 Communication::Send Data","code":"B0030.001"},{"objective":"COMMUNICATION","behavior":"HTTP Communication","code":"C0002"},{"objective":"COMMUNICATION","behavior":"HTTP Communication::Create Request","code":"C0002.012"},{"objective":"COMMUNICATION","behavior":"HTTP Communication::Get Response","code":"C0002.017"},{"objective":"COMMUNICATION","behavior":"HTTP Communication::Read Header","code":"C0002.014"},{"objective":"COMMUNICATION","behavior":"HTTP Communication::Send Request","code":"C0002.003"},{"objective":"COMMUNICATION","behavior":"Socket Communication::Create TCP Socket","code":"C0001.011"},{"objective":"COMMUNICATION","behavior":"Socket Communication::TCP Client","code":"C0001.008"},{"objective":"CRYPTOGRAPHY","behavior":"Decrypt Data","code":"C0031"},{"objective":"CRYPTOGRAPHY","behavior":"Encrypt Data","code":"C0027"},{"objective":"CRYPTOGRAPHY","behavior":"Generate Pseudo-random Sequence::Use API","code":"C0021.003"},{"objective":"DATA","behavior":"Check String","code":"C0019"},{"objective":"DATA","behavior":"Decode Data::Base64","code":"C0053.001"},{"objective":"DATA","behavior":"Encode Data::Base64","code":"C0026.001"},{"objective":"DEFENSE EVASION","behavior":"Disable or Evade Security Tools","code":"F0004"},{"objective":"DEFENSE EVASION","behavior":"Self Deletion::COMSPEC Environment Variable","code":""},{"objective":"DEFENSE EVASION","behavior":"[F0007.001]","code":""},{"objective":"DISCOVERY","behavior":"File and Directory Discovery","code":"E1083"},{"objective":"DISCOVERY","behavior":"System Information Discovery","code":"E1082"},{"objective":"DISCOVERY","behavior":"Taskbar Discovery","code":"B0043"},{"objective":"FILE SYSTEM","behavior":"Copy File","code":"C0045"},{"objective":"FILE SYSTEM","behavior":"Create Directory","code":"C0046"},{"objective":"FILE SYSTEM","behavior":"Delete Directory","code":"C0048"},{"objective":"FILE SYSTEM","behavior":"Delete File","code":"C0047"},{"objective":"FILE SYSTEM","behavior":"Get File Attributes","code":"C0049"},{"objective":"FILE SYSTEM","behavior":"Move File","code":"C0063"},{"objective":"FILE SYSTEM","behavior":"Read File","code":"C0051"},{"objective":"FILE SYSTEM","behavior":"Set File Attributes","code":"C0050"},{"objective":"FILE SYSTEM","behavior":"Writes File","code":"C0052"},{"objective":"OPERATING SYSTEM","behavior":"Console","code":"C0033"},{"objective":"OPERATING SYSTEM","behavior":"Registry::Delete Registry Key","code":"C0036.002"},{"objective":"OPERATING SYSTEM","behavior":"Registry::Delete Registry Value","code":"C0036.007"},{"objective":"OPERATING SYSTEM","behavior":"Registry::Query Registry Key","code":"C0036.005"},{"objective":"OPERATING SYSTEM","behavior":"Registry::Query Registry Value","code":"C0036.006"},{"objective":"OPERATING SYSTEM","behavior":"Registry::Set Registry Key","code":"C0036.001"},{"objective":"OPERATING SYSTEM","behavior":"Wallpaper","code":"C0035"},{"objective":"PERSISTENCE","behavior":"Registry Run Keys / Startup Folder","code":"F0012"},{"objective":"PROCESS","behavior":"Create Mutex","code":"C0042"},{"objective":"PROCESS","behavior":"Create Process","code":"C0017"},{"objective":"PROCESS","behavior":"Create Thread","code":"C0038"},{"objective":"PROCESS","behavior":"Suspend Thread","code":"C0055"},{"objective":"PROCESS","behavior":"Terminate Process","code":"C0018"}],"capabilities":[{"capability":"self delete (3 matches)","namespace":"anti-analysis/anti-forensic/self-de…"},{"capability":"get geographical location","namespace":"collection"},{"capability":"save image in .NET","namespace":"collection"},{"capability":"gather firefox profile information","namespace":"collection/browser"},{"capability":"reference SQL statements (2 matches)","namespace":"collection/database/sql"},{"capability":"reference WMI statements","namespace":"collection/database/wmi"},{"capability":"log keystrokes (2 matches)","namespace":"collection/keylog"},{"capability":"log keystrokes via application hook","namespace":"collection/keylog"},{"capability":"log keystrokes via polling (2","namespace":"collection/keylog"},{"capability":"matches)","namespace":"│"},{"capability":"collection/network","namespace":"│ capture screenshot"},{"capability":"│ receive data","namespace":"communication"},{"capability":"send data","namespace":"communication"},{"capability":"manipulate network credentials in","namespace":"communication/authentication"},{"capability":".NET","namespace":"│"},{"capability":"communication/http","namespace":"│ reference HTTP User-Agent string"},{"capability":"│ create HTTP request","namespace":"communication/http/client"},{"capability":"receive HTTP response","namespace":"communication/http/client"},{"capability":"create TCP socket (3 matches)","namespace":"communication/socket/tcp"},{"capability":"act as TCP client","namespace":"communication/tcp/client"},{"capability":"create zip archive in .NET (3","namespace":"data-manipulation/compression"},{"capability":"matches)","namespace":"│"},{"capability":"data-manipulation/encoding/base64","namespace":"│ decode data using Base64 via WinAPI"},{"capability":"│ reference Base64 string","namespace":"data-manipulation/encoding/base64"},{"capability":"encrypt or decrypt data via BCrypt (2","namespace":"data-manipulation/encryption"},{"capability":"matches)","namespace":"│"},{"capability":"data-manipulation/encryption/dpapi","namespace":"│ generate random numbers in .NET"},{"capability":"│ contains PDB path","namespace":"executable/pe/pdb"},{"capability":"extract resource via kernel32","namespace":"executable/resource"},{"capability":"functions","namespace":"│"},{"capability":"host-interaction/clipboard","namespace":"│ monitor clipboard content"},{"capability":"│ read clipboard data (2 matches)","namespace":"host-interaction/clipboard"},{"capability":"manipulate console buffer (8 matches)","namespace":"host-interaction/console"},{"capability":"query environment variable (3","namespace":"host-interaction/environment-variab…"},{"capability":"matches)","namespace":"│"},{"capability":"host-interaction/file-system","namespace":"│ get common file path (7 matches)"},{"capability":"│ copy file (7 matches)","namespace":"host-interaction/file-system/copy"},{"capability":"create directory (8 matches)","namespace":"host-interaction/file-system/create"},{"capability":"delete directory (2 matches)","namespace":"host-interaction/file-system/delete"},{"capability":"delete file (12 matches)","namespace":"host-interaction/file-system/delete"},{"capability":"check if directory exists (15","namespace":"host-interaction/file-system/exists"},{"capability":"matches)","namespace":"│"},{"capability":"host-interaction/file-system/exists","namespace":"│ enumerate files in .NET (6 matches)"},{"capability":"│ get file attributes","namespace":"host-interaction/file-system/meta"},{"capability":"get file size (5 matches)","namespace":"host-interaction/file-system/meta"},{"capability":"set file attributes (2 matches)","namespace":"host-interaction/file-system/meta"},{"capability":"move file (2 matches)","namespace":"host-interaction/file-system/move"},{"capability":"read file on Windows (7 matches)","namespace":"host-interaction/file-system/read"},{"capability":"write file on Windows (11 matches)","namespace":"host-interaction/file-system/write"},{"capability":"enumerate gui resources (2 matches)","namespace":"host-interaction/gui"},{"capability":"change the wallpaper","namespace":"host-interaction/gui/session"},{"capability":"hide the Windows taskbar","namespace":"host-interaction/gui/taskbar/hide"},{"capability":"get disk information","namespace":"host-interaction/hardware/storage"},{"capability":"get disk size","namespace":"host-interaction/hardware/storage"},{"capability":"allocate unmanaged memory in .NET (3","namespace":"host-interaction/memory"},{"capability":"matches)","namespace":"│"},{"capability":"host-interaction/memory","namespace":"│ (14 matches)"},{"capability":"│ create or open mutex on Windows","namespace":"host-interaction/mutex"},{"capability":"get networking interfaces","namespace":"host-interaction/network/interface"},{"capability":"get hostname (2 matches)","namespace":"host-interaction/os/hostname"},{"capability":"get OS version in .NET","namespace":"host-interaction/os/version"},{"capability":"get process image filename (5","namespace":"host-interaction/process"},{"capability":"matches)","namespace":"│"},{"capability":"host-interaction/process/create","namespace":"│ handles and window (14 matches)"},{"capability":"│ create process on Windows (22","namespace":"host-interaction/process/create"},{"capability":"matches)","namespace":"│"},{"capability":"host-interaction/process/list","namespace":"│ find process by PID (2 matches)"},{"capability":"│ find process by name","namespace":"host-interaction/process/list"},{"capability":"acquire debug privileges","namespace":"host-interaction/process/modify"},{"capability":"terminate process (14 matches)","namespace":"host-interaction/process/terminate"},{"capability":"query or enumerate registry key (7","namespace":"host-interaction/registry"},{"capability":"matches)","namespace":"│"},{"capability":"host-interaction/registry","namespace":"│ matches)"},{"capability":"│ delete registry key","namespace":"host-interaction/registry/delete"},{"capability":"delete registry value (2 matches)","namespace":"host-interaction/registry/delete"},{"capability":"get session integrity level (3","namespace":"host-interaction/session"},{"capability":"matches)","namespace":"│"},{"capability":"host-interaction/session","namespace":"│ create thread (3 matches)"},{"capability":"│ suspend thread (9 matches)","namespace":"host-interaction/thread/suspend"},{"capability":"access WMI data in .NET","namespace":"host-interaction/wmi"},{"capability":"reference cryptocurrency strings","namespace":"impact/cryptocurrency"},{"capability":"disable system features via registry","namespace":"impact/features"},{"capability":"on Windows","namespace":"│"},{"capability":"load-code/dotnet","namespace":"│ matches)"},{"capability":"│ load .NET assembly","namespace":"load-code/dotnet"},{"capability":"compile CSharp in .NET","namespace":"load-code/dotnet/csharp"},{"capability":"persist via default file association","namespace":"persistence/registry"},{"capability":"registry key (2 matches)","namespace":"│"},{"capability":"persistence/registry/run","namespace":"│ schedule task via schtasks (2"},{"capability":"│ matches)","namespace":"│"},{"capability":"runtime","namespace":"│ compiled to the .NET platform"}]}
{"_id":{"$oid":"69e716dd59a6632dae07ddfa"},"sha256":"e37c838dc5eaa1b302ffbd8721c6a5f52a068e8f78bbec63b19b950462fe6cf8","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_7y0wi49q/2_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_7y0wi49q/2_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_7y0wi49q/2_very_verbose.txt"}},"outputs":{"normal":"┌───────────┬──────────────────────────────────────────────────────────────────┐\n│ md5       │ be0930fc1d862072effdd01493361fb5                                 │\n│ sha1      │ e421261bf9c56bc5390d1f1b5be10f4fa53ba34c                         │\n│ sha256    │ e37c838dc5eaa1b302ffbd8721c6a5f52a068e8f78bbec63b19b950462fe6cf8 │\n│ analysis  │ static                                                           │\n│ os        │ any                                                              │\n│ format    │ dotnet                                                           │\n│ arch      │ i386                                                             │\n│ path      │ /home/apogean/projects/malware/windows/all_runs/2                │\n└───────────┴──────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic               ┃ ATT&CK Technique                               ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION             │ Reflective Code Loading [T1620]                │\n│ DISCOVERY                   │ File and Directory Discovery [T1083]           │\n└─────────────────────────────┴────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ CRYPTOGRAPHY         │ Generate Pseudo-random Sequence::Use API [C0021.003]  │\n│ DISCOVERY            │ Analysis Tool Discovery::Process detection            │\n│                      │ [B0013.001]                                           │\n│                      │ File and Directory Discovery [E1083]                  │\n│ FILE SYSTEM          │ Create Directory [C0046]                              │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                             ┃ Namespace                           ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ reference analysis tools strings       │ anti-analysis                       │\n│ generate random numbers in .NET (9     │ data-manipulation/prng              │\n│ matches)                               │                                     │\n│ access .NET resource                   │ executable/resource                 │\n│ get common file path                   │ host-interaction/file-system        │\n│ create directory                       │ host-interaction/file-system/create │\n│ check if directory exists              │ host-interaction/file-system/exists │\n│ check if file exists                   │ host-interaction/file-system/exists │\n│ invoke .NET assembly method (2         │ load-code/dotnet                    │\n│ matches)                               │                                     │\n│ load .NET assembly                     │ load-code/dotnet                    │\n│ compiled to the .NET platform          │ runtime/dotnet                      │\n└────────────────────────────────────────┴─────────────────────────────────────┘\n\n","verbose":"md5                     be0930fc1d862072effdd01493361fb5                        \nsha1                    e421261bf9c56bc5390d1f1b5be10f4fa53ba34c                \nsha256                  e37c838dc5eaa1b302ffbd8721c6a5f52a068e8f78bbec63b19b950…\npath                    /home/apogean/projects/malware/windows/all_runs/2       \ntimestamp               2026-04-26 23:28:52.816720                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIKH7B9s/rules                                   \nfunction count          455                                                     \nlibrary function count  0                                                       \ntotal feature count     28675                                                   \n\nreference analysis tools strings\nnamespace  anti-analysis\nscope      file         \n\ngenerate random numbers in .NET (9 matches)\nnamespace  data-manipulation/prng\nscope      function              \nmatches    token(0x6000145)      \n           token(0x6000172)      \n           token(0x6000192)      \n           token(0x6000193)      \n           token(0x6000194)      \n           token(0x6000195)      \n           token(0x6000196)      \n           token(0x6000197)      \n           token(0x6000198)      \n\naccess .NET resource\nnamespace  executable/resource\nscope      function           \nmatches    token(0x60001AF)   \n\nget common file path\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x60000CB)            \n\ncreate directory\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    token(0x60000CB)                   \n\ncheck if directory exists\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x60000CB)                   \n\ncheck if file exists\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x60000CA)                   \n\ninvoke .NET assembly method (2 matches)\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x6000123)\n           token(0x6000154)\n\nload .NET assembly\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x60000EA)\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet\nscope      file          \n\n\n\n","very_verbose":"md5                     be0930fc1d862072effdd01493361fb5                        \nsha1                    e421261bf9c56bc5390d1f1b5be10f4fa53ba34c                \nsha256                  e37c838dc5eaa1b302ffbd8721c6a5f52a068e8f78bbec63b19b950…\npath                    /home/apogean/projects/malware/windows/all_runs/2       \ntimestamp               2026-04-26 23:29:01.820826                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIqYtxZp/rules                                   \nfunction count          455                                                     \nlibrary function count  0                                                       \ntotal feature count     28675                                                   \n\nreference analysis tools strings\nnamespace   anti-analysis                                                       \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \nmbc         Discovery::Analysis Tool Discovery::Process detection [B0013.001]   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /(?<!\\w)ida?(\\.exe)?$/i\n    - \"IDAT\" @ file+0x4E849, file+0x5E849, file+0x8E849, file+0xBE849, and 4 more...\n\ngenerate random numbers in .NET (9 matches)\nnamespace  data-manipulation/prng                                            \nauthor     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com     \nscope      function                                                          \nmbc        Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\nfunction @ token(0x6000145)\n  or:\n    api: System.Random::NextDouble @ token(0x6000145)+0x34, token(0x6000145)+0x1C5\nfunction @ token(0x6000172)\n  or:\n    api: System.Random::Next @ token(0x6000172)+0x2B6\nfunction @ token(0x6000192)\n  or:\n    api: System.Random::Next @ token(0x6000192)+0x6\nfunction @ token(0x6000193)\n  or:\n    api: System.Random::Next @ token(0x6000193)+0x6\nfunction @ token(0x6000194)\n  or:\n    api: System.Random::Next @ token(0x6000194)+0x6\nfunction @ token(0x6000195)\n  or:\n    api: System.Random::Next @ token(0x6000195)+0x6\nfunction @ token(0x6000196)\n  or:\n    api: System.Random::Next @ token(0x6000196)+0x6\nfunction @ token(0x6000197)\n  or:\n    api: System.Random::Next @ token(0x6000197)+0x6\nfunction @ token(0x6000198)\n  or:\n    api: System.Random::Next @ token(0x6000198)+0x6\n\naccess .NET resource\nnamespace  executable/resource\nauthor     @mr-tz             \nscope      function           \nfunction @ token(0x60001AF)\n  and:\n    format: dotnet\n    or:\n      api: System.Resources.ResourceManager::ctor @ token(0x60001AF)+0x4C\n\nget common file path\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ token(0x60000CB)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x60000CB)+0x26\n\ncreate directory\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ token(0x60000CB)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60000CB)+0x18\n\ncheck if directory exists\nnamespace  host-interaction/file-system/exists            \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nfunction @ token(0x60000CB)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60000CB)+0x7\n\ncheck if file exists\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ token(0x60000CA)\n  or:\n    api: System.IO.File::Exists @ token(0x60000CA)+0x37\n\n(internal) .NET file limitation\nnamespace    internal/limitation/dynamic                        \nauthor       @v1bh475u                                          \nscope        file                                               \ndescription  This dynamic analysis trace describes a .NET file. \n                                                                \n             capa rules are not yet tuned for the .NET runtime, \n             so its analysis may be incomplete or misleading.   \n                                                                \nor:\n  format: dotnet\n\ninvoke .NET assembly method (2 matches)\nnamespace  load-code/dotnet                                     \nauthor     anushka.virgaonkar@mandiant.com, mehunhoff@google.com\nscope      function                                             \natt&ck     Defense Evasion::Reflective Code Loading [T1620]     \nfunction @ token(0x6000123)\n  and:\n    format: dotnet\n    or:\n      api: System.Reflection.MethodBase::Invoke @ token(0x6000123)+0x1A\nfunction @ token(0x6000154)\n  and:\n    format: dotnet\n    or:\n      api: System.Type::InvokeMember @ token(0x6000154)+0x9E\n\nload .NET assembly\nnamespace  load-code/dotnet                                \nauthor     anushka.virgaonkar@mandiant.com                 \nscope      function                                        \natt&ck     Defense Evasion::Reflective Code Loading [T1620]\nfunction @ token(0x60000EA)\n  or:\n    api: System.AppDomain::Load @ token(0x60000EA)+0x52E\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  format: dotnet\n\n\n\n"},"hashes":{"md5":"be0930fc1d862072effdd01493361fb5","sha1":"e421261bf9c56bc5390d1f1b5be10f4fa53ba34c","sha256":"e37c838dc5eaa1b302ffbd8721c6a5f52a068e8f78bbec63b19b950462fe6cf8"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 455</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 28675</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"2\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"be0930fc1d862072effdd01493361fb5\",\n        \"sha256\": \"e37c838dc5eaa1b302ffbd8721c6a5f52a068e8f78bbec63b19b950\",\n        \"arch\": \"i386\",\n        \"os\": \"any\",\n        \"format\": \"dotnet\"\n      }\n    },\n    {\n      \"id\": \"cap_reference_analysis_tools_strings\",\n      \"label\": \"reference analysis tools strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_in__net__9_matches_\",\n      \"label\": \"generate random numbers in .NET (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_System\",\n      \"label\": \"System\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_access__net_resource\",\n      \"label\": \"access .NET resource\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz\",\n      \"label\": \"author     @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path\",\n      \"label\": \"get common file path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory\",\n      \"label\": \"create directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_directory_exists\",\n      \"label\": \"check if directory exists\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_file_exists\",\n      \"label\": \"check if file exists\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal___net_file_limitation\",\n      \"label\": \"(internal) .NET file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author________v1bh475u\",\n      \"label\": \"author       @v1bh475u\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_invoke__net_assembly_method__2_matches_\",\n      \"label\": \"invoke .NET assembly method (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_load__net_assembly\",\n      \"label\": \"load .NET assembly\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_compiled_to_the__net_platform\",\n      \"label\": \"compiled to the .NET platform\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_analysis_tools_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_in__net__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access__net_resource\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_directory_exists\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal___net_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________v1bh475u\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_invoke__net_assembly_method__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_load__net_assembly\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_to_the__net_platform\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-04-26 23:29:01.820826\",\n    \"total_functions\": \"455\",\n    \"total_features\": \"28675\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-04-26 23:29:02"}
{"_id":{"$oid":"69e917b359a6632dae07de10"},"md5":"9a5ff998dbf0f6923d0b454d89800fb4","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_zt2bevqd/360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f1585432b28f.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_zt2bevqd/360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f1585432b28f.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_zt2bevqd/360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f1585432b28f.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 9a5ff998dbf0f6923d0b454d89800fb4                                  │\n│ sha1     │ 4f4fa23e9c503b941a5e91584d6ecc3813962ba1                          │\n│ sha256   │ 360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f1585432b28f  │\n│ analysis │ static                                                            │\n│ os       │ any                                                               │\n│ format   │ dotnet                                                            │\n│ arch     │ any                                                               │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/360e6f2288b6c836… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Clipboard Data [T1115]                                │\n│                      │ Data from Information Repositories [T1213]            │\n│                      │ Input Capture::Keylogging [T1056.001]                 │\n│                      │ Screen Capture [T1113]                                │\n│ CREDENTIAL ACCESS    │ Credentials from Password Stores::Credentials from    │\n│                      │ Web Browsers [T1555.003]                              │\n│ DEFENSE EVASION      │ Deobfuscate/Decode Files or Information [T1140]       │\n│                      │ File and Directory Permissions Modification [T1222]   │\n│                      │ Hide Artifacts [T1564]                                │\n│                      │ Hide Artifacts::Hidden Window [T1564.003]             │\n│                      │ Impair Defenses::Disable or Modify Tools [T1562.001]  │\n│                      │ Indicator Removal::File Deletion [T1070.004]          │\n│                      │ Modify Registry [T1112]                               │\n│                      │ Obfuscated Files or Information [T1027]               │\n│                      │ Obfuscated Files or Information::Compile After        │\n│                      │ Delivery [T1027.004]                                  │\n│                      │ Reflective Code Loading [T1620]                       │\n│ DISCOVERY            │ Account Discovery [T1087]                             │\n│                      │ Application Window Discovery [T1010]                  │\n│                      │ File and Directory Discovery [T1083]                  │\n│                      │ Process Discovery [T1057]                             │\n│                      │ Query Registry [T1012]                                │\n│                      │ Software Discovery [T1518]                            │\n│                      │ System Information Discovery [T1082]                  │\n│                      │ System Location Discovery [T1614]                     │\n│                      │ System Network Configuration Discovery [T1016]        │\n│                      │ System Owner/User Discovery [T1033]                   │\n│ EXECUTION            │ Windows Management Instrumentation [T1047]            │\n│ IMPACT               │ Resource Hijacking [T1496]                            │\n│ PERSISTENCE          │ Boot or Logon Autostart Execution::Registry Run Keys  │\n│                      │ / Startup Folder [T1547.001]                          │\n│                      │ Event Triggered Execution::Change Default File        │\n│                      │ Association [T1546.001]                               │\n│                      │ Scheduled Task/Job::Scheduled Task [T1053.005]        │\n│ PRIVILEGE ESCALATION │ Access Token Manipulation [T1134]                     │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MAEC Category                                    ┃ MAEC Value                ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ malware-category                                 │ launcher                  │\n└──────────────────────────────────────────────────┴───────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Keylogging::Application Hook [F0002.001]              │\n│                      │ Keylogging::Polling [F0002.002]                       │\n│                      │ Screen Capture::WinAPI [E1113.m01]                    │\n│ COMMAND AND CONTROL  │ C2 Communication::Receive Data [B0030.002]            │\n│                      │ C2 Communication::Send Data [B0030.001]               │\n│ COMMUNICATION        │ HTTP Communication [C0002]                            │\n│                      │ HTTP Communication::Create Request [C0002.012]        │\n│                      │ HTTP Communication::Get Response [C0002.017]          │\n│                      │ HTTP Communication::Read Header [C0002.014]           │\n│                      │ HTTP Communication::Send Request [C0002.003]          │\n│                      │ Socket Communication::Create TCP Socket [C0001.011]   │\n│                      │ Socket Communication::TCP Client [C0001.008]          │\n│ CRYPTOGRAPHY         │ Decrypt Data [C0031]                                  │\n│                      │ Encrypt Data [C0027]                                  │\n│                      │ Generate Pseudo-random Sequence::Use API [C0021.003]  │\n│ DATA                 │ Check String [C0019]                                  │\n│                      │ Decode Data::Base64 [C0053.001]                       │\n│                      │ Encode Data::Base64 [C0026.001]                       │\n│ DEFENSE EVASION      │ Disable or Evade Security Tools [F0004]               │\n│                      │ Self Deletion::COMSPEC Environment Variable           │\n│                      │ [F0007.001]                                           │\n│ DISCOVERY            │ File and Directory Discovery [E1083]                  │\n│                      │ System Information Discovery [E1082]                  │\n│                      │ Taskbar Discovery [B0043]                             │\n│ FILE SYSTEM          │ Copy File [C0045]                                     │\n│                      │ Create Directory [C0046]                              │\n│                      │ Delete Directory [C0048]                              │\n│                      │ Delete File [C0047]                                   │\n│                      │ Get File Attributes [C0049]                           │\n│                      │ Move File [C0063]                                     │\n│                      │ Read File [C0051]                                     │\n│                      │ Set File Attributes [C0050]                           │\n│                      │ Writes File [C0052]                                   │\n│ OPERATING SYSTEM     │ Console [C0033]                                       │\n│                      │ Registry::Delete Registry Key [C0036.002]             │\n│                      │ Registry::Delete Registry Value [C0036.007]           │\n│                      │ Registry::Query Registry Key [C0036.005]              │\n│                      │ Registry::Query Registry Value [C0036.006]            │\n│                      │ Registry::Set Registry Key [C0036.001]                │\n│                      │ Wallpaper [C0035]                                     │\n│ PERSISTENCE          │ Registry Run Keys / Startup Folder [F0012]            │\n│ PROCESS              │ Create Mutex [C0042]                                  │\n│                      │ Create Process [C0017]                                │\n│                      │ Create Thread [C0038]                                 │\n│                      │ Suspend Thread [C0055]                                │\n│                      │ Terminate Process [C0018]                             │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ self delete (3 matches)               │ anti-analysis/anti-forensic/self-de… │\n│ get geographical location             │ collection                           │\n│ save image in .NET                    │ collection                           │\n│ gather firefox profile information    │ collection/browser                   │\n│ reference SQL statements (2 matches)  │ collection/database/sql              │\n│ reference WMI statements              │ collection/database/wmi              │\n│ log keystrokes (2 matches)            │ collection/keylog                    │\n│ log keystrokes via application hook   │ collection/keylog                    │\n│ log keystrokes via polling (2         │ collection/keylog                    │\n│ matches)                              │                                      │\n│ get MAC address in .NET               │ collection/network                   │\n│ capture screenshot                    │ collection/screenshot                │\n│ receive data                          │ communication                        │\n│ send data                             │ communication                        │\n│ manipulate network credentials in     │ communication/authentication         │\n│ .NET                                  │                                      │\n│ read HTTP header                      │ communication/http                   │\n│ reference HTTP User-Agent string      │ communication/http                   │\n│ create HTTP request                   │ communication/http/client            │\n│ receive HTTP response                 │ communication/http/client            │\n│ create TCP socket (3 matches)         │ communication/socket/tcp             │\n│ act as TCP client                     │ communication/tcp/client             │\n│ create zip archive in .NET (3         │ data-manipulation/compression        │\n│ matches)                              │                                      │\n│ decode data using Base64 in .NET      │ data-manipulation/encoding/base64    │\n│ decode data using Base64 via WinAPI   │ data-manipulation/encoding/base64    │\n│ reference Base64 string               │ data-manipulation/encoding/base64    │\n│ encrypt or decrypt data via BCrypt (2 │ data-manipulation/encryption         │\n│ matches)                              │                                      │\n│ encrypt data using DPAPI              │ data-manipulation/encryption/dpapi   │\n│ generate random numbers in .NET       │ data-manipulation/prng               │\n│ contains PDB path                     │ executable/pe/pdb                    │\n│ extract resource via kernel32         │ executable/resource                  │\n│ functions                             │                                      │\n│ check clipboard data (2 matches)      │ host-interaction/clipboard           │\n│ monitor clipboard content             │ host-interaction/clipboard           │\n│ read clipboard data (2 matches)       │ host-interaction/clipboard           │\n│ manipulate console buffer (8 matches) │ host-interaction/console             │\n│ query environment variable (3         │ host-interaction/environment-variab… │\n│ matches)                              │                                      │\n│ enumerate drives                      │ host-interaction/file-system         │\n│ get common file path (7 matches)      │ host-interaction/file-system         │\n│ copy file (7 matches)                 │ host-interaction/file-system/copy    │\n│ create directory (8 matches)          │ host-interaction/file-system/create  │\n│ delete directory (2 matches)          │ host-interaction/file-system/delete  │\n│ delete file (12 matches)              │ host-interaction/file-system/delete  │\n│ check if directory exists (15         │ host-interaction/file-system/exists  │\n│ matches)                              │                                      │\n│ check if file exists (22 matches)     │ host-interaction/file-system/exists  │\n│ enumerate files in .NET (6 matches)   │ host-interaction/file-system/files/… │\n│ get file attributes                   │ host-interaction/file-system/meta    │\n│ get file size (5 matches)             │ host-interaction/file-system/meta    │\n│ set file attributes (2 matches)       │ host-interaction/file-system/meta    │\n│ move file (2 matches)                 │ host-interaction/file-system/move    │\n│ read file on Windows (7 matches)      │ host-interaction/file-system/read    │\n│ write file on Windows (11 matches)    │ host-interaction/file-system/write   │\n│ enumerate gui resources (2 matches)   │ host-interaction/gui                 │\n│ change the wallpaper                  │ host-interaction/gui/session         │\n│ hide the Windows taskbar              │ host-interaction/gui/taskbar/hide    │\n│ get disk information                  │ host-interaction/hardware/storage    │\n│ get disk size                         │ host-interaction/hardware/storage    │\n│ allocate unmanaged memory in .NET (3  │ host-interaction/memory              │\n│ matches)                              │                                      │\n│ manipulate unmanaged memory in .NET   │ host-interaction/memory              │\n│ (14 matches)                          │                                      │\n│ create or open mutex on Windows       │ host-interaction/mutex               │\n│ get networking interfaces             │ host-interaction/network/interface   │\n│ get hostname (2 matches)              │ host-interaction/os/hostname         │\n│ get OS version in .NET                │ host-interaction/os/version          │\n│ get process image filename (5         │ host-interaction/process             │\n│ matches)                              │                                      │\n│ create a process with modified I/O    │ host-interaction/process/create      │\n│ handles and window (14 matches)       │                                      │\n│ create process on Windows (22         │ host-interaction/process/create      │\n│ matches)                              │                                      │\n│ enumerate processes (2 matches)       │ host-interaction/process/list        │\n│ find process by PID (2 matches)       │ host-interaction/process/list        │\n│ find process by name                  │ host-interaction/process/list        │\n│ acquire debug privileges              │ host-interaction/process/modify      │\n│ terminate process (14 matches)        │ host-interaction/process/terminate   │\n│ query or enumerate registry key (7    │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ query or enumerate registry value (2  │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ delete registry key                   │ host-interaction/registry/delete     │\n│ delete registry value (2 matches)     │ host-interaction/registry/delete     │\n│ get session integrity level (3        │ host-interaction/session             │\n│ matches)                              │                                      │\n│ get session user name (5 matches)     │ host-interaction/session             │\n│ create thread (3 matches)             │ host-interaction/thread/create       │\n│ suspend thread (9 matches)            │ host-interaction/thread/suspend      │\n│ access WMI data in .NET               │ host-interaction/wmi                 │\n│ reference cryptocurrency strings      │ impact/cryptocurrency                │\n│ disable system features via registry  │ impact/features                      │\n│ on Windows                            │                                      │\n│ invoke .NET assembly method (2        │ load-code/dotnet                     │\n│ matches)                              │                                      │\n│ load .NET assembly                    │ load-code/dotnet                     │\n│ compile CSharp in .NET                │ load-code/dotnet/csharp              │\n│ persist via default file association  │ persistence/registry                 │\n│ registry key (2 matches)              │                                      │\n│ persist via Run registry key          │ persistence/registry/run             │\n│ schedule task via schtasks (2         │ persistence/scheduled-tasks          │\n│ matches)                              │                                      │\n│ unmanaged call (42 matches)           │ runtime                              │\n│ compiled to the .NET platform         │ runtime/dotnet                       │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     9a5ff998dbf0f6923d0b454d89800fb4                        \nsha1                    4f4fa23e9c503b941a5e91584d6ecc3813962ba1                \nsha256                  360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f15…\npath                    /home/apogean/projects/malware/windows/all_runs/360e6f2…\ntimestamp               2026-04-23 00:40:14.063332                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    any                                                     \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEI7sgq78/rules                                   \nfunction count          574                                                     \nlibrary function count  0                                                       \ntotal feature count     18525                                                   \n\nself delete (3 matches)\nnamespace  anti-analysis/anti-forensic/self-deletion\nscope      function                                 \nmatches    token(0x6000039)                         \n           token(0x600003E)                         \n           token(0x600003E)                         \n\nget geographical location\nnamespace  collection      \nscope      function        \nmatches    token(0x600004C)\n\nsave image in .NET\nnamespace  collection      \nscope      function        \nmatches    token(0x6000054)\n\ngather firefox profile information\nnamespace  collection/browser\nscope      function          \nmatches    token(0x60001CC)  \n\nreference SQL statements (2 matches)\nnamespace  collection/database/sql\nscope      function               \nmatches    token(0x6000147)       \n           token(0x600015B)       \n\nreference WMI statements\nnamespace  collection/database/wmi\nscope      function               \nmatches    token(0x600004B)       \n\nlog keystrokes (2 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    token(0x600017A) \n           token(0x600017B) \n\nlog keystrokes via application hook\nnamespace  collection/keylog\nscope      basic block      \nmatches    token(0x60000A7) \n\nlog keystrokes via polling (2 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    token(0x60000AA) \n           token(0x600017C) \n\nget MAC address in .NET\nnamespace  collection/network\nscope      function          \nmatches    token(0x600011C)  \n\ncapture screenshot\nnamespace  collection/screenshot\nscope      function             \nmatches    token(0x6000054)     \n\nreceive data\nnamespace    communication                                                     \ndescription  all known techniques for receiving data from a potential C2 server\nscope        function                                                          \nmatches      token(0x600004C)                                                  \n\nsend data\nnamespace    communication                                                 \ndescription  all known techniques for sending data to a potential C2 server\nscope        function                                                      \nmatches      token(0x60001BF)                                              \n\nmanipulate network credentials in .NET\nnamespace  communication/authentication\nscope      function                    \nmatches    token(0x60001BF)            \n\nread HTTP header\nnamespace  communication/http\nscope      function          \nmatches    token(0x600004C)  \n\nreference HTTP User-Agent string\nnamespace  communication/http\nscope      function          \nmatches    token(0x600004C)  \n\ncreate HTTP request\nnamespace  communication/http/client\nscope      function                 \nmatches    token(0x60001BF)         \n\nread data from Internet\nnamespace  communication/http/client\nscope      function                 \nmatches    token(0x600004C)         \n\nreceive HTTP response\nnamespace  communication/http/client\nscope      function                 \nmatches    token(0x60001BF)         \n\nsend HTTP request\nnamespace  communication/http/client\nscope      function                 \nmatches    token(0x60001BF)         \n\ncreate TCP socket (3 matches)\nnamespace  communication/socket/tcp\nscope      basic block             \nmatches    token(0x600000C)        \n           token(0x600000E)        \n           token(0x6000014)        \n\nact as TCP client\nnamespace  communication/tcp/client\nscope      function                \nmatches    token(0x600000E)        \n\ncreate zip archive in .NET (3 matches)\nnamespace  data-manipulation/compression\nscope      basic block                  \nmatches    token(0x60000B8)             \n           token(0x60000BB)             \n           token(0x60001BC)             \n\ndecode data using Base64 in .NET\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    token(0x60001B5)                 \n\ndecode data using Base64 via WinAPI\nnamespace  data-manipulation/encoding/base64\nscope      basic block                      \nmatches    token(0x60001B5)                 \n\nreference Base64 string\nnamespace  data-manipulation/encoding/base64\nscope      file                             \n\nencrypt or decrypt data via BCrypt (2 matches)\nnamespace  data-manipulation/encryption\nscope      function                    \nmatches    token(0x60001AD)            \n           token(0x60001B0)            \n\nencrypt data using DPAPI\nnamespace  data-manipulation/encryption/dpapi\nscope      function                          \nmatches    token(0x60001AF)                  \n\ngenerate random numbers in .NET\nnamespace  data-manipulation/prng\nscope      function              \nmatches    token(0x600003E)      \n\ncontains PDB path\nnamespace  executable/pe/pdb\nscope      file             \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    token(0x60000E5)   \n\ncheck clipboard data (2 matches)\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    token(0x60000EE)          \n           token(0x600024C)          \n\nmonitor clipboard content\nnamespace  host-interaction/clipboard\nscope      basic block               \nmatches    token(0x60000F4)          \n\nread clipboard data (2 matches)\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    token(0x60000EE)          \n           token(0x600024C)          \n\nmanipulate console buffer (8 matches)\nnamespace  host-interaction/console\nscope      function                \nmatches    token(0x6000019)        \n           token(0x6000029)        \n           token(0x6000033)        \n           token(0x6000044)        \n           token(0x600014A)        \n           token(0x600015E)        \n           token(0x6000181)        \n           token(0x6000182)        \n\nquery environment variable (3 matches)\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    token(0x6000095)                     \n           token(0x60001A1)                     \n           token(0x60001AB)                     \n\nenumerate drives\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x6000093)            \n\nget common file path (7 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x600004E)            \n           token(0x60000B7)            \n           token(0x60000F8)            \n           token(0x60000FA)            \n           token(0x6000146)            \n           token(0x6000149)            \n           token(0x600015D)            \n\ncopy file (7 matches)\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    token(0x60000BC)                 \n           token(0x6000144)                 \n           token(0x6000159)                 \n           token(0x60001A5)                 \n           token(0x60001A6)                 \n           token(0x60001AB)                 \n           token(0x60001BF)                 \n\ncreate directory (8 matches)\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    token(0x6000097)                   \n           token(0x6000098)                   \n           token(0x60000B8)                   \n           token(0x60000BB)                   \n           token(0x60000BC)                   \n           token(0x6000144)                   \n           token(0x6000159)                   \n           token(0x60001A0)                   \n\ndelete directory (2 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    token(0x60000B8)                   \n           token(0x60000BB)                   \n\ndelete file (12 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    token(0x60000B8)                   \n           token(0x60000BB)                   \n           token(0x6000144)                   \n           token(0x6000147)                   \n           token(0x6000159)                   \n           token(0x600015B)                   \n           token(0x60001A8)                   \n           token(0x60001A9)                   \n           token(0x60001AA)                   \n           token(0x60001AB)                   \n           token(0x60001BC)                   \n           token(0x60001BF)                   \n\ncheck if directory exists (15 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x600004E)                   \n           token(0x6000095)                   \n           token(0x6000097)                   \n           token(0x6000098)                   \n           token(0x60000B7)                   \n           token(0x60000B8)                   \n           token(0x60000BC)                   \n           token(0x6000144)                   \n           token(0x6000149)                   \n           token(0x6000159)                   \n           token(0x600015D)                   \n           token(0x60001A7)                   \n           token(0x60001A9)                   \n           token(0x60001AB)                   \n           token(0x600021B)                   \n\ncheck if file exists (22 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x6000095)                   \n           token(0x6000096)                   \n           token(0x60000D6)                   \n           token(0x60000D7)                   \n           token(0x60000F8)                   \n           token(0x60000FA)                   \n           token(0x6000144)                   \n           token(0x6000146)                   \n           token(0x6000149)                   \n           token(0x6000159)                   \n           token(0x600015D)                   \n           token(0x60001A6)                   \n           token(0x60001A7)                   \n           token(0x60001A8)                   \n           token(0x60001A9)                   \n           token(0x60001AA)                   \n           token(0x60001AB)                   \n           token(0x60001BC)                   \n           token(0x60001BD)                   \n           token(0x60001BF)                   \n           token(0x600026B)                   \n           token(0x600026F)                   \n\nenumerate files in .NET (6 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    token(0x60000BC)                       \n           token(0x6000149)                       \n           token(0x600015D)                       \n           token(0x60001A7)                       \n           token(0x60001A9)                       \n           token(0x60001AB)                       \n\nget file attributes\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    token(0x6000095)                 \n\nget file size (5 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    token(0x6000095)                 \n           token(0x60001A5)                 \n           token(0x60001A8)                 \n           token(0x60001AA)                 \n           token(0x600026B)                 \n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    token(0x600003C)                 \n           token(0x60001BF)                 \n\nmove file (2 matches)\nnamespace  host-interaction/file-system/move\nscope      function                         \nmatches    token(0x6000144)                 \n           token(0x6000159)                 \n\nread file on Windows (7 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    token(0x6000096)                 \n           token(0x60000B8)                 \n           token(0x60000BB)                 \n           token(0x60001A5)                 \n           token(0x60001AC)                 \n           token(0x60001AD)                 \n           token(0x60001BD)                 \n\nwrite file on Windows (11 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    token(0x6000019)                  \n           token(0x6000044)                  \n           token(0x6000097)                  \n           token(0x60000BB)                  \n           token(0x60000DD)                  \n           token(0x6000147)                  \n           token(0x600014A)                  \n           token(0x600015B)                  \n           token(0x600015E)                  \n           token(0x60001A5)                  \n           token(0x60001E8)                  \n\nenumerate gui resources (2 matches)\nnamespace  host-interaction/gui\nscope      function            \nmatches    token(0x600004D)    \n           token(0x6000054)    \n\nset application hook (2 matches)\nnamespace  host-interaction/gui \nscope      instruction          \nmatches    token(0x60000A7)+0x1C\n           token(0x60000AF)+0x66\n\nchange the wallpaper\nnamespace  host-interaction/gui/session\nscope      basic block                 \nmatches    token(0x60000D7)            \n\nfind taskbar (3 matches)\nnamespace  host-interaction/gui/taskbar/find\nscope      basic block                      \nmatches    token(0x60000C2)                 \n           token(0x60000C3)                 \n           token(0x60000C9)                 \n\nhide the Windows taskbar\nnamespace  host-interaction/gui/taskbar/hide\nscope      function                         \nmatches    token(0x60000C2)                 \n\nfind graphical window (3 matches)\nnamespace  host-interaction/gui/window/find\nscope      instruction                     \nmatches    token(0x60000C2)+0xA            \n           token(0x60000C3)+0xA            \n           token(0x60000C9)+0xA            \n\nhide graphical window\nnamespace  host-interaction/gui/window/hide\nscope      basic block                     \nmatches    token(0x60000C2)                \n\nget disk information\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    token(0x6000093)                 \n\nget disk size\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    token(0x6000093)                 \n\nallocate unmanaged memory in .NET (3 matches)\nnamespace  host-interaction/memory\nscope      function               \nmatches    token(0x60001AD)       \n           token(0x60001AF)       \n           token(0x60001B0)       \n\nmanipulate unmanaged memory in .NET (14 matches)\nnamespace  host-interaction/memory\nscope      function               \nmatches    token(0x6000055)       \n           token(0x60000A8)       \n           token(0x60000C7)       \n           token(0x60000C8)       \n           token(0x60000D7)       \n           token(0x60000E5)       \n           token(0x60001A5)       \n           token(0x60001AD)       \n           token(0x60001AF)       \n           token(0x60001B0)       \n           token(0x60001BB)       \n           token(0x60001CA)       \n           token(0x60001CB)       \n           token(0x60001CC)       \n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex\nscope      instruction           \nmatches    token(0x6000033)+0x211\n\nget networking interfaces\nnamespace  host-interaction/network/interface\nscope      function                          \nmatches    token(0x600011C)                  \n\nget hostname (2 matches)\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    token(0x6000049)            \n           token(0x60001A0)            \n\nget OS version in .NET\nnamespace  host-interaction/os/version\nscope      basic block                \nmatches    token(0x600004B)           \n\nget process image filename (5 matches)\nnamespace  host-interaction/process\nscope      basic block             \nmatches    token(0x6000033)        \n           token(0x600003A)        \n           token(0x600003C)        \n           token(0x600003E)        \n           token(0x60001E8)        \n\ncreate a process with modified I/O handles and window (14 matches)\nnamespace  host-interaction/process/create\nscope      function                       \nmatches    token(0x6000033)               \n           token(0x600003A)               \n           token(0x600003B)               \n           token(0x600003E)               \n           token(0x60000F7)               \n           token(0x600011D)               \n           token(0x600011E)               \n           token(0x6000144)               \n           token(0x6000147)               \n           token(0x6000148)               \n           token(0x6000159)               \n           token(0x600015B)               \n           token(0x600015C)               \n           token(0x60001E8)               \n\ncreate process on Windows (22 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    token(0x6000033)               \n           token(0x6000039)               \n           token(0x600003A)               \n           token(0x600003B)               \n           token(0x600003E)               \n           token(0x6000099)               \n           token(0x60000D5)               \n           token(0x60000D8)               \n           token(0x60000DB)               \n           token(0x60000DC)               \n           token(0x60000DD)               \n           token(0x60000F7)               \n           token(0x600011D)               \n           token(0x600011E)               \n           token(0x6000144)               \n           token(0x6000147)               \n           token(0x6000148)               \n           token(0x6000159)               \n           token(0x600015B)               \n           token(0x600015C)               \n           token(0x60001E8)               \n           token(0x6000207)               \n\nenumerate processes (2 matches)\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    token(0x6000060)             \n           token(0x60000D9)             \n\nfind process by PID (2 matches)\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    token(0x6000061)             \n           token(0x6000062)             \n\nfind process by name\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    token(0x60001BB)             \n\nacquire debug privileges\nnamespace  host-interaction/process/modify\nscope      basic block                    \nmatches    token(0x60001BA)               \n\nmodify access privileges\nnamespace  host-interaction/process/modify\nscope      instruction                    \nmatches    token(0x60001BA)+0x59          \n\nterminate process (14 matches)\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    token(0x600003A)                  \n           token(0x600003B)                  \n           token(0x6000061)                  \n           token(0x60000F7)                  \n           token(0x600011D)                  \n           token(0x600011E)                  \n           token(0x6000144)                  \n           token(0x6000147)                  \n           token(0x6000148)                  \n           token(0x6000159)                  \n           token(0x600015B)                  \n           token(0x600015C)                  \n           token(0x60001E7)                  \n           token(0x60001E8)                  \n\nquery or enumerate registry key (7 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    token(0x6000039)         \n           token(0x600006F)         \n           token(0x6000071)         \n           token(0x60000F9)         \n           token(0x6000255)         \n           token(0x6000257)         \n           token(0x6000259)         \n\nquery or enumerate registry value (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    token(0x600006F)         \n           token(0x6000255)         \n\nset registry value (5 matches)\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    token(0x6000039)                \n           token(0x600003E)                \n           token(0x600003E)                \n           token(0x6000070)                \n           token(0x6000257)                \n\ndelete registry key\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    token(0x600003E)                \n\ndelete registry value (2 matches)\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    token(0x6000071)                \n           token(0x6000259)                \n\nget session integrity level (3 matches)\nnamespace  host-interaction/session\nscope      function                \nmatches    token(0x600003D)        \n           token(0x600007A)        \n           token(0x60001B9)        \n\nget session user name (5 matches)\nnamespace  host-interaction/session\nscope      function                \nmatches    token(0x600003D)        \n           token(0x600004A)        \n           token(0x600007A)        \n           token(0x6000149)        \n           token(0x60001B9)        \n\ncreate thread (3 matches)\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    token(0x60000A4)              \n           token(0x60000C4)              \n           token(0x60000EC)              \n\nsuspend thread (9 matches)\nnamespace  host-interaction/thread/suspend\nscope      basic block                    \nmatches    token(0x6000010)               \n           token(0x6000011)               \n           token(0x6000033)               \n           token(0x6000035)               \n           token(0x6000037)               \n           token(0x600003E)               \n           token(0x60000DA)               \n           token(0x60001E7)               \n           token(0x6000207)               \n\naccess WMI data in .NET\nnamespace  host-interaction/wmi\nscope      function            \nmatches    token(0x600004B)    \n\nreference cryptocurrency strings\nnamespace  impact/cryptocurrency\nscope      file                 \n\ndisable system features via registry on Windows\nnamespace  impact/features \nscope      function        \nmatches    token(0x6000039)\n\ncompile .NET assembly\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x600027A)\n\ninvoke .NET assembly method (2 matches)\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x6000146)\n           token(0x600027A)\n\nload .NET assembly\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x6000146)\n\ncompile CSharp in .NET\nnamespace  load-code/dotnet/csharp\nscope      function               \nmatches    token(0x600027A)       \n\npersist via default file association registry key (2 matches)\nnamespace  persistence/registry\nscope      function            \nmatches    token(0x600003E)    \n           token(0x600003E)    \n\npersist via Run registry key\nnamespace  persistence/registry/run\nscope      function                \nmatches    token(0x6000070)        \n\nschedule task via schtasks (2 matches)\nnamespace  persistence/scheduled-tasks\nscope      function                   \nmatches    token(0x600003A)           \n           token(0x600003A)           \n\nunmanaged call (42 matches)\nnamespace    runtime                                                       \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nscope        function                                                      \nmatches      token(0x6000055)                                              \n             token(0x6000063)                                              \n             token(0x60000A5)                                              \n             token(0x60000A7)                                              \n             token(0x60000A8)                                              \n             token(0x60000AA)                                              \n             token(0x60000AF)                                              \n             token(0x60000C2)                                              \n             token(0x60000C3)                                              \n             token(0x60000C7)                                              \n             token(0x60000C8)                                              \n             token(0x60000C9)                                              \n             token(0x60000CA)                                              \n             token(0x60000CB)                                              \n             token(0x60000D2)                                              \n             token(0x60000D3)                                              \n             token(0x60000D4)                                              \n             token(0x60000D6)                                              \n             token(0x60000D7)                                              \n             token(0x60000DA)                                              \n             token(0x60000E5)                                              \n             token(0x60000ED)                                              \n             token(0x60000F4)                                              \n             token(0x6000176)                                              \n             token(0x6000177)                                              \n             token(0x6000178)                                              \n             token(0x6000179)                                              \n             token(0x600017A)                                              \n             token(0x600017B)                                              \n             token(0x600017C)                                              \n             token(0x60001A0)                                              \n             token(0x60001A5)                                              \n             token(0x60001AD)                                              \n             token(0x60001AF)                                              \n             token(0x60001B0)                                              \n             token(0x60001B5)                                              \n             token(0x60001B7)                                              \n             token(0x60001BA)                                              \n             token(0x60001BB)                                              \n             token(0x60001CA)                                              \n             token(0x60001CB)                                              \n             token(0x60001CC)                                              \n\ncompiled to the .NET platform\nnamespace  runtime/dotnet\nscope      file          \n\n\n\n","very_verbose":"md5                     9a5ff998dbf0f6923d0b454d89800fb4                        \nsha1                    4f4fa23e9c503b941a5e91584d6ecc3813962ba1                \nsha256                  360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f15…\npath                    /home/apogean/projects/malware/windows/all_runs/360e6f2…\ntimestamp               2026-04-23 00:40:18.704360                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    any                                                     \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIqmmSAd/rules                                   \nfunction count          574                                                     \nlibrary function count  0                                                       \ntotal feature count     18525                                                   \n\ncontain loop (library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ token(0x60000BC)\n  or:\n    characteristic: recursive call @ token(0x60000BC)\n\ncreate or open file (library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ token(0x60001A5)+0x48\n  or:\n    api: CreateFile @ token(0x60001A5)+0x48\n\ncreate or open registry key (9 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ token(0x6000039) in function token(0x6000039)\n  or:\n    api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000039)+0x1FE8\n\nopen process (library rule)\nauthor  0x534a@mailbox.org           \nscope   basic block                  \nmbc     Process::Open Process [C0065]\nbasic block @ token(0x60001BB) in function token(0x60001BB)\n  or:\n    api: OpenProcess @ token(0x60001BB)+0x59, token(0x60001BB)+0x90\n\nopen thread (library rule)\nauthor  0x534a@mailbox.org          \nscope   basic block                 \nmbc     Process::Open Thread [C0066]\nbasic block @ token(0x6000063) in function token(0x6000063)\n  or:\n    api: OpenThread @ token(0x6000063)+0x22\n\nself delete (3 matches)\nnamespace  anti-analysis/anti-forensic/self-deletion                            \nauthor     michael.hunhoff@mandiant.com, @mr-tz                                 \nscope      function                                                             \natt&ck     Defense Evasion::Indicator Removal::File Deletion [T1070.004]        \nmbc        Defense Evasion::Self Deletion::COMSPEC Environment Variable         \n           [F0007.001]                                                          \nfunction @ token(0x6000039)\n  and:\n    or:\n      match: host-interaction/process/create @ token(0x6000039)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x6000039)+0x1DE1, token(0x6000039)+0x1FD1\n    or:\n      regex: /(^|[\\&;\\|]\\s*)del(\\s.*)?/i\n        - \"delta\" @ token(0x6000039)+0xC4B\nfunction @ token(0x600003E)\n  and:\n    or:\n      match: host-interaction/process/create @ token(0x600003E)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x600003E)+0x7B\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x600003E)+0x7B\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600003E)+0x68\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600003E)+0x6F\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600003E)+0x61\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600003E)+0x76\n    or:\n      regex: /(^|[\\&;\\|]\\s*)del(\\s.*)?/i\n        - \"DelegateExecute\" @ token(0x600003E)+0x3A\nfunction @ token(0x600003E)\n  and:\n    or:\n      match: host-interaction/process/create @ token(0x600003E)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x600003E)+0x7B\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x600003E)+0x7B\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600003E)+0x68\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600003E)+0x6F\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600003E)+0x61\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600003E)+0x76\n    or:\n      regex: /(^|[\\&;\\|]\\s*)del(\\s.*)?/i\n        - \"DelegateExecute\" @ token(0x600003E)+0x3A\n\nget geographical location\nnamespace  collection                                  \nauthor     moritz.raabe, michael.hunhoff@mandiant.com  \nscope      function                                    \natt&ck     Discovery::System Location Discovery [T1614]\nfunction @ token(0x600004C)\n  or:\n    regex: /countrycode/i\n      - \"\\\"countryCode\\\":\\\"\" @ token(0x600004C)+0x28\n      - \"http://ip-api.com/json/?fields=countryCode\" @ token(0x600004C)+0x1C\n\nsave image in .NET\nnamespace  collection                  \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x6000054)\n  and:\n    api: System.Drawing.Image::Save @ token(0x6000054)+0x1D6\n\ngather firefox profile information\nnamespace  collection/browser                                                   \nauthor     @_re_fox, still@teamt5.org                                           \nscope      function                                                             \natt&ck     Credential Access::Credentials from Password Stores::Credentials from\n           Web Browsers [T1555.003]                                             \nfunction @ token(0x60001CC)\n  and:\n    2 or more:\n      regex: /SELECT\\s+{5,}FROM moz_(logins|cookies)/i\n        - \"SELECT host, name, value, path, isSecure, expiry FROM moz_cookies\" @ token(0x60001CC)+0x38\n      regex: /FROM moz_(logins|cookies)/i\n        - \"SELECT host, name, value, path, isSecure, expiry FROM moz_cookies\" @ token(0x60001CC)+0x38\n\nreference SQL statements (2 matches)\nnamespace  collection/database/sql                               \nauthor     william.ballenthin@mandiant.com                       \nscope      function                                              \natt&ck     Collection::Data from Information Repositories [T1213]\nfunction @ token(0x6000147)\n  and:\n    regex: /SELECT.*FROM.*WHERE/\n      - \"'\\r\\n    if not os.path.exists(db_path):\\r\\n        print('ERROR:Database file \nnot found: ' + db_path)\\r\\n        sys.exit(1)\\r\\n    \\r\\n    # Check file \nsize\\r\\n    file_size = os.path.getsize(db_path)\\r\\n    if file_size == 0:\\r\\n  \nprint('ERROR:Database file is empty')\\r\\n        sys.exit(1)\\r\\n    \\r\\n    conn\n= sqlite3.connect(db_path)\\r\\n    conn.row_factory = sqlite3.Row\\r\\n    cursor =\nconn.cursor()\\r\\n    \\r\\n    # First, check if urls table exists\\r\\n    \ncursor.execute(\\\"SELECT name FROM sqlite_master WHERE type='table' AND \nname='urls'\\\")\\r\\n    table_exists = cursor.fetchone()\\r\\n    \\r\\n    if not \ntable_exists:\\r\\n        print('ERROR:urls table does not exist in \ndatabase')\\r\\n        # List available tables for debugging\\r\\n        \ncursor.execute(\\\"SELECT name FROM sqlite_master WHERE type='table'\\\")\\r\\n       \ntables = cursor.fetchall()\\r\\n        if tables:\\r\\n            table_names = ',\n'.join([t[0] for t in tables])\\r\\n            print('ERROR:Available tables: ' +\ntable_names)\\r\\n        conn.close()\\r\\n        sys.exit(1)\\r\\n    \\r\\n    # Try\nto query the urls table\\r\\n    try:\\r\\n        # Check if columns exist\\r\\n     \ncursor.execute(\\\"PRAGMA table_info(urls)\\\")\\r\\n        columns = [row[1] for row\nin cursor.fetchall()]\\r\\n        required_columns = ['url', 'title', \n'visit_count', 'last_visit_time']\\r\\n        missing_columns = \\r\\n        \\r\\n \nif missing_columns:\\r\\n            print('ERROR:Missing columns: ' + ', \n'.join(missing_columns))\\r\\n            print('ERROR:Available columns: ' + ', \n'.join(columns))\\r\\n            conn.close()\\r\\n            sys.exit(1)\\r\\n     \n\\r\\n        cursor.execute('SELECT url, title, visit_count, last_visit_time FROM\nurls ORDER BY last_visit_time DESC LIMIT 1000')\\r\\n        rows = \ncursor.fetchall()\\r\\n        \\r\\n        if len(rows) == 0:\\r\\n            \nprint('ERROR:No rows found in urls table')\\r\\n            conn.close()\\r\\n      \nsys.exit(1)\\r\\n        \\r\\n        for row in rows:\\r\\n            url = \nrow['url'] if row['url'] else ''\\r\\n            title = row['title'] if \nrow['title'] else ''\\r\\n            visit_count = int(row['visit_count']) if \nrow['visit_count'] is not None else 0\\r\\n            last_visit = \nint(row['last_visit_time']) if row['last_visit_time'] is not None else 0\\r\\n    \n# Escape pipe characters in URL/title\\r\\n            url = url.replace('|', \n'{PIPE}')\\r\\n            title = title.replace('|', '{PIPE}')\\r\\n            \nprint(f'{url}|{title}|{visit_count}|{last_visit}')\\r\\n    except \nsqlite3.OperationalError as e:\\r\\n        print(f'ERROR:SQL error: \n{str(e)}')\\r\\n        conn.close()\\r\\n        sys.exit(1)\\r\\n    except \nException as e:\\r\\n        print(f'ERROR:Query error: {str(e)}')\\r\\n        \nconn.close()\\r\\n        sys.exit(1)\\r\\n    \\r\\n    conn.close()\\r\\nexcept \nException as e:\\r\\n    print(f'ERROR:{str(e)}')\\r\\n    import traceback\\r\\n    \nprint('ERROR:Traceback: ' + traceback.format_exc())\\r\\n    sys.exit(1)\\r\\n\" @ token(0x6000147)+0x26\nfunction @ token(0x600015B)\n  and:\n    regex: /SELECT.*FROM.*WHERE/\n      - \"'\\r\\n    if not os.path.exists(db_path):\\r\\n        print('ERROR:Database file \nnot found')\\r\\n        sys.exit(1)\\r\\n    \\r\\n    conn = \nsqlite3.connect(db_path)\\r\\n    conn.row_factory = sqlite3.Row\\r\\n    cursor = \nconn.cursor()\\r\\n    \\r\\n    # Check if autofill table exists\\r\\n    \ncursor.execute(\\\"SELECT name FROM sqlite_master WHERE type='table' AND \nname='autofill'\\\")\\r\\n    if not cursor.fetchone():\\r\\n        \nprint('ERROR:autofill table does not exist')\\r\\n        conn.close()\\r\\n        \nsys.exit(1)\\r\\n    \\r\\n    # Query autofill data\\r\\n    cursor.execute('SELECT \nname, value, date_created, date_last_used, count FROM autofill ORDER BY \ndate_last_used DESC LIMIT 500')\\r\\n    rows = cursor.fetchall()\\r\\n    \\r\\n    \nfor row in rows:\\r\\n        name = row['name'] if row['name'] else ''\\r\\n       \nvalue = row['value'] if row['value'] else ''\\r\\n        date_created = \nrow['date_created'] if row['date_created'] else 0\\r\\n        date_last_used = \nrow['date_last_used'] if row['date_last_used'] else 0\\r\\n        count = \nrow['count'] if row['count'] else 0\\r\\n        name = name.replace('|', \n'{PIPE}')\\r\\n        value = value.replace('|', '{PIPE}')\\r\\n        \nprint(f'{name}|{value}|{date_created}|{date_last_used}|{count}')\\r\\n    \\r\\n    \nconn.close()\\r\\nexcept Exception as e:\\r\\n    print(f'ERROR:{str(e)}')\\r\\n    \nimport traceback\\r\\n    print('ERROR:Traceback: ' + traceback.format_exc())\\r\\n \nsys.exit(1)\\r\\n\" @ token(0x600015B)+0x1B\n\nreference WMI statements\nnamespace  collection/database/wmi                               \nauthor     michael.hunhoff@mandiant.com                          \nscope      function                                              \natt&ck     Collection::Data from Information Repositories [T1213]\nfunction @ token(0x600004B)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_OperatingSystem\" @ token(0x600004B)+0x0\n\nlog keystrokes (2 matches)\nnamespace  collection/keylog                                \nauthor     moritz.raabe@mandiant.com                        \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nfunction @ token(0x600017A)\n  or:\n    api: MapVirtualKey @ token(0x600017A)+0x39\nfunction @ token(0x600017B)\n  or:\n    api: MapVirtualKey @ token(0x600017B)+0xF\n\nlog keystrokes via application hook\nnamespace  collection/keylog                                   \nauthor     michael.hunhoff@mandiant.com                        \nscope      basic block                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]   \nmbc        Collection::Keylogging::Application Hook [F0002.001]\nbasic block @ token(0x60000A7) in function token(0x60000A7)\n  and:\n    match: set application hook @ token(0x60000A7)+0x1C\n      or:\n        api: SetWindowsHookEx @ token(0x60000A7)+0x1C\n    or:\n      number: 0xD = WH_KEYBOARD_LL @ token(0x60000A7)+0xD\n\nlog keystrokes via polling (2 matches)\nnamespace  collection/keylog                                \nauthor     michael.hunhoff@mandiant.com                     \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nmbc        Collection::Keylogging::Polling [F0002.002]      \nfunction @ token(0x60000AA)\n  or:\n    api: GetKeyState @ token(0x60000AA)+0xE9, token(0x60000AA)+0xFA\nfunction @ token(0x600017C)\n  or:\n    api: VkKeyScan @ token(0x600017C)+0x3CB, token(0x600017C)+0x3F6\n\nget MAC address in .NET\nnamespace  collection/network                                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           echernofsky@google.com                                               \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nfunction @ token(0x600011C)\n  or:\n    api: System.Net.NetworkInformation.NetworkInterface::GetPhysicalAddress @ token(0x600011C)+0x150\n\ncapture screenshot\nnamespace  collection/screenshot                                            \nauthor     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\nscope      function                                                         \natt&ck     Collection::Screen Capture [T1113]                               \nmbc        Collection::Screen Capture::WinAPI [E1113.m01]                   \nfunction @ token(0x6000054)\n  or:\n    api: System.Drawing.Graphics::CopyFromScreen @ token(0x6000054)+0xC7, token(0x6000054)+0x133\n\nreceive data\nnamespace    communication                                                     \nauthor       william.ballenthin@mandiant.com                                   \nscope        function                                                          \nmbc          Command and Control::C2 Communication::Receive Data [B0030.002]   \ndescription  all known techniques for receiving data from a potential C2 server\nfunction @ token(0x600004C)\n  or:\n    match: read data from Internet @ token(0x600004C)\n      and:\n        or:\n          api: System.Net.WebClient::DownloadString @ token(0x600004C)+0x21\n\nsend data\nnamespace    communication                                                 \nauthor       william.ballenthin@mandiant.com, joakim@intezer.com           \nscope        function                                                      \nmbc          Command and Control::C2 Communication::Send Data [B0030.001]  \ndescription  all known techniques for sending data to a potential C2 server\nfunction @ token(0x60001BF)\n  or:\n    and:\n      os: windows\n      or:\n        match: send HTTP request @ token(0x60001BF)\n          or:\n            api: System.Net.WebRequest::GetResponse @ token(0x60001BF)+0x97\n\nmanipulate network credentials in .NET\nnamespace  communication/authentication\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x60001BF)\n  and:\n    api: System.Net.NetworkCredential::ctor @ token(0x60001BF)+0x7F\n\nwrite and execute a file (4 matches)\nnamespace              communication/c2/file-transfer               \nmaec/malware-category  launcher                                     \nauthor                 moritz.raabe@mandiant.com                    \nscope                  function                                     \nmbc                    Execution::Install Additional Program [B0023]\nfunction @ token(0x60000DD)\n  and:\n    match: host-interaction/file-system/write @ token(0x60000DD)\n      or:\n        api: System.IO.File::WriteAllText @ token(0x60000DD)+0x2A\n    match: host-interaction/process/create @ token(0x60000DD)\n      or:\n        api: System.Diagnostics.Process::Start @ token(0x60000DD)+0x35\nfunction @ token(0x6000147)\n  and:\n    match: host-interaction/file-system/write @ token(0x6000147)\n      or:\n        api: System.IO.File::WriteAllText @ token(0x6000147)+0x72\n    match: host-interaction/process/create @ token(0x6000147)\n      or:\n        api: System.Diagnostics.Process::Start @ token(0x6000147)+0x100\n      or:\n        and:\n          api: System.Diagnostics.Process::Start @ token(0x6000147)+0x100\n          or:\n            property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000147)+0xD6\n            property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000147)+0xF2\n            property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000147)+0xB9\n            property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000147)+0xCF\n            property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000147)+0xEB\n            property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x6000147)+0xDD\n            property/read: System.Diagnostics.Process::StandardOutput @ token(0x6000147)+0x108\nfunction @ token(0x600015B)\n  and:\n    match: host-interaction/file-system/write @ token(0x600015B)\n      or:\n        api: System.IO.File::WriteAllText @ token(0x600015B)+0x47\n    match: host-interaction/process/create @ token(0x600015B)\n      or:\n        api: System.Diagnostics.Process::Start @ token(0x600015B)+0xCB\n      or:\n        and:\n          api: System.Diagnostics.Process::Start @ token(0x600015B)+0xCB\n          or:\n            property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600015B)+0xA4\n            property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600015B)+0xC0\n            property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600015B)+0x87\n            property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600015B)+0x9D\n            property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600015B)+0xB9\n            property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600015B)+0xAB\n            property/read: System.Diagnostics.Process::StandardOutput @ token(0x600015B)+0xD2\nfunction @ token(0x60001E8)\n  and:\n    match: host-interaction/file-system/write @ token(0x60001E8)\n      or:\n        api: System.IO.File::WriteAllText @ token(0x60001E8)+0x6D\n    match: host-interaction/process/create @ token(0x60001E8)\n      or:\n        api: System.Diagnostics.Process::Start @ token(0x60001E8)+0x8C\n      or:\n        and:\n          api: System.Diagnostics.Process::Start @ token(0x60001E8)+0x8C\n          or:\n            property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x60001E8)+0x80\n            property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x60001E8)+0x79\n            property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x60001E8)+0x87\n\nread HTTP header\nnamespace  communication/http                                           \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Read Header [C0002.014]   \nfunction @ token(0x600004C)\n  or:\n    property/read: System.Net.WebClient::Headers @ token(0x600004C)+0x7\n\nreference HTTP User-Agent string\nnamespace   communication/http                                                  \nauthor      @mr-tz                                                              \nscope       function                                                            \nmbc         Communication::HTTP Communication [C0002]                           \nreferences  https://www.useragents.me/,                                         \n            https://www.whatismybrowser.com/guides/the-latest-user-agent/       \nfunction @ token(0x600004C)\n  or:\n    substring: Mozilla/5.0\n      - \"Mozilla/5.0\" @ token(0x600004C)+0x11\n\ncreate HTTP request\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Create Request [C0002.012]\nfunction @ token(0x60001BF)\n  and:\n    or:\n      api: System.Net.WebRequest::Create @ token(0x60001BF)+0x5F\n\nread data from Internet\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Get Response [C0002.017]  \nfunction @ token(0x600004C)\n  and:\n    or:\n      api: System.Net.WebClient::DownloadString @ token(0x600004C)+0x21\n\nreceive HTTP response\nnamespace  communication/http/client                                  \nauthor     michael.hunhoff@mandiant.com                               \nscope      function                                                   \nmbc        Communication::HTTP Communication::Get Response [C0002.017]\nfunction @ token(0x60001BF)\n  or:\n    api: System.Net.WebRequest::GetResponse @ token(0x60001BF)+0x97\n\nsend HTTP request\nnamespace  communication/http/client                                  \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com    \nscope      function                                                   \nmbc        Communication::HTTP Communication::Send Request [C0002.003]\nfunction @ token(0x60001BF)\n  or:\n    api: System.Net.WebRequest::GetResponse @ token(0x60001BF)+0x97\n\ncreate TCP socket (3 matches)\nnamespace   communication/socket/tcp                                            \nauthor      william.ballenthin@mandiant.com, joakim@intezer.com,                \n            anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com       \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create TCP Socket [C0001.011]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ token(0x600000C) in function token(0x600000C)\n  or:\n    property/read: System.Net.Sockets.TcpClient::Client @ token(0x600000C)+0x34, token(0x600000C)+0x41, token(0x600000C)+0x53\nbasic block @ token(0x600000E) in function token(0x600000E)\n  or:\n    property/read: System.Net.Sockets.TcpClient::Client @ token(0x600000E)+0x63, token(0x600000E)+0x70, token(0x600000E)+0xBE, \ntoken(0x600000E)+0xD7\nbasic block @ token(0x6000014) in function token(0x6000014)\n  or:\n    property/read: System.Net.Sockets.TcpClient::Client @ token(0x6000014)+0x34, token(0x6000014)+0x41\n\nact as TCP client\nnamespace  communication/tcp/client                                     \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                                     \nmbc        Communication::Socket Communication::TCP Client [C0001.008]  \nfunction @ token(0x600000E)\n  or:\n    api: System.Net.Sockets.TcpClient::ctor @ token(0x600000E)+0x7\n\ncreate zip archive in .NET (3 matches)\nnamespace  data-manipulation/compression\nauthor     michael.hunhoff@mandiant.com \nscope      basic block                  \nbasic block @ token(0x60000B8) in function token(0x60000B8)\n  and:\n    or:\n      api: System.IO.Compression.ZipFile::CreateFromDirectory @ token(0x60000B8)+0x14A\nbasic block @ token(0x60000BB) in function token(0x60000BB)\n  and:\n    or:\n      api: System.IO.Compression.ZipFile::CreateFromDirectory @ token(0x60000BB)+0x79\nbasic block @ token(0x60001BC) in function token(0x60001BC)\n  and:\n    or:\n      api: System.IO.Compression.ZipFile::CreateFromDirectory @ token(0x60001BC)+0x3F\n\ndecode data using Base64 in .NET\nnamespace  data-manipulation/encoding/base64                               \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \natt&ck     Defense Evasion::Deobfuscate/Decode Files or Information [T1140]\nmbc        Data::Decode Data::Base64 [C0053.001]                           \nfunction @ token(0x60001B5)\n  or:\n    api: System.Convert::FromBase64String @ token(0x60001B5)+0x1\n\ndecode data using Base64 via WinAPI\nnamespace  data-manipulation/encoding/base64                               \nauthor     michael.hunhoff@mandiant.com                                    \nscope      basic block                                                     \natt&ck     Defense Evasion::Deobfuscate/Decode Files or Information [T1140]\nbasic block @ token(0x60001B5) in function token(0x60001B5)\n  and:\n    api: CryptStringToBinary @ token(0x60001B5)+0x21, token(0x60001B5)+0x43\n    or:\n      number: 0x1 = dwFlags=CRYPT_STRING_BASE64 @ token(0x60001B5)+0x13, token(0x60001B5)+0x35\n\nreference Base64 string\nnamespace  data-manipulation/encoding/base64                                \nauthor     moritz.raabe@mandiant.com                                        \nscope      file                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]         \nmbc        Data::Encode Data::Base64 [C0026.001], Data::Check String [C0019]\nregex: /ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/\n  - \"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/\" @ file+0x254AC\n\nencrypt or decrypt data via BCrypt (2 matches)\nnamespace  data-manipulation/encryption                                         \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Decrypt Data [C0031], Cryptography::Encrypt Data       \n           [C0027]                                                              \nfunction @ token(0x60001AD)\n  and:\n    or:\n      api: BCryptDecrypt @ token(0x60001AD)+0x441\n    optional:\n      api: BCryptOpenAlgorithmProvider @ token(0x60001AD)+0x37D\n      api: BCryptCloseAlgorithmProvider @ token(0x60001AD)+0x4B1\n      api: BCryptGenerateSymmetricKey @ token(0x60001AD)+0x39E\n      api: BCryptDestroyKey @ token(0x60001AD)+0x49A\nfunction @ token(0x60001B0)\n  and:\n    or:\n      api: BCryptDecrypt @ token(0x60001B0)+0x1D1\n    optional:\n      api: BCryptOpenAlgorithmProvider @ token(0x60001B0)+0x70\n      api: BCryptCloseAlgorithmProvider @ token(0x60001B0)+0x280\n      api: BCryptGenerateSymmetricKey @ token(0x60001B0)+0xFC\n      api: BCryptDestroyKey @ token(0x60001B0)+0x26B\n\nencrypt data using DPAPI\nnamespace  data-manipulation/encryption/dpapi                           \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]     \nmbc        Cryptography::Encrypt Data [C0027]                           \nfunction @ token(0x60001AF)\n  or:\n    api: CryptUnprotectData @ token(0x60001AF)+0x52\n\ngenerate random numbers in .NET\nnamespace  data-manipulation/prng                                            \nauthor     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com     \nscope      function                                                          \nmbc        Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\nfunction @ token(0x600003E)\n  or:\n    api: System.Random::Next @ token(0x600003E)+0x90\n\ncontains PDB path\nnamespace  executable/pe/pdb        \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nregex: /:\\\\.*\\.pdb/\n  - \"C:\\\\Users\\\\sulum\\\\OneDrive\\\\Desktop\\\\datacenter\\\\stubCsharp\\\\obj\\\\Release\\\\Clie\nnt.pdb\" @ file+0x370BC\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ token(0x60000E5)\n  or:\n    and:\n      or:\n        api: LoadResource @ token(0x60000E5)+0x3D\n        api: LockResource @ token(0x60000E5)+0x5D\n      optional:\n        or:\n          api: FindResource @ token(0x60000E5)+0x12\n        api: SizeofResource @ token(0x60000E5)+0x82\n\ncheck clipboard data (2 matches)\nnamespace  host-interaction/clipboard        \nauthor     anushka.virgaonkar@mandiant.com   \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ token(0x60000EE)\n  or:\n    api: System.Windows.Forms.Clipboard::ContainsText @ token(0x60000EE)+0x10\nfunction @ token(0x600024C)\n  or:\n    api: System.Windows.Forms.Clipboard::ContainsText @ token(0x600024C)+0xA5, token(0x600024C)+0xB4\n\nmonitor clipboard content\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      basic block                       \natt&ck     Collection::Clipboard Data [T1115]\nbasic block @ token(0x60000F4) in function token(0x60000F4)\n  and:\n    api: AddClipboardFormatListener @ token(0x60000F4)+0x17\n\nread clipboard data (2 matches)\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Collection::Clipboard Data [T1115]                                  \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ token(0x60000EE)\n  and:\n    or:\n      api: System.Windows.Forms.Clipboard::GetText @ token(0x60000EE)+0x17\nfunction @ token(0x600024C)\n  and:\n    or:\n      api: System.Windows.Forms.Clipboard::GetText @ token(0x600024C)+0xAC, token(0x600024C)+0xBB\n\nmanipulate console buffer (8 matches)\nnamespace   host-interaction/console                                     \nauthor      william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope       function                                                     \nmbc         Operating System::Console [C0033]                            \nreferences  https://stackoverflow.com/a/15770935/87207                   \nfunction @ token(0x6000019)\n  or:\n    api: System.Console::WriteLine @ token(0x6000019)+0x21, token(0x6000019)+0x58\nfunction @ token(0x6000029)\n  or:\n    api: System.Console::WriteLine @ token(0x6000029)+0x1F\nfunction @ token(0x6000033)\n  or:\n    api: System.Console::WriteLine @ token(0x6000033)+0x19, token(0x6000033)+0x7B, token(0x6000033)+0x9B, \ntoken(0x6000033)+0xBF, and 6 more...\nfunction @ token(0x6000044)\n  or:\n    api: System.Console::WriteLine @ token(0x6000044)+0x21, token(0x6000044)+0x58\nfunction @ token(0x600014A)\n  or:\n    api: System.Console::WriteLine @ token(0x600014A)+0x21\nfunction @ token(0x600015E)\n  or:\n    api: System.Console::WriteLine @ token(0x600015E)+0x21\nfunction @ token(0x6000181)\n  or:\n    api: System.Console::WriteLine @ token(0x6000181)+0x79\nfunction @ token(0x6000182)\n  or:\n    api: System.Console::WriteLine @ token(0x6000182)+0x8, token(0x6000182)+0x2B\n\nquery environment variable (3 matches)\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ token(0x6000095)\n  or:\n    api: System.Environment::ExpandEnvironmentVariables @ token(0x6000095)+0x17\nfunction @ token(0x60001A1)\n  or:\n    api: System.Environment::GetEnvironmentVariable @ token(0x60001A1)+0x28, token(0x60001A1)+0x33, token(0x60001A1)+0x3E\nfunction @ token(0x60001AB)\n  or:\n    api: System.Environment::GetEnvironmentVariable @ token(0x60001AB)+0xF\n\nenumerate drives\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x6000093)\n  or:\n    api: System.IO.DriveInfo::GetDrives @ token(0x6000093)+0x6\n\nget common file path (7 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ token(0x600004E)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x600004E)+0xA, token(0x600004E)+0x1E, token(0x600004E)+0x32, \ntoken(0x600004E)+0x46\nfunction @ token(0x60000B7)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x60000B7)+0x8, token(0x60000B7)+0x10\nfunction @ token(0x60000F8)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x60000F8)+0x10, token(0x60000F8)+0x90\nfunction @ token(0x60000FA)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x60000FA)+0x8\nfunction @ token(0x6000146)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x6000146)+0x10, token(0x6000146)+0x29, token(0x6000146)+0x42\nfunction @ token(0x6000149)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x6000149)+0x8, token(0x6000149)+0x10\nfunction @ token(0x600015D)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x600015D)+0x8, token(0x600015D)+0x10\n\ncopy file (7 matches)\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ token(0x60000BC)\n  or:\n    api: System.IO.File::Copy @ token(0x60000BC)+0x2C\nfunction @ token(0x6000144)\n  or:\n    api: System.IO.File::Copy @ token(0x6000144)+0xC7\nfunction @ token(0x6000159)\n  or:\n    api: System.IO.File::Copy @ token(0x6000159)+0xA3\nfunction @ token(0x60001A5)\n  or:\n    api: System.IO.File::Copy @ token(0x60001A5)+0x92\nfunction @ token(0x60001A6)\n  or:\n    api: System.IO.File::Copy @ token(0x60001A6)+0x2D, token(0x60001A6)+0x5F\nfunction @ token(0x60001AB)\n  or:\n    api: System.IO.File::Copy @ token(0x60001AB)+0x81\nfunction @ token(0x60001BF)\n  or:\n    api: System.IO.File::Copy @ token(0x60001BF)+0x43, token(0x60001BF)+0xE7, token(0x60001BF)+0xF6\n\ncreate directory (8 matches)\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ token(0x6000097)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000097)+0x18\nfunction @ token(0x6000098)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000098)+0x18\nfunction @ token(0x60000B8)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60000B8)+0x5F\nfunction @ token(0x60000BB)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60000BB)+0x2C\nfunction @ token(0x60000BC)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60000BC)+0x9\nfunction @ token(0x6000144)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000144)+0x120\nfunction @ token(0x6000159)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000159)+0xFB\nfunction @ token(0x60001A0)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60001A0)+0x8C, token(0x60001A0)+0x98\n\ndelete directory (2 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ token(0x60000B8)\n  or:\n    api: System.IO.Directory::Delete @ token(0x60000B8)+0x176\nfunction @ token(0x60000BB)\n  or:\n    api: System.IO.Directory::Delete @ token(0x60000BB)+0x87\n\ndelete file (12 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ token(0x60000B8)\n  or:\n    api: System.IO.File::Delete @ token(0x60000B8)+0x182\nfunction @ token(0x60000BB)\n  or:\n    api: System.IO.File::Delete @ token(0x60000BB)+0x93\nfunction @ token(0x6000144)\n  or:\n    api: System.IO.File::Delete @ token(0x6000144)+0x233, token(0x6000144)+0x329\nfunction @ token(0x6000147)\n  or:\n    api: System.IO.File::Delete @ token(0x6000147)+0x3DE\nfunction @ token(0x6000159)\n  or:\n    api: System.IO.File::Delete @ token(0x6000159)+0x1D1, token(0x6000159)+0x256\nfunction @ token(0x600015B)\n  or:\n    api: System.IO.File::Delete @ token(0x600015B)+0x22F, token(0x600015B)+0x255\nfunction @ token(0x60001A8)\n  or:\n    api: System.IO.File::Delete @ token(0x60001A8)+0x280\nfunction @ token(0x60001A9)\n  or:\n    api: System.IO.File::Delete @ token(0x60001A9)+0x30D, token(0x60001A9)+0x337, token(0x60001A9)+0x361\nfunction @ token(0x60001AA)\n  or:\n    api: System.IO.File::Delete @ token(0x60001AA)+0x27E, token(0x60001AA)+0x2A6, token(0x60001AA)+0x2CE\nfunction @ token(0x60001AB)\n  or:\n    api: System.IO.File::Delete @ token(0x60001AB)+0x12D\nfunction @ token(0x60001BC)\n  or:\n    api: System.IO.File::Delete @ token(0x60001BC)+0x33\nfunction @ token(0x60001BF)\n  or:\n    api: System.IO.File::Delete @ token(0x60001BF)+0x109\n\ncheck if directory exists (15 matches)\nnamespace  host-interaction/file-system/exists            \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nfunction @ token(0x600004E)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600004E)+0x5E\nfunction @ token(0x6000095)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000095)+0x64\nfunction @ token(0x6000097)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000097)+0x10\nfunction @ token(0x6000098)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000098)+0x10\nfunction @ token(0x60000B7)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60000B7)+0x347\nfunction @ token(0x60000B8)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60000B8)+0xC0\nfunction @ token(0x60000BC)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60000BC)+0x1\nfunction @ token(0x6000144)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000144)+0x117\nfunction @ token(0x6000149)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000149)+0x11D, token(0x6000149)+0x237, token(0x6000149)+0x324, \ntoken(0x6000149)+0x469, and 2 more...\nfunction @ token(0x6000159)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000159)+0xF2\nfunction @ token(0x600015D)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600015D)+0x7B, token(0x600015D)+0x109, token(0x600015D)+0x198, \ntoken(0x600015D)+0x21D, and 1 more...\nfunction @ token(0x60001A7)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60001A7)+0x16\nfunction @ token(0x60001A9)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60001A9)+0xB\nfunction @ token(0x60001AB)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60001AB)+0x2A\nfunction @ token(0x600021B)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600021B)+0x24\n\ncheck if file exists (22 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ token(0x6000095)\n  or:\n    property/read: System.IO.FileSystemInfo::Exists @ token(0x6000095)+0x88\nfunction @ token(0x6000096)\n  or:\n    api: System.IO.File::Exists @ token(0x6000096)+0x1\nfunction @ token(0x60000D6)\n  or:\n    api: System.IO.File::Exists @ token(0x60000D6)+0x1\nfunction @ token(0x60000D7)\n  or:\n    api: System.IO.File::Exists @ token(0x60000D7)+0x1\nfunction @ token(0x60000F8)\n  or:\n    api: System.IO.File::Exists @ token(0x60000F8)+0x45, token(0x60000F8)+0xC5\nfunction @ token(0x60000FA)\n  or:\n    api: System.IO.File::Exists @ token(0x60000FA)+0x1E\nfunction @ token(0x6000144)\n  or:\n    api: System.IO.File::Exists @ token(0x6000144)+0x219, token(0x6000144)+0x22B, token(0x6000144)+0x321\nfunction @ token(0x6000146)\n  or:\n    api: System.IO.File::Exists @ token(0x6000146)+0x71\nfunction @ token(0x6000149)\n  or:\n    api: System.IO.File::Exists @ token(0x6000149)+0x170, token(0x6000149)+0x28B, token(0x6000149)+0x378, \ntoken(0x6000149)+0x4B1, and 2 more...\nfunction @ token(0x6000159)\n  or:\n    api: System.IO.File::Exists @ token(0x6000159)+0x1B7, token(0x6000159)+0x1C9, token(0x6000159)+0x24E\nfunction @ token(0x600015D)\n  or:\n    api: System.IO.File::Exists @ token(0x600015D)+0xCE, token(0x600015D)+0x15D, token(0x600015D)+0x1EC, \ntoken(0x600015D)+0x265, and 1 more...\nfunction @ token(0x60001A6)\n  or:\n    api: System.IO.File::Exists @ token(0x60001A6)+0x19, token(0x60001A6)+0x4B\nfunction @ token(0x60001A7)\n  or:\n    api: System.IO.File::Exists @ token(0x60001A7)+0x2F, token(0x60001A7)+0x140, token(0x60001A7)+0x15E, \ntoken(0x60001A7)+0x174, and 1 more...\nfunction @ token(0x60001A8)\n  or:\n    api: System.IO.File::Exists @ token(0x60001A8)+0x25, token(0x60001A8)+0x278\nfunction @ token(0x60001A9)\n  or:\n    api: System.IO.File::Exists @ token(0x60001A9)+0x64, token(0x60001A9)+0x304, token(0x60001A9)+0x324, \ntoken(0x60001A9)+0x34E\nfunction @ token(0x60001AA)\n  or:\n    api: System.IO.File::Exists @ token(0x60001AA)+0x66, token(0x60001AA)+0x276, token(0x60001AA)+0x294, \ntoken(0x60001AA)+0x2BC\nfunction @ token(0x60001AB)\n  or:\n    api: System.IO.File::Exists @ token(0x60001AB)+0x61\nfunction @ token(0x60001BC)\n  or:\n    api: System.IO.File::Exists @ token(0x60001BC)+0x2B, token(0x60001BC)+0x45\nfunction @ token(0x60001BD)\n  or:\n    api: System.IO.File::Exists @ token(0x60001BD)+0x13\nfunction @ token(0x60001BF)\n  or:\n    api: System.IO.File::Exists @ token(0x60001BF)+0x31, token(0x60001BF)+0x39\nfunction @ token(0x600026B)\n  or:\n    api: System.IO.File::Exists @ token(0x600026B)+0x9B\nfunction @ token(0x600026F)\n  or:\n    api: System.IO.File::Exists @ token(0x600026F)+0x70\n\nenumerate files in .NET (6 matches)\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ token(0x60000BC)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x60000BC)+0x10\n    api: System.IO.Directory::GetDirectories @ token(0x60000BC)+0x41\nfunction @ token(0x6000149)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x6000149)+0x128, token(0x6000149)+0x243, token(0x6000149)+0x330, \ntoken(0x6000149)+0x475, and 2 more...\nfunction @ token(0x600015D)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x600015D)+0x86, token(0x600015D)+0x115, token(0x600015D)+0x1A4, \ntoken(0x600015D)+0x229, and 1 more...\nfunction @ token(0x60001A7)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x60001A7)+0xCB\nfunction @ token(0x60001A9)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x60001A9)+0x20\nfunction @ token(0x60001AB)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x60001AB)+0x3F\n\nget file attributes\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ token(0x6000095) in function token(0x6000095)\n  or:\n    property/read: System.IO.FileSystemInfo::Attributes @ token(0x6000095)+0xFD\n\nget file size (5 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ token(0x6000095)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x6000095)+0x15D\nfunction @ token(0x60001A5)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x60001A5)+0xD4\nfunction @ token(0x60001A8)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x60001A8)+0x79\nfunction @ token(0x60001AA)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x60001AA)+0xB6\nfunction @ token(0x600026B)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x600026B)+0xD3\n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ token(0x600003C) in function token(0x600003C)\n  or:\n    api: System.IO.File::SetAttributes @ token(0x600003C)+0x19\nbasic block @ token(0x60001BF) in function token(0x60001BF)\n  or:\n    api: System.IO.File::SetAttributes @ token(0x60001BF)+0x4A, token(0x60001BF)+0xEE, token(0x60001BF)+0xFD\n\nmove file (2 matches)\nnamespace  host-interaction/file-system/move                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Move File [C0063]                         \nfunction @ token(0x6000144)\n  or:\n    api: System.IO.File::Move @ token(0x6000144)+0x23B\nfunction @ token(0x6000159)\n  or:\n    api: System.IO.File::Move @ token(0x6000159)+0x1D9\n\nread file on Windows (7 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ token(0x6000096)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x6000096)+0x3F\nfunction @ token(0x60000B8)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x60000B8)+0x150\nfunction @ token(0x60000BB)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x60000BB)+0x7F\nfunction @ token(0x60001A5)\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ token(0x60001A5)+0xF5\nfunction @ token(0x60001AC)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x60001AC)+0x1\nfunction @ token(0x60001AD)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x60001AD)+0xB\nfunction @ token(0x60001BD)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x60001BD)+0x70\n\nwrite file on Windows (11 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ token(0x6000019)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000019)+0x40\nfunction @ token(0x6000044)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000044)+0x40\nfunction @ token(0x6000097)\n  or:\n    api: System.IO.File::WriteAllBytes @ token(0x6000097)+0x20\nfunction @ token(0x60000BB)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x60000BB)+0x42\nfunction @ token(0x60000DD)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x60000DD)+0x2A\nfunction @ token(0x6000147)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x6000147)+0x72\nfunction @ token(0x600014A)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x600014A)+0x40\nfunction @ token(0x600015B)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x600015B)+0x47\nfunction @ token(0x600015E)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x600015E)+0x40\nfunction @ token(0x60001A5)\n  or:\n    api: System.IO.File::WriteAllBytes @ token(0x60001A5)+0x136\nfunction @ token(0x60001E8)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x60001E8)+0x6D\n\nenumerate gui resources (2 matches)\nnamespace  host-interaction/gui                           \nauthor     johnk3r, anushka.virgaonkar@mandiant.com       \nscope      function                                       \natt&ck     Discovery::Application Window Discovery [T1010]\nfunction @ token(0x600004D)\n  or:\n    property/read: System.Windows.Forms.Screen::AllScreens @ token(0x600004D)+0x0\nfunction @ token(0x6000054)\n  or:\n    property/read: System.Windows.Forms.Screen::AllScreens @ token(0x6000054)+0x0\n\nset application hook (2 matches)\nnamespace  host-interaction/gui        \nauthor     michael.hunhoff@mandiant.com\nscope      instruction                 \ninstruction @ token(0x60000A7)+0x1C\n  or:\n    api: SetWindowsHookEx @ token(0x60000A7)+0x1C\ninstruction @ token(0x60000AF)+0x66\n  or:\n    api: UnhookWindowsHookEx @ token(0x60000AF)+0x66\n\nchange the wallpaper\nnamespace  host-interaction/gui/session       \nauthor     @_re_fox                           \nscope      basic block                        \nmbc        Operating System::Wallpaper [C0035]\nbasic block @ token(0x60000D7) in function token(0x60000D7)\n  and:\n    api: SystemParametersInfo @ token(0x60000D7)+0x12\n    number: 0x14 = SPI_SETDESKWALLPAPER @ token(0x60000D7)+0x8\n    number: 0x3 = SPIF_SENDWININICHANGE | SPIF_UPDATEINIFILE @ token(0x60000D7)+0x11\n\nfind taskbar (3 matches)\nnamespace  host-interaction/gui/taskbar/find   \nauthor     moritz.raabe@mandiant.com           \nscope      basic block                         \nmbc        Discovery::Taskbar Discovery [B0043]\nbasic block @ token(0x60000C2) in function token(0x60000C2)\n  and:\n    string: \"Shell_TrayWnd\" @ token(0x60000C2)+0x0\n    match: find graphical window @ token(0x60000C2)+0xA\n      or:\n        api: FindWindow @ token(0x60000C2)+0xA\nbasic block @ token(0x60000C3) in function token(0x60000C3)\n  and:\n    string: \"Shell_TrayWnd\" @ token(0x60000C3)+0x0\n    match: find graphical window @ token(0x60000C3)+0xA\n      or:\n        api: FindWindow @ token(0x60000C3)+0xA\nbasic block @ token(0x60000C9) in function token(0x60000C9)\n  and:\n    string: \"Shell_TrayWnd\" @ token(0x60000C9)+0x0\n    match: find graphical window @ token(0x60000C9)+0xA\n      or:\n        api: FindWindow @ token(0x60000C9)+0xA\n\nhide the Windows taskbar\nnamespace  host-interaction/gui/taskbar/hide      \nauthor     michael.hunhoff@mandiant.com           \nscope      function                               \natt&ck     Defense Evasion::Hide Artifacts [T1564]\nfunction @ token(0x60000C2)\n  and:\n    match: find taskbar @ token(0x60000C2)\n      and:\n        string: \"Shell_TrayWnd\" @ token(0x60000C2)+0x0\n        match: find graphical window @ token(0x60000C2)+0xA\n          or:\n            api: FindWindow @ token(0x60000C2)+0xA\n    match: hide graphical window @ token(0x60000C2)\n      and:\n        number: 0x0 = SW_HIDE @ token(0x60000C2)+0xF\n        api: ShowWindow @ token(0x60000C2)+0x10\n\nfind graphical window (3 matches)\nnamespace  host-interaction/gui/window/find               \nauthor     moritz.raabe@mandiant.com                      \nscope      instruction                                    \natt&ck     Discovery::Application Window Discovery [T1010]\ninstruction @ token(0x60000C2)+0xA\n  or:\n    api: FindWindow @ token(0x60000C2)+0xA\ninstruction @ token(0x60000C3)+0xA\n  or:\n    api: FindWindow @ token(0x60000C3)+0xA\ninstruction @ token(0x60000C9)+0xA\n  or:\n    api: FindWindow @ token(0x60000C9)+0xA\n\nhide graphical window\nnamespace  host-interaction/gui/window/hide                          \nauthor     michael.hunhoff@mandiant.com                              \nscope      basic block                                               \natt&ck     Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\nbasic block @ token(0x60000C2) in function token(0x60000C2)\n  and:\n    number: 0x0 = SW_HIDE @ token(0x60000C2)+0xF\n    api: ShowWindow @ token(0x60000C2)+0x10\n\nget disk information\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ token(0x6000093)\n  or:\n    property/read: System.IO.DriveInfo::VolumeLabel @ token(0x6000093)+0x3E, token(0x6000093)+0x4B\n    property/read: System.IO.DriveInfo::DriveType @ token(0x6000093)+0x1E\n    property/read: System.IO.DriveInfo::Name @ token(0x6000093)+0x32\n\nget disk size\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ token(0x6000093)\n  or:\n    property/read: System.IO.DriveInfo::TotalSize @ token(0x6000093)+0x63\n    property/read: System.IO.DriveInfo::AvailableFreeSpace @ token(0x6000093)+0x6F\n\nallocate unmanaged memory in .NET (3 matches)\nnamespace  host-interaction/memory     \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x60001AD)\n  or:\n    api: System.Runtime.InteropServices.Marshal::AllocHGlobal @ token(0x60001AD)+0x3D2, token(0x60001AD)+0x3FA\nfunction @ token(0x60001AF)\n  or:\n    api: System.Runtime.InteropServices.Marshal::AllocHGlobal @ token(0x60001AF)+0x15\nfunction @ token(0x60001B0)\n  or:\n    api: System.Runtime.InteropServices.Marshal::AllocHGlobal @ token(0x60001B0)+0x158, token(0x60001B0)+0x163\n\nmanipulate unmanaged memory in .NET (14 matches)\nnamespace  host-interaction/memory     \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x6000055)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x6000055)+0x14\nfunction @ token(0x60000A8)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60000A8)+0x29\nfunction @ token(0x60000C7)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60000C7)+0x14\nfunction @ token(0x60000C8)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60000C8)+0x14\nfunction @ token(0x60000D7)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60000D7)+0xC\nfunction @ token(0x60000E5)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60000E5)+0x25, token(0x60000E5)+0xA4\nfunction @ token(0x60001A5)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60001A5)+0x5B, token(0x60001A5)+0xFC\nfunction @ token(0x60001AD)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60001AD)+0x3BC, token(0x60001AD)+0x3D2, token(0x60001AD)+0x3E8, \ntoken(0x60001AD)+0x3FA, and 3 more...\nfunction @ token(0x60001AF)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60001AF)+0x15, token(0x60001AF)+0x34, token(0x60001AF)+0x73, \ntoken(0x60001AF)+0xA2\nfunction @ token(0x60001B0)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60001B0)+0x143, token(0x60001B0)+0x158, token(0x60001B0)+0x163, \ntoken(0x60001B0)+0x171, and 3 more...\nfunction @ token(0x60001BB)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60001BB)+0x6C, token(0x60001BB)+0xA3, token(0x60001BB)+0xDE, \ntoken(0x60001BB)+0x11F, and 1 more...\nfunction @ token(0x60001CA)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60001CA)+0x160, token(0x60001CA)+0x187, token(0x60001CA)+0x1C6\nfunction @ token(0x60001CB)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60001CB)+0x15A, token(0x60001CB)+0x181, token(0x60001CB)+0x1C0, \ntoken(0x60001CB)+0x1E5\nfunction @ token(0x60001CC)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60001CC)+0x92, token(0x60001CC)+0xB9, token(0x60001CC)+0xE0, \ntoken(0x60001CC)+0x107\n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex                                               \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           mehunhoff@google.com                                                 \nscope      instruction                                                          \nmbc        Process::Create Mutex [C0042]                                        \ninstruction @ token(0x6000033)+0x211\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Threading.Mutex::ctor @ token(0x6000033)+0x211\n\nget networking interfaces\nnamespace  host-interaction/network/interface                                   \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Network Configuration Discovery [T1016]            \nfunction @ token(0x600011C)\n  or:\n    and:\n      or:\n        api: System.Net.NetworkInformation.NetworkInterface::GetIPProperties @ token(0x600011C)+0x18\n      optional:\n        api: System.Net.NetworkInformation.NetworkInterface::GetAllNetworkInterfaces @ token(0x600011C)+0x6\n\nget hostname (2 matches)\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ token(0x6000049)\n  or:\n    property/read: System.Environment::MachineName @ token(0x6000049)+0x0\nfunction @ token(0x60001A0)\n  or:\n    api: GetComputerName @ token(0x60001A0)+0x18\n    property/read: System.Environment::MachineName @ token(0x60001A0)+0x35\n\nget OS version in .NET\nnamespace  host-interaction/os/version                    \nauthor     michael.hunhoff@mandiant.com                   \nscope      basic block                                    \natt&ck     Discovery::System Information Discovery [T1082]\nbasic block @ token(0x600004B) in function token(0x600004B)\n  or:\n    property/read: System.Environment::OSVersion @ token(0x600004B)+0x6D\n\nget process image filename (5 matches)\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ token(0x6000033) in function token(0x6000033)\n  or:\n    and:\n      api: System.Diagnostics.Process::GetCurrentProcess @ token(0x6000033)+0xC4\n      property/read: System.Diagnostics.Process::MainModule @ token(0x6000033)+0xC9\n      property/read: System.Diagnostics.ProcessModule::FileName @ token(0x6000033)+0xCE\nbasic block @ token(0x600003A) in function token(0x600003A)\n  or:\n    and:\n      api: System.Diagnostics.Process::GetCurrentProcess @ token(0x600003A)+0x0\n      property/read: System.Diagnostics.Process::MainModule @ token(0x600003A)+0x5\n      property/read: System.Diagnostics.ProcessModule::FileName @ token(0x600003A)+0xA\nbasic block @ token(0x600003C) in function token(0x600003C)\n  or:\n    and:\n      api: System.Diagnostics.Process::GetCurrentProcess @ token(0x600003C)+0x9\n      property/read: System.Diagnostics.Process::MainModule @ token(0x600003C)+0xE\n      property/read: System.Diagnostics.ProcessModule::FileName @ token(0x600003C)+0x13\nbasic block @ token(0x600003E) in function token(0x600003E)\n  or:\n    and:\n      api: System.Diagnostics.Process::GetCurrentProcess @ token(0x600003E)+0x0\n      property/read: System.Diagnostics.Process::MainModule @ token(0x600003E)+0x5\n      property/read: System.Diagnostics.ProcessModule::FileName @ token(0x600003E)+0xA\nbasic block @ token(0x60001E8) in function token(0x60001E8)\n  or:\n    and:\n      api: System.Diagnostics.Process::GetCurrentProcess @ token(0x60001E8)+0x0, token(0x60001E8)+0x42\n      property/read: System.Diagnostics.Process::MainModule @ token(0x60001E8)+0x5\n      property/read: System.Diagnostics.ProcessModule::FileName @ token(0x60001E8)+0xA\n\ncreate a process with modified I/O handles and window (14 matches)\nnamespace   host-interaction/process/create                                     \nauthor      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com      \nscope       function                                                            \nmbc         Process::Create Process [C0017]                                     \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/processthreadsap…\nfunction @ token(0x6000033)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000033)+0xF4\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000033)+0xE4\n        property/write: System.Diagnostics.ProcessStartInfo::Verb @ token(0x6000033)+0xEF\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000033)+0xDD\nfunction @ token(0x600003A)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600003A)+0x5F, token(0x600003A)+0xE0\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600003A)+0x4C, token(0x600003A)+0xCC\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600003A)+0x3E, token(0x600003A)+0xBE\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600003A)+0x21, token(0x600003A)+0x86\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600003A)+0x37, token(0x600003A)+0xB7\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600003A)+0x45, token(0x600003A)+0xC5\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600003A)+0x53, token(0x600003A)+0xD3\nfunction @ token(0x600003B)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600003B)+0x4F\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600003B)+0x3C\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600003B)+0x2E\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600003B)+0x11\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600003B)+0x27\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600003B)+0x35\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600003B)+0x43\nfunction @ token(0x600003E)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600003E)+0x7B\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600003E)+0x68\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600003E)+0x6F\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600003E)+0x61\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600003E)+0x76\nfunction @ token(0x60000F7)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x60000F7)+0x42, token(0x60000F7)+0x11F\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x60000F7)+0x29, token(0x60000F7)+0x106\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x60000F7)+0x17, token(0x60000F7)+0xE8\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x60000F7)+0x22, token(0x60000F7)+0xFF\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x60000F7)+0x37, token(0x60000F7)+0x114\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x60000F7)+0x30, token(0x60000F7)+0x10D\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x60000F7)+0x49, token(0x60000F7)+0x126\nfunction @ token(0x600011D)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600011D)+0x42, token(0x600011D)+0x11F\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600011D)+0x29, token(0x600011D)+0x106\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600011D)+0x17, token(0x600011D)+0xE8\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600011D)+0x22, token(0x600011D)+0xFF\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600011D)+0x37, token(0x600011D)+0x114\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600011D)+0x30, token(0x600011D)+0x10D\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x600011D)+0x49, token(0x600011D)+0x126\nfunction @ token(0x600011E)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600011E)+0x42\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600011E)+0x29\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600011E)+0x17\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600011E)+0x22\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600011E)+0x37\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600011E)+0x30\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x600011E)+0x49\nfunction @ token(0x6000144)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000144)+0x1B8\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000144)+0x186\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000144)+0x1A6\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000144)+0x13D\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000144)+0x17E\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000144)+0x19E\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x6000144)+0x18E\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x6000144)+0x1C0\nfunction @ token(0x6000147)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000147)+0x100\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000147)+0xD6\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000147)+0xF2\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000147)+0xB9\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000147)+0xCF\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000147)+0xEB\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x6000147)+0xDD\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x6000147)+0x108\nfunction @ token(0x6000148)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000148)+0xD5\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000148)+0xAD\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000148)+0xC9\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000148)+0x81\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000148)+0xA6\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000148)+0xC2\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x6000148)+0xB4\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x6000148)+0xDC\nfunction @ token(0x6000159)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000159)+0x190\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000159)+0x161\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000159)+0x181\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000159)+0x118\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000159)+0x159\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000159)+0x179\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x6000159)+0x169\nfunction @ token(0x600015B)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600015B)+0xCB\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600015B)+0xA4\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600015B)+0xC0\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600015B)+0x87\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600015B)+0x9D\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600015B)+0xB9\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600015B)+0xAB\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x600015B)+0xD2\nfunction @ token(0x600015C)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600015C)+0x99\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600015C)+0x72\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600015C)+0x8E\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600015C)+0x46\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600015C)+0x6B\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600015C)+0x87\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600015C)+0x79\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x600015C)+0xA0\nfunction @ token(0x60001E8)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x60001E8)+0x8C\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x60001E8)+0x80\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x60001E8)+0x79\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x60001E8)+0x87\n\ncreate process on Windows (22 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ token(0x6000033) in function token(0x6000033)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000033)+0xF4\nbasic block @ token(0x6000039) in function token(0x6000039)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000039)+0x1DE1, token(0x6000039)+0x1FD1\nbasic block @ token(0x600003A) in function token(0x600003A)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600003A)+0x5F, token(0x600003A)+0xE0\nbasic block @ token(0x600003B) in function token(0x600003B)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600003B)+0x4F\nbasic block @ token(0x600003E) in function token(0x600003E)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600003E)+0x7B\nbasic block @ token(0x6000099) in function token(0x6000099)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000099)+0x1\nbasic block @ token(0x60000D5) in function token(0x60000D5)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x60000D5)+0x28\nbasic block @ token(0x60000D8) in function token(0x60000D8)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x60000D8)+0xA\nbasic block @ token(0x60000DB) in function token(0x60000DB)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x60000DB)+0x5\nbasic block @ token(0x60000DC) in function token(0x60000DC)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x60000DC)+0x5\nbasic block @ token(0x60000DD) in function token(0x60000DD)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x60000DD)+0x35\nbasic block @ token(0x60000F7) in function token(0x60000F7)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x60000F7)+0x42, token(0x60000F7)+0x11F\nbasic block @ token(0x600011D) in function token(0x600011D)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600011D)+0x42, token(0x600011D)+0x11F\nbasic block @ token(0x600011E) in function token(0x600011E)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600011E)+0x42\nbasic block @ token(0x6000144) in function token(0x6000144)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000144)+0x1B8\nbasic block @ token(0x6000147) in function token(0x6000147)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000147)+0x100\nbasic block @ token(0x6000148) in function token(0x6000148)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000148)+0xD5\nbasic block @ token(0x6000159) in function token(0x6000159)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000159)+0x190\nbasic block @ token(0x600015B) in function token(0x600015B)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600015B)+0xCB\nbasic block @ token(0x600015C) in function token(0x600015C)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600015C)+0x99\nbasic block @ token(0x60001E8) in function token(0x60001E8)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x60001E8)+0x8C\nbasic block @ token(0x6000207) in function token(0x6000207)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000207)+0x10\n\nenumerate processes (2 matches)\nnamespace  host-interaction/process/list                                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      function                                                             \natt&ck     Discovery::Process Discovery [T1057], Discovery::Software Discovery  \n           [T1518]                                                              \nfunction @ token(0x6000060)\n  or:\n    api: System.Diagnostics.Process::GetProcesses @ token(0x6000060)+0x6\nfunction @ token(0x60000D9)\n  or:\n    api: System.Diagnostics.Process::GetProcesses @ token(0x60000D9)+0xD\n\nfind process by PID (2 matches)\nnamespace  host-interaction/process/list                                \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::Process Discovery [T1057]                         \nfunction @ token(0x6000061)\n  and:\n    or:\n      api: System.Diagnostics.Process::GetProcessById @ token(0x6000061)+0x1\nfunction @ token(0x6000062)\n  and:\n    or:\n      api: System.Diagnostics.Process::GetProcessById @ token(0x6000062)+0x1\n\nfind process by name\nnamespace  host-interaction/process/list       \nauthor     anushka.virgaonkar@mandiant.com     \nscope      function                            \natt&ck     Discovery::Process Discovery [T1057]\nfunction @ token(0x60001BB)\n  and:\n    api: System.Diagnostics.Process::GetProcessesByName @ token(0x60001BB)+0x7\n\nacquire debug privileges\nnamespace  host-interaction/process/modify                        \nauthor     william.ballenthin@mandiant.com                        \nscope      basic block                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\nbasic block @ token(0x60001BA) in function token(0x60001BA)\n  and:\n    string: \"SeDebugPrivilege\" @ token(0x60001BA)+0x13\n    optional:\n      match: modify access privileges @ token(0x60001BA)+0x59\n        and:\n          api: AdjustTokenPrivileges @ token(0x60001BA)+0x59\n\nmodify access privileges\nnamespace  host-interaction/process/modify                        \nauthor     moritz.raabe@mandiant.com                              \nscope      instruction                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\ninstruction @ token(0x60001BA)+0x59\n  and:\n    api: AdjustTokenPrivileges @ token(0x60001BA)+0x59\n\nterminate process (14 matches)\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ token(0x600003A)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x600003A)+0x6F, token(0x600003A)+0xEF\nfunction @ token(0x600003B)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x600003B)+0x5E\nfunction @ token(0x6000061)\n  or:\n    api: System.Diagnostics.Process::Kill @ token(0x6000061)+0x25, token(0x6000061)+0x3C\n    api: System.Diagnostics.Process::WaitForExit @ token(0x6000061)+0x14, token(0x6000061)+0x30, token(0x6000061)+0x47\nfunction @ token(0x60000F7)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x60000F7)+0x54, token(0x60000F7)+0x132\nfunction @ token(0x600011D)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x600011D)+0x54, token(0x600011D)+0x132\nfunction @ token(0x600011E)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x600011E)+0x54\nfunction @ token(0x6000144)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x6000144)+0x1E0\nfunction @ token(0x6000147)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x6000147)+0x129\nfunction @ token(0x6000148)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x6000148)+0xFB\nfunction @ token(0x6000159)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x6000159)+0x19C\nfunction @ token(0x600015B)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x600015B)+0xF0\nfunction @ token(0x600015C)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x600015C)+0xB1\nfunction @ token(0x60001E7)\n  or:\n    api: System.Environment::Exit @ token(0x60001E7)+0x2F\nfunction @ token(0x60001E8)\n  or:\n    api: System.Environment::Exit @ token(0x60001E8)+0x99\n\nquery or enumerate registry key (7 matches)\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ token(0x6000039)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000039)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000039)+0x1FE8\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000039)+0x1FE8\nfunction @ token(0x600006F)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600006F)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600006F)+0x10, token(0x600006F)+0x8E\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600006F)+0x10, token(0x600006F)+0x8E\nfunction @ token(0x6000071)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000071)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000071)+0xB\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000071)+0xB\nfunction @ token(0x60000F9)\n  and:\n    optional:\n      match: create or open registry key @ token(0x60000F9)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000F9)+0x10\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000F9)+0x10\nfunction @ token(0x6000255)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000255)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000255)+0x67\n    or:\n      api: Microsoft.Win32.RegistryKey::GetSubKeyNames @ token(0x6000255)+0x7F\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000255)+0x67\nfunction @ token(0x6000257)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000257)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000257)+0x3C\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000257)+0x3C\nfunction @ token(0x6000259)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000259)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000259)+0x36\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000259)+0x36\n\nquery or enumerate registry value (2 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ token(0x600006F)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600006F)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600006F)+0x10, token(0x600006F)+0x8E\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x600006F)+0x2C, token(0x600006F)+0xAE\n      api: Microsoft.Win32.RegistryKey::GetValueNames @ token(0x600006F)+0x1A, token(0x600006F)+0x9B\nfunction @ token(0x6000255)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000255)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000255)+0x67\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x6000255)+0xFE\n      api: Microsoft.Win32.RegistryKey::GetValueKind @ token(0x6000255)+0x108\n      api: Microsoft.Win32.RegistryKey::GetValueNames @ token(0x6000255)+0xE5\n\nset registry value (5 matches)\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ token(0x6000039)\n  or:\n    and:\n      match: host-interaction/process/create @ token(0x6000039)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x6000039)+0x1DE1, token(0x6000039)+0x1FD1\n      regex: /add/i\n        - \"add_startup\" @ token(0x6000039)+0x6C2\n        - \"add_to_startup\" @ token(0x6000039)+0x79E\n      or:\n        regex: /reg(|.exe)/i\n          - \"Listing registry (normalized): \" @ token(0x6000039)+0x23A4\n          - \"Registry list packet data: \" @ token(0x6000039)+0x2153\n          - \"Setting registry value: \" @ token(0x6000039)+0x2434\n          - \"list_registry\" @ token(0x6000039)+0x453\n          - \"set_registry_value\" @ token(0x6000039)+0x8E8\n        regex: /hklm/i\n          - \"HKLM\" @ token(0x6000039)+0x21FC\n        regex: /HKEY_LOCAL_MACHINE/i\n          - \"HKEY_LOCAL_MACHINE\" @ token(0x6000039)+0x21CC\n        regex: /hkcu/i\n          - \"HKCU\" @ token(0x6000039)+0x21F4\n        regex: /HKEY_CURRENT_USER/i\n          - \"HKEY_CURRENT_USER\" @ token(0x6000039)+0x218F, token(0x6000039)+0x21C4\n    and:\n      optional:\n        match: create or open registry key @ token(0x6000039)\n          or:\n            api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000039)+0x1FE8\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000039)+0x2000\nfunction @ token(0x600003E)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x600003E)\n          or:\n            api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x600003E)+0x1C\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x600003E)+0x34, token(0x600003E)+0x45\nfunction @ token(0x600003E)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x600003E)\n          or:\n            api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x600003E)+0x1C\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x600003E)+0x34, token(0x600003E)+0x45\nfunction @ token(0x6000070)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x6000070)\n          or:\n            api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x6000070)+0xA\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000070)+0x13\nfunction @ token(0x6000257)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x6000257)\n          or:\n            api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000257)+0x3C\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000257)+0x14B\n\ndelete registry key\nnamespace  host-interaction/registry/delete                                \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\nscope      function                                                        \natt&ck     Defense Evasion::Modify Registry [T1112]                        \nmbc        Operating System::Registry::Delete Registry Key [C0036.002]     \nfunction @ token(0x600003E)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600003E)\n        or:\n          api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x600003E)+0x1C\n    or:\n      api: Microsoft.Win32.RegistryKey::DeleteSubKeyTree @ token(0x600003E)+0xA6, token(0x600003E)+0xC0\n\ndelete registry value (2 matches)\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ token(0x6000071)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000071)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000071)+0xB\n    or:\n      api: Microsoft.Win32.RegistryKey::DeleteValue @ token(0x6000071)+0x17\nfunction @ token(0x6000259)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000259)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000259)+0x36\n    or:\n      api: Microsoft.Win32.RegistryKey::DeleteValue @ token(0x6000259)+0x4A\n\nget session integrity level (3 matches)\nnamespace  host-interaction/session                                     \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::System Owner/User Discovery [T1033]               \nfunction @ token(0x600003D)\n  or:\n    and:\n      api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x600003D)+0x0\n      number: 0x220 = BUILTIN\\Administrators @ token(0x600003D)+0xA\n      api: System.Security.Principal.WindowsPrincipal::IsInRole @ token(0x600003D)+0xF\nfunction @ token(0x600007A)\n  or:\n    and:\n      api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x600007A)+0x0\n      number: 0x220 = BUILTIN\\Administrators @ token(0x600007A)+0xA\n      api: System.Security.Principal.WindowsPrincipal::IsInRole @ token(0x600007A)+0xF\nfunction @ token(0x60001B9)\n  or:\n    and:\n      api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x60001B9)+0x0\n      number: 0x220 = BUILTIN\\Administrators @ token(0x60001B9)+0xA\n      api: System.Security.Principal.WindowsPrincipal::IsInRole @ token(0x60001B9)+0xF\n\nget session user name (5 matches)\nnamespace  host-interaction/session                                             \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope      function                                                             \natt&ck     Discovery::System Owner/User Discovery [T1033], Discovery::Account   \n           Discovery [T1087]                                                    \nfunction @ token(0x600003D)\n  or:\n    api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x600003D)+0x0\nfunction @ token(0x600004A)\n  or:\n    property/read: System.Environment::UserName @ token(0x600004A)+0x0\nfunction @ token(0x600007A)\n  or:\n    api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x600007A)+0x0\nfunction @ token(0x6000149)\n  or:\n    property/read: System.Environment::UserName @ token(0x6000149)+0x16\nfunction @ token(0x60001B9)\n  or:\n    api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x60001B9)+0x0\n\ncreate thread (3 matches)\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ token(0x60000A4) in function token(0x60000A4)\n  or:\n    and:\n      api: System.Threading.Thread::Start @ token(0x60000A4)+0x47\n      optional:\n        api: System.Threading.Thread::ctor @ token(0x60000A4)+0x24\nbasic block @ token(0x60000C4) in function token(0x60000C4)\n  or:\n    and:\n      api: System.Threading.Thread::Start @ token(0x60000C4)+0x38\n      optional:\n        api: System.Threading.Thread::ctor @ token(0x60000C4)+0x25\nbasic block @ token(0x60000EC) in function token(0x60000EC)\n  or:\n    and:\n      api: System.Threading.Thread::Start @ token(0x60000EC)+0x57\n      optional:\n        api: System.Threading.Thread::ctor @ token(0x60000EC)+0x2F\n\nsuspend thread (9 matches)\nnamespace  host-interaction/thread/suspend                    \nauthor     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\nscope      basic block                                        \nmbc        Process::Suspend Thread [C0055]                    \nbasic block @ token(0x6000010) in function token(0x6000010)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000010)+0x16D, token(0x6000010)+0x1B4, token(0x6000010)+0x1CB\nbasic block @ token(0x6000011) in function token(0x6000011)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000011)+0xEC, token(0x6000011)+0x134\nbasic block @ token(0x6000033) in function token(0x6000033)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000033)+0xA5\nbasic block @ token(0x6000035) in function token(0x6000035)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000035)+0xC1, token(0x6000035)+0xED\nbasic block @ token(0x6000037) in function token(0x6000037)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000037)+0x24A, token(0x6000037)+0x363, token(0x6000037)+0x370, \ntoken(0x6000037)+0x3A1, and 2 more...\nbasic block @ token(0x600003E) in function token(0x600003E)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x600003E)+0x96\nbasic block @ token(0x60000DA) in function token(0x60000DA)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x60000DA)+0x55\nbasic block @ token(0x60001E7) in function token(0x60001E7)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x60001E7)+0x14\nbasic block @ token(0x6000207) in function token(0x6000207)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000207)+0x18\n\naccess WMI data in .NET\nnamespace  host-interaction/wmi                                 \nauthor     michael.hunhoff@mandiant.com                         \nscope      function                                             \natt&ck     Execution::Windows Management Instrumentation [T1047]\nfunction @ token(0x600004B)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x600004B)+0xC\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x600004B)+0x5\n\nreference cryptocurrency strings\nnamespace   impact/cryptocurrency                                               \nauthor      moritz.raabe@mandiant.com                                           \nscope       file                                                                \natt&ck      Impact::Resource Hijacking [T1496]                                  \nreferences  https://github.com/ctxis/CAPE/blob/master/modules/signatures/crypto…\nor:\n  string: \"Bitcoin\" @ file+0x258F8\n  string: \"Ethereum\" @ file+0x2591A\n  string: \"Dash\" @ file+0x25A16\n  string: \"Monero\" @ file+0x25A46\n  string: \"Zcash\" @ file+0x25A2C\n\ndisable system features via registry on Windows\nnamespace  impact/features                                                      \nauthor     mehunhoff@google.com                                                 \nscope      function                                                             \natt&ck     Defense Evasion::Impair Defenses::Disable or Modify Tools [T1562.001]\nmbc        Defense Evasion::Disable or Evade Security Tools [F0004]             \nfunction @ token(0x6000039)\n  and:\n    match: set registry value @ token(0x6000039)\n      or:\n        and:\n          match: host-interaction/process/create @ token(0x6000039)\n            or:\n              api: System.Diagnostics.Process::Start @ token(0x6000039)+0x1DE1, token(0x6000039)+0x1FD1\n          regex: /add/i\n            - \"add_startup\" @ token(0x6000039)+0x6C2\n            - \"add_to_startup\" @ token(0x6000039)+0x79E\n          or:\n            regex: /reg(|.exe)/i\n              - \"Listing registry (normalized): \" @ token(0x6000039)+0x23A4\n              - \"Registry list packet data: \" @ token(0x6000039)+0x2153\n              - \"Setting registry value: \" @ token(0x6000039)+0x2434\n              - \"list_registry\" @ token(0x6000039)+0x453\n              - \"set_registry_value\" @ token(0x6000039)+0x8E8\n            regex: /hklm/i\n              - \"HKLM\" @ token(0x6000039)+0x21FC\n            regex: /HKEY_LOCAL_MACHINE/i\n              - \"HKEY_LOCAL_MACHINE\" @ token(0x6000039)+0x21CC\n            regex: /hkcu/i\n              - \"HKCU\" @ token(0x6000039)+0x21F4\n            regex: /HKEY_CURRENT_USER/i\n              - \"HKEY_CURRENT_USER\" @ token(0x6000039)+0x218F, token(0x6000039)+0x21C4\n        and:\n          optional:\n            match: create or open registry key @ token(0x6000039)\n              or:\n                api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000039)+0x1FE8\n          or:\n            api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000039)+0x2000\n    or:\n      and:\n        regex: /SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Policies\\\\System/i\n          - \"SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Policies\\\\System\" @ token(0x6000039)+0x1FE2\n        or:\n          regex: /EnableLUA/i\n            - \"EnableLUA\" @ token(0x6000039)+0x1FF5\n\n(internal) .NET file limitation\nnamespace    internal/limitation/dynamic                        \nauthor       @v1bh475u                                          \nscope        file                                               \ndescription  This dynamic analysis trace describes a .NET file. \n                                                                \n             capa rules are not yet tuned for the .NET runtime, \n             so its analysis may be incomplete or misleading.   \n                                                                \nor:\n  format: dotnet\n\ncompile .NET assembly\nnamespace  load-code/dotnet                                                     \nauthor     anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information::Compile After      \n           Delivery [T1027.004]                                                 \nfunction @ token(0x600027A)\n  or:\n    api: System.CodeDom.Compiler.CodeDomProvider::CompileAssemblyFromSource @ token(0x600027A)+0x138\n\ninvoke .NET assembly method (2 matches)\nnamespace  load-code/dotnet                                     \nauthor     anushka.virgaonkar@mandiant.com, mehunhoff@google.com\nscope      function                                             \natt&ck     Defense Evasion::Reflective Code Loading [T1620]     \nfunction @ token(0x6000146)\n  and:\n    format: dotnet\n    or:\n      api: System.Reflection.MethodBase::Invoke @ token(0x6000146)+0x187, token(0x6000146)+0x19B, token(0x6000146)+0x1CB, \ntoken(0x6000146)+0x207, and 6 more...\n    optional:\n      api: System.Type::GetMethod @ token(0x6000146)+0x17F, token(0x6000146)+0x193, token(0x6000146)+0x1C3, \ntoken(0x6000146)+0x1F1, and 6 more...\nfunction @ token(0x600027A)\n  and:\n    format: dotnet\n    or:\n      api: System.Reflection.MethodBase::Invoke @ token(0x600027A)+0x2A8\n    optional:\n      api: System.Type::GetMethod @ token(0x600027A)+0x257\n\nload .NET assembly\nnamespace  load-code/dotnet                                \nauthor     anushka.virgaonkar@mandiant.com                 \nscope      function                                        \natt&ck     Defense Evasion::Reflective Code Loading [T1620]\nfunction @ token(0x6000146)\n  or:\n    api: System.Reflection.Assembly::LoadFrom @ token(0x6000146)+0x7A\n\ncompile CSharp in .NET\nnamespace  load-code/dotnet/csharp                                              \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information::Compile After      \n           Delivery [T1027.004]                                                 \nfunction @ token(0x600027A)\n  and:\n    match: compile .NET assembly @ token(0x600027A)\n      or:\n        api: System.CodeDom.Compiler.CodeDomProvider::CompileAssemblyFromSource @ token(0x600027A)+0x138\n    api: Microsoft.CSharp.CSharpCodeProvider::ctor @ token(0x600027A)+0x12\n\npersist via default file association registry key (2 matches)\nnamespace   persistence/registry                                                \nauthor      j.j.vannielen@utwente.nl                                            \nscope       function                                                            \natt&ck      Persistence::Event Triggered Execution::Change Default File         \n            Association [T1546.001]                                             \nreferences  https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/…\n            https://giuliocomi.blogspot.com/2019/10/abusing-windows-10-narrator…\nfunction @ token(0x600003E)\n  and:\n    match: set registry value @ token(0x600003E)\n      or:\n        and:\n          optional:\n            match: create or open registry key @ token(0x600003E)\n              or:\n                api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x600003E)+0x1C\n          or:\n            api: Microsoft.Win32.RegistryKey::SetValue @ token(0x600003E)+0x34, token(0x600003E)+0x45\n    or:\n      regex: /\\\\shell\\\\open\\\\command/i\n        - \"Software\\\\Classes\\\\ms-settings\\\\Shell\\\\Open\\\\command\" @ token(0x600003E)+0x10\nfunction @ token(0x600003E)\n  and:\n    match: set registry value @ token(0x600003E)\n      or:\n        and:\n          optional:\n            match: create or open registry key @ token(0x600003E)\n              or:\n                api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x600003E)+0x1C\n          or:\n            api: Microsoft.Win32.RegistryKey::SetValue @ token(0x600003E)+0x34, token(0x600003E)+0x45\n    or:\n      regex: /\\\\shell\\\\open\\\\command/i\n        - \"Software\\\\Classes\\\\ms-settings\\\\Shell\\\\Open\\\\command\" @ token(0x600003E)+0x10\n\npersist via Run registry key\nnamespace  persistence/registry/run                                             \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com                      \nscope      function                                                             \natt&ck     Persistence::Boot or Logon Autostart Execution::Registry Run Keys /  \n           Startup Folder [T1547.001]                                           \nmbc        Persistence::Registry Run Keys / Startup Folder [F0012]              \nfunction @ token(0x6000070)\n  and:\n    or:\n      match: set registry value @ token(0x6000070)\n        or:\n          and:\n            optional:\n              match: create or open registry key @ token(0x6000070)\n                or:\n                  api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x6000070)+0xA\n            or:\n              api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000070)+0x13\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\" @ token(0x6000070)+0x5\n\nschedule task via schtasks (2 matches)\nnamespace   persistence/scheduled-tasks                                         \nauthor      0x534a@mailbox.org, j.j.vannielen@utwente.nl                        \nscope       function                                                            \natt&ck      Persistence::Scheduled Task/Job::Scheduled Task [T1053.005]         \nreferences  https://learn.microsoft.com/en-us/windows/win32/taskschd/task-sched…\n            https://stmxcsr.com/persistence/scheduled-tasks.html                \nfunction @ token(0x600003A)\n  or:\n    and:\n      match: host-interaction/process/create @ token(0x600003A)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x600003A)+0x5F, token(0x600003A)+0xE0\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x600003A)+0x5F, token(0x600003A)+0xE0\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600003A)+0x4C, token(0x600003A)+0xCC\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600003A)+0x3E, token(0x600003A)+0xBE\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600003A)+0x21, token(0x600003A)+0x86\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600003A)+0x37, token(0x600003A)+0xB7\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600003A)+0x45, token(0x600003A)+0xC5\n              property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600003A)+0x53, token(0x600003A)+0xD3\n      or:\n        and:\n          regex: /schtasks/i\n            - \"schtasks.exe\" @ token(0x600003A)+0x1C, token(0x600003A)+0x81\n          or:\n            regex: /\\/create/i\n              - \"/create /tn \\\"\" @ token(0x600003A)+0x94\nfunction @ token(0x600003A)\n  or:\n    and:\n      match: host-interaction/process/create @ token(0x600003A)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x600003A)+0x5F, token(0x600003A)+0xE0\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x600003A)+0x5F, token(0x600003A)+0xE0\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600003A)+0x4C, token(0x600003A)+0xCC\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600003A)+0x3E, token(0x600003A)+0xBE\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600003A)+0x21, token(0x600003A)+0x86\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600003A)+0x37, token(0x600003A)+0xB7\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600003A)+0x45, token(0x600003A)+0xC5\n              property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600003A)+0x53, token(0x600003A)+0xD3\n      or:\n        and:\n          regex: /schtasks/i\n            - \"schtasks.exe\" @ token(0x600003A)+0x1C, token(0x600003A)+0x81\n          or:\n            regex: /\\/create/i\n              - \"/create /tn \\\"\" @ token(0x600003A)+0x94\n\nunmanaged call (42 matches)\nnamespace    runtime                                                       \nauthor       michael.hunhoff@mandiant.com                                  \nscope        function                                                      \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nfunction @ token(0x6000055)\n  or:\n    characteristic: unmanaged call @ token(0x6000055)+0x20, token(0x6000055)+0x8E, token(0x6000055)+0xFF, \ntoken(0x6000055)+0x12A, and 1 more...\nfunction @ token(0x6000063)\n  or:\n    characteristic: unmanaged call @ token(0x6000063)+0x22, token(0x6000063)+0x36, token(0x6000063)+0x3D\nfunction @ token(0x60000A5)\n  or:\n    characteristic: unmanaged call @ token(0x60000A5)+0x3C\nfunction @ token(0x60000A7)\n  or:\n    characteristic: unmanaged call @ token(0x60000A7)+0x16, token(0x60000A7)+0x1C\nfunction @ token(0x60000A8)\n  or:\n    characteristic: unmanaged call @ token(0x60000A8)+0x79\nfunction @ token(0x60000AA)\n  or:\n    characteristic: unmanaged call @ token(0x60000AA)+0xE9, token(0x60000AA)+0xFA\nfunction @ token(0x60000AF)\n  or:\n    characteristic: unmanaged call @ token(0x60000AF)+0x3A, token(0x60000AF)+0x42, token(0x60000AF)+0x51, \ntoken(0x60000AF)+0x66\nfunction @ token(0x60000C2)\n  or:\n    characteristic: unmanaged call @ token(0x60000C2)+0xA, token(0x60000C2)+0x10\nfunction @ token(0x60000C3)\n  or:\n    characteristic: unmanaged call @ token(0x60000C3)+0xA, token(0x60000C3)+0x10\nfunction @ token(0x60000C7)\n  or:\n    characteristic: unmanaged call @ token(0x60000C7)+0x23, token(0x60000C7)+0x4A\nfunction @ token(0x60000C8)\n  or:\n    characteristic: unmanaged call @ token(0x60000C8)+0x23, token(0x60000C8)+0x41\nfunction @ token(0x60000C9)\n  or:\n    characteristic: unmanaged call @ token(0x60000C9)+0xA, token(0x60000C9)+0x1A\nfunction @ token(0x60000CA)\n  or:\n    characteristic: unmanaged call @ token(0x60000CA)+0x9\nfunction @ token(0x60000CB)\n  or:\n    characteristic: unmanaged call @ token(0x60000CB)+0x9\nfunction @ token(0x60000D2)\n  or:\n    characteristic: unmanaged call @ token(0x60000D2)+0xC\nfunction @ token(0x60000D3)\n  or:\n    characteristic: unmanaged call @ token(0x60000D3)+0xC\nfunction @ token(0x60000D4)\n  or:\n    characteristic: unmanaged call @ token(0x60000D4)+0x1\nfunction @ token(0x60000D6)\n  or:\n    characteristic: unmanaged call @ token(0x60000D6)+0x13, token(0x60000D6)+0x26\nfunction @ token(0x60000D7)\n  or:\n    characteristic: unmanaged call @ token(0x60000D7)+0x12\nfunction @ token(0x60000DA)\n  or:\n    characteristic: unmanaged call @ token(0x60000DA)+0x3, token(0x60000DA)+0x4D, token(0x60000DA)+0x70\nfunction @ token(0x60000E5)\n  or:\n    characteristic: unmanaged call @ token(0x60000E5)+0x12, token(0x60000E5)+0x3D, token(0x60000E5)+0x5D, \ntoken(0x60000E5)+0x82\nfunction @ token(0x60000ED)\n  or:\n    characteristic: unmanaged call @ token(0x60000ED)+0x31\nfunction @ token(0x60000F4)\n  or:\n    characteristic: unmanaged call @ token(0x60000F4)+0x17\nfunction @ token(0x6000176)\n  or:\n    characteristic: unmanaged call @ token(0x6000176)+0x2\nfunction @ token(0x6000177)\n  or:\n    characteristic: unmanaged call @ token(0x6000177)+0x2, token(0x6000177)+0x31\nfunction @ token(0x6000178)\n  or:\n    characteristic: unmanaged call @ token(0x6000178)+0x2, token(0x6000178)+0x32\nfunction @ token(0x6000179)\n  or:\n    characteristic: unmanaged call @ token(0x6000179)+0x2, token(0x6000179)+0x27\nfunction @ token(0x600017A)\n  or:\n    characteristic: unmanaged call @ token(0x600017A)+0x9, token(0x600017A)+0x17, token(0x600017A)+0x25, \ntoken(0x600017A)+0x39, and 1 more...\nfunction @ token(0x600017B)\n  or:\n    characteristic: unmanaged call @ token(0x600017B)+0xF, token(0x600017B)+0x1A, token(0x600017B)+0x28, \ntoken(0x600017B)+0x36, and 1 more...\nfunction @ token(0x600017C)\n  or:\n    characteristic: unmanaged call @ token(0x600017C)+0x3CB, token(0x600017C)+0x3F6\nfunction @ token(0x60001A0)\n  or:\n    characteristic: unmanaged call @ token(0x60001A0)+0x18\nfunction @ token(0x60001A5)\n  or:\n    characteristic: unmanaged call @ token(0x60001A5)+0x48, token(0x60001A5)+0xF5, token(0x60001A5)+0x158\nfunction @ token(0x60001AD)\n  or:\n    characteristic: unmanaged call @ token(0x60001AD)+0x105, token(0x60001AD)+0x37D, token(0x60001AD)+0x39E, \ntoken(0x60001AD)+0x441, and 3 more...\nfunction @ token(0x60001AF)\n  or:\n    characteristic: unmanaged call @ token(0x60001AF)+0x52, token(0x60001AF)+0x7E\nfunction @ token(0x60001B0)\n  or:\n    characteristic: unmanaged call @ token(0x60001B0)+0x70, token(0x60001B0)+0xBB, token(0x60001B0)+0xFC, \ntoken(0x60001B0)+0x1D1, and 2 more...\nfunction @ token(0x60001B5)\n  or:\n    characteristic: unmanaged call @ token(0x60001B5)+0x21, token(0x60001B5)+0x43\nfunction @ token(0x60001B7)\n  or:\n    characteristic: unmanaged call @ token(0x60001B7)+0x20, token(0x60001B7)+0x5A, token(0x60001B7)+0x79, \ntoken(0x60001B7)+0xAD, and 7 more...\nfunction @ token(0x60001BA)\n  or:\n    characteristic: unmanaged call @ token(0x60001BA)+0x0, token(0x60001BA)+0x9, token(0x60001BA)+0x1A, \ntoken(0x60001BA)+0x22, and 2 more...\nfunction @ token(0x60001BB)\n  or:\n    characteristic: unmanaged call @ token(0x60001BB)+0x59, token(0x60001BB)+0x90, token(0x60001BB)+0xD7, \ntoken(0x60001BB)+0xFC, and 7 more...\nfunction @ token(0x60001CA)\n  or:\n    characteristic: unmanaged call @ token(0x60001CA)+0x39, token(0x60001CA)+0xAE, token(0x60001CA)+0xF1, \ntoken(0x60001CA)+0x142, and 5 more...\nfunction @ token(0x60001CB)\n  or:\n    characteristic: unmanaged call @ token(0x60001CB)+0x39, token(0x60001CB)+0xA8, token(0x60001CB)+0xEB, \ntoken(0x60001CB)+0x13C, and 8 more...\nfunction @ token(0x60001CC)\n  or:\n    characteristic: unmanaged call @ token(0x60001CC)+0x29, token(0x60001CC)+0x60, token(0x60001CC)+0x74, \ntoken(0x60001CC)+0x9B, and 7 more...\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  format: dotnet\n\n\n\n"},"hashes":{"md5":"9a5ff998dbf0f6923d0b454d89800fb4","sha1":"4f4fa23e9c503b941a5e91584d6ecc3813962ba1","sha256":"360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f1585432b28f"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 574</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 18525</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"360e6f2\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"9a5ff998dbf0f6923d0b454d89800fb4\",\n        \"sha256\": \"360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f15\",\n        \"arch\": \"any\",\n        \"os\": \"any\",\n        \"format\": \"dotnet\"\n      }\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_Microsoft\",\n      \"label\": \"Microsoft\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_self_delete__3_matches_\",\n      \"label\": \"self delete (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_System\",\n      \"label\": \"System\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_geographical_location\",\n      \"label\": \"get geographical location\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"cap_save_image_in__net\",\n      \"label\": \"save image in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_gather_firefox_profile_information\",\n      \"label\": \"gather firefox profile information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Credential Access::Credentials from Password Stores::Credentials from\",\n        \"Web Browsers [T1555.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______re_fox__still_teamt5_org\",\n      \"label\": \"author     @_re_fox, still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Credential Access::Credentials from Password Stores::Credentials from\",\n        \"Web Browsers [T1555.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_sql_statements__2_matches_\",\n      \"label\": \"reference SQL statements (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_wmi_statements\",\n      \"label\": \"reference WMI statements\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes__2_matches_\",\n      \"label\": \"log keystrokes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_MapVirtualKey\",\n      \"label\": \"MapVirtualKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_application_hook\",\n      \"label\": \"log keystrokes via application hook\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Application Hook [F0002.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_SetWindowsHookEx\",\n      \"label\": \"SetWindowsHookEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"label\": \"log keystrokes via polling (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"api_VkKeyScan\",\n      \"label\": \"VkKeyScan\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetKeyState\",\n      \"label\": \"GetKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_mac_address_in__net\",\n      \"label\": \"get MAC address in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_echernofsky_google_com\",\n      \"label\": \"echernofsky@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_capture_screenshot\",\n      \"label\": \"capture screenshot\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_data\",\n      \"label\": \"receive data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data\",\n      \"label\": \"send data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_manipulate_network_credentials_in__net\",\n      \"label\": \"manipulate network credentials in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_write_and_execute_a_file__4_matches_\",\n      \"label\": \"write and execute a file (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_maec_malware_category__launcher\",\n      \"label\": \"maec/malware-category  launcher\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_http_header\",\n      \"label\": \"read HTTP header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Read Header [C0002.014]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Read Header [C0002.014]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_http_user_agent_string\",\n      \"label\": \"reference HTTP User-Agent string\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication [C0002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______mr_tz\",\n      \"label\": \"author      @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication [C0002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_http_request\",\n      \"label\": \"create HTTP request\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_data_from_internet\",\n      \"label\": \"read data from Internet\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_http_response\",\n      \"label\": \"receive HTTP response\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_http_request\",\n      \"label\": \"send HTTP request\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Send Request [C0002.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Send Request [C0002.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_tcp_socket__3_matches_\",\n      \"label\": \"create TCP socket (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_act_as_tcp_client\",\n      \"label\": \"act as TCP client\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_zip_archive_in__net__3_matches_\",\n      \"label\": \"create zip archive in .NET (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_decode_data_using_base64_in__net\",\n      \"label\": \"decode data using Base64 in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decode Data::Base64 [C0053.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_decode_data_using_base64_via_winapi\",\n      \"label\": \"decode data using Base64 via WinAPI\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Deobfuscate/Decode Files or Information [T1140]\"\n      ]\n    },\n    {\n      \"id\": \"api_CryptStringToBinary\",\n      \"label\": \"CryptStringToBinary\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_reference_base64_string\",\n      \"label\": \"reference Base64 string\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Encode Data::Base64 [C0026.001]\",\n        \"Data::Check String [C0019]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_or_decrypt_data_via_bcrypt__2_matches_\",\n      \"label\": \"encrypt or decrypt data via BCrypt (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Decrypt Data [C0031]\",\n        \"Cryptography::Encrypt Data\",\n        \"[C0027]\"\n      ]\n    },\n    {\n      \"id\": \"api_BCryptCloseAlgorithmProvider\",\n      \"label\": \"BCryptCloseAlgorithmProvider\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_BCryptDestroyKey\",\n      \"label\": \"BCryptDestroyKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_BCryptGenerateSymmetricKey\",\n      \"label\": \"BCryptGenerateSymmetricKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_BCryptOpenAlgorithmProvider\",\n      \"label\": \"BCryptOpenAlgorithmProvider\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_BCryptDecrypt\",\n      \"label\": \"BCryptDecrypt\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_dpapi\",\n      \"label\": \"encrypt data using DPAPI\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data [C0027]\"\n      ]\n    },\n    {\n      \"id\": \"api_CryptUnprotectData\",\n      \"label\": \"CryptUnprotectData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_in__net\",\n      \"label\": \"generate random numbers in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contains_pdb_path\",\n      \"label\": \"contains PDB path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_check_clipboard_data__2_matches_\",\n      \"label\": \"check clipboard data (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_monitor_clipboard_content\",\n      \"label\": \"monitor clipboard content\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"api_AddClipboardFormatListener\",\n      \"label\": \"AddClipboardFormatListener\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_clipboard_data__2_matches_\",\n      \"label\": \"read clipboard data (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_manipulate_console_buffer__8_matches_\",\n      \"label\": \"manipulate console buffer (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Console [C0033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Console [C0033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable__3_matches_\",\n      \"label\": \"query environment variable (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_drives\",\n      \"label\": \"enumerate drives\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__7_matches_\",\n      \"label\": \"get common file path (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_copy_file__7_matches_\",\n      \"label\": \"copy file (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory__8_matches_\",\n      \"label\": \"create directory (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_directory__2_matches_\",\n      \"label\": \"delete directory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_file__12_matches_\",\n      \"label\": \"delete file (12 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_directory_exists__15_matches_\",\n      \"label\": \"check if directory exists (15 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__22_matches_\",\n      \"label\": \"check if file exists (22 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_in__net__6_matches_\",\n      \"label\": \"enumerate files in .NET (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes\",\n      \"label\": \"get file attributes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size__5_matches_\",\n      \"label\": \"get file size (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_file_attributes__2_matches_\",\n      \"label\": \"set file attributes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"cap_move_file__2_matches_\",\n      \"label\": \"move file (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__7_matches_\",\n      \"label\": \"read file on Windows (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__11_matches_\",\n      \"label\": \"write file on Windows (11 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_gui_resources__2_matches_\",\n      \"label\": \"enumerate gui resources (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     johnk3r, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_application_hook__2_matches_\",\n      \"label\": \"set application hook (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_UnhookWindowsHookEx\",\n      \"label\": \"UnhookWindowsHookEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_change_the_wallpaper\",\n      \"label\": \"change the wallpaper\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Wallpaper [C0035]\"\n      ]\n    },\n    {\n      \"id\": \"api_SystemParametersInfo\",\n      \"label\": \"SystemParametersInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox\",\n      \"label\": \"author     @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Wallpaper [C0035]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_taskbar__3_matches_\",\n      \"label\": \"find taskbar (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Taskbar Discovery [B0043]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindWindow\",\n      \"label\": \"FindWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_hide_the_windows_taskbar\",\n      \"label\": \"hide the Windows taskbar\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Hide Artifacts [T1564]\"\n      ]\n    },\n    {\n      \"id\": \"api_ShowWindow\",\n      \"label\": \"ShowWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_find_graphical_window__3_matches_\",\n      \"label\": \"find graphical window (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hide_graphical_window\",\n      \"label\": \"hide graphical window\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_disk_information\",\n      \"label\": \"get disk information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_disk_size\",\n      \"label\": \"get disk size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_allocate_unmanaged_memory_in__net__3_matches_\",\n      \"label\": \"allocate unmanaged memory in .NET (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_manipulate_unmanaged_memory_in__net__14_matches_\",\n      \"label\": \"manipulate unmanaged memory in .NET (14 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_or_open_mutex_on_windows\",\n      \"label\": \"create or open mutex on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_mehunhoff_google_com\",\n      \"label\": \"mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_networking_interfaces\",\n      \"label\": \"get networking interfaces\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Network Configuration Discovery [T1016]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_hostname__2_matches_\",\n      \"label\": \"get hostname (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetComputerName\",\n      \"label\": \"GetComputerName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_os_version_in__net\",\n      \"label\": \"get OS version in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_process_image_filename__5_matches_\",\n      \"label\": \"get process image filename (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_a_process_with_modified_i_o_handles_and_window__14_matches_\",\n      \"label\": \"create a process with modified I/O handles and window (14 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__22_matches_\",\n      \"label\": \"create process on Windows (22 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_processes__2_matches_\",\n      \"label\": \"enumerate processes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\",\n        \"Discovery::Software Discovery\",\n        \"[T1518]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_process_by_pid__2_matches_\",\n      \"label\": \"find process by PID (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_process_by_name\",\n      \"label\": \"find process by name\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\"\n      ]\n    },\n    {\n      \"id\": \"cap_acquire_debug_privileges\",\n      \"label\": \"acquire debug privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"api_AdjustTokenPrivileges\",\n      \"label\": \"AdjustTokenPrivileges\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_modify_access_privileges\",\n      \"label\": \"modify access privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process__14_matches_\",\n      \"label\": \"terminate process (14 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key__7_matches_\",\n      \"label\": \"query or enumerate registry key (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"label\": \"query or enumerate registry value (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_registry_value__5_matches_\",\n      \"label\": \"set registry value (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_key\",\n      \"label\": \"delete registry key\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_value__2_matches_\",\n      \"label\": \"delete registry value (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_session_integrity_level__3_matches_\",\n      \"label\": \"get session integrity level (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_session_user_name__5_matches_\",\n      \"label\": \"get session user name (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\",\n        \"Discovery::Account\",\n        \"Discovery [T1087]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_thread__3_matches_\",\n      \"label\": \"create thread (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_suspend_thread__9_matches_\",\n      \"label\": \"suspend thread (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Suspend Thread [C0055]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Suspend Thread [C0055]\"\n      ]\n    },\n    {\n      \"id\": \"cap_access_wmi_data_in__net\",\n      \"label\": \"access WMI data in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Windows Management Instrumentation [T1047]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_cryptocurrency_strings\",\n      \"label\": \"reference cryptocurrency strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Resource Hijacking [T1496]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Resource Hijacking [T1496]\"\n      ]\n    },\n    {\n      \"id\": \"cap_disable_system_features_via_registry_on_windows\",\n      \"label\": \"disable system features via registry on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Disable or Evade Security Tools [F0004]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____mehunhoff_google_com\",\n      \"label\": \"author     mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Disable or Evade Security Tools [F0004]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal___net_file_limitation\",\n      \"label\": \"(internal) .NET file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author________v1bh475u\",\n      \"label\": \"author       @v1bh475u\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compile__net_assembly\",\n      \"label\": \"compile .NET assembly\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Compile After\",\n        \"Delivery [T1027.004]\"\n      ]\n    },\n    {\n      \"id\": \"cap_invoke__net_assembly_method__2_matches_\",\n      \"label\": \"invoke .NET assembly method (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_load__net_assembly\",\n      \"label\": \"load .NET assembly\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_compile_csharp_in__net\",\n      \"label\": \"compile CSharp in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Compile After\",\n        \"Delivery [T1027.004]\"\n      ]\n    },\n    {\n      \"id\": \"cap_persist_via_default_file_association_registry_key__2_matches_\",\n      \"label\": \"persist via default file association registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Event Triggered Execution::Change Default File\",\n        \"Association [T1546.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______j_j_vannielen_utwente_nl\",\n      \"label\": \"author      j.j.vannielen@utwente.nl\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Event Triggered Execution::Change Default File\",\n        \"Association [T1546.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_persist_via_run_registry_key\",\n      \"label\": \"persist via Run registry key\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Registry Run Keys / Startup Folder [F0012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Registry Run Keys / Startup Folder [F0012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_schedule_task_via_schtasks__2_matches_\",\n      \"label\": \"schedule task via schtasks (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Scheduled Task/Job::Scheduled Task [T1053.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______0x534a_mailbox_org__j_j_vannielen_utwente_nl\",\n      \"label\": \"author      0x534a@mailbox.org, j.j.vannielen@utwente.nl\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Scheduled Task/Job::Scheduled Task [T1053.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_unmanaged_call__42_matches_\",\n      \"label\": \"unmanaged call (42 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"label\": \"author       michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compiled_to_the__net_platform\",\n      \"label\": \"compiled to the .NET platform\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_self_delete__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_geographical_location\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_save_image_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_gather_firefox_profile_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_sql_statements__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_wmi_statements\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_application_hook\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_mac_address_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_echernofsky_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_capture_screenshot\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_manipulate_network_credentials_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_and_execute_a_file__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_maec_malware_category__launcher\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_http_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_http_user_agent_string\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_http_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_data_from_internet\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_http_response\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_http_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_tcp_socket__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_act_as_tcp_client\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_zip_archive_in__net__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decode_data_using_base64_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decode_data_using_base64_via_winapi\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_base64_string\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_or_decrypt_data_via_bcrypt__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_dpapi\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contains_pdb_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_clipboard_data__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_monitor_clipboard_content\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_clipboard_data__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_manipulate_console_buffer__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_drives\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__12_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_directory_exists__15_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__22_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_in__net__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_move_file__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__11_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_gui_resources__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_application_hook__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_change_the_wallpaper\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_taskbar__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hide_the_windows_taskbar\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_graphical_window__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hide_graphical_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_unmanaged_memory_in__net__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_manipulate_unmanaged_memory_in__net__14_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_mutex_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_networking_interfaces\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_process_image_filename__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_a_process_with_modified_i_o_handles_and_window__14_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__22_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_processes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_process_by_pid__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_process_by_name\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_acquire_debug_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_modify_access_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process__14_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_integrity_level__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_user_name__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_suspend_thread__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_wmi_data_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_cryptocurrency_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_disable_system_features_via_registry_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal___net_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________v1bh475u\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compile__net_assembly\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_invoke__net_assembly_method__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_load__net_assembly\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compile_csharp_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_persist_via_default_file_association_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______j_j_vannielen_utwente_nl\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_persist_via_run_registry_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_schedule_task_via_schtasks__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______0x534a_mailbox_org__j_j_vannielen_utwente_nl\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_unmanaged_call__42_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_to_the__net_platform\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-04-23 00:40:18.704360\",\n    \"total_functions\": \"574\",\n    \"total_features\": \"18525\",\n    \"pdb_path\": \"C:\\\\\\\\Users\\\\\\\\sulum\\\\\\\\OneDrive\\\\\\\\Desktop\\\\\\\\datacenter\\\\\\\\stubCsharp\\\\\\\\obj\\\\\\\\Release\\\\\\\\Clie\\nnt.pdb\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-04-23 00:40:20"}
{"_id":{"$oid":"69e9ba7159a6632dae07de1f"},"sha256":"360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f1585432b28f","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_91b8xti6/now_you_see_me_again.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_91b8xti6/now_you_see_me_again.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_91b8xti6/now_you_see_me_again.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 9a5ff998dbf0f6923d0b454d89800fb4                                  │\n│ sha1     │ 4f4fa23e9c503b941a5e91584d6ecc3813962ba1                          │\n│ sha256   │ 360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f1585432b28f  │\n│ analysis │ static                                                            │\n│ os       │ any                                                               │\n│ format   │ dotnet                                                            │\n│ arch     │ any                                                               │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/now_you_see_me_a… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Clipboard Data [T1115]                                │\n│                      │ Data from Information Repositories [T1213]            │\n│                      │ Input Capture::Keylogging [T1056.001]                 │\n│                      │ Screen Capture [T1113]                                │\n│ CREDENTIAL ACCESS    │ Credentials from Password Stores::Credentials from    │\n│                      │ Web Browsers [T1555.003]                              │\n│ DEFENSE EVASION      │ Deobfuscate/Decode Files or Information [T1140]       │\n│                      │ File and Directory Permissions Modification [T1222]   │\n│                      │ Hide Artifacts [T1564]                                │\n│                      │ Hide Artifacts::Hidden Window [T1564.003]             │\n│                      │ Impair Defenses::Disable or Modify Tools [T1562.001]  │\n│                      │ Indicator Removal::File Deletion [T1070.004]          │\n│                      │ Modify Registry [T1112]                               │\n│                      │ Obfuscated Files or Information [T1027]               │\n│                      │ Obfuscated Files or Information::Compile After        │\n│                      │ Delivery [T1027.004]                                  │\n│                      │ Reflective Code Loading [T1620]                       │\n│ DISCOVERY            │ Account Discovery [T1087]                             │\n│                      │ Application Window Discovery [T1010]                  │\n│                      │ File and Directory Discovery [T1083]                  │\n│                      │ Process Discovery [T1057]                             │\n│                      │ Query Registry [T1012]                                │\n│                      │ Software Discovery [T1518]                            │\n│                      │ System Information Discovery [T1082]                  │\n│                      │ System Location Discovery [T1614]                     │\n│                      │ System Network Configuration Discovery [T1016]        │\n│                      │ System Owner/User Discovery [T1033]                   │\n│ EXECUTION            │ Windows Management Instrumentation [T1047]            │\n│ IMPACT               │ Resource Hijacking [T1496]                            │\n│ PERSISTENCE          │ Boot or Logon Autostart Execution::Registry Run Keys  │\n│                      │ / Startup Folder [T1547.001]                          │\n│                      │ Event Triggered Execution::Change Default File        │\n│                      │ Association [T1546.001]                               │\n│                      │ Scheduled Task/Job::Scheduled Task [T1053.005]        │\n│ PRIVILEGE ESCALATION │ Access Token Manipulation [T1134]                     │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MAEC Category                                    ┃ MAEC Value                ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ malware-category                                 │ launcher                  │\n└──────────────────────────────────────────────────┴───────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Keylogging::Application Hook [F0002.001]              │\n│                      │ Keylogging::Polling [F0002.002]                       │\n│                      │ Screen Capture::WinAPI [E1113.m01]                    │\n│ COMMAND AND CONTROL  │ C2 Communication::Receive Data [B0030.002]            │\n│                      │ C2 Communication::Send Data [B0030.001]               │\n│ COMMUNICATION        │ HTTP Communication [C0002]                            │\n│                      │ HTTP Communication::Create Request [C0002.012]        │\n│                      │ HTTP Communication::Get Response [C0002.017]          │\n│                      │ HTTP Communication::Read Header [C0002.014]           │\n│                      │ HTTP Communication::Send Request [C0002.003]          │\n│                      │ Socket Communication::Create TCP Socket [C0001.011]   │\n│                      │ Socket Communication::TCP Client [C0001.008]          │\n│ CRYPTOGRAPHY         │ Decrypt Data [C0031]                                  │\n│                      │ Encrypt Data [C0027]                                  │\n│                      │ Generate Pseudo-random Sequence::Use API [C0021.003]  │\n│ DATA                 │ Check String [C0019]                                  │\n│                      │ Decode Data::Base64 [C0053.001]                       │\n│                      │ Encode Data::Base64 [C0026.001]                       │\n│ DEFENSE EVASION      │ Disable or Evade Security Tools [F0004]               │\n│                      │ Self Deletion::COMSPEC Environment Variable           │\n│                      │ [F0007.001]                                           │\n│ DISCOVERY            │ File and Directory Discovery [E1083]                  │\n│                      │ System Information Discovery [E1082]                  │\n│                      │ Taskbar Discovery [B0043]                             │\n│ FILE SYSTEM          │ Copy File [C0045]                                     │\n│                      │ Create Directory [C0046]                              │\n│                      │ Delete Directory [C0048]                              │\n│                      │ Delete File [C0047]                                   │\n│                      │ Get File Attributes [C0049]                           │\n│                      │ Move File [C0063]                                     │\n│                      │ Read File [C0051]                                     │\n│                      │ Set File Attributes [C0050]                           │\n│                      │ Writes File [C0052]                                   │\n│ OPERATING SYSTEM     │ Console [C0033]                                       │\n│                      │ Registry::Delete Registry Key [C0036.002]             │\n│                      │ Registry::Delete Registry Value [C0036.007]           │\n│                      │ Registry::Query Registry Key [C0036.005]              │\n│                      │ Registry::Query Registry Value [C0036.006]            │\n│                      │ Registry::Set Registry Key [C0036.001]                │\n│                      │ Wallpaper [C0035]                                     │\n│ PERSISTENCE          │ Registry Run Keys / Startup Folder [F0012]            │\n│ PROCESS              │ Create Mutex [C0042]                                  │\n│                      │ Create Process [C0017]                                │\n│                      │ Create Thread [C0038]                                 │\n│                      │ Suspend Thread [C0055]                                │\n│                      │ Terminate Process [C0018]                             │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ self delete (3 matches)               │ anti-analysis/anti-forensic/self-de… │\n│ get geographical location             │ collection                           │\n│ save image in .NET                    │ collection                           │\n│ gather firefox profile information    │ collection/browser                   │\n│ reference SQL statements (2 matches)  │ collection/database/sql              │\n│ reference WMI statements              │ collection/database/wmi              │\n│ log keystrokes (2 matches)            │ collection/keylog                    │\n│ log keystrokes via application hook   │ collection/keylog                    │\n│ log keystrokes via polling (2         │ collection/keylog                    │\n│ matches)                              │                                      │\n│ get MAC address in .NET               │ collection/network                   │\n│ capture screenshot                    │ collection/screenshot                │\n│ receive data                          │ communication                        │\n│ send data                             │ communication                        │\n│ manipulate network credentials in     │ communication/authentication         │\n│ .NET                                  │                                      │\n│ read HTTP header                      │ communication/http                   │\n│ reference HTTP User-Agent string      │ communication/http                   │\n│ create HTTP request                   │ communication/http/client            │\n│ receive HTTP response                 │ communication/http/client            │\n│ create TCP socket (3 matches)         │ communication/socket/tcp             │\n│ act as TCP client                     │ communication/tcp/client             │\n│ create zip archive in .NET (3         │ data-manipulation/compression        │\n│ matches)                              │                                      │\n│ decode data using Base64 in .NET      │ data-manipulation/encoding/base64    │\n│ decode data using Base64 via WinAPI   │ data-manipulation/encoding/base64    │\n│ reference Base64 string               │ data-manipulation/encoding/base64    │\n│ encrypt or decrypt data via BCrypt (2 │ data-manipulation/encryption         │\n│ matches)                              │                                      │\n│ encrypt data using DPAPI              │ data-manipulation/encryption/dpapi   │\n│ generate random numbers in .NET       │ data-manipulation/prng               │\n│ contains PDB path                     │ executable/pe/pdb                    │\n│ extract resource via kernel32         │ executable/resource                  │\n│ functions                             │                                      │\n│ check clipboard data (2 matches)      │ host-interaction/clipboard           │\n│ monitor clipboard content             │ host-interaction/clipboard           │\n│ read clipboard data (2 matches)       │ host-interaction/clipboard           │\n│ manipulate console buffer (8 matches) │ host-interaction/console             │\n│ query environment variable (3         │ host-interaction/environment-variab… │\n│ matches)                              │                                      │\n│ enumerate drives                      │ host-interaction/file-system         │\n│ get common file path (7 matches)      │ host-interaction/file-system         │\n│ copy file (7 matches)                 │ host-interaction/file-system/copy    │\n│ create directory (8 matches)          │ host-interaction/file-system/create  │\n│ delete directory (2 matches)          │ host-interaction/file-system/delete  │\n│ delete file (12 matches)              │ host-interaction/file-system/delete  │\n│ check if directory exists (15         │ host-interaction/file-system/exists  │\n│ matches)                              │                                      │\n│ check if file exists (22 matches)     │ host-interaction/file-system/exists  │\n│ enumerate files in .NET (6 matches)   │ host-interaction/file-system/files/… │\n│ get file attributes                   │ host-interaction/file-system/meta    │\n│ get file size (5 matches)             │ host-interaction/file-system/meta    │\n│ set file attributes (2 matches)       │ host-interaction/file-system/meta    │\n│ move file (2 matches)                 │ host-interaction/file-system/move    │\n│ read file on Windows (7 matches)      │ host-interaction/file-system/read    │\n│ write file on Windows (11 matches)    │ host-interaction/file-system/write   │\n│ enumerate gui resources (2 matches)   │ host-interaction/gui                 │\n│ change the wallpaper                  │ host-interaction/gui/session         │\n│ hide the Windows taskbar              │ host-interaction/gui/taskbar/hide    │\n│ get disk information                  │ host-interaction/hardware/storage    │\n│ get disk size                         │ host-interaction/hardware/storage    │\n│ allocate unmanaged memory in .NET (3  │ host-interaction/memory              │\n│ matches)                              │                                      │\n│ manipulate unmanaged memory in .NET   │ host-interaction/memory              │\n│ (14 matches)                          │                                      │\n│ create or open mutex on Windows       │ host-interaction/mutex               │\n│ get networking interfaces             │ host-interaction/network/interface   │\n│ get hostname (2 matches)              │ host-interaction/os/hostname         │\n│ get OS version in .NET                │ host-interaction/os/version          │\n│ get process image filename (5         │ host-interaction/process             │\n│ matches)                              │                                      │\n│ create a process with modified I/O    │ host-interaction/process/create      │\n│ handles and window (14 matches)       │                                      │\n│ create process on Windows (22         │ host-interaction/process/create      │\n│ matches)                              │                                      │\n│ enumerate processes (2 matches)       │ host-interaction/process/list        │\n│ find process by PID (2 matches)       │ host-interaction/process/list        │\n│ find process by name                  │ host-interaction/process/list        │\n│ acquire debug privileges              │ host-interaction/process/modify      │\n│ terminate process (14 matches)        │ host-interaction/process/terminate   │\n│ query or enumerate registry key (7    │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ query or enumerate registry value (2  │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ delete registry key                   │ host-interaction/registry/delete     │\n│ delete registry value (2 matches)     │ host-interaction/registry/delete     │\n│ get session integrity level (3        │ host-interaction/session             │\n│ matches)                              │                                      │\n│ get session user name (5 matches)     │ host-interaction/session             │\n│ create thread (3 matches)             │ host-interaction/thread/create       │\n│ suspend thread (9 matches)            │ host-interaction/thread/suspend      │\n│ access WMI data in .NET               │ host-interaction/wmi                 │\n│ reference cryptocurrency strings      │ impact/cryptocurrency                │\n│ disable system features via registry  │ impact/features                      │\n│ on Windows                            │                                      │\n│ invoke .NET assembly method (2        │ load-code/dotnet                     │\n│ matches)                              │                                      │\n│ load .NET assembly                    │ load-code/dotnet                     │\n│ compile CSharp in .NET                │ load-code/dotnet/csharp              │\n│ persist via default file association  │ persistence/registry                 │\n│ registry key (2 matches)              │                                      │\n│ persist via Run registry key          │ persistence/registry/run             │\n│ schedule task via schtasks (2         │ persistence/scheduled-tasks          │\n│ matches)                              │                                      │\n│ unmanaged call (42 matches)           │ runtime                              │\n│ compiled to the .NET platform         │ runtime/dotnet                       │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     9a5ff998dbf0f6923d0b454d89800fb4                        \nsha1                    4f4fa23e9c503b941a5e91584d6ecc3813962ba1                \nsha256                  360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f15…\npath                    /home/apogean/projects/malware/windows/all_runs/now_you…\ntimestamp               2026-04-29 20:28:51.566739                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    any                                                     \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIT45nxl/rules                                   \nfunction count          574                                                     \nlibrary function count  0                                                       \ntotal feature count     18525                                                   \n\nself delete (3 matches)\nnamespace  anti-analysis/anti-forensic/self-deletion\nscope      function                                 \nmatches    token(0x6000039)                         \n           token(0x600003E)                         \n           token(0x600003E)                         \n\nget geographical location\nnamespace  collection      \nscope      function        \nmatches    token(0x600004C)\n\nsave image in .NET\nnamespace  collection      \nscope      function        \nmatches    token(0x6000054)\n\ngather firefox profile information\nnamespace  collection/browser\nscope      function          \nmatches    token(0x60001CC)  \n\nreference SQL statements (2 matches)\nnamespace  collection/database/sql\nscope      function               \nmatches    token(0x6000147)       \n           token(0x600015B)       \n\nreference WMI statements\nnamespace  collection/database/wmi\nscope      function               \nmatches    token(0x600004B)       \n\nlog keystrokes (2 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    token(0x600017A) \n           token(0x600017B) \n\nlog keystrokes via application hook\nnamespace  collection/keylog\nscope      basic block      \nmatches    token(0x60000A7) \n\nlog keystrokes via polling (2 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    token(0x60000AA) \n           token(0x600017C) \n\nget MAC address in .NET\nnamespace  collection/network\nscope      function          \nmatches    token(0x600011C)  \n\ncapture screenshot\nnamespace  collection/screenshot\nscope      function             \nmatches    token(0x6000054)     \n\nreceive data\nnamespace    communication                                                     \ndescription  all known techniques for receiving data from a potential C2 server\nscope        function                                                          \nmatches      token(0x600004C)                                                  \n\nsend data\nnamespace    communication                                                 \ndescription  all known techniques for sending data to a potential C2 server\nscope        function                                                      \nmatches      token(0x60001BF)                                              \n\nmanipulate network credentials in .NET\nnamespace  communication/authentication\nscope      function                    \nmatches    token(0x60001BF)            \n\nread HTTP header\nnamespace  communication/http\nscope      function          \nmatches    token(0x600004C)  \n\nreference HTTP User-Agent string\nnamespace  communication/http\nscope      function          \nmatches    token(0x600004C)  \n\ncreate HTTP request\nnamespace  communication/http/client\nscope      function                 \nmatches    token(0x60001BF)         \n\nread data from Internet\nnamespace  communication/http/client\nscope      function                 \nmatches    token(0x600004C)         \n\nreceive HTTP response\nnamespace  communication/http/client\nscope      function                 \nmatches    token(0x60001BF)         \n\nsend HTTP request\nnamespace  communication/http/client\nscope      function                 \nmatches    token(0x60001BF)         \n\ncreate TCP socket (3 matches)\nnamespace  communication/socket/tcp\nscope      basic block             \nmatches    token(0x600000C)        \n           token(0x600000E)        \n           token(0x6000014)        \n\nact as TCP client\nnamespace  communication/tcp/client\nscope      function                \nmatches    token(0x600000E)        \n\ncreate zip archive in .NET (3 matches)\nnamespace  data-manipulation/compression\nscope      basic block                  \nmatches    token(0x60000B8)             \n           token(0x60000BB)             \n           token(0x60001BC)             \n\ndecode data using Base64 in .NET\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    token(0x60001B5)                 \n\ndecode data using Base64 via WinAPI\nnamespace  data-manipulation/encoding/base64\nscope      basic block                      \nmatches    token(0x60001B5)                 \n\nreference Base64 string\nnamespace  data-manipulation/encoding/base64\nscope      file                             \n\nencrypt or decrypt data via BCrypt (2 matches)\nnamespace  data-manipulation/encryption\nscope      function                    \nmatches    token(0x60001AD)            \n           token(0x60001B0)            \n\nencrypt data using DPAPI\nnamespace  data-manipulation/encryption/dpapi\nscope      function                          \nmatches    token(0x60001AF)                  \n\ngenerate random numbers in .NET\nnamespace  data-manipulation/prng\nscope      function              \nmatches    token(0x600003E)      \n\ncontains PDB path\nnamespace  executable/pe/pdb\nscope      file             \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    token(0x60000E5)   \n\ncheck clipboard data (2 matches)\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    token(0x60000EE)          \n           token(0x600024C)          \n\nmonitor clipboard content\nnamespace  host-interaction/clipboard\nscope      basic block               \nmatches    token(0x60000F4)          \n\nread clipboard data (2 matches)\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    token(0x60000EE)          \n           token(0x600024C)          \n\nmanipulate console buffer (8 matches)\nnamespace  host-interaction/console\nscope      function                \nmatches    token(0x6000019)        \n           token(0x6000029)        \n           token(0x6000033)        \n           token(0x6000044)        \n           token(0x600014A)        \n           token(0x600015E)        \n           token(0x6000181)        \n           token(0x6000182)        \n\nquery environment variable (3 matches)\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    token(0x6000095)                     \n           token(0x60001A1)                     \n           token(0x60001AB)                     \n\nenumerate drives\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x6000093)            \n\nget common file path (7 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x600004E)            \n           token(0x60000B7)            \n           token(0x60000F8)            \n           token(0x60000FA)            \n           token(0x6000146)            \n           token(0x6000149)            \n           token(0x600015D)            \n\ncopy file (7 matches)\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    token(0x60000BC)                 \n           token(0x6000144)                 \n           token(0x6000159)                 \n           token(0x60001A5)                 \n           token(0x60001A6)                 \n           token(0x60001AB)                 \n           token(0x60001BF)                 \n\ncreate directory (8 matches)\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    token(0x6000097)                   \n           token(0x6000098)                   \n           token(0x60000B8)                   \n           token(0x60000BB)                   \n           token(0x60000BC)                   \n           token(0x6000144)                   \n           token(0x6000159)                   \n           token(0x60001A0)                   \n\ndelete directory (2 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    token(0x60000B8)                   \n           token(0x60000BB)                   \n\ndelete file (12 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    token(0x60000B8)                   \n           token(0x60000BB)                   \n           token(0x6000144)                   \n           token(0x6000147)                   \n           token(0x6000159)                   \n           token(0x600015B)                   \n           token(0x60001A8)                   \n           token(0x60001A9)                   \n           token(0x60001AA)                   \n           token(0x60001AB)                   \n           token(0x60001BC)                   \n           token(0x60001BF)                   \n\ncheck if directory exists (15 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x600004E)                   \n           token(0x6000095)                   \n           token(0x6000097)                   \n           token(0x6000098)                   \n           token(0x60000B7)                   \n           token(0x60000B8)                   \n           token(0x60000BC)                   \n           token(0x6000144)                   \n           token(0x6000149)                   \n           token(0x6000159)                   \n           token(0x600015D)                   \n           token(0x60001A7)                   \n           token(0x60001A9)                   \n           token(0x60001AB)                   \n           token(0x600021B)                   \n\ncheck if file exists (22 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x6000095)                   \n           token(0x6000096)                   \n           token(0x60000D6)                   \n           token(0x60000D7)                   \n           token(0x60000F8)                   \n           token(0x60000FA)                   \n           token(0x6000144)                   \n           token(0x6000146)                   \n           token(0x6000149)                   \n           token(0x6000159)                   \n           token(0x600015D)                   \n           token(0x60001A6)                   \n           token(0x60001A7)                   \n           token(0x60001A8)                   \n           token(0x60001A9)                   \n           token(0x60001AA)                   \n           token(0x60001AB)                   \n           token(0x60001BC)                   \n           token(0x60001BD)                   \n           token(0x60001BF)                   \n           token(0x600026B)                   \n           token(0x600026F)                   \n\nenumerate files in .NET (6 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    token(0x60000BC)                       \n           token(0x6000149)                       \n           token(0x600015D)                       \n           token(0x60001A7)                       \n           token(0x60001A9)                       \n           token(0x60001AB)                       \n\nget file attributes\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    token(0x6000095)                 \n\nget file size (5 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    token(0x6000095)                 \n           token(0x60001A5)                 \n           token(0x60001A8)                 \n           token(0x60001AA)                 \n           token(0x600026B)                 \n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    token(0x600003C)                 \n           token(0x60001BF)                 \n\nmove file (2 matches)\nnamespace  host-interaction/file-system/move\nscope      function                         \nmatches    token(0x6000144)                 \n           token(0x6000159)                 \n\nread file on Windows (7 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    token(0x6000096)                 \n           token(0x60000B8)                 \n           token(0x60000BB)                 \n           token(0x60001A5)                 \n           token(0x60001AC)                 \n           token(0x60001AD)                 \n           token(0x60001BD)                 \n\nwrite file on Windows (11 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    token(0x6000019)                  \n           token(0x6000044)                  \n           token(0x6000097)                  \n           token(0x60000BB)                  \n           token(0x60000DD)                  \n           token(0x6000147)                  \n           token(0x600014A)                  \n           token(0x600015B)                  \n           token(0x600015E)                  \n           token(0x60001A5)                  \n           token(0x60001E8)                  \n\nenumerate gui resources (2 matches)\nnamespace  host-interaction/gui\nscope      function            \nmatches    token(0x600004D)    \n           token(0x6000054)    \n\nset application hook (2 matches)\nnamespace  host-interaction/gui \nscope      instruction          \nmatches    token(0x60000A7)+0x1C\n           token(0x60000AF)+0x66\n\nchange the wallpaper\nnamespace  host-interaction/gui/session\nscope      basic block                 \nmatches    token(0x60000D7)            \n\nfind taskbar (3 matches)\nnamespace  host-interaction/gui/taskbar/find\nscope      basic block                      \nmatches    token(0x60000C2)                 \n           token(0x60000C3)                 \n           token(0x60000C9)                 \n\nhide the Windows taskbar\nnamespace  host-interaction/gui/taskbar/hide\nscope      function                         \nmatches    token(0x60000C2)                 \n\nfind graphical window (3 matches)\nnamespace  host-interaction/gui/window/find\nscope      instruction                     \nmatches    token(0x60000C2)+0xA            \n           token(0x60000C3)+0xA            \n           token(0x60000C9)+0xA            \n\nhide graphical window\nnamespace  host-interaction/gui/window/hide\nscope      basic block                     \nmatches    token(0x60000C2)                \n\nget disk information\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    token(0x6000093)                 \n\nget disk size\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    token(0x6000093)                 \n\nallocate unmanaged memory in .NET (3 matches)\nnamespace  host-interaction/memory\nscope      function               \nmatches    token(0x60001AD)       \n           token(0x60001AF)       \n           token(0x60001B0)       \n\nmanipulate unmanaged memory in .NET (14 matches)\nnamespace  host-interaction/memory\nscope      function               \nmatches    token(0x6000055)       \n           token(0x60000A8)       \n           token(0x60000C7)       \n           token(0x60000C8)       \n           token(0x60000D7)       \n           token(0x60000E5)       \n           token(0x60001A5)       \n           token(0x60001AD)       \n           token(0x60001AF)       \n           token(0x60001B0)       \n           token(0x60001BB)       \n           token(0x60001CA)       \n           token(0x60001CB)       \n           token(0x60001CC)       \n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex\nscope      instruction           \nmatches    token(0x6000033)+0x211\n\nget networking interfaces\nnamespace  host-interaction/network/interface\nscope      function                          \nmatches    token(0x600011C)                  \n\nget hostname (2 matches)\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    token(0x6000049)            \n           token(0x60001A0)            \n\nget OS version in .NET\nnamespace  host-interaction/os/version\nscope      basic block                \nmatches    token(0x600004B)           \n\nget process image filename (5 matches)\nnamespace  host-interaction/process\nscope      basic block             \nmatches    token(0x6000033)        \n           token(0x600003A)        \n           token(0x600003C)        \n           token(0x600003E)        \n           token(0x60001E8)        \n\ncreate a process with modified I/O handles and window (14 matches)\nnamespace  host-interaction/process/create\nscope      function                       \nmatches    token(0x6000033)               \n           token(0x600003A)               \n           token(0x600003B)               \n           token(0x600003E)               \n           token(0x60000F7)               \n           token(0x600011D)               \n           token(0x600011E)               \n           token(0x6000144)               \n           token(0x6000147)               \n           token(0x6000148)               \n           token(0x6000159)               \n           token(0x600015B)               \n           token(0x600015C)               \n           token(0x60001E8)               \n\ncreate process on Windows (22 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    token(0x6000033)               \n           token(0x6000039)               \n           token(0x600003A)               \n           token(0x600003B)               \n           token(0x600003E)               \n           token(0x6000099)               \n           token(0x60000D5)               \n           token(0x60000D8)               \n           token(0x60000DB)               \n           token(0x60000DC)               \n           token(0x60000DD)               \n           token(0x60000F7)               \n           token(0x600011D)               \n           token(0x600011E)               \n           token(0x6000144)               \n           token(0x6000147)               \n           token(0x6000148)               \n           token(0x6000159)               \n           token(0x600015B)               \n           token(0x600015C)               \n           token(0x60001E8)               \n           token(0x6000207)               \n\nenumerate processes (2 matches)\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    token(0x6000060)             \n           token(0x60000D9)             \n\nfind process by PID (2 matches)\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    token(0x6000061)             \n           token(0x6000062)             \n\nfind process by name\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    token(0x60001BB)             \n\nacquire debug privileges\nnamespace  host-interaction/process/modify\nscope      basic block                    \nmatches    token(0x60001BA)               \n\nmodify access privileges\nnamespace  host-interaction/process/modify\nscope      instruction                    \nmatches    token(0x60001BA)+0x59          \n\nterminate process (14 matches)\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    token(0x600003A)                  \n           token(0x600003B)                  \n           token(0x6000061)                  \n           token(0x60000F7)                  \n           token(0x600011D)                  \n           token(0x600011E)                  \n           token(0x6000144)                  \n           token(0x6000147)                  \n           token(0x6000148)                  \n           token(0x6000159)                  \n           token(0x600015B)                  \n           token(0x600015C)                  \n           token(0x60001E7)                  \n           token(0x60001E8)                  \n\nquery or enumerate registry key (7 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    token(0x6000039)         \n           token(0x600006F)         \n           token(0x6000071)         \n           token(0x60000F9)         \n           token(0x6000255)         \n           token(0x6000257)         \n           token(0x6000259)         \n\nquery or enumerate registry value (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    token(0x600006F)         \n           token(0x6000255)         \n\nset registry value (5 matches)\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    token(0x6000039)                \n           token(0x600003E)                \n           token(0x600003E)                \n           token(0x6000070)                \n           token(0x6000257)                \n\ndelete registry key\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    token(0x600003E)                \n\ndelete registry value (2 matches)\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    token(0x6000071)                \n           token(0x6000259)                \n\nget session integrity level (3 matches)\nnamespace  host-interaction/session\nscope      function                \nmatches    token(0x600003D)        \n           token(0x600007A)        \n           token(0x60001B9)        \n\nget session user name (5 matches)\nnamespace  host-interaction/session\nscope      function                \nmatches    token(0x600003D)        \n           token(0x600004A)        \n           token(0x600007A)        \n           token(0x6000149)        \n           token(0x60001B9)        \n\ncreate thread (3 matches)\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    token(0x60000A4)              \n           token(0x60000C4)              \n           token(0x60000EC)              \n\nsuspend thread (9 matches)\nnamespace  host-interaction/thread/suspend\nscope      basic block                    \nmatches    token(0x6000010)               \n           token(0x6000011)               \n           token(0x6000033)               \n           token(0x6000035)               \n           token(0x6000037)               \n           token(0x600003E)               \n           token(0x60000DA)               \n           token(0x60001E7)               \n           token(0x6000207)               \n\naccess WMI data in .NET\nnamespace  host-interaction/wmi\nscope      function            \nmatches    token(0x600004B)    \n\nreference cryptocurrency strings\nnamespace  impact/cryptocurrency\nscope      file                 \n\ndisable system features via registry on Windows\nnamespace  impact/features \nscope      function        \nmatches    token(0x6000039)\n\ncompile .NET assembly\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x600027A)\n\ninvoke .NET assembly method (2 matches)\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x6000146)\n           token(0x600027A)\n\nload .NET assembly\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x6000146)\n\ncompile CSharp in .NET\nnamespace  load-code/dotnet/csharp\nscope      function               \nmatches    token(0x600027A)       \n\npersist via default file association registry key (2 matches)\nnamespace  persistence/registry\nscope      function            \nmatches    token(0x600003E)    \n           token(0x600003E)    \n\npersist via Run registry key\nnamespace  persistence/registry/run\nscope      function                \nmatches    token(0x6000070)        \n\nschedule task via schtasks (2 matches)\nnamespace  persistence/scheduled-tasks\nscope      function                   \nmatches    token(0x600003A)           \n           token(0x600003A)           \n\nunmanaged call (42 matches)\nnamespace    runtime                                                       \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nscope        function                                                      \nmatches      token(0x6000055)                                              \n             token(0x6000063)                                              \n             token(0x60000A5)                                              \n             token(0x60000A7)                                              \n             token(0x60000A8)                                              \n             token(0x60000AA)                                              \n             token(0x60000AF)                                              \n             token(0x60000C2)                                              \n             token(0x60000C3)                                              \n             token(0x60000C7)                                              \n             token(0x60000C8)                                              \n             token(0x60000C9)                                              \n             token(0x60000CA)                                              \n             token(0x60000CB)                                              \n             token(0x60000D2)                                              \n             token(0x60000D3)                                              \n             token(0x60000D4)                                              \n             token(0x60000D6)                                              \n             token(0x60000D7)                                              \n             token(0x60000DA)                                              \n             token(0x60000E5)                                              \n             token(0x60000ED)                                              \n             token(0x60000F4)                                              \n             token(0x6000176)                                              \n             token(0x6000177)                                              \n             token(0x6000178)                                              \n             token(0x6000179)                                              \n             token(0x600017A)                                              \n             token(0x600017B)                                              \n             token(0x600017C)                                              \n             token(0x60001A0)                                              \n             token(0x60001A5)                                              \n             token(0x60001AD)                                              \n             token(0x60001AF)                                              \n             token(0x60001B0)                                              \n             token(0x60001B5)                                              \n             token(0x60001B7)                                              \n             token(0x60001BA)                                              \n             token(0x60001BB)                                              \n             token(0x60001CA)                                              \n             token(0x60001CB)                                              \n             token(0x60001CC)                                              \n\ncompiled to the .NET platform\nnamespace  runtime/dotnet\nscope      file          \n\n\n\n","very_verbose":"md5                     9a5ff998dbf0f6923d0b454d89800fb4                        \nsha1                    4f4fa23e9c503b941a5e91584d6ecc3813962ba1                \nsha256                  360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f15…\npath                    /home/apogean/projects/malware/windows/all_runs/now_you…\ntimestamp               2026-04-29 20:28:57.517569                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    any                                                     \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIyVCyhQ/rules                                   \nfunction count          574                                                     \nlibrary function count  0                                                       \ntotal feature count     18525                                                   \n\ncontain loop (library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ token(0x60000BC)\n  or:\n    characteristic: recursive call @ token(0x60000BC)\n\ncreate or open file (library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ token(0x60001A5)+0x48\n  or:\n    api: CreateFile @ token(0x60001A5)+0x48\n\ncreate or open registry key (9 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ token(0x6000039) in function token(0x6000039)\n  or:\n    api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000039)+0x1FE8\n\nopen process (library rule)\nauthor  0x534a@mailbox.org           \nscope   basic block                  \nmbc     Process::Open Process [C0065]\nbasic block @ token(0x60001BB) in function token(0x60001BB)\n  or:\n    api: OpenProcess @ token(0x60001BB)+0x59, token(0x60001BB)+0x90\n\nopen thread (library rule)\nauthor  0x534a@mailbox.org          \nscope   basic block                 \nmbc     Process::Open Thread [C0066]\nbasic block @ token(0x6000063) in function token(0x6000063)\n  or:\n    api: OpenThread @ token(0x6000063)+0x22\n\nself delete (3 matches)\nnamespace  anti-analysis/anti-forensic/self-deletion                            \nauthor     michael.hunhoff@mandiant.com, @mr-tz                                 \nscope      function                                                             \natt&ck     Defense Evasion::Indicator Removal::File Deletion [T1070.004]        \nmbc        Defense Evasion::Self Deletion::COMSPEC Environment Variable         \n           [F0007.001]                                                          \nfunction @ token(0x6000039)\n  and:\n    or:\n      match: host-interaction/process/create @ token(0x6000039)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x6000039)+0x1DE1, token(0x6000039)+0x1FD1\n    or:\n      regex: /(^|[\\&;\\|]\\s*)del(\\s.*)?/i\n        - \"delta\" @ token(0x6000039)+0xC4B\nfunction @ token(0x600003E)\n  and:\n    or:\n      match: host-interaction/process/create @ token(0x600003E)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x600003E)+0x7B\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x600003E)+0x7B\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600003E)+0x68\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600003E)+0x6F\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600003E)+0x61\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600003E)+0x76\n    or:\n      regex: /(^|[\\&;\\|]\\s*)del(\\s.*)?/i\n        - \"DelegateExecute\" @ token(0x600003E)+0x3A\nfunction @ token(0x600003E)\n  and:\n    or:\n      match: host-interaction/process/create @ token(0x600003E)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x600003E)+0x7B\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x600003E)+0x7B\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600003E)+0x68\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600003E)+0x6F\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600003E)+0x61\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600003E)+0x76\n    or:\n      regex: /(^|[\\&;\\|]\\s*)del(\\s.*)?/i\n        - \"DelegateExecute\" @ token(0x600003E)+0x3A\n\nget geographical location\nnamespace  collection                                  \nauthor     moritz.raabe, michael.hunhoff@mandiant.com  \nscope      function                                    \natt&ck     Discovery::System Location Discovery [T1614]\nfunction @ token(0x600004C)\n  or:\n    regex: /countrycode/i\n      - \"\\\"countryCode\\\":\\\"\" @ token(0x600004C)+0x28\n      - \"http://ip-api.com/json/?fields=countryCode\" @ token(0x600004C)+0x1C\n\nsave image in .NET\nnamespace  collection                  \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x6000054)\n  and:\n    api: System.Drawing.Image::Save @ token(0x6000054)+0x1D6\n\ngather firefox profile information\nnamespace  collection/browser                                                   \nauthor     @_re_fox, still@teamt5.org                                           \nscope      function                                                             \natt&ck     Credential Access::Credentials from Password Stores::Credentials from\n           Web Browsers [T1555.003]                                             \nfunction @ token(0x60001CC)\n  and:\n    2 or more:\n      regex: /SELECT\\s+{5,}FROM moz_(logins|cookies)/i\n        - \"SELECT host, name, value, path, isSecure, expiry FROM moz_cookies\" @ token(0x60001CC)+0x38\n      regex: /FROM moz_(logins|cookies)/i\n        - \"SELECT host, name, value, path, isSecure, expiry FROM moz_cookies\" @ token(0x60001CC)+0x38\n\nreference SQL statements (2 matches)\nnamespace  collection/database/sql                               \nauthor     william.ballenthin@mandiant.com                       \nscope      function                                              \natt&ck     Collection::Data from Information Repositories [T1213]\nfunction @ token(0x6000147)\n  and:\n    regex: /SELECT.*FROM.*WHERE/\n      - \"'\\r\\n    if not os.path.exists(db_path):\\r\\n        print('ERROR:Database file \nnot found: ' + db_path)\\r\\n        sys.exit(1)\\r\\n    \\r\\n    # Check file \nsize\\r\\n    file_size = os.path.getsize(db_path)\\r\\n    if file_size == 0:\\r\\n  \nprint('ERROR:Database file is empty')\\r\\n        sys.exit(1)\\r\\n    \\r\\n    conn\n= sqlite3.connect(db_path)\\r\\n    conn.row_factory = sqlite3.Row\\r\\n    cursor =\nconn.cursor()\\r\\n    \\r\\n    # First, check if urls table exists\\r\\n    \ncursor.execute(\\\"SELECT name FROM sqlite_master WHERE type='table' AND \nname='urls'\\\")\\r\\n    table_exists = cursor.fetchone()\\r\\n    \\r\\n    if not \ntable_exists:\\r\\n        print('ERROR:urls table does not exist in \ndatabase')\\r\\n        # List available tables for debugging\\r\\n        \ncursor.execute(\\\"SELECT name FROM sqlite_master WHERE type='table'\\\")\\r\\n       \ntables = cursor.fetchall()\\r\\n        if tables:\\r\\n            table_names = ',\n'.join([t[0] for t in tables])\\r\\n            print('ERROR:Available tables: ' +\ntable_names)\\r\\n        conn.close()\\r\\n        sys.exit(1)\\r\\n    \\r\\n    # Try\nto query the urls table\\r\\n    try:\\r\\n        # Check if columns exist\\r\\n     \ncursor.execute(\\\"PRAGMA table_info(urls)\\\")\\r\\n        columns = [row[1] for row\nin cursor.fetchall()]\\r\\n        required_columns = ['url', 'title', \n'visit_count', 'last_visit_time']\\r\\n        missing_columns = \\r\\n        \\r\\n \nif missing_columns:\\r\\n            print('ERROR:Missing columns: ' + ', \n'.join(missing_columns))\\r\\n            print('ERROR:Available columns: ' + ', \n'.join(columns))\\r\\n            conn.close()\\r\\n            sys.exit(1)\\r\\n     \n\\r\\n        cursor.execute('SELECT url, title, visit_count, last_visit_time FROM\nurls ORDER BY last_visit_time DESC LIMIT 1000')\\r\\n        rows = \ncursor.fetchall()\\r\\n        \\r\\n        if len(rows) == 0:\\r\\n            \nprint('ERROR:No rows found in urls table')\\r\\n            conn.close()\\r\\n      \nsys.exit(1)\\r\\n        \\r\\n        for row in rows:\\r\\n            url = \nrow['url'] if row['url'] else ''\\r\\n            title = row['title'] if \nrow['title'] else ''\\r\\n            visit_count = int(row['visit_count']) if \nrow['visit_count'] is not None else 0\\r\\n            last_visit = \nint(row['last_visit_time']) if row['last_visit_time'] is not None else 0\\r\\n    \n# Escape pipe characters in URL/title\\r\\n            url = url.replace('|', \n'{PIPE}')\\r\\n            title = title.replace('|', '{PIPE}')\\r\\n            \nprint(f'{url}|{title}|{visit_count}|{last_visit}')\\r\\n    except \nsqlite3.OperationalError as e:\\r\\n        print(f'ERROR:SQL error: \n{str(e)}')\\r\\n        conn.close()\\r\\n        sys.exit(1)\\r\\n    except \nException as e:\\r\\n        print(f'ERROR:Query error: {str(e)}')\\r\\n        \nconn.close()\\r\\n        sys.exit(1)\\r\\n    \\r\\n    conn.close()\\r\\nexcept \nException as e:\\r\\n    print(f'ERROR:{str(e)}')\\r\\n    import traceback\\r\\n    \nprint('ERROR:Traceback: ' + traceback.format_exc())\\r\\n    sys.exit(1)\\r\\n\" @ token(0x6000147)+0x26\nfunction @ token(0x600015B)\n  and:\n    regex: /SELECT.*FROM.*WHERE/\n      - \"'\\r\\n    if not os.path.exists(db_path):\\r\\n        print('ERROR:Database file \nnot found')\\r\\n        sys.exit(1)\\r\\n    \\r\\n    conn = \nsqlite3.connect(db_path)\\r\\n    conn.row_factory = sqlite3.Row\\r\\n    cursor = \nconn.cursor()\\r\\n    \\r\\n    # Check if autofill table exists\\r\\n    \ncursor.execute(\\\"SELECT name FROM sqlite_master WHERE type='table' AND \nname='autofill'\\\")\\r\\n    if not cursor.fetchone():\\r\\n        \nprint('ERROR:autofill table does not exist')\\r\\n        conn.close()\\r\\n        \nsys.exit(1)\\r\\n    \\r\\n    # Query autofill data\\r\\n    cursor.execute('SELECT \nname, value, date_created, date_last_used, count FROM autofill ORDER BY \ndate_last_used DESC LIMIT 500')\\r\\n    rows = cursor.fetchall()\\r\\n    \\r\\n    \nfor row in rows:\\r\\n        name = row['name'] if row['name'] else ''\\r\\n       \nvalue = row['value'] if row['value'] else ''\\r\\n        date_created = \nrow['date_created'] if row['date_created'] else 0\\r\\n        date_last_used = \nrow['date_last_used'] if row['date_last_used'] else 0\\r\\n        count = \nrow['count'] if row['count'] else 0\\r\\n        name = name.replace('|', \n'{PIPE}')\\r\\n        value = value.replace('|', '{PIPE}')\\r\\n        \nprint(f'{name}|{value}|{date_created}|{date_last_used}|{count}')\\r\\n    \\r\\n    \nconn.close()\\r\\nexcept Exception as e:\\r\\n    print(f'ERROR:{str(e)}')\\r\\n    \nimport traceback\\r\\n    print('ERROR:Traceback: ' + traceback.format_exc())\\r\\n \nsys.exit(1)\\r\\n\" @ token(0x600015B)+0x1B\n\nreference WMI statements\nnamespace  collection/database/wmi                               \nauthor     michael.hunhoff@mandiant.com                          \nscope      function                                              \natt&ck     Collection::Data from Information Repositories [T1213]\nfunction @ token(0x600004B)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_OperatingSystem\" @ token(0x600004B)+0x0\n\nlog keystrokes (2 matches)\nnamespace  collection/keylog                                \nauthor     moritz.raabe@mandiant.com                        \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nfunction @ token(0x600017A)\n  or:\n    api: MapVirtualKey @ token(0x600017A)+0x39\nfunction @ token(0x600017B)\n  or:\n    api: MapVirtualKey @ token(0x600017B)+0xF\n\nlog keystrokes via application hook\nnamespace  collection/keylog                                   \nauthor     michael.hunhoff@mandiant.com                        \nscope      basic block                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]   \nmbc        Collection::Keylogging::Application Hook [F0002.001]\nbasic block @ token(0x60000A7) in function token(0x60000A7)\n  and:\n    match: set application hook @ token(0x60000A7)+0x1C\n      or:\n        api: SetWindowsHookEx @ token(0x60000A7)+0x1C\n    or:\n      number: 0xD = WH_KEYBOARD_LL @ token(0x60000A7)+0xD\n\nlog keystrokes via polling (2 matches)\nnamespace  collection/keylog                                \nauthor     michael.hunhoff@mandiant.com                     \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nmbc        Collection::Keylogging::Polling [F0002.002]      \nfunction @ token(0x60000AA)\n  or:\n    api: GetKeyState @ token(0x60000AA)+0xE9, token(0x60000AA)+0xFA\nfunction @ token(0x600017C)\n  or:\n    api: VkKeyScan @ token(0x600017C)+0x3CB, token(0x600017C)+0x3F6\n\nget MAC address in .NET\nnamespace  collection/network                                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           echernofsky@google.com                                               \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nfunction @ token(0x600011C)\n  or:\n    api: System.Net.NetworkInformation.NetworkInterface::GetPhysicalAddress @ token(0x600011C)+0x150\n\ncapture screenshot\nnamespace  collection/screenshot                                            \nauthor     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\nscope      function                                                         \natt&ck     Collection::Screen Capture [T1113]                               \nmbc        Collection::Screen Capture::WinAPI [E1113.m01]                   \nfunction @ token(0x6000054)\n  or:\n    api: System.Drawing.Graphics::CopyFromScreen @ token(0x6000054)+0xC7, token(0x6000054)+0x133\n\nreceive data\nnamespace    communication                                                     \nauthor       william.ballenthin@mandiant.com                                   \nscope        function                                                          \nmbc          Command and Control::C2 Communication::Receive Data [B0030.002]   \ndescription  all known techniques for receiving data from a potential C2 server\nfunction @ token(0x600004C)\n  or:\n    match: read data from Internet @ token(0x600004C)\n      and:\n        or:\n          api: System.Net.WebClient::DownloadString @ token(0x600004C)+0x21\n\nsend data\nnamespace    communication                                                 \nauthor       william.ballenthin@mandiant.com, joakim@intezer.com           \nscope        function                                                      \nmbc          Command and Control::C2 Communication::Send Data [B0030.001]  \ndescription  all known techniques for sending data to a potential C2 server\nfunction @ token(0x60001BF)\n  or:\n    and:\n      os: windows\n      or:\n        match: send HTTP request @ token(0x60001BF)\n          or:\n            api: System.Net.WebRequest::GetResponse @ token(0x60001BF)+0x97\n\nmanipulate network credentials in .NET\nnamespace  communication/authentication\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x60001BF)\n  and:\n    api: System.Net.NetworkCredential::ctor @ token(0x60001BF)+0x7F\n\nwrite and execute a file (4 matches)\nnamespace              communication/c2/file-transfer               \nmaec/malware-category  launcher                                     \nauthor                 moritz.raabe@mandiant.com                    \nscope                  function                                     \nmbc                    Execution::Install Additional Program [B0023]\nfunction @ token(0x60000DD)\n  and:\n    match: host-interaction/file-system/write @ token(0x60000DD)\n      or:\n        api: System.IO.File::WriteAllText @ token(0x60000DD)+0x2A\n    match: host-interaction/process/create @ token(0x60000DD)\n      or:\n        api: System.Diagnostics.Process::Start @ token(0x60000DD)+0x35\nfunction @ token(0x6000147)\n  and:\n    match: host-interaction/file-system/write @ token(0x6000147)\n      or:\n        api: System.IO.File::WriteAllText @ token(0x6000147)+0x72\n    match: host-interaction/process/create @ token(0x6000147)\n      or:\n        api: System.Diagnostics.Process::Start @ token(0x6000147)+0x100\n      or:\n        and:\n          api: System.Diagnostics.Process::Start @ token(0x6000147)+0x100\n          or:\n            property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000147)+0xD6\n            property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000147)+0xF2\n            property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000147)+0xB9\n            property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000147)+0xCF\n            property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000147)+0xEB\n            property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x6000147)+0xDD\n            property/read: System.Diagnostics.Process::StandardOutput @ token(0x6000147)+0x108\nfunction @ token(0x600015B)\n  and:\n    match: host-interaction/file-system/write @ token(0x600015B)\n      or:\n        api: System.IO.File::WriteAllText @ token(0x600015B)+0x47\n    match: host-interaction/process/create @ token(0x600015B)\n      or:\n        api: System.Diagnostics.Process::Start @ token(0x600015B)+0xCB\n      or:\n        and:\n          api: System.Diagnostics.Process::Start @ token(0x600015B)+0xCB\n          or:\n            property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600015B)+0xA4\n            property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600015B)+0xC0\n            property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600015B)+0x87\n            property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600015B)+0x9D\n            property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600015B)+0xB9\n            property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600015B)+0xAB\n            property/read: System.Diagnostics.Process::StandardOutput @ token(0x600015B)+0xD2\nfunction @ token(0x60001E8)\n  and:\n    match: host-interaction/file-system/write @ token(0x60001E8)\n      or:\n        api: System.IO.File::WriteAllText @ token(0x60001E8)+0x6D\n    match: host-interaction/process/create @ token(0x60001E8)\n      or:\n        api: System.Diagnostics.Process::Start @ token(0x60001E8)+0x8C\n      or:\n        and:\n          api: System.Diagnostics.Process::Start @ token(0x60001E8)+0x8C\n          or:\n            property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x60001E8)+0x80\n            property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x60001E8)+0x79\n            property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x60001E8)+0x87\n\nread HTTP header\nnamespace  communication/http                                           \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Read Header [C0002.014]   \nfunction @ token(0x600004C)\n  or:\n    property/read: System.Net.WebClient::Headers @ token(0x600004C)+0x7\n\nreference HTTP User-Agent string\nnamespace   communication/http                                                  \nauthor      @mr-tz                                                              \nscope       function                                                            \nmbc         Communication::HTTP Communication [C0002]                           \nreferences  https://www.useragents.me/,                                         \n            https://www.whatismybrowser.com/guides/the-latest-user-agent/       \nfunction @ token(0x600004C)\n  or:\n    substring: Mozilla/5.0\n      - \"Mozilla/5.0\" @ token(0x600004C)+0x11\n\ncreate HTTP request\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Create Request [C0002.012]\nfunction @ token(0x60001BF)\n  and:\n    or:\n      api: System.Net.WebRequest::Create @ token(0x60001BF)+0x5F\n\nread data from Internet\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Get Response [C0002.017]  \nfunction @ token(0x600004C)\n  and:\n    or:\n      api: System.Net.WebClient::DownloadString @ token(0x600004C)+0x21\n\nreceive HTTP response\nnamespace  communication/http/client                                  \nauthor     michael.hunhoff@mandiant.com                               \nscope      function                                                   \nmbc        Communication::HTTP Communication::Get Response [C0002.017]\nfunction @ token(0x60001BF)\n  or:\n    api: System.Net.WebRequest::GetResponse @ token(0x60001BF)+0x97\n\nsend HTTP request\nnamespace  communication/http/client                                  \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com    \nscope      function                                                   \nmbc        Communication::HTTP Communication::Send Request [C0002.003]\nfunction @ token(0x60001BF)\n  or:\n    api: System.Net.WebRequest::GetResponse @ token(0x60001BF)+0x97\n\ncreate TCP socket (3 matches)\nnamespace   communication/socket/tcp                                            \nauthor      william.ballenthin@mandiant.com, joakim@intezer.com,                \n            anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com       \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create TCP Socket [C0001.011]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ token(0x600000C) in function token(0x600000C)\n  or:\n    property/read: System.Net.Sockets.TcpClient::Client @ token(0x600000C)+0x34, token(0x600000C)+0x41, token(0x600000C)+0x53\nbasic block @ token(0x600000E) in function token(0x600000E)\n  or:\n    property/read: System.Net.Sockets.TcpClient::Client @ token(0x600000E)+0x63, token(0x600000E)+0x70, token(0x600000E)+0xBE, \ntoken(0x600000E)+0xD7\nbasic block @ token(0x6000014) in function token(0x6000014)\n  or:\n    property/read: System.Net.Sockets.TcpClient::Client @ token(0x6000014)+0x34, token(0x6000014)+0x41\n\nact as TCP client\nnamespace  communication/tcp/client                                     \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                                     \nmbc        Communication::Socket Communication::TCP Client [C0001.008]  \nfunction @ token(0x600000E)\n  or:\n    api: System.Net.Sockets.TcpClient::ctor @ token(0x600000E)+0x7\n\ncreate zip archive in .NET (3 matches)\nnamespace  data-manipulation/compression\nauthor     michael.hunhoff@mandiant.com \nscope      basic block                  \nbasic block @ token(0x60000B8) in function token(0x60000B8)\n  and:\n    or:\n      api: System.IO.Compression.ZipFile::CreateFromDirectory @ token(0x60000B8)+0x14A\nbasic block @ token(0x60000BB) in function token(0x60000BB)\n  and:\n    or:\n      api: System.IO.Compression.ZipFile::CreateFromDirectory @ token(0x60000BB)+0x79\nbasic block @ token(0x60001BC) in function token(0x60001BC)\n  and:\n    or:\n      api: System.IO.Compression.ZipFile::CreateFromDirectory @ token(0x60001BC)+0x3F\n\ndecode data using Base64 in .NET\nnamespace  data-manipulation/encoding/base64                               \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \natt&ck     Defense Evasion::Deobfuscate/Decode Files or Information [T1140]\nmbc        Data::Decode Data::Base64 [C0053.001]                           \nfunction @ token(0x60001B5)\n  or:\n    api: System.Convert::FromBase64String @ token(0x60001B5)+0x1\n\ndecode data using Base64 via WinAPI\nnamespace  data-manipulation/encoding/base64                               \nauthor     michael.hunhoff@mandiant.com                                    \nscope      basic block                                                     \natt&ck     Defense Evasion::Deobfuscate/Decode Files or Information [T1140]\nbasic block @ token(0x60001B5) in function token(0x60001B5)\n  and:\n    api: CryptStringToBinary @ token(0x60001B5)+0x21, token(0x60001B5)+0x43\n    or:\n      number: 0x1 = dwFlags=CRYPT_STRING_BASE64 @ token(0x60001B5)+0x13, token(0x60001B5)+0x35\n\nreference Base64 string\nnamespace  data-manipulation/encoding/base64                                \nauthor     moritz.raabe@mandiant.com                                        \nscope      file                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]         \nmbc        Data::Encode Data::Base64 [C0026.001], Data::Check String [C0019]\nregex: /ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/\n  - \"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/\" @ file+0x254AC\n\nencrypt or decrypt data via BCrypt (2 matches)\nnamespace  data-manipulation/encryption                                         \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Decrypt Data [C0031], Cryptography::Encrypt Data       \n           [C0027]                                                              \nfunction @ token(0x60001AD)\n  and:\n    or:\n      api: BCryptDecrypt @ token(0x60001AD)+0x441\n    optional:\n      api: BCryptOpenAlgorithmProvider @ token(0x60001AD)+0x37D\n      api: BCryptCloseAlgorithmProvider @ token(0x60001AD)+0x4B1\n      api: BCryptGenerateSymmetricKey @ token(0x60001AD)+0x39E\n      api: BCryptDestroyKey @ token(0x60001AD)+0x49A\nfunction @ token(0x60001B0)\n  and:\n    or:\n      api: BCryptDecrypt @ token(0x60001B0)+0x1D1\n    optional:\n      api: BCryptOpenAlgorithmProvider @ token(0x60001B0)+0x70\n      api: BCryptCloseAlgorithmProvider @ token(0x60001B0)+0x280\n      api: BCryptGenerateSymmetricKey @ token(0x60001B0)+0xFC\n      api: BCryptDestroyKey @ token(0x60001B0)+0x26B\n\nencrypt data using DPAPI\nnamespace  data-manipulation/encryption/dpapi                           \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]     \nmbc        Cryptography::Encrypt Data [C0027]                           \nfunction @ token(0x60001AF)\n  or:\n    api: CryptUnprotectData @ token(0x60001AF)+0x52\n\ngenerate random numbers in .NET\nnamespace  data-manipulation/prng                                            \nauthor     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com     \nscope      function                                                          \nmbc        Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\nfunction @ token(0x600003E)\n  or:\n    api: System.Random::Next @ token(0x600003E)+0x90\n\ncontains PDB path\nnamespace  executable/pe/pdb        \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nregex: /:\\\\.*\\.pdb/\n  - \"C:\\\\Users\\\\sulum\\\\OneDrive\\\\Desktop\\\\datacenter\\\\stubCsharp\\\\obj\\\\Release\\\\Clie\nnt.pdb\" @ file+0x370BC\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ token(0x60000E5)\n  or:\n    and:\n      or:\n        api: LoadResource @ token(0x60000E5)+0x3D\n        api: LockResource @ token(0x60000E5)+0x5D\n      optional:\n        or:\n          api: FindResource @ token(0x60000E5)+0x12\n        api: SizeofResource @ token(0x60000E5)+0x82\n\ncheck clipboard data (2 matches)\nnamespace  host-interaction/clipboard        \nauthor     anushka.virgaonkar@mandiant.com   \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ token(0x60000EE)\n  or:\n    api: System.Windows.Forms.Clipboard::ContainsText @ token(0x60000EE)+0x10\nfunction @ token(0x600024C)\n  or:\n    api: System.Windows.Forms.Clipboard::ContainsText @ token(0x600024C)+0xA5, token(0x600024C)+0xB4\n\nmonitor clipboard content\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      basic block                       \natt&ck     Collection::Clipboard Data [T1115]\nbasic block @ token(0x60000F4) in function token(0x60000F4)\n  and:\n    api: AddClipboardFormatListener @ token(0x60000F4)+0x17\n\nread clipboard data (2 matches)\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Collection::Clipboard Data [T1115]                                  \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ token(0x60000EE)\n  and:\n    or:\n      api: System.Windows.Forms.Clipboard::GetText @ token(0x60000EE)+0x17\nfunction @ token(0x600024C)\n  and:\n    or:\n      api: System.Windows.Forms.Clipboard::GetText @ token(0x600024C)+0xAC, token(0x600024C)+0xBB\n\nmanipulate console buffer (8 matches)\nnamespace   host-interaction/console                                     \nauthor      william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope       function                                                     \nmbc         Operating System::Console [C0033]                            \nreferences  https://stackoverflow.com/a/15770935/87207                   \nfunction @ token(0x6000019)\n  or:\n    api: System.Console::WriteLine @ token(0x6000019)+0x21, token(0x6000019)+0x58\nfunction @ token(0x6000029)\n  or:\n    api: System.Console::WriteLine @ token(0x6000029)+0x1F\nfunction @ token(0x6000033)\n  or:\n    api: System.Console::WriteLine @ token(0x6000033)+0x19, token(0x6000033)+0x7B, token(0x6000033)+0x9B, \ntoken(0x6000033)+0xBF, and 6 more...\nfunction @ token(0x6000044)\n  or:\n    api: System.Console::WriteLine @ token(0x6000044)+0x21, token(0x6000044)+0x58\nfunction @ token(0x600014A)\n  or:\n    api: System.Console::WriteLine @ token(0x600014A)+0x21\nfunction @ token(0x600015E)\n  or:\n    api: System.Console::WriteLine @ token(0x600015E)+0x21\nfunction @ token(0x6000181)\n  or:\n    api: System.Console::WriteLine @ token(0x6000181)+0x79\nfunction @ token(0x6000182)\n  or:\n    api: System.Console::WriteLine @ token(0x6000182)+0x8, token(0x6000182)+0x2B\n\nquery environment variable (3 matches)\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ token(0x6000095)\n  or:\n    api: System.Environment::ExpandEnvironmentVariables @ token(0x6000095)+0x17\nfunction @ token(0x60001A1)\n  or:\n    api: System.Environment::GetEnvironmentVariable @ token(0x60001A1)+0x28, token(0x60001A1)+0x33, token(0x60001A1)+0x3E\nfunction @ token(0x60001AB)\n  or:\n    api: System.Environment::GetEnvironmentVariable @ token(0x60001AB)+0xF\n\nenumerate drives\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x6000093)\n  or:\n    api: System.IO.DriveInfo::GetDrives @ token(0x6000093)+0x6\n\nget common file path (7 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ token(0x600004E)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x600004E)+0xA, token(0x600004E)+0x1E, token(0x600004E)+0x32, \ntoken(0x600004E)+0x46\nfunction @ token(0x60000B7)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x60000B7)+0x8, token(0x60000B7)+0x10\nfunction @ token(0x60000F8)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x60000F8)+0x10, token(0x60000F8)+0x90\nfunction @ token(0x60000FA)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x60000FA)+0x8\nfunction @ token(0x6000146)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x6000146)+0x10, token(0x6000146)+0x29, token(0x6000146)+0x42\nfunction @ token(0x6000149)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x6000149)+0x8, token(0x6000149)+0x10\nfunction @ token(0x600015D)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x600015D)+0x8, token(0x600015D)+0x10\n\ncopy file (7 matches)\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ token(0x60000BC)\n  or:\n    api: System.IO.File::Copy @ token(0x60000BC)+0x2C\nfunction @ token(0x6000144)\n  or:\n    api: System.IO.File::Copy @ token(0x6000144)+0xC7\nfunction @ token(0x6000159)\n  or:\n    api: System.IO.File::Copy @ token(0x6000159)+0xA3\nfunction @ token(0x60001A5)\n  or:\n    api: System.IO.File::Copy @ token(0x60001A5)+0x92\nfunction @ token(0x60001A6)\n  or:\n    api: System.IO.File::Copy @ token(0x60001A6)+0x2D, token(0x60001A6)+0x5F\nfunction @ token(0x60001AB)\n  or:\n    api: System.IO.File::Copy @ token(0x60001AB)+0x81\nfunction @ token(0x60001BF)\n  or:\n    api: System.IO.File::Copy @ token(0x60001BF)+0x43, token(0x60001BF)+0xE7, token(0x60001BF)+0xF6\n\ncreate directory (8 matches)\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ token(0x6000097)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000097)+0x18\nfunction @ token(0x6000098)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000098)+0x18\nfunction @ token(0x60000B8)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60000B8)+0x5F\nfunction @ token(0x60000BB)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60000BB)+0x2C\nfunction @ token(0x60000BC)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60000BC)+0x9\nfunction @ token(0x6000144)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000144)+0x120\nfunction @ token(0x6000159)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000159)+0xFB\nfunction @ token(0x60001A0)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60001A0)+0x8C, token(0x60001A0)+0x98\n\ndelete directory (2 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ token(0x60000B8)\n  or:\n    api: System.IO.Directory::Delete @ token(0x60000B8)+0x176\nfunction @ token(0x60000BB)\n  or:\n    api: System.IO.Directory::Delete @ token(0x60000BB)+0x87\n\ndelete file (12 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ token(0x60000B8)\n  or:\n    api: System.IO.File::Delete @ token(0x60000B8)+0x182\nfunction @ token(0x60000BB)\n  or:\n    api: System.IO.File::Delete @ token(0x60000BB)+0x93\nfunction @ token(0x6000144)\n  or:\n    api: System.IO.File::Delete @ token(0x6000144)+0x233, token(0x6000144)+0x329\nfunction @ token(0x6000147)\n  or:\n    api: System.IO.File::Delete @ token(0x6000147)+0x3DE\nfunction @ token(0x6000159)\n  or:\n    api: System.IO.File::Delete @ token(0x6000159)+0x1D1, token(0x6000159)+0x256\nfunction @ token(0x600015B)\n  or:\n    api: System.IO.File::Delete @ token(0x600015B)+0x22F, token(0x600015B)+0x255\nfunction @ token(0x60001A8)\n  or:\n    api: System.IO.File::Delete @ token(0x60001A8)+0x280\nfunction @ token(0x60001A9)\n  or:\n    api: System.IO.File::Delete @ token(0x60001A9)+0x30D, token(0x60001A9)+0x337, token(0x60001A9)+0x361\nfunction @ token(0x60001AA)\n  or:\n    api: System.IO.File::Delete @ token(0x60001AA)+0x27E, token(0x60001AA)+0x2A6, token(0x60001AA)+0x2CE\nfunction @ token(0x60001AB)\n  or:\n    api: System.IO.File::Delete @ token(0x60001AB)+0x12D\nfunction @ token(0x60001BC)\n  or:\n    api: System.IO.File::Delete @ token(0x60001BC)+0x33\nfunction @ token(0x60001BF)\n  or:\n    api: System.IO.File::Delete @ token(0x60001BF)+0x109\n\ncheck if directory exists (15 matches)\nnamespace  host-interaction/file-system/exists            \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nfunction @ token(0x600004E)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600004E)+0x5E\nfunction @ token(0x6000095)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000095)+0x64\nfunction @ token(0x6000097)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000097)+0x10\nfunction @ token(0x6000098)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000098)+0x10\nfunction @ token(0x60000B7)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60000B7)+0x347\nfunction @ token(0x60000B8)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60000B8)+0xC0\nfunction @ token(0x60000BC)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60000BC)+0x1\nfunction @ token(0x6000144)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000144)+0x117\nfunction @ token(0x6000149)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000149)+0x11D, token(0x6000149)+0x237, token(0x6000149)+0x324, \ntoken(0x6000149)+0x469, and 2 more...\nfunction @ token(0x6000159)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000159)+0xF2\nfunction @ token(0x600015D)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600015D)+0x7B, token(0x600015D)+0x109, token(0x600015D)+0x198, \ntoken(0x600015D)+0x21D, and 1 more...\nfunction @ token(0x60001A7)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60001A7)+0x16\nfunction @ token(0x60001A9)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60001A9)+0xB\nfunction @ token(0x60001AB)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60001AB)+0x2A\nfunction @ token(0x600021B)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600021B)+0x24\n\ncheck if file exists (22 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ token(0x6000095)\n  or:\n    property/read: System.IO.FileSystemInfo::Exists @ token(0x6000095)+0x88\nfunction @ token(0x6000096)\n  or:\n    api: System.IO.File::Exists @ token(0x6000096)+0x1\nfunction @ token(0x60000D6)\n  or:\n    api: System.IO.File::Exists @ token(0x60000D6)+0x1\nfunction @ token(0x60000D7)\n  or:\n    api: System.IO.File::Exists @ token(0x60000D7)+0x1\nfunction @ token(0x60000F8)\n  or:\n    api: System.IO.File::Exists @ token(0x60000F8)+0x45, token(0x60000F8)+0xC5\nfunction @ token(0x60000FA)\n  or:\n    api: System.IO.File::Exists @ token(0x60000FA)+0x1E\nfunction @ token(0x6000144)\n  or:\n    api: System.IO.File::Exists @ token(0x6000144)+0x219, token(0x6000144)+0x22B, token(0x6000144)+0x321\nfunction @ token(0x6000146)\n  or:\n    api: System.IO.File::Exists @ token(0x6000146)+0x71\nfunction @ token(0x6000149)\n  or:\n    api: System.IO.File::Exists @ token(0x6000149)+0x170, token(0x6000149)+0x28B, token(0x6000149)+0x378, \ntoken(0x6000149)+0x4B1, and 2 more...\nfunction @ token(0x6000159)\n  or:\n    api: System.IO.File::Exists @ token(0x6000159)+0x1B7, token(0x6000159)+0x1C9, token(0x6000159)+0x24E\nfunction @ token(0x600015D)\n  or:\n    api: System.IO.File::Exists @ token(0x600015D)+0xCE, token(0x600015D)+0x15D, token(0x600015D)+0x1EC, \ntoken(0x600015D)+0x265, and 1 more...\nfunction @ token(0x60001A6)\n  or:\n    api: System.IO.File::Exists @ token(0x60001A6)+0x19, token(0x60001A6)+0x4B\nfunction @ token(0x60001A7)\n  or:\n    api: System.IO.File::Exists @ token(0x60001A7)+0x2F, token(0x60001A7)+0x140, token(0x60001A7)+0x15E, \ntoken(0x60001A7)+0x174, and 1 more...\nfunction @ token(0x60001A8)\n  or:\n    api: System.IO.File::Exists @ token(0x60001A8)+0x25, token(0x60001A8)+0x278\nfunction @ token(0x60001A9)\n  or:\n    api: System.IO.File::Exists @ token(0x60001A9)+0x64, token(0x60001A9)+0x304, token(0x60001A9)+0x324, \ntoken(0x60001A9)+0x34E\nfunction @ token(0x60001AA)\n  or:\n    api: System.IO.File::Exists @ token(0x60001AA)+0x66, token(0x60001AA)+0x276, token(0x60001AA)+0x294, \ntoken(0x60001AA)+0x2BC\nfunction @ token(0x60001AB)\n  or:\n    api: System.IO.File::Exists @ token(0x60001AB)+0x61\nfunction @ token(0x60001BC)\n  or:\n    api: System.IO.File::Exists @ token(0x60001BC)+0x2B, token(0x60001BC)+0x45\nfunction @ token(0x60001BD)\n  or:\n    api: System.IO.File::Exists @ token(0x60001BD)+0x13\nfunction @ token(0x60001BF)\n  or:\n    api: System.IO.File::Exists @ token(0x60001BF)+0x31, token(0x60001BF)+0x39\nfunction @ token(0x600026B)\n  or:\n    api: System.IO.File::Exists @ token(0x600026B)+0x9B\nfunction @ token(0x600026F)\n  or:\n    api: System.IO.File::Exists @ token(0x600026F)+0x70\n\nenumerate files in .NET (6 matches)\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ token(0x60000BC)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x60000BC)+0x10\n    api: System.IO.Directory::GetDirectories @ token(0x60000BC)+0x41\nfunction @ token(0x6000149)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x6000149)+0x128, token(0x6000149)+0x243, token(0x6000149)+0x330, \ntoken(0x6000149)+0x475, and 2 more...\nfunction @ token(0x600015D)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x600015D)+0x86, token(0x600015D)+0x115, token(0x600015D)+0x1A4, \ntoken(0x600015D)+0x229, and 1 more...\nfunction @ token(0x60001A7)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x60001A7)+0xCB\nfunction @ token(0x60001A9)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x60001A9)+0x20\nfunction @ token(0x60001AB)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x60001AB)+0x3F\n\nget file attributes\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ token(0x6000095) in function token(0x6000095)\n  or:\n    property/read: System.IO.FileSystemInfo::Attributes @ token(0x6000095)+0xFD\n\nget file size (5 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ token(0x6000095)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x6000095)+0x15D\nfunction @ token(0x60001A5)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x60001A5)+0xD4\nfunction @ token(0x60001A8)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x60001A8)+0x79\nfunction @ token(0x60001AA)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x60001AA)+0xB6\nfunction @ token(0x600026B)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x600026B)+0xD3\n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ token(0x600003C) in function token(0x600003C)\n  or:\n    api: System.IO.File::SetAttributes @ token(0x600003C)+0x19\nbasic block @ token(0x60001BF) in function token(0x60001BF)\n  or:\n    api: System.IO.File::SetAttributes @ token(0x60001BF)+0x4A, token(0x60001BF)+0xEE, token(0x60001BF)+0xFD\n\nmove file (2 matches)\nnamespace  host-interaction/file-system/move                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Move File [C0063]                         \nfunction @ token(0x6000144)\n  or:\n    api: System.IO.File::Move @ token(0x6000144)+0x23B\nfunction @ token(0x6000159)\n  or:\n    api: System.IO.File::Move @ token(0x6000159)+0x1D9\n\nread file on Windows (7 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ token(0x6000096)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x6000096)+0x3F\nfunction @ token(0x60000B8)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x60000B8)+0x150\nfunction @ token(0x60000BB)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x60000BB)+0x7F\nfunction @ token(0x60001A5)\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ token(0x60001A5)+0xF5\nfunction @ token(0x60001AC)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x60001AC)+0x1\nfunction @ token(0x60001AD)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x60001AD)+0xB\nfunction @ token(0x60001BD)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x60001BD)+0x70\n\nwrite file on Windows (11 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ token(0x6000019)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000019)+0x40\nfunction @ token(0x6000044)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000044)+0x40\nfunction @ token(0x6000097)\n  or:\n    api: System.IO.File::WriteAllBytes @ token(0x6000097)+0x20\nfunction @ token(0x60000BB)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x60000BB)+0x42\nfunction @ token(0x60000DD)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x60000DD)+0x2A\nfunction @ token(0x6000147)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x6000147)+0x72\nfunction @ token(0x600014A)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x600014A)+0x40\nfunction @ token(0x600015B)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x600015B)+0x47\nfunction @ token(0x600015E)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x600015E)+0x40\nfunction @ token(0x60001A5)\n  or:\n    api: System.IO.File::WriteAllBytes @ token(0x60001A5)+0x136\nfunction @ token(0x60001E8)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x60001E8)+0x6D\n\nenumerate gui resources (2 matches)\nnamespace  host-interaction/gui                           \nauthor     johnk3r, anushka.virgaonkar@mandiant.com       \nscope      function                                       \natt&ck     Discovery::Application Window Discovery [T1010]\nfunction @ token(0x600004D)\n  or:\n    property/read: System.Windows.Forms.Screen::AllScreens @ token(0x600004D)+0x0\nfunction @ token(0x6000054)\n  or:\n    property/read: System.Windows.Forms.Screen::AllScreens @ token(0x6000054)+0x0\n\nset application hook (2 matches)\nnamespace  host-interaction/gui        \nauthor     michael.hunhoff@mandiant.com\nscope      instruction                 \ninstruction @ token(0x60000A7)+0x1C\n  or:\n    api: SetWindowsHookEx @ token(0x60000A7)+0x1C\ninstruction @ token(0x60000AF)+0x66\n  or:\n    api: UnhookWindowsHookEx @ token(0x60000AF)+0x66\n\nchange the wallpaper\nnamespace  host-interaction/gui/session       \nauthor     @_re_fox                           \nscope      basic block                        \nmbc        Operating System::Wallpaper [C0035]\nbasic block @ token(0x60000D7) in function token(0x60000D7)\n  and:\n    api: SystemParametersInfo @ token(0x60000D7)+0x12\n    number: 0x14 = SPI_SETDESKWALLPAPER @ token(0x60000D7)+0x8\n    number: 0x3 = SPIF_SENDWININICHANGE | SPIF_UPDATEINIFILE @ token(0x60000D7)+0x11\n\nfind taskbar (3 matches)\nnamespace  host-interaction/gui/taskbar/find   \nauthor     moritz.raabe@mandiant.com           \nscope      basic block                         \nmbc        Discovery::Taskbar Discovery [B0043]\nbasic block @ token(0x60000C2) in function token(0x60000C2)\n  and:\n    string: \"Shell_TrayWnd\" @ token(0x60000C2)+0x0\n    match: find graphical window @ token(0x60000C2)+0xA\n      or:\n        api: FindWindow @ token(0x60000C2)+0xA\nbasic block @ token(0x60000C3) in function token(0x60000C3)\n  and:\n    string: \"Shell_TrayWnd\" @ token(0x60000C3)+0x0\n    match: find graphical window @ token(0x60000C3)+0xA\n      or:\n        api: FindWindow @ token(0x60000C3)+0xA\nbasic block @ token(0x60000C9) in function token(0x60000C9)\n  and:\n    string: \"Shell_TrayWnd\" @ token(0x60000C9)+0x0\n    match: find graphical window @ token(0x60000C9)+0xA\n      or:\n        api: FindWindow @ token(0x60000C9)+0xA\n\nhide the Windows taskbar\nnamespace  host-interaction/gui/taskbar/hide      \nauthor     michael.hunhoff@mandiant.com           \nscope      function                               \natt&ck     Defense Evasion::Hide Artifacts [T1564]\nfunction @ token(0x60000C2)\n  and:\n    match: find taskbar @ token(0x60000C2)\n      and:\n        string: \"Shell_TrayWnd\" @ token(0x60000C2)+0x0\n        match: find graphical window @ token(0x60000C2)+0xA\n          or:\n            api: FindWindow @ token(0x60000C2)+0xA\n    match: hide graphical window @ token(0x60000C2)\n      and:\n        number: 0x0 = SW_HIDE @ token(0x60000C2)+0xF\n        api: ShowWindow @ token(0x60000C2)+0x10\n\nfind graphical window (3 matches)\nnamespace  host-interaction/gui/window/find               \nauthor     moritz.raabe@mandiant.com                      \nscope      instruction                                    \natt&ck     Discovery::Application Window Discovery [T1010]\ninstruction @ token(0x60000C2)+0xA\n  or:\n    api: FindWindow @ token(0x60000C2)+0xA\ninstruction @ token(0x60000C3)+0xA\n  or:\n    api: FindWindow @ token(0x60000C3)+0xA\ninstruction @ token(0x60000C9)+0xA\n  or:\n    api: FindWindow @ token(0x60000C9)+0xA\n\nhide graphical window\nnamespace  host-interaction/gui/window/hide                          \nauthor     michael.hunhoff@mandiant.com                              \nscope      basic block                                               \natt&ck     Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\nbasic block @ token(0x60000C2) in function token(0x60000C2)\n  and:\n    number: 0x0 = SW_HIDE @ token(0x60000C2)+0xF\n    api: ShowWindow @ token(0x60000C2)+0x10\n\nget disk information\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ token(0x6000093)\n  or:\n    property/read: System.IO.DriveInfo::VolumeLabel @ token(0x6000093)+0x3E, token(0x6000093)+0x4B\n    property/read: System.IO.DriveInfo::DriveType @ token(0x6000093)+0x1E\n    property/read: System.IO.DriveInfo::Name @ token(0x6000093)+0x32\n\nget disk size\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ token(0x6000093)\n  or:\n    property/read: System.IO.DriveInfo::TotalSize @ token(0x6000093)+0x63\n    property/read: System.IO.DriveInfo::AvailableFreeSpace @ token(0x6000093)+0x6F\n\nallocate unmanaged memory in .NET (3 matches)\nnamespace  host-interaction/memory     \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x60001AD)\n  or:\n    api: System.Runtime.InteropServices.Marshal::AllocHGlobal @ token(0x60001AD)+0x3D2, token(0x60001AD)+0x3FA\nfunction @ token(0x60001AF)\n  or:\n    api: System.Runtime.InteropServices.Marshal::AllocHGlobal @ token(0x60001AF)+0x15\nfunction @ token(0x60001B0)\n  or:\n    api: System.Runtime.InteropServices.Marshal::AllocHGlobal @ token(0x60001B0)+0x158, token(0x60001B0)+0x163\n\nmanipulate unmanaged memory in .NET (14 matches)\nnamespace  host-interaction/memory     \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x6000055)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x6000055)+0x14\nfunction @ token(0x60000A8)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60000A8)+0x29\nfunction @ token(0x60000C7)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60000C7)+0x14\nfunction @ token(0x60000C8)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60000C8)+0x14\nfunction @ token(0x60000D7)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60000D7)+0xC\nfunction @ token(0x60000E5)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60000E5)+0x25, token(0x60000E5)+0xA4\nfunction @ token(0x60001A5)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60001A5)+0x5B, token(0x60001A5)+0xFC\nfunction @ token(0x60001AD)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60001AD)+0x3BC, token(0x60001AD)+0x3D2, token(0x60001AD)+0x3E8, \ntoken(0x60001AD)+0x3FA, and 3 more...\nfunction @ token(0x60001AF)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60001AF)+0x15, token(0x60001AF)+0x34, token(0x60001AF)+0x73, \ntoken(0x60001AF)+0xA2\nfunction @ token(0x60001B0)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60001B0)+0x143, token(0x60001B0)+0x158, token(0x60001B0)+0x163, \ntoken(0x60001B0)+0x171, and 3 more...\nfunction @ token(0x60001BB)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60001BB)+0x6C, token(0x60001BB)+0xA3, token(0x60001BB)+0xDE, \ntoken(0x60001BB)+0x11F, and 1 more...\nfunction @ token(0x60001CA)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60001CA)+0x160, token(0x60001CA)+0x187, token(0x60001CA)+0x1C6\nfunction @ token(0x60001CB)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60001CB)+0x15A, token(0x60001CB)+0x181, token(0x60001CB)+0x1C0, \ntoken(0x60001CB)+0x1E5\nfunction @ token(0x60001CC)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60001CC)+0x92, token(0x60001CC)+0xB9, token(0x60001CC)+0xE0, \ntoken(0x60001CC)+0x107\n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex                                               \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           mehunhoff@google.com                                                 \nscope      instruction                                                          \nmbc        Process::Create Mutex [C0042]                                        \ninstruction @ token(0x6000033)+0x211\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Threading.Mutex::ctor @ token(0x6000033)+0x211\n\nget networking interfaces\nnamespace  host-interaction/network/interface                                   \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Network Configuration Discovery [T1016]            \nfunction @ token(0x600011C)\n  or:\n    and:\n      or:\n        api: System.Net.NetworkInformation.NetworkInterface::GetIPProperties @ token(0x600011C)+0x18\n      optional:\n        api: System.Net.NetworkInformation.NetworkInterface::GetAllNetworkInterfaces @ token(0x600011C)+0x6\n\nget hostname (2 matches)\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ token(0x6000049)\n  or:\n    property/read: System.Environment::MachineName @ token(0x6000049)+0x0\nfunction @ token(0x60001A0)\n  or:\n    api: GetComputerName @ token(0x60001A0)+0x18\n    property/read: System.Environment::MachineName @ token(0x60001A0)+0x35\n\nget OS version in .NET\nnamespace  host-interaction/os/version                    \nauthor     michael.hunhoff@mandiant.com                   \nscope      basic block                                    \natt&ck     Discovery::System Information Discovery [T1082]\nbasic block @ token(0x600004B) in function token(0x600004B)\n  or:\n    property/read: System.Environment::OSVersion @ token(0x600004B)+0x6D\n\nget process image filename (5 matches)\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ token(0x6000033) in function token(0x6000033)\n  or:\n    and:\n      api: System.Diagnostics.Process::GetCurrentProcess @ token(0x6000033)+0xC4\n      property/read: System.Diagnostics.Process::MainModule @ token(0x6000033)+0xC9\n      property/read: System.Diagnostics.ProcessModule::FileName @ token(0x6000033)+0xCE\nbasic block @ token(0x600003A) in function token(0x600003A)\n  or:\n    and:\n      api: System.Diagnostics.Process::GetCurrentProcess @ token(0x600003A)+0x0\n      property/read: System.Diagnostics.Process::MainModule @ token(0x600003A)+0x5\n      property/read: System.Diagnostics.ProcessModule::FileName @ token(0x600003A)+0xA\nbasic block @ token(0x600003C) in function token(0x600003C)\n  or:\n    and:\n      api: System.Diagnostics.Process::GetCurrentProcess @ token(0x600003C)+0x9\n      property/read: System.Diagnostics.Process::MainModule @ token(0x600003C)+0xE\n      property/read: System.Diagnostics.ProcessModule::FileName @ token(0x600003C)+0x13\nbasic block @ token(0x600003E) in function token(0x600003E)\n  or:\n    and:\n      api: System.Diagnostics.Process::GetCurrentProcess @ token(0x600003E)+0x0\n      property/read: System.Diagnostics.Process::MainModule @ token(0x600003E)+0x5\n      property/read: System.Diagnostics.ProcessModule::FileName @ token(0x600003E)+0xA\nbasic block @ token(0x60001E8) in function token(0x60001E8)\n  or:\n    and:\n      api: System.Diagnostics.Process::GetCurrentProcess @ token(0x60001E8)+0x0, token(0x60001E8)+0x42\n      property/read: System.Diagnostics.Process::MainModule @ token(0x60001E8)+0x5\n      property/read: System.Diagnostics.ProcessModule::FileName @ token(0x60001E8)+0xA\n\ncreate a process with modified I/O handles and window (14 matches)\nnamespace   host-interaction/process/create                                     \nauthor      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com      \nscope       function                                                            \nmbc         Process::Create Process [C0017]                                     \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/processthreadsap…\nfunction @ token(0x6000033)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000033)+0xF4\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000033)+0xE4\n        property/write: System.Diagnostics.ProcessStartInfo::Verb @ token(0x6000033)+0xEF\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000033)+0xDD\nfunction @ token(0x600003A)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600003A)+0x5F, token(0x600003A)+0xE0\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600003A)+0x4C, token(0x600003A)+0xCC\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600003A)+0x3E, token(0x600003A)+0xBE\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600003A)+0x21, token(0x600003A)+0x86\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600003A)+0x37, token(0x600003A)+0xB7\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600003A)+0x45, token(0x600003A)+0xC5\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600003A)+0x53, token(0x600003A)+0xD3\nfunction @ token(0x600003B)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600003B)+0x4F\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600003B)+0x3C\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600003B)+0x2E\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600003B)+0x11\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600003B)+0x27\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600003B)+0x35\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600003B)+0x43\nfunction @ token(0x600003E)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600003E)+0x7B\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600003E)+0x68\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600003E)+0x6F\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600003E)+0x61\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600003E)+0x76\nfunction @ token(0x60000F7)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x60000F7)+0x42, token(0x60000F7)+0x11F\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x60000F7)+0x29, token(0x60000F7)+0x106\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x60000F7)+0x17, token(0x60000F7)+0xE8\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x60000F7)+0x22, token(0x60000F7)+0xFF\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x60000F7)+0x37, token(0x60000F7)+0x114\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x60000F7)+0x30, token(0x60000F7)+0x10D\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x60000F7)+0x49, token(0x60000F7)+0x126\nfunction @ token(0x600011D)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600011D)+0x42, token(0x600011D)+0x11F\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600011D)+0x29, token(0x600011D)+0x106\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600011D)+0x17, token(0x600011D)+0xE8\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600011D)+0x22, token(0x600011D)+0xFF\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600011D)+0x37, token(0x600011D)+0x114\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600011D)+0x30, token(0x600011D)+0x10D\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x600011D)+0x49, token(0x600011D)+0x126\nfunction @ token(0x600011E)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600011E)+0x42\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600011E)+0x29\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600011E)+0x17\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600011E)+0x22\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600011E)+0x37\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600011E)+0x30\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x600011E)+0x49\nfunction @ token(0x6000144)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000144)+0x1B8\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000144)+0x186\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000144)+0x1A6\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000144)+0x13D\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000144)+0x17E\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000144)+0x19E\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x6000144)+0x18E\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x6000144)+0x1C0\nfunction @ token(0x6000147)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000147)+0x100\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000147)+0xD6\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000147)+0xF2\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000147)+0xB9\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000147)+0xCF\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000147)+0xEB\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x6000147)+0xDD\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x6000147)+0x108\nfunction @ token(0x6000148)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000148)+0xD5\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000148)+0xAD\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000148)+0xC9\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000148)+0x81\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000148)+0xA6\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000148)+0xC2\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x6000148)+0xB4\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x6000148)+0xDC\nfunction @ token(0x6000159)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000159)+0x190\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000159)+0x161\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000159)+0x181\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000159)+0x118\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000159)+0x159\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000159)+0x179\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x6000159)+0x169\nfunction @ token(0x600015B)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600015B)+0xCB\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600015B)+0xA4\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600015B)+0xC0\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600015B)+0x87\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600015B)+0x9D\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600015B)+0xB9\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600015B)+0xAB\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x600015B)+0xD2\nfunction @ token(0x600015C)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600015C)+0x99\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600015C)+0x72\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600015C)+0x8E\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600015C)+0x46\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600015C)+0x6B\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600015C)+0x87\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600015C)+0x79\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x600015C)+0xA0\nfunction @ token(0x60001E8)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x60001E8)+0x8C\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x60001E8)+0x80\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x60001E8)+0x79\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x60001E8)+0x87\n\ncreate process on Windows (22 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ token(0x6000033) in function token(0x6000033)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000033)+0xF4\nbasic block @ token(0x6000039) in function token(0x6000039)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000039)+0x1DE1, token(0x6000039)+0x1FD1\nbasic block @ token(0x600003A) in function token(0x600003A)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600003A)+0x5F, token(0x600003A)+0xE0\nbasic block @ token(0x600003B) in function token(0x600003B)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600003B)+0x4F\nbasic block @ token(0x600003E) in function token(0x600003E)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600003E)+0x7B\nbasic block @ token(0x6000099) in function token(0x6000099)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000099)+0x1\nbasic block @ token(0x60000D5) in function token(0x60000D5)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x60000D5)+0x28\nbasic block @ token(0x60000D8) in function token(0x60000D8)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x60000D8)+0xA\nbasic block @ token(0x60000DB) in function token(0x60000DB)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x60000DB)+0x5\nbasic block @ token(0x60000DC) in function token(0x60000DC)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x60000DC)+0x5\nbasic block @ token(0x60000DD) in function token(0x60000DD)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x60000DD)+0x35\nbasic block @ token(0x60000F7) in function token(0x60000F7)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x60000F7)+0x42, token(0x60000F7)+0x11F\nbasic block @ token(0x600011D) in function token(0x600011D)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600011D)+0x42, token(0x600011D)+0x11F\nbasic block @ token(0x600011E) in function token(0x600011E)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600011E)+0x42\nbasic block @ token(0x6000144) in function token(0x6000144)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000144)+0x1B8\nbasic block @ token(0x6000147) in function token(0x6000147)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000147)+0x100\nbasic block @ token(0x6000148) in function token(0x6000148)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000148)+0xD5\nbasic block @ token(0x6000159) in function token(0x6000159)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000159)+0x190\nbasic block @ token(0x600015B) in function token(0x600015B)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600015B)+0xCB\nbasic block @ token(0x600015C) in function token(0x600015C)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600015C)+0x99\nbasic block @ token(0x60001E8) in function token(0x60001E8)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x60001E8)+0x8C\nbasic block @ token(0x6000207) in function token(0x6000207)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000207)+0x10\n\nenumerate processes (2 matches)\nnamespace  host-interaction/process/list                                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      function                                                             \natt&ck     Discovery::Process Discovery [T1057], Discovery::Software Discovery  \n           [T1518]                                                              \nfunction @ token(0x6000060)\n  or:\n    api: System.Diagnostics.Process::GetProcesses @ token(0x6000060)+0x6\nfunction @ token(0x60000D9)\n  or:\n    api: System.Diagnostics.Process::GetProcesses @ token(0x60000D9)+0xD\n\nfind process by PID (2 matches)\nnamespace  host-interaction/process/list                                \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::Process Discovery [T1057]                         \nfunction @ token(0x6000061)\n  and:\n    or:\n      api: System.Diagnostics.Process::GetProcessById @ token(0x6000061)+0x1\nfunction @ token(0x6000062)\n  and:\n    or:\n      api: System.Diagnostics.Process::GetProcessById @ token(0x6000062)+0x1\n\nfind process by name\nnamespace  host-interaction/process/list       \nauthor     anushka.virgaonkar@mandiant.com     \nscope      function                            \natt&ck     Discovery::Process Discovery [T1057]\nfunction @ token(0x60001BB)\n  and:\n    api: System.Diagnostics.Process::GetProcessesByName @ token(0x60001BB)+0x7\n\nacquire debug privileges\nnamespace  host-interaction/process/modify                        \nauthor     william.ballenthin@mandiant.com                        \nscope      basic block                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\nbasic block @ token(0x60001BA) in function token(0x60001BA)\n  and:\n    string: \"SeDebugPrivilege\" @ token(0x60001BA)+0x13\n    optional:\n      match: modify access privileges @ token(0x60001BA)+0x59\n        and:\n          api: AdjustTokenPrivileges @ token(0x60001BA)+0x59\n\nmodify access privileges\nnamespace  host-interaction/process/modify                        \nauthor     moritz.raabe@mandiant.com                              \nscope      instruction                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\ninstruction @ token(0x60001BA)+0x59\n  and:\n    api: AdjustTokenPrivileges @ token(0x60001BA)+0x59\n\nterminate process (14 matches)\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ token(0x600003A)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x600003A)+0x6F, token(0x600003A)+0xEF\nfunction @ token(0x600003B)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x600003B)+0x5E\nfunction @ token(0x6000061)\n  or:\n    api: System.Diagnostics.Process::Kill @ token(0x6000061)+0x25, token(0x6000061)+0x3C\n    api: System.Diagnostics.Process::WaitForExit @ token(0x6000061)+0x14, token(0x6000061)+0x30, token(0x6000061)+0x47\nfunction @ token(0x60000F7)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x60000F7)+0x54, token(0x60000F7)+0x132\nfunction @ token(0x600011D)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x600011D)+0x54, token(0x600011D)+0x132\nfunction @ token(0x600011E)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x600011E)+0x54\nfunction @ token(0x6000144)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x6000144)+0x1E0\nfunction @ token(0x6000147)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x6000147)+0x129\nfunction @ token(0x6000148)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x6000148)+0xFB\nfunction @ token(0x6000159)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x6000159)+0x19C\nfunction @ token(0x600015B)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x600015B)+0xF0\nfunction @ token(0x600015C)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x600015C)+0xB1\nfunction @ token(0x60001E7)\n  or:\n    api: System.Environment::Exit @ token(0x60001E7)+0x2F\nfunction @ token(0x60001E8)\n  or:\n    api: System.Environment::Exit @ token(0x60001E8)+0x99\n\nquery or enumerate registry key (7 matches)\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ token(0x6000039)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000039)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000039)+0x1FE8\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000039)+0x1FE8\nfunction @ token(0x600006F)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600006F)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600006F)+0x10, token(0x600006F)+0x8E\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600006F)+0x10, token(0x600006F)+0x8E\nfunction @ token(0x6000071)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000071)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000071)+0xB\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000071)+0xB\nfunction @ token(0x60000F9)\n  and:\n    optional:\n      match: create or open registry key @ token(0x60000F9)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000F9)+0x10\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000F9)+0x10\nfunction @ token(0x6000255)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000255)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000255)+0x67\n    or:\n      api: Microsoft.Win32.RegistryKey::GetSubKeyNames @ token(0x6000255)+0x7F\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000255)+0x67\nfunction @ token(0x6000257)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000257)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000257)+0x3C\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000257)+0x3C\nfunction @ token(0x6000259)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000259)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000259)+0x36\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000259)+0x36\n\nquery or enumerate registry value (2 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ token(0x600006F)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600006F)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600006F)+0x10, token(0x600006F)+0x8E\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x600006F)+0x2C, token(0x600006F)+0xAE\n      api: Microsoft.Win32.RegistryKey::GetValueNames @ token(0x600006F)+0x1A, token(0x600006F)+0x9B\nfunction @ token(0x6000255)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000255)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000255)+0x67\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x6000255)+0xFE\n      api: Microsoft.Win32.RegistryKey::GetValueKind @ token(0x6000255)+0x108\n      api: Microsoft.Win32.RegistryKey::GetValueNames @ token(0x6000255)+0xE5\n\nset registry value (5 matches)\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ token(0x6000039)\n  or:\n    and:\n      match: host-interaction/process/create @ token(0x6000039)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x6000039)+0x1DE1, token(0x6000039)+0x1FD1\n      regex: /add/i\n        - \"add_startup\" @ token(0x6000039)+0x6C2\n        - \"add_to_startup\" @ token(0x6000039)+0x79E\n      or:\n        regex: /reg(|.exe)/i\n          - \"Listing registry (normalized): \" @ token(0x6000039)+0x23A4\n          - \"Registry list packet data: \" @ token(0x6000039)+0x2153\n          - \"Setting registry value: \" @ token(0x6000039)+0x2434\n          - \"list_registry\" @ token(0x6000039)+0x453\n          - \"set_registry_value\" @ token(0x6000039)+0x8E8\n        regex: /hklm/i\n          - \"HKLM\" @ token(0x6000039)+0x21FC\n        regex: /HKEY_LOCAL_MACHINE/i\n          - \"HKEY_LOCAL_MACHINE\" @ token(0x6000039)+0x21CC\n        regex: /hkcu/i\n          - \"HKCU\" @ token(0x6000039)+0x21F4\n        regex: /HKEY_CURRENT_USER/i\n          - \"HKEY_CURRENT_USER\" @ token(0x6000039)+0x218F, token(0x6000039)+0x21C4\n    and:\n      optional:\n        match: create or open registry key @ token(0x6000039)\n          or:\n            api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000039)+0x1FE8\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000039)+0x2000\nfunction @ token(0x600003E)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x600003E)\n          or:\n            api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x600003E)+0x1C\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x600003E)+0x34, token(0x600003E)+0x45\nfunction @ token(0x600003E)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x600003E)\n          or:\n            api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x600003E)+0x1C\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x600003E)+0x34, token(0x600003E)+0x45\nfunction @ token(0x6000070)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x6000070)\n          or:\n            api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x6000070)+0xA\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000070)+0x13\nfunction @ token(0x6000257)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x6000257)\n          or:\n            api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000257)+0x3C\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000257)+0x14B\n\ndelete registry key\nnamespace  host-interaction/registry/delete                                \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\nscope      function                                                        \natt&ck     Defense Evasion::Modify Registry [T1112]                        \nmbc        Operating System::Registry::Delete Registry Key [C0036.002]     \nfunction @ token(0x600003E)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600003E)\n        or:\n          api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x600003E)+0x1C\n    or:\n      api: Microsoft.Win32.RegistryKey::DeleteSubKeyTree @ token(0x600003E)+0xA6, token(0x600003E)+0xC0\n\ndelete registry value (2 matches)\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ token(0x6000071)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000071)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000071)+0xB\n    or:\n      api: Microsoft.Win32.RegistryKey::DeleteValue @ token(0x6000071)+0x17\nfunction @ token(0x6000259)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000259)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000259)+0x36\n    or:\n      api: Microsoft.Win32.RegistryKey::DeleteValue @ token(0x6000259)+0x4A\n\nget session integrity level (3 matches)\nnamespace  host-interaction/session                                     \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::System Owner/User Discovery [T1033]               \nfunction @ token(0x600003D)\n  or:\n    and:\n      api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x600003D)+0x0\n      number: 0x220 = BUILTIN\\Administrators @ token(0x600003D)+0xA\n      api: System.Security.Principal.WindowsPrincipal::IsInRole @ token(0x600003D)+0xF\nfunction @ token(0x600007A)\n  or:\n    and:\n      api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x600007A)+0x0\n      number: 0x220 = BUILTIN\\Administrators @ token(0x600007A)+0xA\n      api: System.Security.Principal.WindowsPrincipal::IsInRole @ token(0x600007A)+0xF\nfunction @ token(0x60001B9)\n  or:\n    and:\n      api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x60001B9)+0x0\n      number: 0x220 = BUILTIN\\Administrators @ token(0x60001B9)+0xA\n      api: System.Security.Principal.WindowsPrincipal::IsInRole @ token(0x60001B9)+0xF\n\nget session user name (5 matches)\nnamespace  host-interaction/session                                             \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope      function                                                             \natt&ck     Discovery::System Owner/User Discovery [T1033], Discovery::Account   \n           Discovery [T1087]                                                    \nfunction @ token(0x600003D)\n  or:\n    api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x600003D)+0x0\nfunction @ token(0x600004A)\n  or:\n    property/read: System.Environment::UserName @ token(0x600004A)+0x0\nfunction @ token(0x600007A)\n  or:\n    api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x600007A)+0x0\nfunction @ token(0x6000149)\n  or:\n    property/read: System.Environment::UserName @ token(0x6000149)+0x16\nfunction @ token(0x60001B9)\n  or:\n    api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x60001B9)+0x0\n\ncreate thread (3 matches)\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ token(0x60000A4) in function token(0x60000A4)\n  or:\n    and:\n      api: System.Threading.Thread::Start @ token(0x60000A4)+0x47\n      optional:\n        api: System.Threading.Thread::ctor @ token(0x60000A4)+0x24\nbasic block @ token(0x60000C4) in function token(0x60000C4)\n  or:\n    and:\n      api: System.Threading.Thread::Start @ token(0x60000C4)+0x38\n      optional:\n        api: System.Threading.Thread::ctor @ token(0x60000C4)+0x25\nbasic block @ token(0x60000EC) in function token(0x60000EC)\n  or:\n    and:\n      api: System.Threading.Thread::Start @ token(0x60000EC)+0x57\n      optional:\n        api: System.Threading.Thread::ctor @ token(0x60000EC)+0x2F\n\nsuspend thread (9 matches)\nnamespace  host-interaction/thread/suspend                    \nauthor     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\nscope      basic block                                        \nmbc        Process::Suspend Thread [C0055]                    \nbasic block @ token(0x6000010) in function token(0x6000010)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000010)+0x16D, token(0x6000010)+0x1B4, token(0x6000010)+0x1CB\nbasic block @ token(0x6000011) in function token(0x6000011)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000011)+0xEC, token(0x6000011)+0x134\nbasic block @ token(0x6000033) in function token(0x6000033)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000033)+0xA5\nbasic block @ token(0x6000035) in function token(0x6000035)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000035)+0xC1, token(0x6000035)+0xED\nbasic block @ token(0x6000037) in function token(0x6000037)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000037)+0x24A, token(0x6000037)+0x363, token(0x6000037)+0x370, \ntoken(0x6000037)+0x3A1, and 2 more...\nbasic block @ token(0x600003E) in function token(0x600003E)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x600003E)+0x96\nbasic block @ token(0x60000DA) in function token(0x60000DA)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x60000DA)+0x55\nbasic block @ token(0x60001E7) in function token(0x60001E7)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x60001E7)+0x14\nbasic block @ token(0x6000207) in function token(0x6000207)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000207)+0x18\n\naccess WMI data in .NET\nnamespace  host-interaction/wmi                                 \nauthor     michael.hunhoff@mandiant.com                         \nscope      function                                             \natt&ck     Execution::Windows Management Instrumentation [T1047]\nfunction @ token(0x600004B)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x600004B)+0xC\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x600004B)+0x5\n\nreference cryptocurrency strings\nnamespace   impact/cryptocurrency                                               \nauthor      moritz.raabe@mandiant.com                                           \nscope       file                                                                \natt&ck      Impact::Resource Hijacking [T1496]                                  \nreferences  https://github.com/ctxis/CAPE/blob/master/modules/signatures/crypto…\nor:\n  string: \"Bitcoin\" @ file+0x258F8\n  string: \"Ethereum\" @ file+0x2591A\n  string: \"Dash\" @ file+0x25A16\n  string: \"Monero\" @ file+0x25A46\n  string: \"Zcash\" @ file+0x25A2C\n\ndisable system features via registry on Windows\nnamespace  impact/features                                                      \nauthor     mehunhoff@google.com                                                 \nscope      function                                                             \natt&ck     Defense Evasion::Impair Defenses::Disable or Modify Tools [T1562.001]\nmbc        Defense Evasion::Disable or Evade Security Tools [F0004]             \nfunction @ token(0x6000039)\n  and:\n    match: set registry value @ token(0x6000039)\n      or:\n        and:\n          match: host-interaction/process/create @ token(0x6000039)\n            or:\n              api: System.Diagnostics.Process::Start @ token(0x6000039)+0x1DE1, token(0x6000039)+0x1FD1\n          regex: /add/i\n            - \"add_startup\" @ token(0x6000039)+0x6C2\n            - \"add_to_startup\" @ token(0x6000039)+0x79E\n          or:\n            regex: /reg(|.exe)/i\n              - \"Listing registry (normalized): \" @ token(0x6000039)+0x23A4\n              - \"Registry list packet data: \" @ token(0x6000039)+0x2153\n              - \"Setting registry value: \" @ token(0x6000039)+0x2434\n              - \"list_registry\" @ token(0x6000039)+0x453\n              - \"set_registry_value\" @ token(0x6000039)+0x8E8\n            regex: /hklm/i\n              - \"HKLM\" @ token(0x6000039)+0x21FC\n            regex: /HKEY_LOCAL_MACHINE/i\n              - \"HKEY_LOCAL_MACHINE\" @ token(0x6000039)+0x21CC\n            regex: /hkcu/i\n              - \"HKCU\" @ token(0x6000039)+0x21F4\n            regex: /HKEY_CURRENT_USER/i\n              - \"HKEY_CURRENT_USER\" @ token(0x6000039)+0x218F, token(0x6000039)+0x21C4\n        and:\n          optional:\n            match: create or open registry key @ token(0x6000039)\n              or:\n                api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000039)+0x1FE8\n          or:\n            api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000039)+0x2000\n    or:\n      and:\n        regex: /SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Policies\\\\System/i\n          - \"SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Policies\\\\System\" @ token(0x6000039)+0x1FE2\n        or:\n          regex: /EnableLUA/i\n            - \"EnableLUA\" @ token(0x6000039)+0x1FF5\n\n(internal) .NET file limitation\nnamespace    internal/limitation/dynamic                        \nauthor       @v1bh475u                                          \nscope        file                                               \ndescription  This dynamic analysis trace describes a .NET file. \n                                                                \n             capa rules are not yet tuned for the .NET runtime, \n             so its analysis may be incomplete or misleading.   \n                                                                \nor:\n  format: dotnet\n\ncompile .NET assembly\nnamespace  load-code/dotnet                                                     \nauthor     anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information::Compile After      \n           Delivery [T1027.004]                                                 \nfunction @ token(0x600027A)\n  or:\n    api: System.CodeDom.Compiler.CodeDomProvider::CompileAssemblyFromSource @ token(0x600027A)+0x138\n\ninvoke .NET assembly method (2 matches)\nnamespace  load-code/dotnet                                     \nauthor     anushka.virgaonkar@mandiant.com, mehunhoff@google.com\nscope      function                                             \natt&ck     Defense Evasion::Reflective Code Loading [T1620]     \nfunction @ token(0x6000146)\n  and:\n    format: dotnet\n    or:\n      api: System.Reflection.MethodBase::Invoke @ token(0x6000146)+0x187, token(0x6000146)+0x19B, token(0x6000146)+0x1CB, \ntoken(0x6000146)+0x207, and 6 more...\n    optional:\n      api: System.Type::GetMethod @ token(0x6000146)+0x17F, token(0x6000146)+0x193, token(0x6000146)+0x1C3, \ntoken(0x6000146)+0x1F1, and 6 more...\nfunction @ token(0x600027A)\n  and:\n    format: dotnet\n    or:\n      api: System.Reflection.MethodBase::Invoke @ token(0x600027A)+0x2A8\n    optional:\n      api: System.Type::GetMethod @ token(0x600027A)+0x257\n\nload .NET assembly\nnamespace  load-code/dotnet                                \nauthor     anushka.virgaonkar@mandiant.com                 \nscope      function                                        \natt&ck     Defense Evasion::Reflective Code Loading [T1620]\nfunction @ token(0x6000146)\n  or:\n    api: System.Reflection.Assembly::LoadFrom @ token(0x6000146)+0x7A\n\ncompile CSharp in .NET\nnamespace  load-code/dotnet/csharp                                              \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information::Compile After      \n           Delivery [T1027.004]                                                 \nfunction @ token(0x600027A)\n  and:\n    match: compile .NET assembly @ token(0x600027A)\n      or:\n        api: System.CodeDom.Compiler.CodeDomProvider::CompileAssemblyFromSource @ token(0x600027A)+0x138\n    api: Microsoft.CSharp.CSharpCodeProvider::ctor @ token(0x600027A)+0x12\n\npersist via default file association registry key (2 matches)\nnamespace   persistence/registry                                                \nauthor      j.j.vannielen@utwente.nl                                            \nscope       function                                                            \natt&ck      Persistence::Event Triggered Execution::Change Default File         \n            Association [T1546.001]                                             \nreferences  https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/…\n            https://giuliocomi.blogspot.com/2019/10/abusing-windows-10-narrator…\nfunction @ token(0x600003E)\n  and:\n    match: set registry value @ token(0x600003E)\n      or:\n        and:\n          optional:\n            match: create or open registry key @ token(0x600003E)\n              or:\n                api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x600003E)+0x1C\n          or:\n            api: Microsoft.Win32.RegistryKey::SetValue @ token(0x600003E)+0x34, token(0x600003E)+0x45\n    or:\n      regex: /\\\\shell\\\\open\\\\command/i\n        - \"Software\\\\Classes\\\\ms-settings\\\\Shell\\\\Open\\\\command\" @ token(0x600003E)+0x10\nfunction @ token(0x600003E)\n  and:\n    match: set registry value @ token(0x600003E)\n      or:\n        and:\n          optional:\n            match: create or open registry key @ token(0x600003E)\n              or:\n                api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x600003E)+0x1C\n          or:\n            api: Microsoft.Win32.RegistryKey::SetValue @ token(0x600003E)+0x34, token(0x600003E)+0x45\n    or:\n      regex: /\\\\shell\\\\open\\\\command/i\n        - \"Software\\\\Classes\\\\ms-settings\\\\Shell\\\\Open\\\\command\" @ token(0x600003E)+0x10\n\npersist via Run registry key\nnamespace  persistence/registry/run                                             \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com                      \nscope      function                                                             \natt&ck     Persistence::Boot or Logon Autostart Execution::Registry Run Keys /  \n           Startup Folder [T1547.001]                                           \nmbc        Persistence::Registry Run Keys / Startup Folder [F0012]              \nfunction @ token(0x6000070)\n  and:\n    or:\n      match: set registry value @ token(0x6000070)\n        or:\n          and:\n            optional:\n              match: create or open registry key @ token(0x6000070)\n                or:\n                  api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x6000070)+0xA\n            or:\n              api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000070)+0x13\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\" @ token(0x6000070)+0x5\n\nschedule task via schtasks (2 matches)\nnamespace   persistence/scheduled-tasks                                         \nauthor      0x534a@mailbox.org, j.j.vannielen@utwente.nl                        \nscope       function                                                            \natt&ck      Persistence::Scheduled Task/Job::Scheduled Task [T1053.005]         \nreferences  https://learn.microsoft.com/en-us/windows/win32/taskschd/task-sched…\n            https://stmxcsr.com/persistence/scheduled-tasks.html                \nfunction @ token(0x600003A)\n  or:\n    and:\n      match: host-interaction/process/create @ token(0x600003A)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x600003A)+0x5F, token(0x600003A)+0xE0\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x600003A)+0x5F, token(0x600003A)+0xE0\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600003A)+0x4C, token(0x600003A)+0xCC\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600003A)+0x3E, token(0x600003A)+0xBE\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600003A)+0x21, token(0x600003A)+0x86\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600003A)+0x37, token(0x600003A)+0xB7\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600003A)+0x45, token(0x600003A)+0xC5\n              property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600003A)+0x53, token(0x600003A)+0xD3\n      or:\n        and:\n          regex: /schtasks/i\n            - \"schtasks.exe\" @ token(0x600003A)+0x1C, token(0x600003A)+0x81\n          or:\n            regex: /\\/create/i\n              - \"/create /tn \\\"\" @ token(0x600003A)+0x94\nfunction @ token(0x600003A)\n  or:\n    and:\n      match: host-interaction/process/create @ token(0x600003A)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x600003A)+0x5F, token(0x600003A)+0xE0\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x600003A)+0x5F, token(0x600003A)+0xE0\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600003A)+0x4C, token(0x600003A)+0xCC\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600003A)+0x3E, token(0x600003A)+0xBE\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600003A)+0x21, token(0x600003A)+0x86\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600003A)+0x37, token(0x600003A)+0xB7\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600003A)+0x45, token(0x600003A)+0xC5\n              property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x600003A)+0x53, token(0x600003A)+0xD3\n      or:\n        and:\n          regex: /schtasks/i\n            - \"schtasks.exe\" @ token(0x600003A)+0x1C, token(0x600003A)+0x81\n          or:\n            regex: /\\/create/i\n              - \"/create /tn \\\"\" @ token(0x600003A)+0x94\n\nunmanaged call (42 matches)\nnamespace    runtime                                                       \nauthor       michael.hunhoff@mandiant.com                                  \nscope        function                                                      \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nfunction @ token(0x6000055)\n  or:\n    characteristic: unmanaged call @ token(0x6000055)+0x20, token(0x6000055)+0x8E, token(0x6000055)+0xFF, \ntoken(0x6000055)+0x12A, and 1 more...\nfunction @ token(0x6000063)\n  or:\n    characteristic: unmanaged call @ token(0x6000063)+0x22, token(0x6000063)+0x36, token(0x6000063)+0x3D\nfunction @ token(0x60000A5)\n  or:\n    characteristic: unmanaged call @ token(0x60000A5)+0x3C\nfunction @ token(0x60000A7)\n  or:\n    characteristic: unmanaged call @ token(0x60000A7)+0x16, token(0x60000A7)+0x1C\nfunction @ token(0x60000A8)\n  or:\n    characteristic: unmanaged call @ token(0x60000A8)+0x79\nfunction @ token(0x60000AA)\n  or:\n    characteristic: unmanaged call @ token(0x60000AA)+0xE9, token(0x60000AA)+0xFA\nfunction @ token(0x60000AF)\n  or:\n    characteristic: unmanaged call @ token(0x60000AF)+0x3A, token(0x60000AF)+0x42, token(0x60000AF)+0x51, \ntoken(0x60000AF)+0x66\nfunction @ token(0x60000C2)\n  or:\n    characteristic: unmanaged call @ token(0x60000C2)+0xA, token(0x60000C2)+0x10\nfunction @ token(0x60000C3)\n  or:\n    characteristic: unmanaged call @ token(0x60000C3)+0xA, token(0x60000C3)+0x10\nfunction @ token(0x60000C7)\n  or:\n    characteristic: unmanaged call @ token(0x60000C7)+0x23, token(0x60000C7)+0x4A\nfunction @ token(0x60000C8)\n  or:\n    characteristic: unmanaged call @ token(0x60000C8)+0x23, token(0x60000C8)+0x41\nfunction @ token(0x60000C9)\n  or:\n    characteristic: unmanaged call @ token(0x60000C9)+0xA, token(0x60000C9)+0x1A\nfunction @ token(0x60000CA)\n  or:\n    characteristic: unmanaged call @ token(0x60000CA)+0x9\nfunction @ token(0x60000CB)\n  or:\n    characteristic: unmanaged call @ token(0x60000CB)+0x9\nfunction @ token(0x60000D2)\n  or:\n    characteristic: unmanaged call @ token(0x60000D2)+0xC\nfunction @ token(0x60000D3)\n  or:\n    characteristic: unmanaged call @ token(0x60000D3)+0xC\nfunction @ token(0x60000D4)\n  or:\n    characteristic: unmanaged call @ token(0x60000D4)+0x1\nfunction @ token(0x60000D6)\n  or:\n    characteristic: unmanaged call @ token(0x60000D6)+0x13, token(0x60000D6)+0x26\nfunction @ token(0x60000D7)\n  or:\n    characteristic: unmanaged call @ token(0x60000D7)+0x12\nfunction @ token(0x60000DA)\n  or:\n    characteristic: unmanaged call @ token(0x60000DA)+0x3, token(0x60000DA)+0x4D, token(0x60000DA)+0x70\nfunction @ token(0x60000E5)\n  or:\n    characteristic: unmanaged call @ token(0x60000E5)+0x12, token(0x60000E5)+0x3D, token(0x60000E5)+0x5D, \ntoken(0x60000E5)+0x82\nfunction @ token(0x60000ED)\n  or:\n    characteristic: unmanaged call @ token(0x60000ED)+0x31\nfunction @ token(0x60000F4)\n  or:\n    characteristic: unmanaged call @ token(0x60000F4)+0x17\nfunction @ token(0x6000176)\n  or:\n    characteristic: unmanaged call @ token(0x6000176)+0x2\nfunction @ token(0x6000177)\n  or:\n    characteristic: unmanaged call @ token(0x6000177)+0x2, token(0x6000177)+0x31\nfunction @ token(0x6000178)\n  or:\n    characteristic: unmanaged call @ token(0x6000178)+0x2, token(0x6000178)+0x32\nfunction @ token(0x6000179)\n  or:\n    characteristic: unmanaged call @ token(0x6000179)+0x2, token(0x6000179)+0x27\nfunction @ token(0x600017A)\n  or:\n    characteristic: unmanaged call @ token(0x600017A)+0x9, token(0x600017A)+0x17, token(0x600017A)+0x25, \ntoken(0x600017A)+0x39, and 1 more...\nfunction @ token(0x600017B)\n  or:\n    characteristic: unmanaged call @ token(0x600017B)+0xF, token(0x600017B)+0x1A, token(0x600017B)+0x28, \ntoken(0x600017B)+0x36, and 1 more...\nfunction @ token(0x600017C)\n  or:\n    characteristic: unmanaged call @ token(0x600017C)+0x3CB, token(0x600017C)+0x3F6\nfunction @ token(0x60001A0)\n  or:\n    characteristic: unmanaged call @ token(0x60001A0)+0x18\nfunction @ token(0x60001A5)\n  or:\n    characteristic: unmanaged call @ token(0x60001A5)+0x48, token(0x60001A5)+0xF5, token(0x60001A5)+0x158\nfunction @ token(0x60001AD)\n  or:\n    characteristic: unmanaged call @ token(0x60001AD)+0x105, token(0x60001AD)+0x37D, token(0x60001AD)+0x39E, \ntoken(0x60001AD)+0x441, and 3 more...\nfunction @ token(0x60001AF)\n  or:\n    characteristic: unmanaged call @ token(0x60001AF)+0x52, token(0x60001AF)+0x7E\nfunction @ token(0x60001B0)\n  or:\n    characteristic: unmanaged call @ token(0x60001B0)+0x70, token(0x60001B0)+0xBB, token(0x60001B0)+0xFC, \ntoken(0x60001B0)+0x1D1, and 2 more...\nfunction @ token(0x60001B5)\n  or:\n    characteristic: unmanaged call @ token(0x60001B5)+0x21, token(0x60001B5)+0x43\nfunction @ token(0x60001B7)\n  or:\n    characteristic: unmanaged call @ token(0x60001B7)+0x20, token(0x60001B7)+0x5A, token(0x60001B7)+0x79, \ntoken(0x60001B7)+0xAD, and 7 more...\nfunction @ token(0x60001BA)\n  or:\n    characteristic: unmanaged call @ token(0x60001BA)+0x0, token(0x60001BA)+0x9, token(0x60001BA)+0x1A, \ntoken(0x60001BA)+0x22, and 2 more...\nfunction @ token(0x60001BB)\n  or:\n    characteristic: unmanaged call @ token(0x60001BB)+0x59, token(0x60001BB)+0x90, token(0x60001BB)+0xD7, \ntoken(0x60001BB)+0xFC, and 7 more...\nfunction @ token(0x60001CA)\n  or:\n    characteristic: unmanaged call @ token(0x60001CA)+0x39, token(0x60001CA)+0xAE, token(0x60001CA)+0xF1, \ntoken(0x60001CA)+0x142, and 5 more...\nfunction @ token(0x60001CB)\n  or:\n    characteristic: unmanaged call @ token(0x60001CB)+0x39, token(0x60001CB)+0xA8, token(0x60001CB)+0xEB, \ntoken(0x60001CB)+0x13C, and 8 more...\nfunction @ token(0x60001CC)\n  or:\n    characteristic: unmanaged call @ token(0x60001CC)+0x29, token(0x60001CC)+0x60, token(0x60001CC)+0x74, \ntoken(0x60001CC)+0x9B, and 7 more...\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  format: dotnet\n\n\n\n"},"hashes":{"md5":"9a5ff998dbf0f6923d0b454d89800fb4","sha1":"4f4fa23e9c503b941a5e91584d6ecc3813962ba1","sha256":"360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f1585432b28f"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 574</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 18525</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"now_you\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"9a5ff998dbf0f6923d0b454d89800fb4\",\n        \"sha256\": \"360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f15\",\n        \"arch\": \"any\",\n        \"os\": \"any\",\n        \"format\": \"dotnet\"\n      }\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_Microsoft\",\n      \"label\": \"Microsoft\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_self_delete__3_matches_\",\n      \"label\": \"self delete (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_System\",\n      \"label\": \"System\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_geographical_location\",\n      \"label\": \"get geographical location\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"cap_save_image_in__net\",\n      \"label\": \"save image in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_gather_firefox_profile_information\",\n      \"label\": \"gather firefox profile information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Credential Access::Credentials from Password Stores::Credentials from\",\n        \"Web Browsers [T1555.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______re_fox__still_teamt5_org\",\n      \"label\": \"author     @_re_fox, still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Credential Access::Credentials from Password Stores::Credentials from\",\n        \"Web Browsers [T1555.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_sql_statements__2_matches_\",\n      \"label\": \"reference SQL statements (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_wmi_statements\",\n      \"label\": \"reference WMI statements\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes__2_matches_\",\n      \"label\": \"log keystrokes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_MapVirtualKey\",\n      \"label\": \"MapVirtualKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_application_hook\",\n      \"label\": \"log keystrokes via application hook\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Application Hook [F0002.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_SetWindowsHookEx\",\n      \"label\": \"SetWindowsHookEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"label\": \"log keystrokes via polling (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"api_VkKeyScan\",\n      \"label\": \"VkKeyScan\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetKeyState\",\n      \"label\": \"GetKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_mac_address_in__net\",\n      \"label\": \"get MAC address in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_echernofsky_google_com\",\n      \"label\": \"echernofsky@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_capture_screenshot\",\n      \"label\": \"capture screenshot\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_data\",\n      \"label\": \"receive data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data\",\n      \"label\": \"send data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_manipulate_network_credentials_in__net\",\n      \"label\": \"manipulate network credentials in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_write_and_execute_a_file__4_matches_\",\n      \"label\": \"write and execute a file (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_maec_malware_category__launcher\",\n      \"label\": \"maec/malware-category  launcher\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_http_header\",\n      \"label\": \"read HTTP header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Read Header [C0002.014]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Read Header [C0002.014]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_http_user_agent_string\",\n      \"label\": \"reference HTTP User-Agent string\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication [C0002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______mr_tz\",\n      \"label\": \"author      @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication [C0002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_http_request\",\n      \"label\": \"create HTTP request\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_data_from_internet\",\n      \"label\": \"read data from Internet\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_http_response\",\n      \"label\": \"receive HTTP response\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_http_request\",\n      \"label\": \"send HTTP request\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Send Request [C0002.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Send Request [C0002.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_tcp_socket__3_matches_\",\n      \"label\": \"create TCP socket (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_act_as_tcp_client\",\n      \"label\": \"act as TCP client\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_zip_archive_in__net__3_matches_\",\n      \"label\": \"create zip archive in .NET (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_decode_data_using_base64_in__net\",\n      \"label\": \"decode data using Base64 in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decode Data::Base64 [C0053.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_decode_data_using_base64_via_winapi\",\n      \"label\": \"decode data using Base64 via WinAPI\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Deobfuscate/Decode Files or Information [T1140]\"\n      ]\n    },\n    {\n      \"id\": \"api_CryptStringToBinary\",\n      \"label\": \"CryptStringToBinary\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_reference_base64_string\",\n      \"label\": \"reference Base64 string\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Encode Data::Base64 [C0026.001]\",\n        \"Data::Check String [C0019]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_or_decrypt_data_via_bcrypt__2_matches_\",\n      \"label\": \"encrypt or decrypt data via BCrypt (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Decrypt Data [C0031]\",\n        \"Cryptography::Encrypt Data\",\n        \"[C0027]\"\n      ]\n    },\n    {\n      \"id\": \"api_BCryptGenerateSymmetricKey\",\n      \"label\": \"BCryptGenerateSymmetricKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_BCryptCloseAlgorithmProvider\",\n      \"label\": \"BCryptCloseAlgorithmProvider\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_BCryptDestroyKey\",\n      \"label\": \"BCryptDestroyKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_BCryptOpenAlgorithmProvider\",\n      \"label\": \"BCryptOpenAlgorithmProvider\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_BCryptDecrypt\",\n      \"label\": \"BCryptDecrypt\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_dpapi\",\n      \"label\": \"encrypt data using DPAPI\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data [C0027]\"\n      ]\n    },\n    {\n      \"id\": \"api_CryptUnprotectData\",\n      \"label\": \"CryptUnprotectData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_in__net\",\n      \"label\": \"generate random numbers in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contains_pdb_path\",\n      \"label\": \"contains PDB path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_check_clipboard_data__2_matches_\",\n      \"label\": \"check clipboard data (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_monitor_clipboard_content\",\n      \"label\": \"monitor clipboard content\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"api_AddClipboardFormatListener\",\n      \"label\": \"AddClipboardFormatListener\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_clipboard_data__2_matches_\",\n      \"label\": \"read clipboard data (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_manipulate_console_buffer__8_matches_\",\n      \"label\": \"manipulate console buffer (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Console [C0033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Console [C0033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable__3_matches_\",\n      \"label\": \"query environment variable (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_drives\",\n      \"label\": \"enumerate drives\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__7_matches_\",\n      \"label\": \"get common file path (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_copy_file__7_matches_\",\n      \"label\": \"copy file (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory__8_matches_\",\n      \"label\": \"create directory (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_directory__2_matches_\",\n      \"label\": \"delete directory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_file__12_matches_\",\n      \"label\": \"delete file (12 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_directory_exists__15_matches_\",\n      \"label\": \"check if directory exists (15 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__22_matches_\",\n      \"label\": \"check if file exists (22 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_in__net__6_matches_\",\n      \"label\": \"enumerate files in .NET (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes\",\n      \"label\": \"get file attributes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size__5_matches_\",\n      \"label\": \"get file size (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_file_attributes__2_matches_\",\n      \"label\": \"set file attributes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"cap_move_file__2_matches_\",\n      \"label\": \"move file (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__7_matches_\",\n      \"label\": \"read file on Windows (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__11_matches_\",\n      \"label\": \"write file on Windows (11 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_gui_resources__2_matches_\",\n      \"label\": \"enumerate gui resources (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     johnk3r, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_application_hook__2_matches_\",\n      \"label\": \"set application hook (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_UnhookWindowsHookEx\",\n      \"label\": \"UnhookWindowsHookEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_change_the_wallpaper\",\n      \"label\": \"change the wallpaper\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Wallpaper [C0035]\"\n      ]\n    },\n    {\n      \"id\": \"api_SystemParametersInfo\",\n      \"label\": \"SystemParametersInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox\",\n      \"label\": \"author     @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Wallpaper [C0035]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_taskbar__3_matches_\",\n      \"label\": \"find taskbar (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Taskbar Discovery [B0043]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindWindow\",\n      \"label\": \"FindWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_hide_the_windows_taskbar\",\n      \"label\": \"hide the Windows taskbar\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Hide Artifacts [T1564]\"\n      ]\n    },\n    {\n      \"id\": \"api_ShowWindow\",\n      \"label\": \"ShowWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_find_graphical_window__3_matches_\",\n      \"label\": \"find graphical window (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hide_graphical_window\",\n      \"label\": \"hide graphical window\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_disk_information\",\n      \"label\": \"get disk information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_disk_size\",\n      \"label\": \"get disk size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_allocate_unmanaged_memory_in__net__3_matches_\",\n      \"label\": \"allocate unmanaged memory in .NET (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_manipulate_unmanaged_memory_in__net__14_matches_\",\n      \"label\": \"manipulate unmanaged memory in .NET (14 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_or_open_mutex_on_windows\",\n      \"label\": \"create or open mutex on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_mehunhoff_google_com\",\n      \"label\": \"mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_networking_interfaces\",\n      \"label\": \"get networking interfaces\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Network Configuration Discovery [T1016]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_hostname__2_matches_\",\n      \"label\": \"get hostname (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetComputerName\",\n      \"label\": \"GetComputerName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_os_version_in__net\",\n      \"label\": \"get OS version in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_process_image_filename__5_matches_\",\n      \"label\": \"get process image filename (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_a_process_with_modified_i_o_handles_and_window__14_matches_\",\n      \"label\": \"create a process with modified I/O handles and window (14 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__22_matches_\",\n      \"label\": \"create process on Windows (22 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_processes__2_matches_\",\n      \"label\": \"enumerate processes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\",\n        \"Discovery::Software Discovery\",\n        \"[T1518]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_process_by_pid__2_matches_\",\n      \"label\": \"find process by PID (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_process_by_name\",\n      \"label\": \"find process by name\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\"\n      ]\n    },\n    {\n      \"id\": \"cap_acquire_debug_privileges\",\n      \"label\": \"acquire debug privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"api_AdjustTokenPrivileges\",\n      \"label\": \"AdjustTokenPrivileges\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_modify_access_privileges\",\n      \"label\": \"modify access privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process__14_matches_\",\n      \"label\": \"terminate process (14 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key__7_matches_\",\n      \"label\": \"query or enumerate registry key (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"label\": \"query or enumerate registry value (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_registry_value__5_matches_\",\n      \"label\": \"set registry value (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_key\",\n      \"label\": \"delete registry key\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_value__2_matches_\",\n      \"label\": \"delete registry value (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_session_integrity_level__3_matches_\",\n      \"label\": \"get session integrity level (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_session_user_name__5_matches_\",\n      \"label\": \"get session user name (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\",\n        \"Discovery::Account\",\n        \"Discovery [T1087]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_thread__3_matches_\",\n      \"label\": \"create thread (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_suspend_thread__9_matches_\",\n      \"label\": \"suspend thread (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Suspend Thread [C0055]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Suspend Thread [C0055]\"\n      ]\n    },\n    {\n      \"id\": \"cap_access_wmi_data_in__net\",\n      \"label\": \"access WMI data in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Windows Management Instrumentation [T1047]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_cryptocurrency_strings\",\n      \"label\": \"reference cryptocurrency strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Resource Hijacking [T1496]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Resource Hijacking [T1496]\"\n      ]\n    },\n    {\n      \"id\": \"cap_disable_system_features_via_registry_on_windows\",\n      \"label\": \"disable system features via registry on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Disable or Evade Security Tools [F0004]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____mehunhoff_google_com\",\n      \"label\": \"author     mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Disable or Evade Security Tools [F0004]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal___net_file_limitation\",\n      \"label\": \"(internal) .NET file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author________v1bh475u\",\n      \"label\": \"author       @v1bh475u\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compile__net_assembly\",\n      \"label\": \"compile .NET assembly\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Compile After\",\n        \"Delivery [T1027.004]\"\n      ]\n    },\n    {\n      \"id\": \"cap_invoke__net_assembly_method__2_matches_\",\n      \"label\": \"invoke .NET assembly method (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_load__net_assembly\",\n      \"label\": \"load .NET assembly\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_compile_csharp_in__net\",\n      \"label\": \"compile CSharp in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Compile After\",\n        \"Delivery [T1027.004]\"\n      ]\n    },\n    {\n      \"id\": \"cap_persist_via_default_file_association_registry_key__2_matches_\",\n      \"label\": \"persist via default file association registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Event Triggered Execution::Change Default File\",\n        \"Association [T1546.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______j_j_vannielen_utwente_nl\",\n      \"label\": \"author      j.j.vannielen@utwente.nl\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Event Triggered Execution::Change Default File\",\n        \"Association [T1546.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_persist_via_run_registry_key\",\n      \"label\": \"persist via Run registry key\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Registry Run Keys / Startup Folder [F0012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Registry Run Keys / Startup Folder [F0012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_schedule_task_via_schtasks__2_matches_\",\n      \"label\": \"schedule task via schtasks (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Scheduled Task/Job::Scheduled Task [T1053.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______0x534a_mailbox_org__j_j_vannielen_utwente_nl\",\n      \"label\": \"author      0x534a@mailbox.org, j.j.vannielen@utwente.nl\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Scheduled Task/Job::Scheduled Task [T1053.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_unmanaged_call__42_matches_\",\n      \"label\": \"unmanaged call (42 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"label\": \"author       michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compiled_to_the__net_platform\",\n      \"label\": \"compiled to the .NET platform\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_self_delete__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_geographical_location\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_save_image_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_gather_firefox_profile_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_sql_statements__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_wmi_statements\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_application_hook\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_mac_address_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_echernofsky_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_capture_screenshot\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_manipulate_network_credentials_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_and_execute_a_file__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_maec_malware_category__launcher\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_http_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_http_user_agent_string\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_http_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_data_from_internet\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_http_response\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_http_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_tcp_socket__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_act_as_tcp_client\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_zip_archive_in__net__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decode_data_using_base64_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decode_data_using_base64_via_winapi\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_base64_string\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_or_decrypt_data_via_bcrypt__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_dpapi\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contains_pdb_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_clipboard_data__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_monitor_clipboard_content\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_clipboard_data__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_manipulate_console_buffer__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_drives\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__12_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_directory_exists__15_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__22_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_in__net__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_move_file__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__11_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_gui_resources__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_application_hook__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_change_the_wallpaper\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_taskbar__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hide_the_windows_taskbar\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_graphical_window__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hide_graphical_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_unmanaged_memory_in__net__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_manipulate_unmanaged_memory_in__net__14_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_mutex_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_networking_interfaces\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_process_image_filename__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_a_process_with_modified_i_o_handles_and_window__14_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__22_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_processes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_process_by_pid__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_process_by_name\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_acquire_debug_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_modify_access_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process__14_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_integrity_level__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_user_name__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_suspend_thread__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_wmi_data_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_cryptocurrency_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_disable_system_features_via_registry_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal___net_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________v1bh475u\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compile__net_assembly\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_invoke__net_assembly_method__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_load__net_assembly\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compile_csharp_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_persist_via_default_file_association_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______j_j_vannielen_utwente_nl\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_persist_via_run_registry_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_schedule_task_via_schtasks__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______0x534a_mailbox_org__j_j_vannielen_utwente_nl\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_unmanaged_call__42_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_to_the__net_platform\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-04-29 20:28:57.517569\",\n    \"total_functions\": \"574\",\n    \"total_features\": \"18525\",\n    \"pdb_path\": \"C:\\\\\\\\Users\\\\\\\\sulum\\\\\\\\OneDrive\\\\\\\\Desktop\\\\\\\\datacenter\\\\\\\\stubCsharp\\\\\\\\obj\\\\\\\\Release\\\\\\\\Clie\\nnt.pdb\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-04-29 20:28:59"}
{"_id":{"$oid":"69edc49459a6632dae07de34"},"sha256":"2aa5ce3561dc657a157460383c7c9b8db54ac8a6969627009c8d1062316a6130","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         compiled with AutoIt.                                                  \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  AutoIt is a freeware BASIC-like common.py:90\n         scripting language designed for automating the Windows                 \n         GUI.                                                                   \nWARNING  capa.capabilities.common:  capa cannot handle AutoIt       common.py:90\n         scripts. This means that the results will be misleading or             \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You may have to analyze the     common.py:90\n         file manually, using a tool like the AutoIt decompiler                 \n         MyAut2Exe.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         autoit file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":true,"path":"/tmp/sdm_capa_h1fyxxok/001_upx_unpacked.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_h1fyxxok/001_upx_unpacked.exe_very_verbose.txt"}},"outputs":{"normal":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         compiled with AutoIt.                                                  \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  AutoIt is a freeware BASIC-like common.py:90\n         scripting language designed for automating the Windows                 \n         GUI.                                                                   \nWARNING  capa.capabilities.common:  capa cannot handle AutoIt       common.py:90\n         scripts. This means that the results will be misleading or             \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You may have to analyze the     common.py:90\n         file manually, using a tool like the AutoIt decompiler                 \n         MyAut2Exe.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         autoit file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         compiled with AutoIt.                                                  \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  AutoIt is a freeware BASIC-like common.py:90\n         scripting language designed for automating the Windows                 \n         GUI.                                                                   \nWARNING  capa.capabilities.common:  capa cannot handle AutoIt       common.py:90\n         scripts. This means that the results will be misleading or             \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You may have to analyze the     common.py:90\n         file manually, using a tool like the AutoIt decompiler                 \n         MyAut2Exe.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         autoit file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"md5                     1a7bbf68c09e364ac325434493133305                        \nsha1                    b6e8fae23eca1afff3e815286136cfbfa7b11eb9                \nsha256                  952afbda734257d5e14c9f4b09bc8bb48a60e37e7c17a9f3f27b0a9…\npath                    /tmp/sdm_unpack_6wnswgjn/2aa5ce3561dc657a157460383c7c9b…\ntimestamp               2026-05-15 14:31:58.018739                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEI0wzIwT/rules                                   \nfunction count          2043                                                    \nlibrary function count  714                                                     \ntotal feature count     120247                                                  \n\ncheck for time delay via QueryPerformanceCounter (4 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    0x469B67                                       \n           0x469B7E                                       \n           0x46AFC6                                       \n           0x46E899                                       \n\ncheck for unmoving mouse cursor (2 matches)\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      function                          \nmatches    0x498EBB                          \n           0x499468                          \n\nlog keystrokes (9 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    0x4034CE         \n           0x41EFAD         \n           0x4624E6         \n           0x462CEB         \n           0x463985         \n           0x46A90B         \n           0x46B04D         \n           0x46B198         \n           0x46B1FD         \n\nlog keystrokes via polling (11 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    0x4028C0         \n           0x41EA9A         \n           0x469B97         \n           0x469EAF         \n           0x46A90B         \n           0x46A975         \n           0x46AABA         \n           0x46ABF8         \n           0x46ADD8         \n           0x46B198         \n           0x499468         \n\ncapture screenshot\nnamespace  collection/screenshot\nscope      function             \nmatches    0x482483             \n\nquery remote server for available data\nnamespace  communication\nscope      basic block  \nmatches    0x47CE38     \n\nreceive data (4 matches)\nnamespace    communication                                                     \ndescription  all known techniques for receiving data from a potential C2 server\nscope        function                                                          \nmatches      0x47CD62                                                          \n             0x47CE38                                                          \n             0x48135A                                                          \n             0x481B87                                                          \n\nsend data (3 matches)\nnamespace    communication                                                 \ndescription  all known techniques for sending data to a potential C2 server\nscope        function                                                      \nmatches      0x47C394                                                      \n             0x4814F1                                                      \n             0x481F24                                                      \n\nreceive and write data from server to client\nnamespace  communication/c2/file-transfer\nscope      function                      \nmatches    0x47CD62                      \n\nresolve DNS (3 matches)\nnamespace  communication/dns\nscope      function         \nmatches    0x46DD45         \n           0x480482         \n           0x481288         \n\nconnect network resource\nnamespace    communication/http               \ndescription  connect to disk or print resource\nscope        function                         \nmatches      0x4605C7                         \n\nparse URL\nnamespace  communication/http\nscope      basic block       \nmatches    0x47D012          \n\nconnect to HTTP server (2 matches)\nnamespace  communication/http/client\nscope      function                 \nmatches    0x47C061                 \n           0x47C394                 \n\nconnect to URL\nnamespace  communication/http/client\nscope      instruction              \nmatches    0x47C190                 \n\ncreate HTTP request\nnamespace  communication/http/client\nscope      function                 \nmatches    0x47CC3C                 \n\nread data from Internet (2 matches)\nnamespace  communication/http/client\nscope      function                 \nmatches    0x47CD62                 \n           0x47CE38                 \n\nsend HTTP request\nnamespace  communication/http/client\nscope      function                 \nmatches    0x47C394                 \n\nsend ICMP echo request\nnamespace  communication/icmp\nscope      function          \nmatches    0x480482          \n\ncreate pipe (2 matches)\nnamespace  communication/named-pipe/create\nscope      function                       \nmatches    0x4703F0                       \n           0x4704C5                       \n\nconnect socket\nnamespace    communication/socket                                               \ndescription  Detects socket connection attempts using common APIs or ConnectEx  \n             setup.                                                             \nscope        basic block                                                        \nmatches      0x4810AF                                                           \n\nget socket status\nnamespace  communication/socket\nscope      function            \nmatches    0x483070            \n\ninitialize Winsock library (3 matches)\nnamespace  communication/socket\nscope      function            \nmatches    0x46DD45            \n           0x480482            \n           0x4815DA            \n\nset socket configuration (3 matches)\nnamespace  communication/socket\nscope      function            \nmatches    0x480482            \n           0x4819FD            \n           0x482F75            \n\nreceive data on socket (2 matches)\nnamespace  communication/socket/receive\nscope      function                    \nmatches    0x48135A                    \n           0x481B87                    \n\nsend data on socket (2 matches)\nnamespace  communication/socket/send\nscope      function                 \nmatches    0x4814F1                 \n           0x481F24                 \n\nconnect TCP socket\nnamespace  communication/socket/tcp\nscope      function                \nmatches    0x480FDF                \n\ncreate TCP socket (2 matches)\nnamespace  communication/socket/tcp\nscope      basic block             \nmatches    0x481033                \n           0x481197                \n\ncreate UDP socket (2 matches)\nnamespace  communication/socket/udp/send\nscope      basic block                  \nmatches    0x48177E                     \n           0x4819FD                     \n\nact as TCP client\nnamespace  communication/tcp/client\nscope      function                \nmatches    0x480FDF                \n\ncompiled with AutoIt\nnamespace  compiler/autoit\nscope      file           \n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32\nscope      function                        \nmatches    0x4823E8                        \n\nencode data using Base64\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    0x41BEAD                         \n\nencode data using XOR (7 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x4695EE                      \n           0x471F30                      \n           0x471F9C                      \n           0x471FD6                      \n           0x47284B                      \n           0x472ABF                      \n           0x47D73F                      \n\nhash data using djb2\nnamespace  data-manipulation/hashing/djb2\nscope      function                      \nmatches    0x408273                      \n\nauthenticate HMAC\nnamespace  data-manipulation/hmac\nscope      function              \nmatches    0x41BEAD              \n\ngenerate random numbers using a Mersenne Twister (4 matches)\nnamespace  data-manipulation/prng/mersenne\nscope      function                       \nmatches    0x471E7A                       \n           0x471EC0                       \n           0x471F24                       \n           0x471F64                       \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x406122           \n\nlist drag and drop files\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x47EA26                  \n\nopen clipboard (2 matches)\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x47EA26                  \n           0x47EC91                  \n\nread clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x47EA26                  \n\nwrite clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x47EC91                  \n\ninteract with driver via IOCTL (4 matches)\nnamespace  host-interaction/driver\nscope      instruction            \nmatches    0x46D563               \n           0x46D5DD               \n           0x46D690               \n           0x473D73               \n\nget COMSPEC environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x41D70E                             \n\nquery environment variable (3 matches)\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x41D70E                             \n           0x47EE14                             \n           0x487559                             \n\nset environment variable (2 matches)\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x43D170                             \n           0x47EE84                             \n\nget common file path (9 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x40445D                    \n           0x41D70E                    \n           0x41F962                    \n           0x46DE45                    \n           0x472F35                    \n           0x4779B4                    \n           0x477D0E                    \n           0x4780B3                    \n           0x48AF20                    \n\nset current directory (7 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x40445D                    \n           0x40AD7C                    \n           0x4753D4                    \n           0x477D0E                    \n           0x4780B3                    \n           0x479560                    \n           0x4796BB                    \n\ncopy file (3 matches)\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    0x46CE1E                         \n           0x46D1BA                         \n           0x472865                         \n\ncreate directory (2 matches)\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x46D1DF                           \n           0x473C3C                           \n\ndelete directory (2 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x46E77B                           \n           0x473C3C                           \n\ndelete file (6 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x46CF94                           \n           0x46D2C7                           \n           0x46E77B                           \n           0x472865                           \n           0x4755F7                           \n           0x4778BA                           \n\ncheck if file exists (3 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x46D1DF                           \n           0x46DADC                           \n           0x46E0B7                           \n\nenumerate files on Windows (6 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x46CF94                               \n           0x46D2C7                               \n           0x475BB5                               \n           0x479560                               \n           0x4796BB                               \n           0x479A49                               \n\nenumerate files recursively (3 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x479560                               \n           0x4796BB                               \n           0x479A49                               \n\nget file attributes (5 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x46D1DF                         \n           0x46DAFA                         \n           0x46E0B7                         \n           0x477F04                         \n           0x4795B8                         \n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x482A05                         \n           0x498461                         \n\nget file version info\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x46DB2C                         \n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x477F04                         \n           0x4795B8                         \n\nmove file (3 matches)\nnamespace  host-interaction/file-system/move\nscope      function                         \nmatches    0x46CE1E                         \n           0x46CF94                         \n           0x46E319                         \n\nread .ini file (4 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x4783FD                         \n           0x4784BF                         \n           0x4787FC                         \n           0x478A19                         \n\nread file on Windows (9 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x406A95                         \n           0x40B230                         \n           0x40B3B0                         \n           0x43921B                         \n           0x47070D                         \n           0x472475                         \n           0x4725B1                         \n           0x482A05                         \n           0x498461                         \n\nclear file content\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x477FD5                          \n\nwrite file on Windows (7 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x41F5B3                          \n           0x46CC1D                          \n           0x470633                          \n           0x4725F5                          \n           0x472642                          \n           0x472865                          \n           0x47CD62                          \n\nenumerate gui resources\nnamespace  host-interaction/gui\nscope      function            \nmatches    0x464144            \n\nfind taskbar (3 matches)\nnamespace  host-interaction/gui/taskbar/find\nscope      basic block                      \nmatches    0x41EFCE                         \n           0x492255                         \n           0x492289                         \n\nfind graphical window (4 matches)\nnamespace  host-interaction/gui/window/find\nscope      instruction                     \nmatches    0x41EFD4                        \n           0x46E645                        \n           0x49225F                        \n           0x49229F                        \n\nget graphical window text (11 matches)\nnamespace  host-interaction/gui/window/get-text\nscope      function                            \nmatches    0x461A70                            \n           0x46359E                            \n           0x463B0C                            \n           0x46489C                            \n           0x464BD3                            \n           0x465B9A                            \n           0x47E8F7                            \n           0x491E0D                            \n           0x4947A8                            \n           0x496FA4                            \n           0x4972B7                            \n\nhide graphical window (8 matches)\nnamespace  host-interaction/gui/window/hide\nscope      basic block                     \nmatches    0x45F0F9                        \n           0x4827C2                        \n           0x49015D                        \n           0x4950F2                        \n           0x496B61                        \n           0x49813A                        \n           0x4981BF                        \n           0x49A198                        \n\nget keyboard layout\nnamespace  host-interaction/hardware/keyboard\nscope      function                          \nmatches    0x41D70E                          \n\nget memory capacity\nnamespace  host-interaction/hardware/memory\nscope      function                        \nmatches    0x41F370                        \n\nget disk information (6 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x473D97                         \n           0x4743DE                         \n           0x474776                         \n           0x474844                         \n           0x474912                         \n           0x4749FD                         \n\nget disk size (3 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x4750EB                         \n           0x4751CE                         \n           0x4752B1                         \n\nget storage device properties (2 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x46D509                         \n           0x46D588                         \n\nprint debug messages\nnamespace  host-interaction/log/debug/write-event\nscope      function                              \nmatches    0x41F5B3                              \n\nshutdown system\nnamespace  host-interaction/os\nscope      function           \nmatches    0x46E814           \n\nget hostname (2 matches)\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    0x41D70E                    \n           0x46DD45                    \n\nget system information on Windows\nnamespace  host-interaction/os/info\nscope      function                \nmatches    0x40615E                \n\ncreate process on Windows (6 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x4437E0                       \n           0x46134A                       \n           0x461472                       \n           0x48AD7A                       \n           0x48B2C1                       \n           0x498064                       \n\nallocate or change RWX memory\nnamespace  host-interaction/process/inject\nscope      basic block                    \nmatches    0x489881                       \n\nenumerate processes (2 matches)\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    0x46D3FA                     \n           0x48A5A3                     \n\nacquire debug privileges\nnamespace  host-interaction/process/modify\nscope      basic block                    \nmatches    0x48A0B6                       \n\nmodify access privileges (2 matches)\nnamespace  host-interaction/process/modify\nscope      instruction                    \nmatches    0x461018                       \n           0x46167E                       \n\nterminate process (3 matches)\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x46EA3E                          \n           0x487E80                          \n           0x48A009                          \n\nempty the recycle bin\nnamespace  host-interaction/recycle-bin\nscope      function                    \nmatches    0x477953                    \n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x48B8F0                 \n           0x48CB5B                 \n\nquery or enumerate registry value (5 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x40533E                 \n           0x4059A7                 \n           0x4605C7                 \n           0x48BB02                 \n           0x48BD6B                 \n\nset registry value\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x48C2DE                        \n\ndelete registry key (2 matches)\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x48B535                        \n           0x48CB5B                        \n\ndelete registry value\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x48B535                        \n\nget session user name\nnamespace  host-interaction/session\nscope      function                \nmatches    0x41D70E                \n\nget token membership\nnamespace  host-interaction/session\nscope      function                \nmatches    0x4615A7                \n\nget token privileges\nnamespace  host-interaction/session\nscope      function                \nmatches    0x460F58                \n\ncreate thread (5 matches)\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x461747                      \n           0x46E114                      \n           0x470870                      \n           0x470870                      \n           0x47D13B                      \n\nterminate thread\nnamespace  host-interaction/thread/terminate\nscope      basic block                      \nmatches    0x4708A6                         \n\nimpersonate user\nnamespace  host-interaction/user\nscope      function             \nmatches    0x461145             \n\nlink function at runtime on Windows (13 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x4062E6               \n           0x406816               \n           0x406850               \n           0x45DB5B               \n           0x432FC7               \n           0x432FC7               \n           0x4671A3               \n           0x483FF4               \n           0x488EF7               \n           0x488F13               \n           0x488F59               \n           0x48B82B               \n           0x48CBF6               \n\nparse PE header\nnamespace  load-code/pe\nscope      function    \nmatches    0x40B7E0    \n\nresolve function by parsing PE exports (15 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x401641    \n           0x408BAA    \n           0x4095C0    \n           0x40A180    \n           0x40AD7C    \n           0x40D840    \n           0x410540    \n           0x41BEAD    \n           0x466502    \n           0x4681EE    \n           0x4763AC    \n           0x476E0F    \n           0x47902A    \n           0x487E80    \n           0x490F26    \n\nexecute shellcode via indirect call\nnamespace  load-code/shellcode\nscope      function           \nmatches    0x4895BB           \n\ncreate shortcut via IShellLink (2 matches)\nnamespace  persistence\nscope      function   \nmatches    0x47573C   \n           0x4763AC   \n\n\n\n","very_verbose":"md5                     1a7bbf68c09e364ac325434493133305                        \nsha1                    b6e8fae23eca1afff3e815286136cfbfa7b11eb9                \nsha256                  952afbda734257d5e14c9f4b09bc8bb48a60e37e7c17a9f3f27b0a9…\npath                    /tmp/sdm_unpack_6wnswgjn/2aa5ce3561dc657a157460383c7c9b…\ntimestamp               2026-05-15 14:32:59.377830                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIysW1Ae/rules                                   \nfunction count          2043                                                    \nlibrary function count  714                                                     \ntotal feature count     120247                                                  \n\nallocate memory (2 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x46B26C in function 0x46B248\n  or:\n    api: VirtualAllocEx @ 0x46B299\n\nallocate or change RW memory (library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x46B26C in function 0x46B248\n  and:\n    or:\n      match: allocate memory @ 0x46B26C\n        or:\n          api: VirtualAllocEx @ 0x46B299\n    or:\n      number: 0x4 = PAGE_READWRITE @ 0x46B289\n\ncalculate modulo 256 via x86 assembly (9 matches, only showing first match of \nlibrary rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x436DAA\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x436DAA\n    or:\n      number: 0xFF @ 0x436DAA\n\ncontain loop (489 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401202\n  or:\n    characteristic: loop @ 0x401202\n\ncreate or open file (13 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x407113\n  or:\n    api: CreateFile @ 0x407113\n\ncreate or open registry key (9 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x40533E in function 0x40533E\n  or:\n    api: RegOpenKeyEx @ 0x40545B\n\ndelay execution (37 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x40F4AF in function 0x40F060\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x40F4B1\n\nget OS version (library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x40615E\n  or:\n    api: GetVersionEx @ 0x40618D\n\nopen process (7 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org           \nscope   basic block                  \nmbc     Process::Open Process [C0065]\nbasic block @ 0x46B26C in function 0x46B248\n  or:\n    api: OpenProcess @ 0x46B283\n\nwrite process memory (library rule)\nauthor  moritz.raabe@mandiant.com                 \nscope   instruction                               \natt&ck  Defense Evasion::Process Injection [T1055]\ninstruction @ 0x46B34B\n  or:\n    api: WriteProcessMemory @ 0x46B34B\n\ncheck for time delay via QueryPerformanceCounter (4 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection                      \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check     \n           QueryPerformanceCounter [B0001.033]                                  \nfunction @ 0x469B67\n  and:\n    count(api(QueryPerformanceCounter)): 2 or more @ 0x46AFE2, 0x46B011\nfunction @ 0x469B7E\n  and:\n    count(api(QueryPerformanceCounter)): 2 or more @ 0x46AFE2, 0x46B011\nfunction @ 0x46AFC6\n  and:\n    count(api(QueryPerformanceCounter)): 2 or more @ 0x46AFE2, 0x46B011\nfunction @ 0x46E899\n  and:\n    count(api(QueryPerformanceCounter)): 2 or more @ 0x46E8B5, 0x46E8D5\n\ncheck for unmoving mouse cursor (2 matches)\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      BitsOfBinary                                                        \nscope       function                                                            \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::User Activity Based\n            Checks [T1497.002]                                                  \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection::Human User     \n            Check [B0009.012]                                                   \nreferences  https://www.joesecurity.org/blog/5852460122427342172                \nfunction @ 0x498EBB\n  and:\n    count(api(GetCursorPos)): 2 or more @ 0x498EF3, 0x498F50\nfunction @ 0x499468\n  and:\n    count(api(GetCursorPos)): 2 or more @ 0x49990B, 0x499A5A\n\nlog keystrokes (9 matches)\nnamespace  collection/keylog                                \nauthor     moritz.raabe@mandiant.com                        \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nfunction @ 0x4034CE\n  or:\n    api: MapVirtualKey @ 0x4034FF, 0x403507, 0x403512, 0x40351D, and 2 more...\nfunction @ 0x41EFAD\n  or:\n    api: AttachThreadInput @ 0x41F029, 0x41F031, 0x41F039, 0x41F0AD, and 2 more...\n    api: MapVirtualKey @ 0x41F055, 0x41F06A, 0x41F078, 0x41F087\nfunction @ 0x4624E6\n  or:\n    api: MapVirtualKey @ 0x462501, 0x46252D, 0x462553\nfunction @ 0x462CEB\n  or:\n    api: AttachThreadInput @ 0x462D28\nfunction @ 0x463985\n  or:\n    api: AttachThreadInput @ 0x4639AD\nfunction @ 0x46A90B\n  or:\n    api: MapVirtualKey @ 0x46A93A, 0x46A956\nfunction @ 0x46B04D\n  or:\n    api: AttachThreadInput @ 0x46B099, 0x46B0C4, 0x46B0D6, 0x46B11B, and 2 more...\nfunction @ 0x46B198\n  or:\n    api: MapVirtualKey @ 0x46B1CD\nfunction @ 0x46B1FD\n  or:\n    api: MapVirtualKey @ 0x46B21B\n\nlog keystrokes via polling (11 matches)\nnamespace  collection/keylog                                \nauthor     michael.hunhoff@mandiant.com                     \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nmbc        Collection::Keylogging::Polling [F0002.002]      \nfunction @ 0x4028C0\n  or:\n    api: VkKeyScan @ 0x442F79, 0x442F89, 0x442FD2\nfunction @ 0x41EA9A\n  or:\n    api: GetAsyncKeyState @ 0x41EB02, 0x41EB1C\nfunction @ 0x469B97\n  or:\n    api: GetAsyncKeyState @ 0x469C40, 0x469C75, 0x469CA2, 0x469CCC, and 1 more...\n    api: GetKeyState @ 0x469C5B, 0x469C8A, 0x469CB4, 0x469CDE, and 1 more...\n    api: GetKeyboardState @ 0x469BBF\nfunction @ 0x469EAF\n  or:\n    api: GetAsyncKeyState @ 0x469FBB, 0x46A001, 0x46A03E, 0x46A075, and 1 more...\n    api: GetKeyState @ 0x469FD2, 0x46A012, 0x46A04C, 0x46A083, and 1 more...\n    api: GetKeyboardState @ 0x469F30\nfunction @ 0x46A90B\n  or:\n    api: GetKeyState @ 0x46A91B\nfunction @ 0x46A975\n  or:\n    api: GetKeyboardState @ 0x46A9CA\nfunction @ 0x46AABA\n  or:\n    api: GetKeyboardState @ 0x46AB0F\nfunction @ 0x46ABF8\n  or:\n    api: GetKeyboardState @ 0x46AC4C\nfunction @ 0x46ADD8\n  or:\n    api: GetKeyboardState @ 0x46AE2C\nfunction @ 0x46B198\n  or:\n    api: VkKeyScan @ 0x46B1B0\nfunction @ 0x499468\n  or:\n    api: GetKeyState @ 0x49967D, 0x49968A, 0x4996AA\n\ncapture screenshot\nnamespace  collection/screenshot                                            \nauthor     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\nscope      function                                                         \natt&ck     Collection::Screen Capture [T1113]                               \nmbc        Collection::Screen Capture::WinAPI [E1113.m01]                   \nfunction @ 0x482483\n  or:\n    and:\n      or:\n        api: GetDC @ 0x4824FF\n      or:\n        api: GetDIBits @ 0x4825D3, 0x4825F7\n      api: CreateCompatibleDC @ 0x48251B\n      api: CreateCompatibleBitmap @ 0x48250F\n\nquery remote server for available data\nnamespace  communication               \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ 0x47CE38 in function 0x47CE38\n  or:\n    api: InternetQueryDataAvailable @ 0x47CE56\n\nreceive data (4 matches)\nnamespace    communication                                                     \nauthor       william.ballenthin@mandiant.com                                   \nscope        function                                                          \nmbc          Command and Control::C2 Communication::Receive Data [B0030.002]   \ndescription  all known techniques for receiving data from a potential C2 server\nfunction @ 0x47CD62\n  or:\n    match: read data from Internet @ 0x47CD62\n      and:\n        or:\n          api: InternetReadFile @ 0x47CDA7\nfunction @ 0x47CE38\n  or:\n    match: read data from Internet @ 0x47CE38\n      and:\n        or:\n          api: InternetReadFile @ 0x47CE8D\nfunction @ 0x48135A\n  or:\n    match: receive data on socket @ 0x48135A\n      or:\n        api: recv @ 0x481403\nfunction @ 0x481B87\n  or:\n    match: receive data on socket @ 0x481B87\n      or:\n        api: recvfrom @ 0x481D08\n\nsend data (3 matches)\nnamespace    communication                                                 \nauthor       william.ballenthin@mandiant.com, joakim@intezer.com           \nscope        function                                                      \nmbc          Command and Control::C2 Communication::Send Data [B0030.001]  \ndescription  all known techniques for sending data to a potential C2 server\nfunction @ 0x47C394\n  or:\n    and:\n      os: windows\n      or:\n        match: send HTTP request @ 0x47C394\n          or:\n            and:\n              or:\n                api: HttpOpenRequest @ 0x47C40E\n                api: InternetConnect @ 0x47C3CE\n              or:\n                api: HttpSendRequest @ 0x47C472\nfunction @ 0x4814F1\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x4814F1\n          or:\n            api: send @ 0x481525\nfunction @ 0x481F24\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x481F24\n          or:\n            api: sendto @ 0x482063\n\ndownload and write a file\nnamespace              communication/c2/file-transfer                           \nmaec/malware-category  downloader                                               \nauthor                 moritz.raabe@mandiant.com                                \nscope                  function                                                 \natt&ck                 Command and Control::Ingress Tool Transfer [T1105]       \nmbc                    Command and Control::C2 Communication::Server to Client  \n                       File Transfer [B0030.003]                                \nfunction @ 0x47CD62\n  and:\n    match: receive data @ 0x47CD62\n      or:\n        match: read data from Internet @ 0x47CD62\n          and:\n            or:\n              api: InternetReadFile @ 0x47CDA7\n    match: host-interaction/file-system/write @ 0x47CD62\n      or:\n        and:\n          os: windows\n          or:\n            api: _fwrite @ 0x47CDC3\n            api: fwrite @ 0x47CDC3\n\nreceive and write data from server to client\nnamespace  communication/c2/file-transfer \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x47CD62\n  and:\n    match: receive data @ 0x47CD62\n      or:\n        match: read data from Internet @ 0x47CD62\n          and:\n            or:\n              api: InternetReadFile @ 0x47CDA7\n    match: host-interaction/file-system/write @ 0x47CD62\n      or:\n        and:\n          os: windows\n          or:\n            api: _fwrite @ 0x47CDC3\n            api: fwrite @ 0x47CDC3\n\nresolve DNS (3 matches)\nnamespace  communication/dns                                                    \nauthor     william.ballenthin@mandiant.com, johnk3r, joakim@intezer.com,        \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::DNS Communication::Resolve [C0011.001]                \nfunction @ 0x46DD45\n  or:\n    api: gethostbyname @ 0x46DD87\nfunction @ 0x480482\n  or:\n    api: gethostbyname @ 0x48054F\nfunction @ 0x481288\n  or:\n    api: gethostbyname @ 0x4812B7\n\nconnect network resource\nnamespace    communication/http               \nauthor       michael.hunhoff@mandiant.com     \nscope        function                         \ndescription  connect to disk or print resource\nfunction @ 0x4605C7\n  and:\n    or:\n      api: WNetAddConnection2 @ 0x46068B\n\nparse URL\nnamespace  communication/http          \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ 0x47D012 in function 0x47D012\n  or:\n    api: InternetCrackUrl @ 0x47D058\n\nconnect to HTTP server (2 matches)\nnamespace  communication/http/client                                       \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \nmbc        Communication::HTTP Communication::Connect to Server [C0002.009]\nfunction @ 0x47C061\n  and:\n    api: InternetConnect @ 0x47C0A0\nfunction @ 0x47C394\n  and:\n    api: InternetConnect @ 0x47C3CE\n\nconnect to URL\nnamespace  communication/http/client                              \nauthor     michael.hunhoff@mandiant.com                           \nscope      instruction                                            \nmbc        Communication::HTTP Communication::Open URL [C0002.004]\ninstruction @ 0x47C190\n  and:\n    api: InternetOpenUrl @ 0x47C190\n\ncreate HTTP request\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Create Request [C0002.012]\nfunction @ 0x47CC3C\n  and:\n    or:\n      api: InternetOpen @ 0x47CC9B\n\nread data from Internet (2 matches)\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Get Response [C0002.017]  \nfunction @ 0x47CD62\n  and:\n    or:\n      api: InternetReadFile @ 0x47CDA7\nfunction @ 0x47CE38\n  and:\n    or:\n      api: InternetReadFile @ 0x47CE8D\n\nsend HTTP request\nnamespace  communication/http/client                                  \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com    \nscope      function                                                   \nmbc        Communication::HTTP Communication::Send Request [C0002.003]\nfunction @ 0x47C394\n  or:\n    and:\n      or:\n        api: HttpOpenRequest @ 0x47C40E\n        api: InternetConnect @ 0x47C3CE\n      or:\n        api: HttpSendRequest @ 0x47C472\n\nsend ICMP echo request\nnamespace   communication/icmp                                         \nauthor      michael.hunhoff@mandiant.com                               \nscope       function                                                   \nmbc         Communication::ICMP Communication::Echo Request [C0014.002]\nreferences  https://docs.microsoft.com/en-us/windows/win32/api/icmpapi/\nfunction @ 0x480482\n  and:\n    or:\n      api: IcmpSendEcho @ 0x4805ED, 0x48060C\n    optional:\n      or:\n        api: IcmpCreateFile @ 0x48055D\n      api: IcmpCloseHandle @ 0x4806E0\n\ncreate pipe (2 matches)\nnamespace  communication/named-pipe/create                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com           \nscope      function                                                          \nmbc        Communication::Interprocess Communication::Create Pipe [C0003.001]\nfunction @ 0x4703F0\n  or:\n    api: CreatePipe @ 0x47044C\nfunction @ 0x4704C5\n  or:\n    api: CreatePipe @ 0x47051F\n\nconnect socket\nnamespace    communication/socket                                               \nauthor       moritz.raabe@mandiant.com, joakim@intezer.com,                     \n             mrhafizfarhad@gmail.com                                            \nscope        basic block                                                        \ndescription  Detects socket connection attempts using common APIs or ConnectEx  \n             setup.                                                             \nbasic block @ 0x4810AF in function 0x480FDF\n  or:\n    api: connect @ 0x4810B6\n\nget socket status\nnamespace  communication/socket                                              \nauthor     michael.hunhoff@mandiant.com                                      \nscope      function                                                          \natt&ck     Discovery::System Network Configuration Discovery [T1016]         \nmbc        Communication::Socket Communication::Get Socket Status [C0001.012]\nfunction @ 0x483070\n  or:\n    api: select @ 0x4830BC\n\ninitialize Winsock library (3 matches)\nnamespace  communication/socket                                                 \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Initialize Winsock Library      \n           [C0001.009]                                                          \nfunction @ 0x46DD45\n  or:\n    api: WSAStartup @ 0x46DD60\nfunction @ 0x480482\n  or:\n    api: WSAStartup @ 0x4804E3\nfunction @ 0x4815DA\n  or:\n    api: WSAStartup @ 0x4815F5\n\nset socket configuration (3 matches)\nnamespace  communication/socket                                              \nauthor     michael.hunhoff@mandiant.com                                      \nscope      function                                                          \nmbc        Communication::Socket Communication::Set Socket Config [C0001.001]\nfunction @ 0x480482\n  or:\n    api: ioctlsocket @ 0x480543\nfunction @ 0x4819FD\n  or:\n    api: setsockopt @ 0x481AB1\nfunction @ 0x482F75\n  or:\n    api: ioctlsocket @ 0x482FA1\n\nreceive data on socket (2 matches)\nnamespace  communication/socket/receive                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Receive Data [C0001.006]        \nfunction @ 0x48135A\n  or:\n    api: recv @ 0x481403\nfunction @ 0x481B87\n  or:\n    api: recvfrom @ 0x481D08\n\nsend data on socket (2 matches)\nnamespace  communication/socket/send                                            \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Communication::Socket Communication::Send Data [C0001.007]           \nfunction @ 0x4814F1\n  or:\n    api: send @ 0x481525\nfunction @ 0x481F24\n  or:\n    api: sendto @ 0x482063\n\nconnect TCP socket\nnamespace  communication/socket/tcp                                             \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           mrhafizfarhad@gmail.com                                              \nscope      function                                                             \nmbc        Communication::Socket Communication::Connect Socket [C0001.004]      \nfunction @ 0x480FDF\n  and:\n    match: create TCP socket @ 0x481033\n      or:\n        and:\n          or:\n            number: 0x6 = IPPROTO_TCP @ 0x481033\n          number: 0x1 = SOCK_STREAM @ 0x481035\n          number: 0x2 = AF_INET @ 0x481037\n          or:\n            api: socket @ 0x481039\n    match: connect socket @ 0x4810AF\n      or:\n        api: connect @ 0x4810B6\n\ncreate TCP socket (2 matches)\nnamespace   communication/socket/tcp                                            \nauthor      william.ballenthin@mandiant.com, joakim@intezer.com,                \n            anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com       \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create TCP Socket [C0001.011]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ 0x481033 in function 0x480FDF\n  or:\n    and:\n      or:\n        number: 0x6 = IPPROTO_TCP @ 0x481033\n      number: 0x1 = SOCK_STREAM @ 0x481035\n      number: 0x2 = AF_INET @ 0x481037\n      or:\n        api: socket @ 0x481039\nbasic block @ 0x481197 in function 0x48112B\n  or:\n    and:\n      or:\n        number: 0x6 = IPPROTO_TCP @ 0x481197\n      number: 0x1 = SOCK_STREAM @ 0x481199\n      number: 0x2 = AF_INET @ 0x48119B\n      or:\n        api: socket @ 0x48119D\n\ncreate UDP socket (2 matches)\nnamespace   communication/socket/udp/send                                       \nauthor      moritz.raabe@mandiant.com, joakim@intezer.com,                      \n            michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create UDP Socket [C0001.010]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ 0x48177E in function 0x48172D\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x481780, 0x481782\n      or:\n        number: 0x11 = IPPROTO_UDP @ 0x48177E\n      or:\n        api: socket @ 0x481784\nbasic block @ 0x4819FD in function 0x4819FD\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x481A20, 0x481A22\n      or:\n        number: 0x11 = IPPROTO_UDP @ 0x481A1E\n      or:\n        api: socket @ 0x481A24\n\nact as TCP client\nnamespace  communication/tcp/client                                     \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                                     \nmbc        Communication::Socket Communication::TCP Client [C0001.008]  \nfunction @ 0x480FDF\n  or:\n    match: connect TCP socket @ 0x480FDF\n      and:\n        match: create TCP socket @ 0x481033\n          or:\n            and:\n              or:\n                number: 0x6 = IPPROTO_TCP @ 0x481033\n              number: 0x1 = SOCK_STREAM @ 0x481035\n              number: 0x2 = AF_INET @ 0x481037\n              or:\n                api: socket @ 0x481039\n        match: connect socket @ 0x4810AF\n          or:\n            api: connect @ 0x4810B6\n\ncompiled with AutoIt\nnamespace   compiler/autoit                                                     \nauthor      william.ballenthin@mandiant.com                                     \nscope       file                                                                \natt&ck      Execution::Command and Scripting Interpreter [T1059]                \nreferences  https://fumik0.com/2019/03/25/lets-play-with-qulab-an-exotic-malwar…\nor:\n  string: \"AutoIt Error\" @ file+0xD5910\n  string: \">>>AUTOIT NO CMDEXECUTE<<<\" @ file+0x9BF64\n  string: \"#requireadmin\" @ file+0x9EB28\n  string: \"#OnAutoItStartRegister\" @ file+0x9EAD8\n  substring: >>>AUTOIT SCRIPT<<<\n    - \">>>AUTOIT SCRIPT<<<\" @ file+0xC5640\n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32 \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \nmbc        Data::Checksum::CRC32 [C0032.001]\nfunction @ 0x4823E8\n  or:\n    bytes: 00000000963007772c610eeeba51099919c46d078ff46a7035a563e9a395649e = crc32_tab @ 0x48242B, 0x48243F, 0x48244E\n\nencode data using Base64\nnamespace  data-manipulation/encoding/base64                                    \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::Base64 [C0026.001]         \nfunction @ 0x41BEAD\n  or:\n    and:\n      mnemonic: shl @ 0x41C098, 0x45B1BE, 0x45B245, 0x45B424, and 3 more...\n      mnemonic: shr @ 0x41BEE6, 0x41C310, 0x41C500\n      number: 0x3F = modulo 64 @ 0x41C25B, 0x41C296, 0x41C3BA, 0x41C403, and 6 more...\n      or:\n        number: 0x3D = '=' @ 0x41C5C2, 0x459581, 0x45959D, 0x459A4A, and 4 more...\n      match: contain loop @ 0x41BEAD\n        or:\n          characteristic: loop @ 0x41BEAD\n          characteristic: tight loop @ 0x41C0D3, 0x45A209, 0x45A37A, 0x45AD30, and 12 more...\n      optional:\n        number: 0x2 @ 0x41C049, 0x41C14F, 0x41C310, 0x41C32B, and 152 more...\n        number: 0x3 @ 0x41C2DC, 0x459353, 0x459429, 0x459538, and 4 more...\n        number: 0x4 @ 0x41C2BC, 0x41CC04, 0x458FD9, 0x4591CC, and 24 more...\n        number: 0x6 @ 0x41C55C, 0x41C57C, 0x41C604, 0x4590F1, and 8 more...\n        number: 0xF @ 0x41C91D, 0x41CBE2, 0x45A926, 0x45B30B, and 3 more...\n\nencode data using XOR (7 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x4695EE in function 0x46959C\n  and:\n    characteristic: tight loop @ 0x4695EE\n    characteristic: nzxor @ 0x4695EE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x471F30 in function 0x471F24\n  and:\n    characteristic: tight loop @ 0x471F30\n    characteristic: nzxor @ 0x471F3C\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x471F9C in function 0x471F64\n  and:\n    characteristic: tight loop @ 0x471F9C\n    characteristic: nzxor @ 0x471FA1, 0x471FAE, 0x471FBB, 0x471FBD\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x471FD6 in function 0x471F64\n  and:\n    characteristic: tight loop @ 0x471FD6\n    characteristic: nzxor @ 0x471FDB, 0x471FE3, 0x471FF7, 0x471FFB\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x47284B in function 0x47281C\n  and:\n    characteristic: tight loop @ 0x47284B\n    characteristic: nzxor @ 0x472858\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x472ABF in function 0x472865\n  and:\n    characteristic: tight loop @ 0x472ABF\n    characteristic: nzxor @ 0x472ACC\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x47D73F in function 0x47D71C\n  and:\n    characteristic: tight loop @ 0x47D73F\n    characteristic: nzxor @ 0x47D74A\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nhash data using djb2\nnamespace   data-manipulation/hashing/djb2                                      \nauthor      awillia2@cisco.com, still@teamt5.org                                \nscope       function                                                            \nmbc         Data::Non-Cryptographic Hash::djb2 [C0030.006]                      \nreferences  https://twitter.com/r3c0nst/status/1392405576131436546,             \n            http://www.cse.yorku.ca/~oz/hash.html                               \nfunction @ 0x408273\n  and:\n    instruction:\n      and:\n        mnemonic: mov @ 0x408284\n        number: 0x1505 @ 0x408284\n    or:\n      instruction:\n        and:\n          number: 0x21 @ 0x408291\n          or:\n            mnemonic: imul @ 0x408291\n\nauthenticate HMAC\nnamespace   data-manipulation/hmac                                              \nauthor      moritz.raabe@mandiant.com                                           \nscope       function                                                            \nmbc         Cryptography::Hashed Message Authentication Code [C0061]            \nreferences  https://tools.ietf.org/html/rfc2104,                                \n            https://tools.ietf.org/html/rfc4634, https://github.com/ogay/hmac   \nfunction @ 0x41BEAD\n  and:\n    number: 0x36 = inner padding byte value @ 0x45A89F, 0x45BF8B\n    number: 0x5C = outer padding byte value @ 0x41C20E, 0x41C5D0, 0x41C691, 0x41C6A4, and 8 more...\n    match: contain loop @ 0x41BEAD\n      or:\n        characteristic: loop @ 0x41BEAD\n        characteristic: tight loop @ 0x41C0D3, 0x45A209, 0x45A37A, 0x45AD30, and 12 more...\n    count(characteristic(nzxor)): 2 or more @ 0x41BEFA, 0x41C50E\n    optional: = block size\n      number: 0x40 = MD5, SHA-1, SHA-224, or SHA-256 @ 0x45AA0A, 0x45AC60, 0x45B980\n      number: 0x80 = SHA-384 or SHA-512 @ 0x41C089, 0x41C9F5, 0x41CA50, 0x41CAC2, and 2 more...\n\ngenerate random numbers using a Mersenne Twister (4 matches)\nnamespace  data-manipulation/prng/mersenne                      \nauthor     moritz.raabe@mandiant.com                            \nscope      function                                             \nmbc        Cryptography::Generate Pseudo-random Sequence [C0021]\nfunction @ 0x471E7A\n  or:\n    number: 0xFF3A58AD @ 0x471EA0\nfunction @ 0x471EC0\n  or:\n    number: 0xFF3A58AD @ 0x471EEB\nfunction @ 0x471F24\n  or:\n    number: 0x6C078965 @ 0x471F3E\nfunction @ 0x471F64\n  or:\n    number: 0x9908B0DF @ 0x471FB6, 0x471FF2, 0x472029\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x406122\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x4442F5\n        api: LockResource @ 0x44431D\n      optional:\n        or:\n          api: FindResourceEx @ 0x406149\n        api: SizeofResource @ 0x44430A\n\nlist drag and drop files\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ 0x47EA26\n  and:\n    api: DragQueryFile @ 0x47EB9E, 0x47EBBB, 0x47EBF9\n    and:\n      api: GetClipboardData @ 0x47EA6A, 0x47EAF8, 0x47EB6B\n      number: 0xF = HDROP @ 0x47EB5D, 0x47EB69\n\nopen clipboard (2 matches)\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ 0x47EA26\n  and:\n    api: OpenClipboard @ 0x47EA50\n    optional:\n      api: CloseClipboard @ 0x47EA76, 0x47EAB8, 0x47EAE9, 0x47EB58, and 2 more...\nfunction @ 0x47EC91\n  and:\n    api: OpenClipboard @ 0x47ECB8, 0x47ED76\n    optional:\n      api: CloseClipboard @ 0x47ECC4, 0x47EDCA\n\nread clipboard data\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Collection::Clipboard Data [T1115]                                  \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ 0x47EA26\n  and:\n    optional:\n      match: open clipboard @ 0x47EA26\n        and:\n          api: OpenClipboard @ 0x47EA50\n          optional:\n            api: CloseClipboard @ 0x47EA76, 0x47EAB8, 0x47EAE9, 0x47EB58, and 2 more...\n      match: contain loop @ 0x47EA26\n        or:\n          characteristic: tight loop @ 0x47EBAF\n      api: GlobalLock @ 0x47EAAE, 0x47EB09, 0x47EB7C\n      api: GlobalUnlock @ 0x47EAE3, 0x47EB49, 0x47EC1A\n    or:\n      basic block:\n        and:\n          api: GetClipboardData @ 0x47EA6A\n          optional:\n            number: 0xD = CF_UNICODETEXT @ 0x47EA68\n        and:\n          api: GetClipboardData @ 0x47EB6B\n        and:\n          api: GetClipboardData @ 0x47EAF8\n          optional:\n            number: 0x1 = CF_TEXT @ 0x47EAF6\n\nwrite clipboard data\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \nmbc         Impact::Clipboard Modification [E1510]                              \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ 0x47EC91\n  and:\n    optional:\n      match: open clipboard @ 0x47EC91\n        and:\n          api: OpenClipboard @ 0x47ECB8, 0x47ED76\n          optional:\n            api: CloseClipboard @ 0x47ECC4, 0x47EDCA\n      api: EmptyClipboard @ 0x47ECBE, 0x47ED7C\n    or:\n      api: SetClipboardData @ 0x47ED85\n\ninteract with driver via IOCTL (4 matches)\nnamespace  host-interaction/driver  \nauthor     moritz.raabe@mandiant.com\nscope      instruction              \ninstruction @ 0x46D563\n  or:\n    api: DeviceIoControl @ 0x46D563\ninstruction @ 0x46D5DD\n  or:\n    api: DeviceIoControl @ 0x46D5DD\ninstruction @ 0x46D690\n  or:\n    api: DeviceIoControl @ 0x46D690\ninstruction @ 0x473D73\n  or:\n    api: DeviceIoControl @ 0x473D73\n\nget COMSPEC environment variable\nnamespace  host-interaction/environment-variable          \nauthor     matthew.williams@mandiant.com                  \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Operating System::Environment Variable [C0034] \nfunction @ 0x41D70E\n  and:\n    match: query environment variable @ 0x41D70E\n      or:\n        api: GetEnvironmentVariable @ 0x45E05B, 0x45E06E, 0x45E0CA, 0x45E0DD, and 4 more...\n    or:\n      string: \"COMSPEC\" @ 0x45E056\n\nquery environment variable (3 matches)\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x41D70E\n  or:\n    api: GetEnvironmentVariable @ 0x45E05B, 0x45E06E, 0x45E0CA, 0x45E0DD, and 4 more...\nfunction @ 0x47EE14\n  or:\n    api: GetEnvironmentVariable @ 0x47EE51\nfunction @ 0x487559\n  or:\n    api: GetEnvironmentVariable @ 0x4875FD\n\nset environment variable (2 matches)\nnamespace  host-interaction/environment-variable                           \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \nmbc        Operating System::Environment Variable::Set Variable [C0034.001]\nfunction @ 0x43D170\n  or:\n    api: SetEnvironmentVariable @ 0x43D03C\nfunction @ 0x47EE84\n  or:\n    api: SetEnvironmentVariable @ 0x47EEC4\n\nget common file path (9 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x40445D\n  or:\n    api: GetCurrentDirectory @ 0x40448D\nfunction @ 0x41D70E\n  or:\n    api: GetTempPath @ 0x45E085\n    api: GetSystemDirectory @ 0x45DB98\n    api: GetWindowsDirectory @ 0x45DB28\n    api: GetCurrentDirectory @ 0x45DD7F\nfunction @ 0x41F962\n  or:\n    api: GetCurrentDirectory @ 0x41F97E\nfunction @ 0x46DE45\n  or:\n    api: SHGetFolderPath @ 0x46DE5E\nfunction @ 0x472F35\n  or:\n    api: GetTempPath @ 0x472F4D\n    api: GetTempFileName @ 0x472F62\nfunction @ 0x4779B4\n  or:\n    api: SHGetSpecialFolderLocation @ 0x477AAD\nfunction @ 0x477D0E\n  or:\n    api: GetCurrentDirectory @ 0x477ECB\nfunction @ 0x4780B3\n  or:\n    api: GetCurrentDirectory @ 0x47822E\nfunction @ 0x48AF20\n  or:\n    api: GetSystemDirectory @ 0x48B0D7, 0x48B0FB\n    api: GetCurrentDirectory @ 0x48B13B, 0x48B15D\n\nset current directory (7 matches)\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x40445D\n  or:\n    api: SetCurrentDirectory @ 0x404596, 0x443769\nfunction @ 0x40AD7C\n  or:\n    api: SetCurrentDirectory @ 0x40AEF0, 0x40B045\nfunction @ 0x4753D4\n  or:\n    api: SetCurrentDirectory @ 0x4753EC\nfunction @ 0x477D0E\n  or:\n    api: SetCurrentDirectory @ 0x477EDF, 0x477F35, 0x477F7E, 0x477FCE\nfunction @ 0x4780B3\n  or:\n    api: SetCurrentDirectory @ 0x478242, 0x478274, 0x4782AA, 0x4782B3\nfunction @ 0x479560\n  or:\n    api: SetCurrentDirectory @ 0x479668, 0x479686\nfunction @ 0x4796BB\n  or:\n    api: SetCurrentDirectory @ 0x4797AE, 0x4797CC\n\ncopy file (3 matches)\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ 0x46CE1E\n  or:\n    basic block:\n      and:\n        number: 0x2 = FO_COPY @ 0x46CF40\n        or:\n          api: SHFileOperation @ 0x46CF7F\nfunction @ 0x46D1BA\n  or:\n    api: CopyFileEx @ 0x46D1D0\nfunction @ 0x472865\n  or:\n    api: CopyFile @ 0x472BBB\n\ncreate directory (2 matches)\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x46D1DF\n  or:\n    api: CreateDirectory @ 0x46D237, 0x46D294\nfunction @ 0x473C3C\n  or:\n    api: CreateDirectory @ 0x473CBB\n\ndelete directory (2 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ 0x46E77B\n  or:\n    api: RemoveDirectory @ 0x46E7B9\nfunction @ 0x473C3C\n  or:\n    api: RemoveDirectory @ 0x473CEC\n\ndelete file (6 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x46CF94\n  or:\n    api: DeleteFile @ 0x46D0FB, 0x46D12B\nfunction @ 0x46D2C7\n  or:\n    api: DeleteFile @ 0x46D38E\nfunction @ 0x46E77B\n  or:\n    basic block:\n      and:\n        number: 0x3 = FO_DELETE @ 0x46E7D0\n        or:\n          api: SHFileOperation @ 0x46E806\nfunction @ 0x472865\n  or:\n    api: DeleteFile @ 0x472B23, 0x472BA5, 0x472BCC, 0x472BDE\nfunction @ 0x4755F7\n  or:\n    api: DeleteFile @ 0x4756EC\nfunction @ 0x4778BA\n  or:\n    basic block:\n      and:\n        number: 0x3 = FO_DELETE @ 0x4778FA\n        or:\n          api: SHFileOperation @ 0x47792E\n\ncheck if file exists (3 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x46D1DF\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x46D219\n        instruction:\n          and:\n            mnemonic: cmp @ 0x46D21F\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x46D21F\n    basic block:\n      and:\n        api: GetLastError @ 0x46D228\n        instruction:\n          and:\n            mnemonic: cmp @ 0x46D230\n            number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x46D230\nfunction @ 0x46DADC\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x46DAFB\n        instruction:\n          and:\n            mnemonic: cmp @ 0x46DB01\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x46DB01\nfunction @ 0x46E0B7\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x46E0B8\n        instruction:\n          and:\n            mnemonic: cmp @ 0x46E0BE\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x46E0BE\n\nenumerate files on Windows (6 matches)\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ 0x46CF94\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x46D040\n      or:\n        api: FindNextFile @ 0x46D155\n      optional:\n        api: FindClose @ 0x46D171, 0x46D182\n        match: contain loop @ 0x46CF94\n          or:\n            characteristic: loop @ 0x46CF94\nfunction @ 0x46D2C7\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x46D33E\n      or:\n        api: FindNextFile @ 0x46D39F\n      optional:\n        api: FindClose @ 0x46D3B6, 0x46D3BF\n        match: contain loop @ 0x46D2C7\n          or:\n            characteristic: loop @ 0x46D2C7\nfunction @ 0x475BB5\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x475BDF\n      or:\n        api: FindNextFile @ 0x475C35\n      optional:\n        api: FindClose @ 0x475C7D\n        match: contain loop @ 0x475BB5\n          or:\n            characteristic: loop @ 0x475BB5\nfunction @ 0x479560\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x479581, 0x479618\n      or:\n        api: FindNextFile @ 0x4795F1, 0x479690\n      optional:\n        api: FindClose @ 0x4795FC, 0x47969D, 0x4796AD\n        match: contain loop @ 0x479560\n          or:\n            characteristic: loop @ 0x479560\n            characteristic: recursive call @ 0x479560\nfunction @ 0x4796BB\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x4796DC, 0x47975E\n      or:\n        api: FindNextFile @ 0x479737, 0x4797D6\n      optional:\n        api: FindClose @ 0x479742, 0x4797E3, 0x4797F3\n        match: contain loop @ 0x4796BB\n          or:\n            characteristic: loop @ 0x4796BB\n            characteristic: recursive call @ 0x4796BB\nfunction @ 0x479A49\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x479A96\n      or:\n        api: FindNextFile @ 0x479B93\n      optional:\n        api: FindClose @ 0x479BA9\n        match: contain loop @ 0x479A49\n          or:\n            characteristic: loop @ 0x479A49\n            characteristic: recursive call @ 0x479A49\n\nenumerate files recursively (3 matches)\nnamespace  host-interaction/file-system/files/list        \nauthor     @_re_fox, anushka.virgaonkar@mandiant.com      \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nmbc        Discovery::File and Directory Discovery [E1083]\nfunction @ 0x479560\n  and:\n    characteristic: recursive call @ 0x479560\n    or:\n      match: enumerate files on Windows @ 0x479560\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x479581, 0x479618\n            or:\n              api: FindNextFile @ 0x4795F1, 0x479690\n            optional:\n              api: FindClose @ 0x4795FC, 0x47969D, 0x4796AD\n              match: contain loop @ 0x479560\n                or:\n                  characteristic: loop @ 0x479560\n                  characteristic: recursive call @ 0x479560\nfunction @ 0x4796BB\n  and:\n    characteristic: recursive call @ 0x4796BB\n    or:\n      match: enumerate files on Windows @ 0x4796BB\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x4796DC, 0x47975E\n            or:\n              api: FindNextFile @ 0x479737, 0x4797D6\n            optional:\n              api: FindClose @ 0x479742, 0x4797E3, 0x4797F3\n              match: contain loop @ 0x4796BB\n                or:\n                  characteristic: loop @ 0x4796BB\n                  characteristic: recursive call @ 0x4796BB\nfunction @ 0x479A49\n  and:\n    characteristic: recursive call @ 0x479A49\n    or:\n      match: enumerate files on Windows @ 0x479A49\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x479A96\n            or:\n              api: FindNextFile @ 0x479B93\n            optional:\n              api: FindClose @ 0x479BA9\n              match: contain loop @ 0x479A49\n                or:\n                  characteristic: loop @ 0x479A49\n                  characteristic: recursive call @ 0x479A49\n\nget file attributes (5 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x46D1DF in function 0x46D1DF\n  or:\n    api: GetFileAttributes @ 0x46D219\nbasic block @ 0x46DAFA in function 0x46DADC\n  or:\n    api: GetFileAttributes @ 0x46DAFB\nbasic block @ 0x46E0B7 in function 0x46E0B7\n  or:\n    api: GetFileAttributes @ 0x46E0B8\nbasic block @ 0x477F04 in function 0x477D0E\n  or:\n    api: GetFileAttributes @ 0x477F09\nbasic block @ 0x4795B8 in function 0x479560\n  or:\n    api: GetFileAttributes @ 0x4795BF\n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x482A05\n  or:\n    api: GetFileSize @ 0x482C9C\nfunction @ 0x498461\n  or:\n    api: GetFileSize @ 0x498494\n\nget file version info\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x46DB2C\n  and:\n    or:\n      api: GetFileVersionInfo @ 0x46DB64\n    optional: = retrieve specified version information from the version-information resource\n      api: VerQueryValue @ 0x46DBDA, 0x46DC84\n      or:\n        api: GetFileVersionInfoSize @ 0x46DB3E\n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ 0x477F04 in function 0x477D0E\n  or:\n    api: SetFileAttributes @ 0x477F23\nbasic block @ 0x4795B8 in function 0x479560\n  or:\n    api: SetFileAttributes @ 0x4795D9\n\nmove file (3 matches)\nnamespace  host-interaction/file-system/move                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Move File [C0063]                         \nfunction @ 0x46CE1E\n  or:\n    api: MoveFile @ 0x46CE9D\nfunction @ 0x46CF94\n  or:\n    api: MoveFile @ 0x46D10E\nfunction @ 0x46E319\n  or:\n    api: MoveFile @ 0x46E3CA\n    basic block:\n      and:\n        number: 0x1 = FO_MOVE @ 0x46E566\n        or:\n          api: SHFileOperation @ 0x46E56E\n\nread .ini file (4 matches)\nnamespace  host-interaction/file-system/read     \nauthor     @_re_fox, michael.hunhoff@mandiant.com\nscope      function                              \nmbc        File System::Read File [C0051]        \nfunction @ 0x4783FD\n  and:\n    or:\n      api: GetPrivateProfileString @ 0x478482\nfunction @ 0x4784BF\n  and:\n    or:\n      api: GetPrivateProfileSection @ 0x47852A\nfunction @ 0x4787FC\n  and:\n    or:\n      api: GetPrivateProfileSectionNames @ 0x478858\nfunction @ 0x478A19\n  and:\n    or:\n      api: GetPrivateProfileSection @ 0x478ACC, 0x478AF8\n\nread file on Windows (9 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x406A95\n  or:\n    and:\n      os: windows\n      or:\n        api: fread @ 0x406AB3\nfunction @ 0x40B230\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x40B35C\nfunction @ 0x40B3B0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x40B40C\nfunction @ 0x43921B\n  or:\n    and:\n      os: windows\n      or:\n        api: _read @ 0x439134\nfunction @ 0x47070D\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x470765, 0x470811\nfunction @ 0x472475\n  or:\n    and:\n      os: windows\n      or:\n        api: fread @ 0x4724A5\nfunction @ 0x4725B1\n  or:\n    and:\n      os: windows\n      or:\n        api: fread @ 0x4725D3\nfunction @ 0x482A05\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x482C82\n          match: create or open file @ 0x482C89\n            or:\n              api: CreateFile @ 0x482C89\n      or:\n        api: ReadFile @ 0x482CBF\nfunction @ 0x498461\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x49847E\n          match: create or open file @ 0x498484\n            or:\n              api: CreateFile @ 0x498484\n      or:\n        api: ReadFile @ 0x4984C9\n\nclear file content\nnamespace  host-interaction/file-system/write\nauthor     jakeperalta7                      \nscope      function                          \nmbc        File System::Writes File [C0052]  \nfunction @ 0x477FD5\n  and:\n    api: SetEndOfFile @ 0x478019\n    not:\n      api: SetFilePointer\n\nwrite file on Windows (7 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x41F5B3\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x45F3C6\n        api: fwrite @ 0x45F3C6\nfunction @ 0x46CC1D\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x46CC44\nfunction @ 0x470633\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x470664\nfunction @ 0x4725F5\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x47262D\n        api: fwrite @ 0x47262D\nfunction @ 0x472642\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x47265B\n        api: fwrite @ 0x47265B\nfunction @ 0x472865\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x472AF5\n        api: fwrite @ 0x472AF5\nfunction @ 0x47CD62\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x47CDC3\n        api: fwrite @ 0x47CDC3\n\nenumerate gui resources\nnamespace  host-interaction/gui                           \nauthor     johnk3r, anushka.virgaonkar@mandiant.com       \nscope      function                                       \natt&ck     Discovery::Application Window Discovery [T1010]\nfunction @ 0x464144\n  or:\n    api: EnumWindows @ 0x464832\n\nfind taskbar (3 matches)\nnamespace  host-interaction/gui/taskbar/find   \nauthor     moritz.raabe@mandiant.com           \nscope      basic block                         \nmbc        Discovery::Taskbar Discovery [B0043]\nbasic block @ 0x41EFCE in function 0x41EFAD\n  and:\n    string: \"Shell_TrayWnd\" @ 0x41EFCF\n    match: find graphical window @ 0x41EFD4\n      or:\n        api: FindWindow @ 0x41EFD4\nbasic block @ 0x492255 in function 0x492255\n  and:\n    string: \"Shell_TrayWnd\" @ 0x492258\n    match: find graphical window @ 0x49225F\n      or:\n        api: FindWindow @ 0x49225F\nbasic block @ 0x492289 in function 0x492289\n  and:\n    string: \"Shell_TrayWnd\" @ 0x492298\n    match: find graphical window @ 0x49229F\n      or:\n        api: FindWindow @ 0x49229F\n\nfind graphical window (4 matches)\nnamespace  host-interaction/gui/window/find               \nauthor     moritz.raabe@mandiant.com                      \nscope      instruction                                    \natt&ck     Discovery::Application Window Discovery [T1010]\ninstruction @ 0x41EFD4\n  or:\n    api: FindWindow @ 0x41EFD4\ninstruction @ 0x46E645\n  or:\n    api: FindWindowEx @ 0x46E645\ninstruction @ 0x49225F\n  or:\n    api: FindWindow @ 0x49225F\ninstruction @ 0x49229F\n  or:\n    api: FindWindow @ 0x49229F\n\nget graphical window text (11 matches)\nnamespace  host-interaction/gui/window/get-text           \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \nmbc        Discovery::Application Window Discovery [E1010]\nfunction @ 0x461A70\n  or:\n    and:\n      or:\n        basic block:\n          and:\n            number: 0xD = WM_GETTEXT @ 0x461AD9\n            api: SendMessage @ 0x461ADD\nfunction @ 0x46359E\n  or:\n    and:\n      api: GetWindowText @ 0x4638A5\nfunction @ 0x463B0C\n  or:\n    and:\n      or:\n        basic block:\n          and:\n            number: 0xD = WM_GETTEXT @ 0x463B66\n            api: SendMessage @ 0x463B6B\nfunction @ 0x46489C\n  or:\n    and:\n      api: GetWindowText @ 0x464922, 0x4649E9\nfunction @ 0x464BD3\n  or:\n    and:\n      optional:\n        api: IsWindowVisible @ 0x464BEB\n      or:\n        basic block:\n          and:\n            number: 0xD = WM_GETTEXT @ 0x464C3B\n            api: SendMessage @ 0x464C40\nfunction @ 0x465B9A\n  or:\n    and:\n      api: GetWindowText @ 0x465BC5\nfunction @ 0x47E8F7\n  or:\n    and:\n      api: GetWindowText @ 0x47E91E\nfunction @ 0x491E0D\n  or:\n    and:\n      api: GetWindowText @ 0x491F76\nfunction @ 0x4947A8\n  or:\n    and:\n      api: GetWindowText @ 0x494C26, 0x494C8F\nfunction @ 0x496FA4\n  or:\n    and:\n      api: GetWindowText @ 0x4971C3\nfunction @ 0x4972B7\n  or:\n    and:\n      api: GetWindowText @ 0x497423\n\nhide graphical window (8 matches)\nnamespace  host-interaction/gui/window/hide                          \nauthor     michael.hunhoff@mandiant.com                              \nscope      basic block                                               \natt&ck     Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\nbasic block @ 0x45F0F9 in function 0x41EEF7\n  and:\n    number: 0x0 = SW_HIDE @ 0x45F101\n    api: ShowWindow @ 0x45F0FB\nbasic block @ 0x4827C2 in function 0x482638\n  and:\n    number: 0x0 = SW_HIDE @ 0x48294B, 0x48295A\n    api: ShowWindow @ 0x4829BE\nbasic block @ 0x49015D in function 0x490135\n  and:\n    number: 0x0 = SW_HIDE @ 0x490163\n    api: ShowWindow @ 0x490167\nbasic block @ 0x4950F2 in function 0x495009\n  and:\n    number: 0x0 = SW_HIDE @ 0x4950F8\n    api: ShowWindow @ 0x4950FC, 0x495102\nbasic block @ 0x496B61 in function 0x496A44\n  and:\n    number: 0x0 = SW_HIDE @ 0x496B61\n    api: ShowWindow @ 0x496B66\nbasic block @ 0x49813A in function 0x4980CD\n  and:\n    number: 0x0 = SW_HIDE @ 0x49813A\n    api: ShowWindow @ 0x49813E\nbasic block @ 0x4981BF in function 0x4980CD\n  and:\n    number: 0x0 = SW_HIDE @ 0x4981BF\n    api: ShowWindow @ 0x4981C3, 0x4981D7\nbasic block @ 0x49A198 in function 0x499E78\n  and:\n    number: 0x0 = SW_HIDE @ 0x49A198\n    api: ShowWindow @ 0x49A19C\n\nget keyboard layout\nnamespace  host-interaction/hardware/keyboard                                   \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Discovery::System Location Discovery::System Language Discovery      \n           [T1614.001]                                                          \nfunction @ 0x41D70E\n  and:\n    or:\n      api: GetKeyboardLayoutName @ 0x45DF94\n\nget memory capacity\nnamespace  host-interaction/hardware/memory               \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x41F370\n  or:\n    api: GlobalMemoryStatusEx @ 0x41F39A\n\nget disk information (6 matches)\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ 0x473D97\n  or:\n    api: GetDriveType @ 0x473EF4\nfunction @ 0x4743DE\n  or:\n    api: GetDriveType @ 0x474661\nfunction @ 0x474776\n  or:\n    api: GetVolumeInformation @ 0x4747DB\nfunction @ 0x474844\n  or:\n    api: GetVolumeInformation @ 0x4748A9\nfunction @ 0x474912\n  or:\n    api: GetVolumeInformation @ 0x47497A\nfunction @ 0x4749FD\n  or:\n    api: GetDriveType @ 0x474AE8\n\nget disk size (3 matches)\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ 0x4750EB\n  or:\n    api: GetDiskFreeSpaceEx @ 0x475156\nfunction @ 0x4751CE\n  or:\n    api: GetDiskFreeSpaceEx @ 0x475239\nfunction @ 0x4752B1\n  or:\n    api: GetDiskFreeSpace @ 0x475334\n\nget storage device properties (2 matches)\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com                                        \nscope       function                                                            \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/winioctl/ni-wini…\nfunction @ 0x46D509\n  and:\n    number: 0x2D1400 = IOCTL_STORAGE_QUERY_PROPERTY @ 0x46D55D\n    or:\n      match: interact with driver via IOCTL @ 0x46D563\n        or:\n          api: DeviceIoControl @ 0x46D563\nfunction @ 0x46D588\n  and:\n    number: 0x2D1400 = IOCTL_STORAGE_QUERY_PROPERTY @ 0x46D5D7\n    or:\n      match: interact with driver via IOCTL @ 0x46D5DD\n        or:\n          api: DeviceIoControl @ 0x46D5DD\n\nprint debug messages\nnamespace  host-interaction/log/debug/write-event\nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \nfunction @ 0x41F5B3\n  or:\n    api: OutputDebugString @ 0x45F3E1\n\nshutdown system\nnamespace  host-interaction/os                   \nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \natt&ck     Impact::System Shutdown/Reboot [T1529]\nfunction @ 0x46E814\n  or:\n    api: ExitWindowsEx @ 0x46E850\n    api: InitiateSystemShutdownEx @ 0x46E870\n\nget hostname (2 matches)\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ 0x41D70E\n  or:\n    api: GetComputerName @ 0x45DB11\nfunction @ 0x46DD45\n  or:\n    api: gethostname @ 0x46DD7A\n\nget system information on Windows\nnamespace  host-interaction/os/info                       \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com  \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x40615E\n  and:\n    os: windows\n    or:\n      api: GetSystemInfo @ 0x406320, 0x44455F\n\ncreate process on Windows (6 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x4437E0 in function 0x40445D\n  or:\n    api: ShellExecute @ 0x4437F9\nbasic block @ 0x46134A in function 0x461145\n  or:\n    api: CreateProcessAsUser @ 0x46136D\nbasic block @ 0x461472 in function 0x461412\n  or:\n    api: CreateProcessWithLogon @ 0x461493\nbasic block @ 0x48AD7A in function 0x48AC8B\n  or:\n    api: ShellExecuteEx @ 0x48ADCA\nbasic block @ 0x48B2C1 in function 0x48AF20\n  or:\n    api: CreateProcess @ 0x48B2DD\nbasic block @ 0x498064 in function 0x498064\n  or:\n    api: CreateProcess @ 0x4980B1\n\nallocate or change RWX memory\nnamespace  host-interaction/process/inject\nauthor     @mr-tz, mehunhoff@google.com   \nscope      basic block                    \nmbc        Memory::Allocate Memory [C0007]\nbasic block @ 0x489881 in function 0x4895BB\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x489881\n            or:\n              api: VirtualAlloc @ 0x489895\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x489881\n\nenumerate processes (2 matches)\nnamespace  host-interaction/process/list                                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      function                                                             \natt&ck     Discovery::Process Discovery [T1057], Discovery::Software Discovery  \n           [T1518]                                                              \nfunction @ 0x46D3FA\n  or:\n    and:\n      api: Process32First @ 0x46D42D\n      api: Process32Next @ 0x46D44D\n      optional:\n        basic block:\n          and:\n            api: CreateToolhelp32Snapshot @ 0x46D41F\n            or:\n              number: 0x2 = TH32CS_SNAPPROCESS @ 0x46D411\nfunction @ 0x48A5A3\n  or:\n    and:\n      api: Process32First @ 0x48A5E1\n      api: Process32Next @ 0x48A6C3\n      optional:\n        basic block:\n          and:\n            api: CreateToolhelp32Snapshot @ 0x48A5D3\n            or:\n              number: 0x2 = TH32CS_SNAPPROCESS @ 0x48A5BD\n\nacquire debug privileges\nnamespace  host-interaction/process/modify                        \nauthor     william.ballenthin@mandiant.com                        \nscope      basic block                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\nbasic block @ 0x48A0B6 in function 0x48A009\n  and:\n    string: \"SeDebugPrivilege\" @ 0x48A0B6\n\nmodify access privileges (2 matches)\nnamespace  host-interaction/process/modify                        \nauthor     moritz.raabe@mandiant.com                              \nscope      instruction                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\ninstruction @ 0x461018\n  and:\n    api: AdjustTokenPrivileges @ 0x461018\ninstruction @ 0x46167E\n  and:\n    api: AdjustTokenPrivileges @ 0x46167E\n\nterminate process (3 matches)\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x46EA3E\n  or:\n    and:\n      optional:\n        match: open process @ 0x46EA6E\n          or:\n            api: OpenProcess @ 0x46EA82\n      or:\n        api: TerminateProcess @ 0x46EA8C\nfunction @ 0x487E80\n  or:\n    and:\n      or:\n        api: TerminateProcess @ 0x488223\nfunction @ 0x48A009\n  or:\n    and:\n      optional:\n        match: open process @ 0x48A08D, 0x48A0D2\n          or:\n            api: OpenProcess @ 0x48A0DA\n          or:\n            api: OpenProcess @ 0x48A094\n      or:\n        api: TerminateProcess @ 0x48A18F\n\nempty the recycle bin\nnamespace  host-interaction/recycle-bin\nauthor     moritz.raabe@mandiant.com   \nscope      function                    \nfunction @ 0x477953\n  or:\n    api: SHEmptyRecycleBin @ 0x477977\n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ 0x48B8F0\n  and:\n    optional:\n      match: create or open registry key @ 0x48BA11\n        or:\n          api: RegOpenKeyEx @ 0x48BA27\n    or:\n      api: RegEnumKeyEx @ 0x48BA8A\nfunction @ 0x48CB5B\n  and:\n    optional:\n      match: create or open registry key @ 0x48CBA6\n        or:\n          api: RegOpenKeyEx @ 0x48CBB4\n    or:\n      api: RegEnumKeyEx @ 0x48CB8B, 0x48CC4F\n\nquery or enumerate registry value (5 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x40533E\n  and:\n    optional:\n      match: create or open registry key @ 0x40533E\n        or:\n          api: RegOpenKeyEx @ 0x40545B\n    or:\n      api: RegQueryValueEx @ 0x443EEC, 0x443F2D\nfunction @ 0x4059A7\n  and:\n    optional:\n      match: create or open registry key @ 0x4059BB\n        or:\n          api: RegOpenKeyEx @ 0x4059CB\n    or:\n      api: RegQueryValueEx @ 0x4059EC\nfunction @ 0x4605C7\n  and:\n    optional:\n      match: create or open registry key @ 0x4606B3\n        or:\n          api: RegOpenKeyEx @ 0x4606C3\n    or:\n      api: RegQueryValueEx @ 0x4606ED\nfunction @ 0x48BB02\n  and:\n    optional:\n      match: create or open registry key @ 0x48BC36\n        or:\n          api: RegOpenKeyEx @ 0x48BC4C\n    or:\n      api: RegEnumValue @ 0x48BCC0\nfunction @ 0x48BD6B\n  and:\n    optional:\n      match: create or open registry key @ 0x48BEB9\n        or:\n          api: RegOpenKeyEx @ 0x48BED0\n    or:\n      api: RegQueryValueEx @ 0x48BF53, 0x48C00E, 0x48C07B, 0x48C110, and 2 more...\n\nset registry value\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x48C2DE\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x48C448\n          or:\n            api: RegCreateKeyEx @ 0x48C46B\n      or:\n        api: RegSetValueEx @ 0x48C5D9, 0x48C6E8, 0x48C774, 0x48C887\n\ndelete registry key (2 matches)\nnamespace  host-interaction/registry/delete                                \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\nscope      function                                                        \natt&ck     Defense Evasion::Modify Registry [T1112]                        \nmbc        Operating System::Registry::Delete Registry Key [C0036.002]     \nfunction @ 0x48B535\n  and:\n    optional:\n      match: create or open registry key @ 0x48B683\n        or:\n          api: RegOpenKeyEx @ 0x48B699\n    or:\n      api: RegDeleteKey @ 0x48B849\nfunction @ 0x48CB5B\n  and:\n    optional:\n      match: create or open registry key @ 0x48CBA6\n        or:\n          api: RegOpenKeyEx @ 0x48CBB4\n    or:\n      api: RegDeleteKey @ 0x48CC1A\n\ndelete registry value\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ 0x48B535\n  and:\n    optional:\n      match: create or open registry key @ 0x48B683\n        or:\n          api: RegOpenKeyEx @ 0x48B699\n    or:\n      api: RegDeleteValue @ 0x48B731\n\nget session user name\nnamespace  host-interaction/session                                             \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope      function                                                             \natt&ck     Discovery::System Owner/User Discovery [T1033], Discovery::Account   \n           Discovery [T1087]                                                    \nfunction @ 0x41D70E\n  or:\n    api: GetUserName @ 0x45DA28\n\nget token membership\nnamespace  host-interaction/session                      \nauthor     michael.hunhoff@mandiant.com                  \nscope      function                                      \natt&ck     Discovery::System Owner/User Discovery [T1033]\nfunction @ 0x4615A7\n  and:\n    api: CheckTokenMembership @ 0x4615E5\n    optional:\n      api: AllocateAndInitializeSid @ 0x4615D0\n      api: FreeSid @ 0x4615F5\n\nget token privileges\nnamespace  host-interaction/session    \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x460F58\n  and:\n    or:\n      basic block:\n        and:\n          api: GetTokenInformation @ 0x460F6E\n          number: 0x3 = TokenPrivileges @ 0x460F6B\n        and:\n          api: GetTokenInformation @ 0x460FA6\n          number: 0x3 = TokenPrivileges @ 0x460FA3\n\ncreate thread (5 matches)\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x461747 in function 0x461747\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x4617AC\nbasic block @ 0x46E114 in function 0x46E0F4\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthreadex @ 0x46E139\nbasic block @ 0x470870 in function 0x4708F7\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x47087D\nbasic block @ 0x470870 in function 0x4708F7\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x47087D\nbasic block @ 0x47D13B in function 0x47D126\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthread @ 0x47D151\n\nterminate thread\nnamespace  host-interaction/thread/terminate                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \nmbc        Process::Terminate Thread [C0039]                                    \nbasic block @ 0x4708A6 in function 0x470889\n  or:\n    api: TerminateThread @ 0x4708B9\n\nimpersonate user\nnamespace  host-interaction/user                                                \nauthor     michael.hunhoff@mandiant.com, 99.elad.levi@gmail.com                 \nscope      function                                                             \natt&ck     Privilege Escalation::Access Token Manipulation::Token               \n           Impersonation/Theft [T1134.001]                                      \nfunction @ 0x461145\n  or:\n    api: LogonUser @ 0x4611CA\n    and:\n      api: LoadUserProfile @ 0x461327\n\n(internal) autoit file limitation\nnamespace    internal/limitation/static                                         \nauthor       william.ballenthin@mandiant.com                                    \nscope        file                                                               \ndescription  This sample appears to be compiled with AutoIt.                    \n                                                                                \n             AutoIt is a freeware BASIC-like scripting language designed for    \n             automating the Windows GUI.                                        \n             capa cannot handle AutoIt scripts. This means that the results will\n             be misleading or incomplete.                                       \n             You may have to analyze the file manually, using a tool like the   \n             AutoIt decompiler MyAut2Exe.                                       \n                                                                                \nor:\n  match: compiler/autoit @ global\n    or:\n      string: \"AutoIt Error\" @ file+0xD5910\n      string: \">>>AUTOIT NO CMDEXECUTE<<<\" @ file+0x9BF64\n      string: \"#requireadmin\" @ file+0x9EB28\n      string: \"#OnAutoItStartRegister\" @ file+0x9EAD8\n      substring: >>>AUTOIT SCRIPT<<<\n        - \">>>AUTOIT SCRIPT<<<\" @ file+0xC5640\n\nlink function at runtime on Windows (13 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x4062E6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4062E6\ninstruction @ 0x406816\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x406816\ninstruction @ 0x406850\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x406850\ninstruction @ 0x432FC7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x432FC7\ninstruction @ 0x432FC7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x432FC7\ninstruction @ 0x45DB5B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x45DB5B\ninstruction @ 0x4671A3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4671A3\ninstruction @ 0x483FF4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x483FF4\ninstruction @ 0x488EF7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x488EF7\ninstruction @ 0x488F13\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x488F13\ninstruction @ 0x488F59\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x488F59\ninstruction @ 0x48B82B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x48B82B\ninstruction @ 0x48CBF6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x48CBF6\n\nparse PE header\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x40B7E0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x40B810, 0x40B824, 0x40B82D, 0x40B84F, and 43 more...\n      or:\n        and:\n          number: 0x50 @ 0x450313\n          number: 0x45 @ 0x40BC73\n      or:\n        and:\n          number: 0x4D @ 0x40BB79\n          number: 0x5A @ 0x40B92F, 0x40B973, 0x40BCA4\n\nresolve function by parsing PE exports (15 matches)\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x401641\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x401641\n      mnemonic: movzx @ 0x401B19, 0x401B67, 0x401BA4, 0x401BEE, and 2 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x401AB7, 0x401AF7, 0x442A22\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x401760\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x401B05, 0x401B29, 0x401B5B, 0x401B63, and 11 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x40165B, 0x401679, 0x401A7C, 0x401BB7, and 8 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x401A6C, 0x401A9E, 0x401ADE, 0x401B15, and 8 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x401AB3, 0x401AC0, 0x401AF0, 0x401B25, and 12 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x401AA2, 0x401AD4, 0x401BD5, 0x4425C7, and 11 more...\nfunction @ 0x408BAA\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x408BAA\n      mnemonic: movzx @ 0x445922, 0x445B7A\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x408D85, 0x408DDB\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x445A85, 0x445B3F\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x408C7B, 0x408CD7, 0x408D0F, 0x408D4C, and 9 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x408BB8, 0x408CBE, 0x408DC2, 0x408DD1, and 7 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x408BF6, 0x408C12, 0x408C87, 0x408D89\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x408D20, 0x445980, 0x445A4F, 0x445AB4, and 2 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x408CA5, 0x408CD3, 0x408DAF, 0x408E24, and 2 more...\nfunction @ 0x4095C0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x4095C0\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x4096AC, 0x409887, 0x4098DD, 0x4099C7\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x4463CA, 0x446461, 0x4465C9, 0x44661E, and 1 more...\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x409653, 0x409864, 0x446280, 0x4462A5, and 9 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x4096B0, 0x4098EC, 0x4465C1\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x4096BC, 0x40988B, 0x40989D, 0x4098AE, and 6 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x4096A4, 0x409963, 0x40996D, 0x409971, and 7 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x4096B8, 0x4097D8, 0x409909, 0x409931, and 6 more...\nfunction @ 0x40A180\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x40A180\n      mnemonic: movzx @ 0x40A1DD, 0x40A1FF, 0x40A20D, 0x40A21F, and 490 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x40A558, 0x449751, 0x44976C\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x40A670, 0x40A8C8, 0x44738C, 0x447398, and 18 more...\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x40A647, 0x40A887, 0x447695, 0x447A2F, and 1 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x4474A1, 0x4474D4, 0x447577, 0x4475AA, and 2 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x40A7ED, 0x447F8A, 0x448031, 0x44806F, and 14 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x40A7FB, 0x447F9C, 0x447FBA, 0x44803B, and 23 more...\nfunction @ 0x40AD7C\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x40AD7C\n      mnemonic: movzx @ 0x40AF89, 0x44FB38\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x44FAEE, 0x44FAFC, 0x44FB1F, 0x44FCE1\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x40ADD7, 0x40B08A\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x40AD92, 0x40AF43, 0x40B0D0, 0x44FAA7, and 6 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x40ADBC, 0x40AE73, 0x44FBCB, 0x44FC8B, and 1 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x40AFA8, 0x40B019, 0x40B02B, 0x44FBCF, and 2 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x40ADB8, 0x40AF21, 0x40AF49, 0x40B0CC, and 6 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x40AF4D, 0x40AFCD, 0x40B011, 0x44FC5F, and 2 more...\nfunction @ 0x40D840\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x40D840\n      mnemonic: movzx @ 0x40DD22, 0x40DEE0, 0x40DEE7, 0x40DEF0, and 4 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x40D863, 0x40D996, 0x40DD88, 0x40DE6E, and 8 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x40D8C7\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x40D92B, 0x40D989, 0x40D9C0, 0x40DA03, and 9 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x40D8E3, 0x40DC92, 0x40DCC7, 0x40DFCA, and 8 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x40D8CB, 0x40D927, 0x40DAB6, 0x40DBBC, and 14 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x40D9B7, 0x40DA33, 0x40DAC0, 0x40DB79, and 20 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x40D85D, 0x40D922, 0x40D98E, 0x40DE85, and 11 more...\nfunction @ 0x410540\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x410540\n      mnemonic: movzx @ 0x410600, 0x41062B, 0x41066B, 0x4107F2, and 29 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x410592\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x410876, 0x410AAA, 0x410BFC, 0x410C2C, and 7 more...\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x41059A, 0x4105D1, 0x410652, 0x4106C4, and 22 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x410A1F, 0x411150, 0x411166, 0x4112C1, and 9 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x41058A, 0x4105B5, 0x41065A, 0x410A26, and 14 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x410552, 0x4108D8, 0x41092E, 0x410938, and 23 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x410691, 0x410842, 0x4108BB, 0x4108C4, and 27 more...\nfunction @ 0x41BEAD\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x41BEAD\n      mnemonic: movzx @ 0x41C06A, 0x41C091, 0x41C0A0, 0x41C0A8, and 128 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x41C16F, 0x45A1E8, 0x45A34E, 0x45B07F\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x459C84, 0x45B005\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x459F7A, 0x45B03F, 0x45B060, 0x45B07C, and 2 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x45933F, 0x45AF58, 0x45B1CB, 0x45B252\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x41C052, 0x41C302, 0x41C338, 0x41C408, and 23 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x458F91, 0x458FCD, 0x459172, 0x4591C1, and 1 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x459046, 0x459E17\nfunction @ 0x466502\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x466502\n      mnemonic: movzx @ 0x4666E8, 0x4667E7, 0x4669E6, 0x4669EC\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x46656E, 0x46659F, 0x466602, 0x46674E, and 7 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x46661E\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x466641, 0x466652, 0x466662, 0x466686, and 11 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x466554, 0x466571, 0x46657B, 0x46682E, and 7 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x466596, 0x4665CF, 0x466616, 0x4667A9, and 3 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x4665C4, 0x46665B, 0x4667AD, 0x46683F, and 1 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x46671D, 0x466769, 0x4667B1, 0x4667CC, and 2 more...\nfunction @ 0x4681EE\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x4681EE\n      mnemonic: movzx @ 0x468256, 0x46826B, 0x4682A7, 0x4682F8, and 8 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x4684CE\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x46852F\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x4683DF, 0x4686B0\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x468378, 0x468407, 0x468439\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x468401\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x4683E5, 0x468612\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x4683FB, 0x4687AF\nfunction @ 0x4763AC\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x4763AC\n      mnemonic: movzx @ 0x47645E, 0x476474, 0x476480, 0x476489\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x476405, 0x476580, 0x476597, 0x4767DE\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x476707\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x47652F, 0x4765A3, 0x4765EC, 0x476638, and 4 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x4763D3, 0x47642F, 0x4764C2, 0x4764C7, and 3 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x476626\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x476542, 0x4765C2, 0x4765F9, 0x476645, and 9 more...\nfunction @ 0x476E0F\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x476E0F\n      mnemonic: movzx @ 0x476EA3, 0x476EA6\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x476E8F\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x477044, 0x4770D8, 0x4771A4\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x476E7D, 0x476E9B, 0x476EAA, 0x476FA1, and 1 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x476E26, 0x476EE6, 0x476EFE, 0x476F13, and 4 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x476F24, 0x476F3C, 0x47706B, 0x4770B0\nfunction @ 0x47902A\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x47902A\n      mnemonic: movzx @ 0x47912D, 0x47913D, 0x47916B, 0x479184\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x4790E8, 0x479508\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x479080\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x479131, 0x479174, 0x479266, 0x47929D, and 3 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x4791BC, 0x4791CA, 0x4791F4, 0x479225, and 4 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x479051, 0x4790B8, 0x479202, 0x47930A, and 1 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x47916F, 0x47927E, 0x4792D5, 0x4794E8, and 1 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x47926E, 0x4794FC\nfunction @ 0x487E80\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x487E80\n      mnemonic: movzx @ 0x487E8C\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x487FF3, 0x48829E\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x487F41, 0x4881C4, 0x488201\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x487EF1, 0x487F23, 0x487F9A, 0x487FDB, and 7 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x488092, 0x488118, 0x488136\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x487FBF, 0x488192, 0x488197, 0x4881DA, and 3 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x487F38, 0x487FAF, 0x487FEA, 0x488018, and 7 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x487FE6, 0x487FF8, 0x488004, 0x48808E, and 2 more...\nfunction @ 0x490F26\n  and:\n    os: windows\n    or:\n      mnemonic: movzx @ 0x49110E, 0x4912C4, 0x4912CA\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x491140, 0x491288\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x491028\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x490FB0, 0x490FC8, 0x490FDA, 0x490FED, and 6 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x490F4B, 0x490FD6, 0x4910C5\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x490F43, 0x49107D, 0x4912B0\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x49106A, 0x4910BB, 0x491298, 0x4912A6, and 1 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x490F57, 0x490FC4, 0x4910E2, 0x491184, and 2 more...\n\nexecute shellcode via indirect call\nnamespace  load-code/shellcode            \nauthor     ronnie.salomonsen@mandiant.com \nscope      function                       \nmbc        Memory::Allocate Memory [C0007]\nfunction @ 0x4895BB\n  and:\n    match: allocate or change RWX memory @ 0x489881\n      or:\n        basic block:\n          and:\n            or:\n              match: allocate memory @ 0x489881\n                or:\n                  api: VirtualAlloc @ 0x489895\n            or:\n              number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x489881\n    or:\n      characteristic: indirect call @ 0x48963F, 0x489682\n\ncreate shortcut via IShellLink (2 matches)\nnamespace   persistence                                                         \nauthor      matthew.williams@mandiant.com                                       \nscope       function                                                            \natt&ck      Persistence::Boot or Logon Autostart Execution::Shortcut            \n            Modification [T1547.009]                                            \nreferences  https://docs.microsoft.com/en-us/windows/win32/shell/links#creating…\nfunction @ 0x47573C\n  and:\n    offset: 0x50 = psl->SetPath @ 0x475910, 0x4759CE, 0x4759FC\n    offset: 0x18 = ppf->Save @ 0x475790, 0x4757C8, 0x47585F, 0x475864, and 4 more...\n    api: CoCreateInstance @ 0x4758CC\n    bytes: 0114020000000000c000000000000046 = CLSID_ShellLink @ 0x4758C7\n    bytes: 0b01000000000000c000000000000046 = IID_IPersistFile @ 0x475AB3\n    or:\n      bytes: f914020000000000c000000000000046 = IID_IShellLinkW @ 0x4758BE\nfunction @ 0x4763AC\n  and:\n    offset: 0x50 = psl->SetPath @ 0x4763F4, 0x476610, 0x47665C, 0x4766A8, and 2 more...\n    offset: 0x18 = ppf->Save @ 0x476542, 0x4765C2, 0x4765F9, 0x476645, and 9 more...\n    api: CoCreateInstance @ 0x47656E\n    bytes: 0114020000000000c000000000000046 = CLSID_ShellLink @ 0x476569\n    bytes: 0b01000000000000c000000000000046 = IID_IPersistFile @ 0x476585\n    or:\n      bytes: f914020000000000c000000000000046 = IID_IShellLinkW @ 0x476562\n\n\n\n"},"hashes":{"md5":"1a7bbf68c09e364ac325434493133305","sha1":"b6e8fae23eca1afff3e815286136cfbfa7b11eb9","sha256":"952afbda734257d5e14c9f4b09bc8bb48a60e37e7c17a9f3f27b0a96f4f0fc47"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 2043</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 120247</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"2aa5ce3561dc657a157460383c7c9b\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"1a7bbf68c09e364ac325434493133305\",\n        \"sha256\": \"952afbda734257d5e14c9f4b09bc8bb48a60e37e7c17a9f3f27b0a9\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_allocate_memory__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"allocate memory (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x46B26C\",\n      \"label\": \"Block 0x46B26C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46B26C\"\n    },\n    {\n      \"id\": \"api_VirtualAllocEx\",\n      \"label\": \"VirtualAllocEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_library_rule_\",\n      \"label\": \"library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Modulo [C0058]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_loop__489_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (489 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401202\",\n      \"label\": \"Function 0x401202\",\n      \"type\": \"function\",\n      \"address\": \"0x401202\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__13_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (13 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40533E\",\n      \"label\": \"Block 0x40533E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40533E\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__37_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (37 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40F4AF\",\n      \"label\": \"Block 0x40F4AF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40F4AF\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_open_process__7_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"open process (7 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Open Process [C0065]\"\n      ]\n    },\n    {\n      \"id\": \"api_OpenProcess\",\n      \"label\": \"OpenProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"label\": \"check for time delay via QueryPerformanceCounter (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"QueryPerformanceCounter [B0001.033]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x469B67\",\n      \"label\": \"Function 0x469B67\",\n      \"type\": \"function\",\n      \"address\": \"0x469B67\"\n    },\n    {\n      \"id\": \"func_0x46E899\",\n      \"label\": \"Function 0x46E899\",\n      \"type\": \"function\",\n      \"address\": \"0x46E899\"\n    },\n    {\n      \"id\": \"func_0x469B7E\",\n      \"label\": \"Function 0x469B7E\",\n      \"type\": \"function\",\n      \"address\": \"0x469B7E\"\n    },\n    {\n      \"id\": \"func_0x46AFC6\",\n      \"label\": \"Function 0x46AFC6\",\n      \"type\": \"function\",\n      \"address\": \"0x46AFC6\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"QueryPerformanceCounter [B0001.033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_for_unmoving_mouse_cursor__2_matches_\",\n      \"label\": \"check for unmoving mouse cursor (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection::Human User\",\n        \"Check [B0009.012]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x499468\",\n      \"label\": \"Function 0x499468\",\n      \"type\": \"function\",\n      \"address\": \"0x499468\"\n    },\n    {\n      \"id\": \"func_0x498EBB\",\n      \"label\": \"Function 0x498EBB\",\n      \"type\": \"function\",\n      \"address\": \"0x498EBB\"\n    },\n    {\n      \"id\": \"cap_author______bitsofbinary\",\n      \"label\": \"author      BitsOfBinary\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection::Human User\",\n        \"Check [B0009.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes__9_matches_\",\n      \"label\": \"log keystrokes (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x462CEB\",\n      \"label\": \"Function 0x462CEB\",\n      \"type\": \"function\",\n      \"address\": \"0x462CEB\"\n    },\n    {\n      \"id\": \"func_0x46B04D\",\n      \"label\": \"Function 0x46B04D\",\n      \"type\": \"function\",\n      \"address\": \"0x46B04D\"\n    },\n    {\n      \"id\": \"func_0x4624E6\",\n      \"label\": \"Function 0x4624E6\",\n      \"type\": \"function\",\n      \"address\": \"0x4624E6\"\n    },\n    {\n      \"id\": \"func_0x4034CE\",\n      \"label\": \"Function 0x4034CE\",\n      \"type\": \"function\",\n      \"address\": \"0x4034CE\"\n    },\n    {\n      \"id\": \"func_0x41EFAD\",\n      \"label\": \"Function 0x41EFAD\",\n      \"type\": \"function\",\n      \"address\": \"0x41EFAD\"\n    },\n    {\n      \"id\": \"func_0x46A90B\",\n      \"label\": \"Function 0x46A90B\",\n      \"type\": \"function\",\n      \"address\": \"0x46A90B\"\n    },\n    {\n      \"id\": \"func_0x463985\",\n      \"label\": \"Function 0x463985\",\n      \"type\": \"function\",\n      \"address\": \"0x463985\"\n    },\n    {\n      \"id\": \"func_0x46B1FD\",\n      \"label\": \"Function 0x46B1FD\",\n      \"type\": \"function\",\n      \"address\": \"0x46B1FD\"\n    },\n    {\n      \"id\": \"func_0x46B198\",\n      \"label\": \"Function 0x46B198\",\n      \"type\": \"function\",\n      \"address\": \"0x46B198\"\n    },\n    {\n      \"id\": \"api_MapVirtualKey\",\n      \"label\": \"MapVirtualKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_AttachThreadInput\",\n      \"label\": \"AttachThreadInput\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"label\": \"log keystrokes via polling (11 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46ABF8\",\n      \"label\": \"Function 0x46ABF8\",\n      \"type\": \"function\",\n      \"address\": \"0x46ABF8\"\n    },\n    {\n      \"id\": \"func_0x469B97\",\n      \"label\": \"Function 0x469B97\",\n      \"type\": \"function\",\n      \"address\": \"0x469B97\"\n    },\n    {\n      \"id\": \"func_0x469EAF\",\n      \"label\": \"Function 0x469EAF\",\n      \"type\": \"function\",\n      \"address\": \"0x469EAF\"\n    },\n    {\n      \"id\": \"func_0x41EA9A\",\n      \"label\": \"Function 0x41EA9A\",\n      \"type\": \"function\",\n      \"address\": \"0x41EA9A\"\n    },\n    {\n      \"id\": \"func_0x46A975\",\n      \"label\": \"Function 0x46A975\",\n      \"type\": \"function\",\n      \"address\": \"0x46A975\"\n    },\n    {\n      \"id\": \"func_0x46ADD8\",\n      \"label\": \"Function 0x46ADD8\",\n      \"type\": \"function\",\n      \"address\": \"0x46ADD8\"\n    },\n    {\n      \"id\": \"func_0x4028C0\",\n      \"label\": \"Function 0x4028C0\",\n      \"type\": \"function\",\n      \"address\": \"0x4028C0\"\n    },\n    {\n      \"id\": \"func_0x46AABA\",\n      \"label\": \"Function 0x46AABA\",\n      \"type\": \"function\",\n      \"address\": \"0x46AABA\"\n    },\n    {\n      \"id\": \"api_GetAsyncKeyState\",\n      \"label\": \"GetAsyncKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetKeyState\",\n      \"label\": \"GetKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_VkKeyScan\",\n      \"label\": \"VkKeyScan\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetKeyboardState\",\n      \"label\": \"GetKeyboardState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_capture_screenshot\",\n      \"label\": \"capture screenshot\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x482483\",\n      \"label\": \"Function 0x482483\",\n      \"type\": \"function\",\n      \"address\": \"0x482483\"\n    },\n    {\n      \"id\": \"api_CreateCompatibleBitmap\",\n      \"label\": \"CreateCompatibleBitmap\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateCompatibleDC\",\n      \"label\": \"CreateCompatibleDC\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetDC\",\n      \"label\": \"GetDC\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetDIBits\",\n      \"label\": \"GetDIBits\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_remote_server_for_available_data\",\n      \"label\": \"query remote server for available data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x47CE38\",\n      \"label\": \"Block 0x47CE38\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x47CE38\"\n    },\n    {\n      \"id\": \"api_InternetQueryDataAvailable\",\n      \"label\": \"InternetQueryDataAvailable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_receive_data__4_matches_\",\n      \"label\": \"receive data (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x481B87\",\n      \"label\": \"Function 0x481B87\",\n      \"type\": \"function\",\n      \"address\": \"0x481B87\"\n    },\n    {\n      \"id\": \"func_0x47CE38\",\n      \"label\": \"Function 0x47CE38\",\n      \"type\": \"function\",\n      \"address\": \"0x47CE38\"\n    },\n    {\n      \"id\": \"func_0x48135A\",\n      \"label\": \"Function 0x48135A\",\n      \"type\": \"function\",\n      \"address\": \"0x48135A\"\n    },\n    {\n      \"id\": \"func_0x47CD62\",\n      \"label\": \"Function 0x47CD62\",\n      \"type\": \"function\",\n      \"address\": \"0x47CD62\"\n    },\n    {\n      \"id\": \"api_recvfrom\",\n      \"label\": \"recvfrom\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"api_InternetReadFile\",\n      \"label\": \"InternetReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_recv\",\n      \"label\": \"recv\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data__3_matches_\",\n      \"label\": \"send data (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4814F1\",\n      \"label\": \"Function 0x4814F1\",\n      \"type\": \"function\",\n      \"address\": \"0x4814F1\"\n    },\n    {\n      \"id\": \"func_0x481F24\",\n      \"label\": \"Function 0x481F24\",\n      \"type\": \"function\",\n      \"address\": \"0x481F24\"\n    },\n    {\n      \"id\": \"func_0x47C394\",\n      \"label\": \"Function 0x47C394\",\n      \"type\": \"function\",\n      \"address\": \"0x47C394\"\n    },\n    {\n      \"id\": \"api_sendto\",\n      \"label\": \"sendto\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"api_send\",\n      \"label\": \"send\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"api_HttpSendRequest\",\n      \"label\": \"HttpSendRequest\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"api_InternetConnect\",\n      \"label\": \"InternetConnect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_HttpOpenRequest\",\n      \"label\": \"HttpOpenRequest\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_download_and_write_a_file\",\n      \"label\": \"download and write a file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"downloader\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Server to Client\",\n        \"File Transfer [B0030.003]\"\n      ]\n    },\n    {\n      \"id\": \"api__fwrite\",\n      \"label\": \"_fwrite\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_fwrite\",\n      \"label\": \"fwrite\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_maec_malware_category__downloader\",\n      \"label\": \"maec/malware-category  downloader\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"downloader\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Server to Client\",\n        \"File Transfer [B0030.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_and_write_data_from_server_to_client\",\n      \"label\": \"receive and write data from server to client\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_resolve_dns__3_matches_\",\n      \"label\": \"resolve DNS (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::DNS Communication::Resolve [C0011.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46DD45\",\n      \"label\": \"Function 0x46DD45\",\n      \"type\": \"function\",\n      \"address\": \"0x46DD45\"\n    },\n    {\n      \"id\": \"func_0x481288\",\n      \"label\": \"Function 0x481288\",\n      \"type\": \"function\",\n      \"address\": \"0x481288\"\n    },\n    {\n      \"id\": \"func_0x480482\",\n      \"label\": \"Function 0x480482\",\n      \"type\": \"function\",\n      \"address\": \"0x480482\"\n    },\n    {\n      \"id\": \"api_gethostbyname\",\n      \"label\": \"gethostbyname\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::DNS Communication::Resolve [C0011.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_network_resource\",\n      \"label\": \"connect network resource\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x4605C7\",\n      \"label\": \"Function 0x4605C7\",\n      \"type\": \"function\",\n      \"address\": \"0x4605C7\"\n    },\n    {\n      \"id\": \"api_WNetAddConnection2\",\n      \"label\": \"WNetAddConnection2\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"label\": \"author       michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_parse_url\",\n      \"label\": \"parse URL\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x47D012\",\n      \"label\": \"Block 0x47D012\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x47D012\"\n    },\n    {\n      \"id\": \"api_InternetCrackUrl\",\n      \"label\": \"InternetCrackUrl\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_connect_to_http_server__2_matches_\",\n      \"label\": \"connect to HTTP server (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Connect to Server [C0002.009]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47C061\",\n      \"label\": \"Function 0x47C061\",\n      \"type\": \"function\",\n      \"address\": \"0x47C061\"\n    },\n    {\n      \"id\": \"cap_connect_to_url\",\n      \"label\": \"connect to URL\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Open URL [C0002.004]\"\n      ]\n    },\n    {\n      \"id\": \"api_InternetOpenUrl\",\n      \"label\": \"InternetOpenUrl\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_create_http_request\",\n      \"label\": \"create HTTP request\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47CC3C\",\n      \"label\": \"Function 0x47CC3C\",\n      \"type\": \"function\",\n      \"address\": \"0x47CC3C\"\n    },\n    {\n      \"id\": \"api_InternetOpen\",\n      \"label\": \"InternetOpen\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_data_from_internet__2_matches_\",\n      \"label\": \"read data from Internet (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_http_request\",\n      \"label\": \"send HTTP request\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Send Request [C0002.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Send Request [C0002.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_icmp_echo_request\",\n      \"label\": \"send ICMP echo request\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::ICMP Communication::Echo Request [C0014.002]\"\n      ]\n    },\n    {\n      \"id\": \"api_IcmpCloseHandle\",\n      \"label\": \"IcmpCloseHandle\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_IcmpSendEcho\",\n      \"label\": \"IcmpSendEcho\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_IcmpCreateFile\",\n      \"label\": \"IcmpCreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::ICMP Communication::Echo Request [C0014.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_pipe__2_matches_\",\n      \"label\": \"create pipe (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Interprocess Communication::Create Pipe [C0003.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4703F0\",\n      \"label\": \"Function 0x4703F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4703F0\"\n    },\n    {\n      \"id\": \"func_0x4704C5\",\n      \"label\": \"Function 0x4704C5\",\n      \"type\": \"function\",\n      \"address\": \"0x4704C5\"\n    },\n    {\n      \"id\": \"api_CreatePipe\",\n      \"label\": \"CreatePipe\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_connect_socket\",\n      \"label\": \"connect socket\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x4810AF\",\n      \"label\": \"Block 0x4810AF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4810AF\"\n    },\n    {\n      \"id\": \"api_connect\",\n      \"label\": \"connect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_mrhafizfarhad_gmail_com\",\n      \"label\": \"mrhafizfarhad@gmail.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_socket_status\",\n      \"label\": \"get socket status\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Get Socket Status [C0001.012]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x483070\",\n      \"label\": \"Function 0x483070\",\n      \"type\": \"function\",\n      \"address\": \"0x483070\"\n    },\n    {\n      \"id\": \"api_select\",\n      \"label\": \"select\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_initialize_winsock_library__3_matches_\",\n      \"label\": \"initialize Winsock library (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Initialize Winsock Library\",\n        \"[C0001.009]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4815DA\",\n      \"label\": \"Function 0x4815DA\",\n      \"type\": \"function\",\n      \"address\": \"0x4815DA\"\n    },\n    {\n      \"id\": \"api_WSAStartup\",\n      \"label\": \"WSAStartup\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_socket_configuration__3_matches_\",\n      \"label\": \"set socket configuration (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Set Socket Config [C0001.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x482F75\",\n      \"label\": \"Function 0x482F75\",\n      \"type\": \"function\",\n      \"address\": \"0x482F75\"\n    },\n    {\n      \"id\": \"func_0x4819FD\",\n      \"label\": \"Function 0x4819FD\",\n      \"type\": \"function\",\n      \"address\": \"0x4819FD\"\n    },\n    {\n      \"id\": \"api_setsockopt\",\n      \"label\": \"setsockopt\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_ioctlsocket\",\n      \"label\": \"ioctlsocket\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_receive_data_on_socket__2_matches_\",\n      \"label\": \"receive data on socket (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Receive Data [C0001.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data_on_socket__2_matches_\",\n      \"label\": \"send data on socket (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_tcp_socket\",\n      \"label\": \"connect TCP socket\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Connect Socket [C0001.004]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x480FDF\",\n      \"label\": \"Function 0x480FDF\",\n      \"type\": \"function\",\n      \"address\": \"0x480FDF\"\n    },\n    {\n      \"id\": \"api_socket\",\n      \"label\": \"socket\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_tcp_socket__2_matches_\",\n      \"label\": \"create TCP socket (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x481197\",\n      \"label\": \"Block 0x481197\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x481197\"\n    },\n    {\n      \"id\": \"bb_0x481033\",\n      \"label\": \"Block 0x481033\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x481033\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_udp_socket__2_matches_\",\n      \"label\": \"create UDP socket (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create UDP Socket [C0001.010]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4819FD\",\n      \"label\": \"Block 0x4819FD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4819FD\"\n    },\n    {\n      \"id\": \"bb_0x48177E\",\n      \"label\": \"Block 0x48177E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x48177E\"\n    },\n    {\n      \"id\": \"cap_act_as_tcp_client\",\n      \"label\": \"act as TCP client\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_compiled_with_autoit\",\n      \"label\": \"compiled with AutoIt\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [T1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [T1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_with_crc32\",\n      \"label\": \"hash data with CRC32\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4823E8\",\n      \"label\": \"Function 0x4823E8\",\n      \"type\": \"function\",\n      \"address\": \"0x4823E8\"\n    },\n    {\n      \"id\": \"cap_encode_data_using_base64\",\n      \"label\": \"encode data using Base64\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x41BEAD\",\n      \"label\": \"Function 0x41BEAD\",\n      \"type\": \"function\",\n      \"address\": \"0x41BEAD\"\n    },\n    {\n      \"id\": \"cap_hash_data_using_djb2\",\n      \"label\": \"hash data using djb2\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::djb2 [C0030.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408273\",\n      \"label\": \"Function 0x408273\",\n      \"type\": \"function\",\n      \"address\": \"0x408273\"\n    },\n    {\n      \"id\": \"cap_author______awillia2_cisco_com__still_teamt5_org\",\n      \"label\": \"author      awillia2@cisco.com, still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::djb2 [C0030.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_authenticate_hmac\",\n      \"label\": \"authenticate HMAC\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Hashed Message Authentication Code [C0061]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Hashed Message Authentication Code [C0061]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"label\": \"generate random numbers using a Mersenne Twister (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence [C0021]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x471E7A\",\n      \"label\": \"Function 0x471E7A\",\n      \"type\": \"function\",\n      \"address\": \"0x471E7A\"\n    },\n    {\n      \"id\": \"func_0x471EC0\",\n      \"label\": \"Function 0x471EC0\",\n      \"type\": \"function\",\n      \"address\": \"0x471EC0\"\n    },\n    {\n      \"id\": \"func_0x471F64\",\n      \"label\": \"Function 0x471F64\",\n      \"type\": \"function\",\n      \"address\": \"0x471F64\"\n    },\n    {\n      \"id\": \"func_0x471F24\",\n      \"label\": \"Function 0x471F24\",\n      \"type\": \"function\",\n      \"address\": \"0x471F24\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x406122\",\n      \"label\": \"Function 0x406122\",\n      \"type\": \"function\",\n      \"address\": \"0x406122\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResourceEx\",\n      \"label\": \"FindResourceEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_list_drag_and_drop_files\",\n      \"label\": \"list drag and drop files\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47EA26\",\n      \"label\": \"Function 0x47EA26\",\n      \"type\": \"function\",\n      \"address\": \"0x47EA26\"\n    },\n    {\n      \"id\": \"api_DragQueryFile\",\n      \"label\": \"DragQueryFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetClipboardData\",\n      \"label\": \"GetClipboardData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_open_clipboard__2_matches_\",\n      \"label\": \"open clipboard (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47EC91\",\n      \"label\": \"Function 0x47EC91\",\n      \"type\": \"function\",\n      \"address\": \"0x47EC91\"\n    },\n    {\n      \"id\": \"api_CloseClipboard\",\n      \"label\": \"CloseClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_OpenClipboard\",\n      \"label\": \"OpenClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_clipboard_data\",\n      \"label\": \"read clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"api_GlobalLock\",\n      \"label\": \"GlobalLock\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GlobalUnlock\",\n      \"label\": \"GlobalUnlock\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_clipboard_data\",\n      \"label\": \"write clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"api_EmptyClipboard\",\n      \"label\": \"EmptyClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SetClipboardData\",\n      \"label\": \"SetClipboardData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_interact_with_driver_via_ioctl__4_matches_\",\n      \"label\": \"interact with driver via IOCTL (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_DeviceIoControl\",\n      \"label\": \"DeviceIoControl\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_comspec_environment_variable\",\n      \"label\": \"get COMSPEC environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable [C0034]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x41D70E\",\n      \"label\": \"Function 0x41D70E\",\n      \"type\": \"function\",\n      \"address\": \"0x41D70E\"\n    },\n    {\n      \"id\": \"api_GetEnvironmentVariable\",\n      \"label\": \"GetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"label\": \"author     matthew.williams@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable [C0034]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable__3_matches_\",\n      \"label\": \"query environment variable (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47EE14\",\n      \"label\": \"Function 0x47EE14\",\n      \"type\": \"function\",\n      \"address\": \"0x47EE14\"\n    },\n    {\n      \"id\": \"func_0x487559\",\n      \"label\": \"Function 0x487559\",\n      \"type\": \"function\",\n      \"address\": \"0x487559\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_environment_variable__2_matches_\",\n      \"label\": \"set environment variable (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable::Set Variable [C0034.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x43D170\",\n      \"label\": \"Function 0x43D170\",\n      \"type\": \"function\",\n      \"address\": \"0x43D170\"\n    },\n    {\n      \"id\": \"func_0x47EE84\",\n      \"label\": \"Function 0x47EE84\",\n      \"type\": \"function\",\n      \"address\": \"0x47EE84\"\n    },\n    {\n      \"id\": \"api_SetEnvironmentVariable\",\n      \"label\": \"SetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__9_matches_\",\n      \"label\": \"get common file path (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46DE45\",\n      \"label\": \"Function 0x46DE45\",\n      \"type\": \"function\",\n      \"address\": \"0x46DE45\"\n    },\n    {\n      \"id\": \"func_0x472F35\",\n      \"label\": \"Function 0x472F35\",\n      \"type\": \"function\",\n      \"address\": \"0x472F35\"\n    },\n    {\n      \"id\": \"func_0x40445D\",\n      \"label\": \"Function 0x40445D\",\n      \"type\": \"function\",\n      \"address\": \"0x40445D\"\n    },\n    {\n      \"id\": \"func_0x4779B4\",\n      \"label\": \"Function 0x4779B4\",\n      \"type\": \"function\",\n      \"address\": \"0x4779B4\"\n    },\n    {\n      \"id\": \"func_0x477D0E\",\n      \"label\": \"Function 0x477D0E\",\n      \"type\": \"function\",\n      \"address\": \"0x477D0E\"\n    },\n    {\n      \"id\": \"func_0x48AF20\",\n      \"label\": \"Function 0x48AF20\",\n      \"type\": \"function\",\n      \"address\": \"0x48AF20\"\n    },\n    {\n      \"id\": \"func_0x41F962\",\n      \"label\": \"Function 0x41F962\",\n      \"type\": \"function\",\n      \"address\": \"0x41F962\"\n    },\n    {\n      \"id\": \"func_0x4780B3\",\n      \"label\": \"Function 0x4780B3\",\n      \"type\": \"function\",\n      \"address\": \"0x4780B3\"\n    },\n    {\n      \"id\": \"api_SHGetSpecialFolderLocation\",\n      \"label\": \"SHGetSpecialFolderLocation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHGetFolderPath\",\n      \"label\": \"SHGetFolderPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetCurrentDirectory\",\n      \"label\": \"GetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempFileName\",\n      \"label\": \"GetTempFileName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_current_directory__7_matches_\",\n      \"label\": \"set current directory (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x40AD7C\",\n      \"label\": \"Function 0x40AD7C\",\n      \"type\": \"function\",\n      \"address\": \"0x40AD7C\"\n    },\n    {\n      \"id\": \"func_0x479560\",\n      \"label\": \"Function 0x479560\",\n      \"type\": \"function\",\n      \"address\": \"0x479560\"\n    },\n    {\n      \"id\": \"func_0x4753D4\",\n      \"label\": \"Function 0x4753D4\",\n      \"type\": \"function\",\n      \"address\": \"0x4753D4\"\n    },\n    {\n      \"id\": \"func_0x4796BB\",\n      \"label\": \"Function 0x4796BB\",\n      \"type\": \"function\",\n      \"address\": \"0x4796BB\"\n    },\n    {\n      \"id\": \"api_SetCurrentDirectory\",\n      \"label\": \"SetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_copy_file__3_matches_\",\n      \"label\": \"copy file (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x472865\",\n      \"label\": \"Function 0x472865\",\n      \"type\": \"function\",\n      \"address\": \"0x472865\"\n    },\n    {\n      \"id\": \"func_0x46D1BA\",\n      \"label\": \"Function 0x46D1BA\",\n      \"type\": \"function\",\n      \"address\": \"0x46D1BA\"\n    },\n    {\n      \"id\": \"func_0x46CE1E\",\n      \"label\": \"Function 0x46CE1E\",\n      \"type\": \"function\",\n      \"address\": \"0x46CE1E\"\n    },\n    {\n      \"id\": \"api_CopyFileEx\",\n      \"label\": \"CopyFileEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHFileOperation\",\n      \"label\": \"SHFileOperation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CopyFile\",\n      \"label\": \"CopyFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_directory__2_matches_\",\n      \"label\": \"create directory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46D1DF\",\n      \"label\": \"Function 0x46D1DF\",\n      \"type\": \"function\",\n      \"address\": \"0x46D1DF\"\n    },\n    {\n      \"id\": \"func_0x473C3C\",\n      \"label\": \"Function 0x473C3C\",\n      \"type\": \"function\",\n      \"address\": \"0x473C3C\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_delete_directory__2_matches_\",\n      \"label\": \"delete directory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46E77B\",\n      \"label\": \"Function 0x46E77B\",\n      \"type\": \"function\",\n      \"address\": \"0x46E77B\"\n    },\n    {\n      \"id\": \"api_RemoveDirectory\",\n      \"label\": \"RemoveDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_file__6_matches_\",\n      \"label\": \"delete file (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46CF94\",\n      \"label\": \"Function 0x46CF94\",\n      \"type\": \"function\",\n      \"address\": \"0x46CF94\"\n    },\n    {\n      \"id\": \"func_0x4778BA\",\n      \"label\": \"Function 0x4778BA\",\n      \"type\": \"function\",\n      \"address\": \"0x4778BA\"\n    },\n    {\n      \"id\": \"func_0x46D2C7\",\n      \"label\": \"Function 0x46D2C7\",\n      \"type\": \"function\",\n      \"address\": \"0x46D2C7\"\n    },\n    {\n      \"id\": \"func_0x4755F7\",\n      \"label\": \"Function 0x4755F7\",\n      \"type\": \"function\",\n      \"address\": \"0x4755F7\"\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__3_matches_\",\n      \"label\": \"check if file exists (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46E0B7\",\n      \"label\": \"Function 0x46E0B7\",\n      \"type\": \"function\",\n      \"address\": \"0x46E0B7\"\n    },\n    {\n      \"id\": \"func_0x46DADC\",\n      \"label\": \"Function 0x46DADC\",\n      \"type\": \"function\",\n      \"address\": \"0x46DADC\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_GetLastError\",\n      \"label\": \"GetLastError\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"label\": \"enumerate files on Windows (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x479A49\",\n      \"label\": \"Function 0x479A49\",\n      \"type\": \"function\",\n      \"address\": \"0x479A49\"\n    },\n    {\n      \"id\": \"func_0x475BB5\",\n      \"label\": \"Function 0x475BB5\",\n      \"type\": \"function\",\n      \"address\": \"0x475BB5\"\n    },\n    {\n      \"id\": \"api_FindClose\",\n      \"label\": \"FindClose\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindNextFile\",\n      \"label\": \"FindNextFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindFirstFile\",\n      \"label\": \"FindFirstFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_recursively__3_matches_\",\n      \"label\": \"enumerate files recursively (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     @_re_fox, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes__5_matches_\",\n      \"label\": \"get file attributes (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x477F04\",\n      \"label\": \"Block 0x477F04\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x477F04\"\n    },\n    {\n      \"id\": \"bb_0x46D1DF\",\n      \"label\": \"Block 0x46D1DF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46D1DF\"\n    },\n    {\n      \"id\": \"bb_0x46E0B7\",\n      \"label\": \"Block 0x46E0B7\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46E0B7\"\n    },\n    {\n      \"id\": \"bb_0x46DAFA\",\n      \"label\": \"Block 0x46DAFA\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46DAFA\"\n    },\n    {\n      \"id\": \"bb_0x4795B8\",\n      \"label\": \"Block 0x4795B8\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4795B8\"\n    },\n    {\n      \"id\": \"cap_get_file_size__2_matches_\",\n      \"label\": \"get file size (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x482A05\",\n      \"label\": \"Function 0x482A05\",\n      \"type\": \"function\",\n      \"address\": \"0x482A05\"\n    },\n    {\n      \"id\": \"func_0x498461\",\n      \"label\": \"Function 0x498461\",\n      \"type\": \"function\",\n      \"address\": \"0x498461\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_file_version_info\",\n      \"label\": \"get file version info\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46DB2C\",\n      \"label\": \"Function 0x46DB2C\",\n      \"type\": \"function\",\n      \"address\": \"0x46DB2C\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfoSize\",\n      \"label\": \"GetFileVersionInfoSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_VerQueryValue\",\n      \"label\": \"VerQueryValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfo\",\n      \"label\": \"GetFileVersionInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_file_attributes__2_matches_\",\n      \"label\": \"set file attributes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"api_SetFileAttributes\",\n      \"label\": \"SetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_move_file__3_matches_\",\n      \"label\": \"move file (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46E319\",\n      \"label\": \"Function 0x46E319\",\n      \"type\": \"function\",\n      \"address\": \"0x46E319\"\n    },\n    {\n      \"id\": \"api_MoveFile\",\n      \"label\": \"MoveFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read__ini_file__4_matches_\",\n      \"label\": \"read .ini file (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x478A19\",\n      \"label\": \"Function 0x478A19\",\n      \"type\": \"function\",\n      \"address\": \"0x478A19\"\n    },\n    {\n      \"id\": \"func_0x4783FD\",\n      \"label\": \"Function 0x4783FD\",\n      \"type\": \"function\",\n      \"address\": \"0x4783FD\"\n    },\n    {\n      \"id\": \"func_0x4787FC\",\n      \"label\": \"Function 0x4787FC\",\n      \"type\": \"function\",\n      \"address\": \"0x4787FC\"\n    },\n    {\n      \"id\": \"func_0x4784BF\",\n      \"label\": \"Function 0x4784BF\",\n      \"type\": \"function\",\n      \"address\": \"0x4784BF\"\n    },\n    {\n      \"id\": \"api_GetPrivateProfileString\",\n      \"label\": \"GetPrivateProfileString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetPrivateProfileSectionNames\",\n      \"label\": \"GetPrivateProfileSectionNames\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetPrivateProfileSection\",\n      \"label\": \"GetPrivateProfileSection\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__9_matches_\",\n      \"label\": \"read file on Windows (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x43921B\",\n      \"label\": \"Function 0x43921B\",\n      \"type\": \"function\",\n      \"address\": \"0x43921B\"\n    },\n    {\n      \"id\": \"func_0x472475\",\n      \"label\": \"Function 0x472475\",\n      \"type\": \"function\",\n      \"address\": \"0x472475\"\n    },\n    {\n      \"id\": \"func_0x47070D\",\n      \"label\": \"Function 0x47070D\",\n      \"type\": \"function\",\n      \"address\": \"0x47070D\"\n    },\n    {\n      \"id\": \"func_0x4725B1\",\n      \"label\": \"Function 0x4725B1\",\n      \"type\": \"function\",\n      \"address\": \"0x4725B1\"\n    },\n    {\n      \"id\": \"func_0x40B230\",\n      \"label\": \"Function 0x40B230\",\n      \"type\": \"function\",\n      \"address\": \"0x40B230\"\n    },\n    {\n      \"id\": \"func_0x40B3B0\",\n      \"label\": \"Function 0x40B3B0\",\n      \"type\": \"function\",\n      \"address\": \"0x40B3B0\"\n    },\n    {\n      \"id\": \"func_0x406A95\",\n      \"label\": \"Function 0x406A95\",\n      \"type\": \"function\",\n      \"address\": \"0x406A95\"\n    },\n    {\n      \"id\": \"api__read\",\n      \"label\": \"_read\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_fread\",\n      \"label\": \"fread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_clear_file_content\",\n      \"label\": \"clear file content\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x477FD5\",\n      \"label\": \"Function 0x477FD5\",\n      \"type\": \"function\",\n      \"address\": \"0x477FD5\"\n    },\n    {\n      \"id\": \"api_SetEndOfFile\",\n      \"label\": \"SetEndOfFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SetFilePointer\",\n      \"label\": \"SetFilePointer\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____jakeperalta7\",\n      \"label\": \"author     jakeperalta7\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__7_matches_\",\n      \"label\": \"write file on Windows (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x41F5B3\",\n      \"label\": \"Function 0x41F5B3\",\n      \"type\": \"function\",\n      \"address\": \"0x41F5B3\"\n    },\n    {\n      \"id\": \"func_0x472642\",\n      \"label\": \"Function 0x472642\",\n      \"type\": \"function\",\n      \"address\": \"0x472642\"\n    },\n    {\n      \"id\": \"func_0x4725F5\",\n      \"label\": \"Function 0x4725F5\",\n      \"type\": \"function\",\n      \"address\": \"0x4725F5\"\n    },\n    {\n      \"id\": \"func_0x470633\",\n      \"label\": \"Function 0x470633\",\n      \"type\": \"function\",\n      \"address\": \"0x470633\"\n    },\n    {\n      \"id\": \"func_0x46CC1D\",\n      \"label\": \"Function 0x46CC1D\",\n      \"type\": \"function\",\n      \"address\": \"0x46CC1D\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_gui_resources\",\n      \"label\": \"enumerate gui resources\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x464144\",\n      \"label\": \"Function 0x464144\",\n      \"type\": \"function\",\n      \"address\": \"0x464144\"\n    },\n    {\n      \"id\": \"api_EnumWindows\",\n      \"label\": \"EnumWindows\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     johnk3r, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_taskbar__3_matches_\",\n      \"label\": \"find taskbar (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Taskbar Discovery [B0043]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x492255\",\n      \"label\": \"Block 0x492255\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x492255\"\n    },\n    {\n      \"id\": \"bb_0x492289\",\n      \"label\": \"Block 0x492289\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x492289\"\n    },\n    {\n      \"id\": \"bb_0x41EFCE\",\n      \"label\": \"Block 0x41EFCE\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x41EFCE\"\n    },\n    {\n      \"id\": \"api_FindWindow\",\n      \"label\": \"FindWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_find_graphical_window__4_matches_\",\n      \"label\": \"find graphical window (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindWindowEx\",\n      \"label\": \"FindWindowEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_graphical_window_text__11_matches_\",\n      \"label\": \"get graphical window text (11 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x464BD3\",\n      \"label\": \"Function 0x464BD3\",\n      \"type\": \"function\",\n      \"address\": \"0x464BD3\"\n    },\n    {\n      \"id\": \"func_0x47E8F7\",\n      \"label\": \"Function 0x47E8F7\",\n      \"type\": \"function\",\n      \"address\": \"0x47E8F7\"\n    },\n    {\n      \"id\": \"func_0x461A70\",\n      \"label\": \"Function 0x461A70\",\n      \"type\": \"function\",\n      \"address\": \"0x461A70\"\n    },\n    {\n      \"id\": \"func_0x496FA4\",\n      \"label\": \"Function 0x496FA4\",\n      \"type\": \"function\",\n      \"address\": \"0x496FA4\"\n    },\n    {\n      \"id\": \"func_0x465B9A\",\n      \"label\": \"Function 0x465B9A\",\n      \"type\": \"function\",\n      \"address\": \"0x465B9A\"\n    },\n    {\n      \"id\": \"func_0x46359E\",\n      \"label\": \"Function 0x46359E\",\n      \"type\": \"function\",\n      \"address\": \"0x46359E\"\n    },\n    {\n      \"id\": \"func_0x4947A8\",\n      \"label\": \"Function 0x4947A8\",\n      \"type\": \"function\",\n      \"address\": \"0x4947A8\"\n    },\n    {\n      \"id\": \"func_0x46489C\",\n      \"label\": \"Function 0x46489C\",\n      \"type\": \"function\",\n      \"address\": \"0x46489C\"\n    },\n    {\n      \"id\": \"func_0x463B0C\",\n      \"label\": \"Function 0x463B0C\",\n      \"type\": \"function\",\n      \"address\": \"0x463B0C\"\n    },\n    {\n      \"id\": \"func_0x4972B7\",\n      \"label\": \"Function 0x4972B7\",\n      \"type\": \"function\",\n      \"address\": \"0x4972B7\"\n    },\n    {\n      \"id\": \"func_0x491E0D\",\n      \"label\": \"Function 0x491E0D\",\n      \"type\": \"function\",\n      \"address\": \"0x491E0D\"\n    },\n    {\n      \"id\": \"api_SendMessage\",\n      \"label\": \"SendMessage\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetWindowText\",\n      \"label\": \"GetWindowText\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_IsWindowVisible\",\n      \"label\": \"IsWindowVisible\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_hide_graphical_window__8_matches_\",\n      \"label\": \"hide graphical window (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4981BF\",\n      \"label\": \"Block 0x4981BF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4981BF\"\n    },\n    {\n      \"id\": \"bb_0x4827C2\",\n      \"label\": \"Block 0x4827C2\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4827C2\"\n    },\n    {\n      \"id\": \"bb_0x4950F2\",\n      \"label\": \"Block 0x4950F2\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4950F2\"\n    },\n    {\n      \"id\": \"bb_0x49015D\",\n      \"label\": \"Block 0x49015D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x49015D\"\n    },\n    {\n      \"id\": \"bb_0x45F0F9\",\n      \"label\": \"Block 0x45F0F9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x45F0F9\"\n    },\n    {\n      \"id\": \"bb_0x496B61\",\n      \"label\": \"Block 0x496B61\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x496B61\"\n    },\n    {\n      \"id\": \"bb_0x49A198\",\n      \"label\": \"Block 0x49A198\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x49A198\"\n    },\n    {\n      \"id\": \"bb_0x49813A\",\n      \"label\": \"Block 0x49813A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x49813A\"\n    },\n    {\n      \"id\": \"api_ShowWindow\",\n      \"label\": \"ShowWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_keyboard_layout\",\n      \"label\": \"get keyboard layout\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery::System Language Discovery\",\n        \"[T1614.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetKeyboardLayoutName\",\n      \"label\": \"GetKeyboardLayoutName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_memory_capacity\",\n      \"label\": \"get memory capacity\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x41F370\",\n      \"label\": \"Function 0x41F370\",\n      \"type\": \"function\",\n      \"address\": \"0x41F370\"\n    },\n    {\n      \"id\": \"api_GlobalMemoryStatusEx\",\n      \"label\": \"GlobalMemoryStatusEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_information__6_matches_\",\n      \"label\": \"get disk information (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x474844\",\n      \"label\": \"Function 0x474844\",\n      \"type\": \"function\",\n      \"address\": \"0x474844\"\n    },\n    {\n      \"id\": \"func_0x4749FD\",\n      \"label\": \"Function 0x4749FD\",\n      \"type\": \"function\",\n      \"address\": \"0x4749FD\"\n    },\n    {\n      \"id\": \"func_0x474912\",\n      \"label\": \"Function 0x474912\",\n      \"type\": \"function\",\n      \"address\": \"0x474912\"\n    },\n    {\n      \"id\": \"func_0x4743DE\",\n      \"label\": \"Function 0x4743DE\",\n      \"type\": \"function\",\n      \"address\": \"0x4743DE\"\n    },\n    {\n      \"id\": \"func_0x474776\",\n      \"label\": \"Function 0x474776\",\n      \"type\": \"function\",\n      \"address\": \"0x474776\"\n    },\n    {\n      \"id\": \"func_0x473D97\",\n      \"label\": \"Function 0x473D97\",\n      \"type\": \"function\",\n      \"address\": \"0x473D97\"\n    },\n    {\n      \"id\": \"api_GetDriveType\",\n      \"label\": \"GetDriveType\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetVolumeInformation\",\n      \"label\": \"GetVolumeInformation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_size__3_matches_\",\n      \"label\": \"get disk size (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4750EB\",\n      \"label\": \"Function 0x4750EB\",\n      \"type\": \"function\",\n      \"address\": \"0x4750EB\"\n    },\n    {\n      \"id\": \"func_0x4751CE\",\n      \"label\": \"Function 0x4751CE\",\n      \"type\": \"function\",\n      \"address\": \"0x4751CE\"\n    },\n    {\n      \"id\": \"func_0x4752B1\",\n      \"label\": \"Function 0x4752B1\",\n      \"type\": \"function\",\n      \"address\": \"0x4752B1\"\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpace\",\n      \"label\": \"GetDiskFreeSpace\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpaceEx\",\n      \"label\": \"GetDiskFreeSpaceEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_storage_device_properties__2_matches_\",\n      \"label\": \"get storage device properties (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x46D588\",\n      \"label\": \"Function 0x46D588\",\n      \"type\": \"function\",\n      \"address\": \"0x46D588\"\n    },\n    {\n      \"id\": \"func_0x46D509\",\n      \"label\": \"Function 0x46D509\",\n      \"type\": \"function\",\n      \"address\": \"0x46D509\"\n    },\n    {\n      \"id\": \"cap_print_debug_messages\",\n      \"label\": \"print debug messages\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_OutputDebugString\",\n      \"label\": \"OutputDebugString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_shutdown_system\",\n      \"label\": \"shutdown system\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::System Shutdown/Reboot [T1529]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46E814\",\n      \"label\": \"Function 0x46E814\",\n      \"type\": \"function\",\n      \"address\": \"0x46E814\"\n    },\n    {\n      \"id\": \"api_ExitWindowsEx\",\n      \"label\": \"ExitWindowsEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_InitiateSystemShutdownEx\",\n      \"label\": \"InitiateSystemShutdownEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_hostname__2_matches_\",\n      \"label\": \"get hostname (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetComputerName\",\n      \"label\": \"GetComputerName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_gethostname\",\n      \"label\": \"gethostname\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_system_information_on_windows\",\n      \"label\": \"get system information on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40615E\",\n      \"label\": \"Function 0x40615E\",\n      \"type\": \"function\",\n      \"address\": \"0x40615E\"\n    },\n    {\n      \"id\": \"api_GetSystemInfo\",\n      \"label\": \"GetSystemInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__6_matches_\",\n      \"label\": \"create process on Windows (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x498064\",\n      \"label\": \"Block 0x498064\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x498064\"\n    },\n    {\n      \"id\": \"bb_0x4437E0\",\n      \"label\": \"Block 0x4437E0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4437E0\"\n    },\n    {\n      \"id\": \"bb_0x461472\",\n      \"label\": \"Block 0x461472\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x461472\"\n    },\n    {\n      \"id\": \"bb_0x48B2C1\",\n      \"label\": \"Block 0x48B2C1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x48B2C1\"\n    },\n    {\n      \"id\": \"bb_0x46134A\",\n      \"label\": \"Block 0x46134A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46134A\"\n    },\n    {\n      \"id\": \"bb_0x48AD7A\",\n      \"label\": \"Block 0x48AD7A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x48AD7A\"\n    },\n    {\n      \"id\": \"api_ShellExecuteEx\",\n      \"label\": \"ShellExecuteEx\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_CreateProcessWithLogon\",\n      \"label\": \"CreateProcessWithLogon\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_CreateProcessAsUser\",\n      \"label\": \"CreateProcessAsUser\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_ShellExecute\",\n      \"label\": \"ShellExecute\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_allocate_or_change_rwx_memory\",\n      \"label\": \"allocate or change RWX memory\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x489881\",\n      \"label\": \"Block 0x489881\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x489881\"\n    },\n    {\n      \"id\": \"api_VirtualAlloc\",\n      \"label\": \"VirtualAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"label\": \"author     @mr-tz, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_processes__2_matches_\",\n      \"label\": \"enumerate processes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\",\n        \"Discovery::Software Discovery\",\n        \"[T1518]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46D3FA\",\n      \"label\": \"Function 0x46D3FA\",\n      \"type\": \"function\",\n      \"address\": \"0x46D3FA\"\n    },\n    {\n      \"id\": \"func_0x48A5A3\",\n      \"label\": \"Function 0x48A5A3\",\n      \"type\": \"function\",\n      \"address\": \"0x48A5A3\"\n    },\n    {\n      \"id\": \"api_Process32First\",\n      \"label\": \"Process32First\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_Process32Next\",\n      \"label\": \"Process32Next\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateToolhelp32Snapshot\",\n      \"label\": \"CreateToolhelp32Snapshot\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_acquire_debug_privileges\",\n      \"label\": \"acquire debug privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x48A0B6\",\n      \"label\": \"Block 0x48A0B6\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x48A0B6\"\n    },\n    {\n      \"id\": \"cap_modify_access_privileges__2_matches_\",\n      \"label\": \"modify access privileges (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"api_AdjustTokenPrivileges\",\n      \"label\": \"AdjustTokenPrivileges\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_terminate_process__3_matches_\",\n      \"label\": \"terminate process (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x487E80\",\n      \"label\": \"Function 0x487E80\",\n      \"type\": \"function\",\n      \"address\": \"0x487E80\"\n    },\n    {\n      \"id\": \"func_0x46EA3E\",\n      \"label\": \"Function 0x46EA3E\",\n      \"type\": \"function\",\n      \"address\": \"0x46EA3E\"\n    },\n    {\n      \"id\": \"func_0x48A009\",\n      \"label\": \"Function 0x48A009\",\n      \"type\": \"function\",\n      \"address\": \"0x48A009\"\n    },\n    {\n      \"id\": \"api_TerminateProcess\",\n      \"label\": \"TerminateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_empty_the_recycle_bin\",\n      \"label\": \"empty the recycle bin\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x477953\",\n      \"label\": \"Function 0x477953\",\n      \"type\": \"function\",\n      \"address\": \"0x477953\"\n    },\n    {\n      \"id\": \"api_SHEmptyRecycleBin\",\n      \"label\": \"SHEmptyRecycleBin\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"label\": \"query or enumerate registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x48B8F0\",\n      \"label\": \"Function 0x48B8F0\",\n      \"type\": \"function\",\n      \"address\": \"0x48B8F0\"\n    },\n    {\n      \"id\": \"func_0x48CB5B\",\n      \"label\": \"Function 0x48CB5B\",\n      \"type\": \"function\",\n      \"address\": \"0x48CB5B\"\n    },\n    {\n      \"id\": \"api_RegEnumKeyEx\",\n      \"label\": \"RegEnumKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"label\": \"query or enumerate registry value (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x48BD6B\",\n      \"label\": \"Function 0x48BD6B\",\n      \"type\": \"function\",\n      \"address\": \"0x48BD6B\"\n    },\n    {\n      \"id\": \"func_0x48BB02\",\n      \"label\": \"Function 0x48BB02\",\n      \"type\": \"function\",\n      \"address\": \"0x48BB02\"\n    },\n    {\n      \"id\": \"func_0x40533E\",\n      \"label\": \"Function 0x40533E\",\n      \"type\": \"function\",\n      \"address\": \"0x40533E\"\n    },\n    {\n      \"id\": \"func_0x4059A7\",\n      \"label\": \"Function 0x4059A7\",\n      \"type\": \"function\",\n      \"address\": \"0x4059A7\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegEnumValue\",\n      \"label\": \"RegEnumValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value\",\n      \"label\": \"set registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x48C2DE\",\n      \"label\": \"Function 0x48C2DE\",\n      \"type\": \"function\",\n      \"address\": \"0x48C2DE\"\n    },\n    {\n      \"id\": \"api_RegCreateKeyEx\",\n      \"label\": \"RegCreateKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delete_registry_key__2_matches_\",\n      \"label\": \"delete registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x48B535\",\n      \"label\": \"Function 0x48B535\",\n      \"type\": \"function\",\n      \"address\": \"0x48B535\"\n    },\n    {\n      \"id\": \"api_RegDeleteKey\",\n      \"label\": \"RegDeleteKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_value\",\n      \"label\": \"delete registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegDeleteValue\",\n      \"label\": \"RegDeleteValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_session_user_name\",\n      \"label\": \"get session user name\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\",\n        \"Discovery::Account\",\n        \"Discovery [T1087]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetUserName\",\n      \"label\": \"GetUserName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_token_membership\",\n      \"label\": \"get token membership\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4615A7\",\n      \"label\": \"Function 0x4615A7\",\n      \"type\": \"function\",\n      \"address\": \"0x4615A7\"\n    },\n    {\n      \"id\": \"api_FreeSid\",\n      \"label\": \"FreeSid\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_AllocateAndInitializeSid\",\n      \"label\": \"AllocateAndInitializeSid\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CheckTokenMembership\",\n      \"label\": \"CheckTokenMembership\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_token_privileges\",\n      \"label\": \"get token privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x460F58\",\n      \"label\": \"Function 0x460F58\",\n      \"type\": \"function\",\n      \"address\": \"0x460F58\"\n    },\n    {\n      \"id\": \"api_GetTokenInformation\",\n      \"label\": \"GetTokenInformation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_thread__5_matches_\",\n      \"label\": \"create thread (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x47D13B\",\n      \"label\": \"Block 0x47D13B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x47D13B\"\n    },\n    {\n      \"id\": \"bb_0x461747\",\n      \"label\": \"Block 0x461747\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x461747\"\n    },\n    {\n      \"id\": \"bb_0x470870\",\n      \"label\": \"Block 0x470870\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x470870\"\n    },\n    {\n      \"id\": \"bb_0x46E114\",\n      \"label\": \"Block 0x46E114\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46E114\"\n    },\n    {\n      \"id\": \"api_CreateThread\",\n      \"label\": \"CreateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api__beginthreadex\",\n      \"label\": \"_beginthreadex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api__beginthread\",\n      \"label\": \"_beginthread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_thread\",\n      \"label\": \"terminate thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Thread [C0039]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4708A6\",\n      \"label\": \"Block 0x4708A6\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4708A6\"\n    },\n    {\n      \"id\": \"api_TerminateThread\",\n      \"label\": \"TerminateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_impersonate_user\",\n      \"label\": \"impersonate user\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation::Token\",\n        \"Impersonation/Theft [T1134.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x461145\",\n      \"label\": \"Function 0x461145\",\n      \"type\": \"function\",\n      \"address\": \"0x461145\"\n    },\n    {\n      \"id\": \"api_LoadUserProfile\",\n      \"label\": \"LoadUserProfile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LogonUser\",\n      \"label\": \"LogonUser\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__99_elad_levi_gmail_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, 99.elad.levi@gmail.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation::Token\",\n        \"Impersonation/Theft [T1134.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal__autoit_file_limitation\",\n      \"label\": \"(internal) autoit file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__13_matches_\",\n      \"label\": \"link function at runtime on Windows (13 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header\",\n      \"label\": \"parse PE header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40B7E0\",\n      \"label\": \"Function 0x40B7E0\",\n      \"type\": \"function\",\n      \"address\": \"0x40B7E0\"\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"label\": \"resolve function by parsing PE exports (15 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x476E0F\",\n      \"label\": \"Function 0x476E0F\",\n      \"type\": \"function\",\n      \"address\": \"0x476E0F\"\n    },\n    {\n      \"id\": \"func_0x40D840\",\n      \"label\": \"Function 0x40D840\",\n      \"type\": \"function\",\n      \"address\": \"0x40D840\"\n    },\n    {\n      \"id\": \"func_0x47902A\",\n      \"label\": \"Function 0x47902A\",\n      \"type\": \"function\",\n      \"address\": \"0x47902A\"\n    },\n    {\n      \"id\": \"func_0x40A180\",\n      \"label\": \"Function 0x40A180\",\n      \"type\": \"function\",\n      \"address\": \"0x40A180\"\n    },\n    {\n      \"id\": \"func_0x490F26\",\n      \"label\": \"Function 0x490F26\",\n      \"type\": \"function\",\n      \"address\": \"0x490F26\"\n    },\n    {\n      \"id\": \"func_0x466502\",\n      \"label\": \"Function 0x466502\",\n      \"type\": \"function\",\n      \"address\": \"0x466502\"\n    },\n    {\n      \"id\": \"func_0x401641\",\n      \"label\": \"Function 0x401641\",\n      \"type\": \"function\",\n      \"address\": \"0x401641\"\n    },\n    {\n      \"id\": \"func_0x4681EE\",\n      \"label\": \"Function 0x4681EE\",\n      \"type\": \"function\",\n      \"address\": \"0x4681EE\"\n    },\n    {\n      \"id\": \"func_0x4763AC\",\n      \"label\": \"Function 0x4763AC\",\n      \"type\": \"function\",\n      \"address\": \"0x4763AC\"\n    },\n    {\n      \"id\": \"func_0x408BAA\",\n      \"label\": \"Function 0x408BAA\",\n      \"type\": \"function\",\n      \"address\": \"0x408BAA\"\n    },\n    {\n      \"id\": \"func_0x410540\",\n      \"label\": \"Function 0x410540\",\n      \"type\": \"function\",\n      \"address\": \"0x410540\"\n    },\n    {\n      \"id\": \"func_0x4095C0\",\n      \"label\": \"Function 0x4095C0\",\n      \"type\": \"function\",\n      \"address\": \"0x4095C0\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_execute_shellcode_via_indirect_call\",\n      \"label\": \"execute shellcode via indirect call\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4895BB\",\n      \"label\": \"Function 0x4895BB\",\n      \"type\": \"function\",\n      \"address\": \"0x4895BB\"\n    },\n    {\n      \"id\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"label\": \"author     ronnie.salomonsen@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_shortcut_via_ishelllink__2_matches_\",\n      \"label\": \"create shortcut via IShellLink (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47573C\",\n      \"label\": \"Function 0x47573C\",\n      \"type\": \"function\",\n      \"address\": \"0x47573C\"\n    },\n    {\n      \"id\": \"api_CoCreateInstance\",\n      \"label\": \"CoCreateInstance\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_memory__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_memory__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x46B26C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__489_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__489_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401202\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__13_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x40533E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__37_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__37_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x40F4AF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_process__7_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_process__7_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x46B26C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"target\": \"func_0x469B67\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"target\": \"func_0x46E899\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"target\": \"func_0x469B7E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"target\": \"func_0x46AFC6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x469B67\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E899\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x469B7E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46AFC6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_unmoving_mouse_cursor__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_unmoving_mouse_cursor__2_matches_\",\n      \"target\": \"func_0x499468\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_unmoving_mouse_cursor__2_matches_\",\n      \"target\": \"func_0x498EBB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______bitsofbinary\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______bitsofbinary\",\n      \"target\": \"func_0x499468\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______bitsofbinary\",\n      \"target\": \"func_0x498EBB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x462CEB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x46B04D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x4624E6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x4034CE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x41EFAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x46A90B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x463985\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x46B1FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x46B198\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x462CEB\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B04D\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4624E6\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4034CE\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EFAD\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463985\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B1FD\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x462CEB\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B04D\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4624E6\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4034CE\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EFAD\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463985\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B1FD\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x462CEB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46B04D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4624E6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4034CE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x41EFAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46A90B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x463985\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46B1FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46B198\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x462CEB\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B04D\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4624E6\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4034CE\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EFAD\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463985\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B1FD\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x462CEB\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B04D\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4624E6\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4034CE\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EFAD\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463985\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B1FD\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x499468\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46ABF8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x469B97\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x469EAF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x41EA9A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46A975\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46A90B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46ADD8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x4028C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46B198\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46AABA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x499468\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ABF8\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469B97\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469EAF\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EA9A\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A975\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ADD8\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4028C0\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46AABA\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499468\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ABF8\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469B97\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469EAF\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EA9A\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A975\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ADD8\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4028C0\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46AABA\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499468\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ABF8\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469B97\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469EAF\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EA9A\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A975\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ADD8\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4028C0\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46AABA\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499468\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ABF8\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469B97\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469EAF\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EA9A\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A975\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ADD8\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4028C0\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46AABA\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x499468\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46ABF8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x469B97\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x469EAF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x41EA9A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46A975\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46A90B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46ADD8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4028C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46B198\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46AABA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x499468\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ABF8\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469B97\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469EAF\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EA9A\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A975\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ADD8\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4028C0\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46AABA\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499468\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ABF8\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469B97\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469EAF\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EA9A\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A975\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ADD8\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4028C0\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46AABA\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499468\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ABF8\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469B97\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469EAF\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EA9A\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A975\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ADD8\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4028C0\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46AABA\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499468\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ABF8\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469B97\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469EAF\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EA9A\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A975\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ADD8\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4028C0\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46AABA\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_capture_screenshot\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_capture_screenshot\",\n      \"target\": \"func_0x482483\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x482483\",\n      \"target\": \"api_CreateCompatibleBitmap\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482483\",\n      \"target\": \"api_CreateCompatibleDC\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482483\",\n      \"target\": \"api_GetDC\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482483\",\n      \"target\": \"api_GetDIBits\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x482483\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x482483\",\n      \"target\": \"api_CreateCompatibleBitmap\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482483\",\n      \"target\": \"api_CreateCompatibleDC\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482483\",\n      \"target\": \"api_GetDC\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482483\",\n      \"target\": \"api_GetDIBits\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_remote_server_for_available_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_remote_server_for_available_data\",\n      \"target\": \"bb_0x47CE38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x47CE38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data__4_matches_\",\n      \"target\": \"func_0x481B87\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__4_matches_\",\n      \"target\": \"func_0x47CE38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__4_matches_\",\n      \"target\": \"func_0x48135A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__4_matches_\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CE38\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CE38\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CE38\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x481B87\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x47CE38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x48135A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CE38\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CE38\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CE38\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data__3_matches_\",\n      \"target\": \"func_0x4814F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__3_matches_\",\n      \"target\": \"func_0x481F24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__3_matches_\",\n      \"target\": \"func_0x47C394\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x4814F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x481F24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x47C394\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_download_and_write_a_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_download_and_write_a_file\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_maec_malware_category__downloader\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_maec_malware_category__downloader\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_and_write_data_from_server_to_client\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_and_write_data_from_server_to_client\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_dns__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_dns__3_matches_\",\n      \"target\": \"func_0x46DD45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_dns__3_matches_\",\n      \"target\": \"func_0x481288\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_dns__3_matches_\",\n      \"target\": \"func_0x480482\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46DD45\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481288\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46DD45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x481288\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x480482\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46DD45\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481288\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_network_resource\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_network_resource\",\n      \"target\": \"func_0x4605C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4605C7\",\n      \"target\": \"api_WNetAddConnection2\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4605C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4605C7\",\n      \"target\": \"api_WNetAddConnection2\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_url\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_url\",\n      \"target\": \"bb_0x47D012\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x47D012\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_to_http_server__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_to_http_server__2_matches_\",\n      \"target\": \"func_0x47C061\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_to_http_server__2_matches_\",\n      \"target\": \"func_0x47C394\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47C061\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47C061\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47C394\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47C061\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_to_url\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_http_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_http_request\",\n      \"target\": \"func_0x47CC3C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CC3C\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47CC3C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CC3C\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_data_from_internet__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__2_matches_\",\n      \"target\": \"func_0x47CE38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__2_matches_\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CE38\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47CE38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CE38\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_http_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_http_request\",\n      \"target\": \"func_0x47C394\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47C394\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_icmp_echo_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_icmp_echo_request\",\n      \"target\": \"func_0x480482\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_IcmpCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_IcmpSendEcho\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_IcmpCreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x480482\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_IcmpCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_IcmpSendEcho\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_IcmpCreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_pipe__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_pipe__2_matches_\",\n      \"target\": \"func_0x4703F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_pipe__2_matches_\",\n      \"target\": \"func_0x4704C5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4703F0\",\n      \"target\": \"api_CreatePipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4704C5\",\n      \"target\": \"api_CreatePipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4703F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4704C5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4703F0\",\n      \"target\": \"api_CreatePipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4704C5\",\n      \"target\": \"api_CreatePipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_socket\",\n      \"target\": \"bb_0x4810AF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mrhafizfarhad_gmail_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x4810AF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_socket_status\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_socket_status\",\n      \"target\": \"func_0x483070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x483070\",\n      \"target\": \"api_select\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x483070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x483070\",\n      \"target\": \"api_select\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_initialize_winsock_library__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_initialize_winsock_library__3_matches_\",\n      \"target\": \"func_0x46DD45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_initialize_winsock_library__3_matches_\",\n      \"target\": \"func_0x4815DA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_initialize_winsock_library__3_matches_\",\n      \"target\": \"func_0x480482\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46DD45\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4815DA\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46DD45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4815DA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x480482\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46DD45\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4815DA\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_socket_configuration__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__3_matches_\",\n      \"target\": \"func_0x482F75\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__3_matches_\",\n      \"target\": \"func_0x4819FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__3_matches_\",\n      \"target\": \"func_0x480482\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x482F75\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4819FD\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482F75\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4819FD\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x482F75\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4819FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x480482\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x482F75\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4819FD\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482F75\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4819FD\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data_on_socket__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__2_matches_\",\n      \"target\": \"func_0x481B87\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__2_matches_\",\n      \"target\": \"func_0x48135A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x481B87\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x48135A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data_on_socket__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__2_matches_\",\n      \"target\": \"func_0x4814F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__2_matches_\",\n      \"target\": \"func_0x481F24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4814F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x481F24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_tcp_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_tcp_socket\",\n      \"target\": \"func_0x480FDF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480FDF\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480FDF\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x480FDF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480FDF\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480FDF\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_tcp_socket__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__2_matches_\",\n      \"target\": \"bb_0x481197\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__2_matches_\",\n      \"target\": \"bb_0x481033\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x481197\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x481033\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_udp_socket__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__2_matches_\",\n      \"target\": \"bb_0x4819FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__2_matches_\",\n      \"target\": \"bb_0x48177E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4819FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x48177E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_act_as_tcp_client\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_act_as_tcp_client\",\n      \"target\": \"func_0x480FDF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480FDF\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480FDF\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x480FDF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480FDF\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480FDF\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_with_autoit\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_crc32\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_with_crc32\",\n      \"target\": \"func_0x4823E8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4823E8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encode_data_using_base64\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64\",\n      \"target\": \"func_0x41BEAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x41BEAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_djb2\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_djb2\",\n      \"target\": \"func_0x408273\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______awillia2_cisco_com__still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______awillia2_cisco_com__still_teamt5_org\",\n      \"target\": \"func_0x408273\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_authenticate_hmac\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac\",\n      \"target\": \"func_0x41BEAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x41BEAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"target\": \"func_0x471E7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"target\": \"func_0x471EC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"target\": \"func_0x471F64\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"target\": \"func_0x471F24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x471E7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x471EC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x471F64\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x471F24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x406122\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406122\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406122\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406122\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406122\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x406122\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406122\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406122\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406122\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406122\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_list_drag_and_drop_files\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_list_drag_and_drop_files\",\n      \"target\": \"func_0x47EA26\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_DragQueryFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_GetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47EA26\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_DragQueryFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_GetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_clipboard__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_clipboard__2_matches_\",\n      \"target\": \"func_0x47EA26\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_open_clipboard__2_matches_\",\n      \"target\": \"func_0x47EC91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47EA26\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47EC91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_clipboard_data\",\n      \"target\": \"func_0x47EA26\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_GlobalLock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_GetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_GlobalUnlock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47EA26\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_GlobalLock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_GetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_GlobalUnlock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_clipboard_data\",\n      \"target\": \"func_0x47EC91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47EC91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_interact_with_driver_via_ioctl__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_comspec_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_comspec_environment_variable\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__3_matches_\",\n      \"target\": \"func_0x47EE14\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__3_matches_\",\n      \"target\": \"func_0x487559\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__3_matches_\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EE14\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x487559\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x47EE14\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x487559\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EE14\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x487559\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_environment_variable__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_environment_variable__2_matches_\",\n      \"target\": \"func_0x43D170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_environment_variable__2_matches_\",\n      \"target\": \"func_0x47EE84\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x43D170\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EE84\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x43D170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47EE84\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x43D170\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EE84\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x46DE45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x472F35\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x40445D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x4779B4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x477D0E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x48AF20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x41F962\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x4780B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46DE45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472F35\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40445D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4779B4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x477D0E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48AF20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41F962\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4780B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_current_directory__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x40445D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x40AD7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x477D0E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x479560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x4753D4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x4796BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x4780B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AD7C\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4753D4\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40445D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40AD7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x477D0E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x479560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4753D4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4796BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4780B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AD7C\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4753D4\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_copy_file__3_matches_\",\n      \"target\": \"func_0x472865\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_copy_file__3_matches_\",\n      \"target\": \"func_0x46D1BA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_copy_file__3_matches_\",\n      \"target\": \"func_0x46CE1E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1BA\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1BA\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1BA\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x472865\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D1BA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46CE1E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1BA\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1BA\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1BA\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory__2_matches_\",\n      \"target\": \"func_0x46D1DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__2_matches_\",\n      \"target\": \"func_0x473C3C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46D1DF\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473C3C\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D1DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x473C3C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46D1DF\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473C3C\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_directory__2_matches_\",\n      \"target\": \"func_0x46E77B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_directory__2_matches_\",\n      \"target\": \"func_0x473C3C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46E77B\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473C3C\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E77B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x473C3C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46E77B\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473C3C\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x46CF94\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x4778BA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x46D2C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x4755F7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x472865\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x46E77B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4778BA\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4755F7\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E77B\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4778BA\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4755F7\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E77B\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46CF94\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4778BA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D2C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4755F7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x472865\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E77B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4778BA\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4755F7\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E77B\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4778BA\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4755F7\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E77B\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x46D1DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x46E0B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x46DADC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46D1DF\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E0B7\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DADC\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1DF\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E0B7\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DADC\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D1DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E0B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46DADC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46D1DF\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E0B7\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DADC\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1DF\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E0B7\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DADC\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x479A49\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x46CF94\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x46D2C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x479560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x475BB5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x4796BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475BB5\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475BB5\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475BB5\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x479A49\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46CF94\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46D2C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x479560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x475BB5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4796BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475BB5\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475BB5\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475BB5\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_recursively__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively__3_matches_\",\n      \"target\": \"func_0x4796BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively__3_matches_\",\n      \"target\": \"func_0x479560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively__3_matches_\",\n      \"target\": \"func_0x479A49\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4796BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x479560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x479A49\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x477F04\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x46D1DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x46E0B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x46DAFA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x4795B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x477F04\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x46D1DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x46E0B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x46DAFA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4795B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x482A05\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x498461\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x482A05\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x498461\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_version_info\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_version_info\",\n      \"target\": \"func_0x46DB2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46DB2C\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB2C\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB2C\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46DB2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46DB2C\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB2C\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB2C\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__2_matches_\",\n      \"target\": \"bb_0x477F04\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__2_matches_\",\n      \"target\": \"bb_0x4795B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x477F04\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4795B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_move_file__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_move_file__3_matches_\",\n      \"target\": \"func_0x46CF94\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__3_matches_\",\n      \"target\": \"func_0x46E319\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__3_matches_\",\n      \"target\": \"func_0x46CE1E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E319\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E319\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46CF94\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E319\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46CE1E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E319\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E319\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read__ini_file__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__4_matches_\",\n      \"target\": \"func_0x478A19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__4_matches_\",\n      \"target\": \"func_0x4783FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__4_matches_\",\n      \"target\": \"func_0x4787FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__4_matches_\",\n      \"target\": \"func_0x4784BF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x478A19\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783FD\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4787FC\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4784BF\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478A19\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783FD\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4787FC\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4784BF\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478A19\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783FD\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4787FC\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4784BF\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x478A19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4783FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4787FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4784BF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x478A19\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783FD\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4787FC\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4784BF\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478A19\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783FD\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4787FC\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4784BF\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478A19\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783FD\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4787FC\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4784BF\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x482A05\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x43921B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x472475\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x47070D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x4725B1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x40B230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x40B3B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x406A95\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x498461\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43921B\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472475\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47070D\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725B1\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B230\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B3B0\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406A95\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43921B\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472475\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47070D\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725B1\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B230\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B3B0\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406A95\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43921B\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472475\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47070D\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725B1\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B230\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B3B0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406A95\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43921B\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472475\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47070D\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725B1\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B230\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B3B0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406A95\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x482A05\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x43921B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472475\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47070D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4725B1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B3B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406A95\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x498461\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43921B\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472475\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47070D\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725B1\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B230\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B3B0\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406A95\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43921B\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472475\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47070D\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725B1\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B230\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B3B0\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406A95\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43921B\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472475\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47070D\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725B1\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B230\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B3B0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406A95\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43921B\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472475\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47070D\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725B1\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B230\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B3B0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406A95\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_clear_file_content\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_clear_file_content\",\n      \"target\": \"func_0x477FD5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x477FD5\",\n      \"target\": \"api_SetEndOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477FD5\",\n      \"target\": \"api_SetFilePointer\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____jakeperalta7\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____jakeperalta7\",\n      \"target\": \"func_0x477FD5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x477FD5\",\n      \"target\": \"api_SetEndOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477FD5\",\n      \"target\": \"api_SetFilePointer\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x41F5B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x472642\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x4725F5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x472865\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x470633\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x46CC1D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F5B3\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472642\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725F5\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470633\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CC1D\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F5B3\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472642\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725F5\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470633\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CC1D\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F5B3\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472642\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725F5\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470633\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CC1D\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41F5B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472642\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4725F5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472865\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x470633\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46CC1D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F5B3\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472642\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725F5\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470633\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CC1D\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F5B3\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472642\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725F5\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470633\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CC1D\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F5B3\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472642\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725F5\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470633\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CC1D\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_gui_resources\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_gui_resources\",\n      \"target\": \"func_0x464144\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x464144\",\n      \"target\": \"api_EnumWindows\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x464144\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x464144\",\n      \"target\": \"api_EnumWindows\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_taskbar__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_find_taskbar__3_matches_\",\n      \"target\": \"bb_0x492255\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_find_taskbar__3_matches_\",\n      \"target\": \"bb_0x492289\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_find_taskbar__3_matches_\",\n      \"target\": \"bb_0x41EFCE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x492255\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x492289\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x41EFCE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_graphical_window__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_graphical_window_text__11_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x464BD3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x47E8F7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x461A70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x496FA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x465B9A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x46359E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x4947A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x46489C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x463B0C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x4972B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x491E0D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x464BD3\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47E8F7\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461A70\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x496FA4\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465B9A\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46359E\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4947A8\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46489C\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463B0C\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4972B7\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x491E0D\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x464BD3\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47E8F7\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461A70\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x496FA4\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465B9A\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46359E\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4947A8\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46489C\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463B0C\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4972B7\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x491E0D\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x464BD3\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47E8F7\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461A70\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x496FA4\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465B9A\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46359E\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4947A8\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46489C\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463B0C\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4972B7\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x491E0D\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x464BD3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x47E8F7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x461A70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x496FA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x465B9A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46359E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4947A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46489C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x463B0C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4972B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x491E0D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x464BD3\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47E8F7\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461A70\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x496FA4\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465B9A\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46359E\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4947A8\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46489C\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463B0C\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4972B7\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x491E0D\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x464BD3\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47E8F7\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461A70\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x496FA4\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465B9A\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46359E\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4947A8\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46489C\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463B0C\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4972B7\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x491E0D\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x464BD3\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47E8F7\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461A70\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x496FA4\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465B9A\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46359E\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4947A8\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46489C\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463B0C\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4972B7\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x491E0D\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hide_graphical_window__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x4981BF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x4827C2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x4950F2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x49015D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x45F0F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x496B61\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x49A198\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x49813A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4981BF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4827C2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4950F2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x49015D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x45F0F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x496B61\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x49A198\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x49813A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_keyboard_layout\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_keyboard_layout\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetKeyboardLayoutName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetKeyboardLayoutName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_memory_capacity\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_memory_capacity\",\n      \"target\": \"func_0x41F370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41F370\",\n      \"target\": \"api_GlobalMemoryStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x41F370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41F370\",\n      \"target\": \"api_GlobalMemoryStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x474844\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x4749FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x474912\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x4743DE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x474776\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x473D97\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x474844\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4749FD\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474912\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4743DE\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474776\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473D97\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474844\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4749FD\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474912\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4743DE\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474776\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473D97\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x474844\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4749FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x474912\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4743DE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x474776\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x473D97\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x474844\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4749FD\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474912\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4743DE\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474776\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473D97\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474844\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4749FD\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474912\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4743DE\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474776\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473D97\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_size__3_matches_\",\n      \"target\": \"func_0x4750EB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_size__3_matches_\",\n      \"target\": \"func_0x4751CE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_size__3_matches_\",\n      \"target\": \"func_0x4752B1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4750EB\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4751CE\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4752B1\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4750EB\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4751CE\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4752B1\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4750EB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4751CE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4752B1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4750EB\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4751CE\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4752B1\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4750EB\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4751CE\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4752B1\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_storage_device_properties__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_storage_device_properties__2_matches_\",\n      \"target\": \"func_0x46D588\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_storage_device_properties__2_matches_\",\n      \"target\": \"func_0x46D509\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46D588\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D509\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D588\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D509\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46D588\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D509\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_print_debug_messages\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_print_debug_messages\",\n      \"target\": \"func_0x41F5B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41F5B3\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x41F5B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41F5B3\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_shutdown_system\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_shutdown_system\",\n      \"target\": \"func_0x46E814\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46E814\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E814\",\n      \"target\": \"api_InitiateSystemShutdownEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E814\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46E814\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E814\",\n      \"target\": \"api_InitiateSystemShutdownEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_hostname__2_matches_\",\n      \"target\": \"func_0x46DD45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_hostname__2_matches_\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46DD45\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DD45\",\n      \"target\": \"api_gethostname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_gethostname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46DD45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46DD45\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DD45\",\n      \"target\": \"api_gethostname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_gethostname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_system_information_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_system_information_on_windows\",\n      \"target\": \"func_0x40615E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40615E\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x40615E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40615E\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x498064\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x4437E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x461472\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x48B2C1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x46134A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x48AD7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x498064\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4437E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x461472\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x48B2C1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x46134A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x48AD7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_or_change_rwx_memory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory\",\n      \"target\": \"bb_0x489881\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x489881\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_processes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_processes__2_matches_\",\n      \"target\": \"func_0x46D3FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_processes__2_matches_\",\n      \"target\": \"func_0x48A5A3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46D3FA\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A5A3\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D3FA\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A5A3\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D3FA\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A5A3\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D3FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x48A5A3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46D3FA\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A5A3\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D3FA\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A5A3\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D3FA\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A5A3\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_acquire_debug_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_acquire_debug_privileges\",\n      \"target\": \"bb_0x48A0B6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"bb_0x48A0B6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_modify_access_privileges__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process__3_matches_\",\n      \"target\": \"func_0x487E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__3_matches_\",\n      \"target\": \"func_0x46EA3E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__3_matches_\",\n      \"target\": \"func_0x48A009\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x487E80\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EA3E\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A009\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x487E80\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EA3E\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A009\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x487E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46EA3E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48A009\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x487E80\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EA3E\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A009\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x487E80\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EA3E\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A009\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_empty_the_recycle_bin\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_empty_the_recycle_bin\",\n      \"target\": \"func_0x477953\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x477953\",\n      \"target\": \"api_SHEmptyRecycleBin\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x477953\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x477953\",\n      \"target\": \"api_SHEmptyRecycleBin\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"target\": \"func_0x48B8F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"target\": \"func_0x48CB5B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48B8F0\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48CB5B\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B8F0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48CB5B\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x48B8F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x48CB5B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48B8F0\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48CB5B\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B8F0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48CB5B\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x48BD6B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x48BB02\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x40533E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x4605C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x4059A7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48BD6B\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BB02\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40533E\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4605C7\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A7\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BD6B\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BB02\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40533E\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4605C7\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A7\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BD6B\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BB02\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40533E\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4605C7\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A7\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48BD6B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48BB02\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40533E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4605C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4059A7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48BD6B\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BB02\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40533E\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4605C7\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A7\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BD6B\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BB02\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40533E\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4605C7\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A7\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BD6B\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BB02\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40533E\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4605C7\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A7\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value\",\n      \"target\": \"func_0x48C2DE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48C2DE\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C2DE\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x48C2DE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48C2DE\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C2DE\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key__2_matches_\",\n      \"target\": \"func_0x48CB5B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key__2_matches_\",\n      \"target\": \"func_0x48B535\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48CB5B\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B535\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48CB5B\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B535\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x48CB5B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x48B535\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48CB5B\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B535\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48CB5B\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B535\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value\",\n      \"target\": \"func_0x48B535\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48B535\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B535\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48B535\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48B535\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B535\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_user_name\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_session_user_name\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetUserName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetUserName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_token_membership\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_token_membership\",\n      \"target\": \"func_0x4615A7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4615A7\",\n      \"target\": \"api_FreeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4615A7\",\n      \"target\": \"api_AllocateAndInitializeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4615A7\",\n      \"target\": \"api_CheckTokenMembership\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4615A7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4615A7\",\n      \"target\": \"api_FreeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4615A7\",\n      \"target\": \"api_AllocateAndInitializeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4615A7\",\n      \"target\": \"api_CheckTokenMembership\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_token_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_token_privileges\",\n      \"target\": \"func_0x460F58\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x460F58\",\n      \"target\": \"api_GetTokenInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x460F58\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x460F58\",\n      \"target\": \"api_GetTokenInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread__5_matches_\",\n      \"target\": \"bb_0x47D13B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__5_matches_\",\n      \"target\": \"bb_0x461747\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__5_matches_\",\n      \"target\": \"bb_0x470870\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__5_matches_\",\n      \"target\": \"bb_0x46E114\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x47D13B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x461747\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x470870\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x46E114\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_thread\",\n      \"target\": \"bb_0x4708A6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4708A6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_impersonate_user\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_impersonate_user\",\n      \"target\": \"func_0x461145\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x461145\",\n      \"target\": \"api_LoadUserProfile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461145\",\n      \"target\": \"api_LogonUser\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__99_elad_levi_gmail_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__99_elad_levi_gmail_com\",\n      \"target\": \"func_0x461145\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x461145\",\n      \"target\": \"api_LoadUserProfile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461145\",\n      \"target\": \"api_LogonUser\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal__autoit_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__13_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header\",\n      \"target\": \"func_0x40B7E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x40B7E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x476E0F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x487E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x41BEAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x40D840\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x47902A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x40A180\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x40AD7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x490F26\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x466502\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x401641\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x4681EE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x4763AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x408BAA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x410540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x4095C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x476E0F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x487E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x41BEAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x40D840\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x47902A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x40A180\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x40AD7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x490F26\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x466502\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x401641\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x4681EE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x4763AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x408BAA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x410540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x4095C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_execute_shellcode_via_indirect_call\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_execute_shellcode_via_indirect_call\",\n      \"target\": \"func_0x4895BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4895BB\",\n      \"target\": \"api_VirtualAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"target\": \"func_0x4895BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4895BB\",\n      \"target\": \"api_VirtualAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_shortcut_via_ishelllink__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_shortcut_via_ishelllink__2_matches_\",\n      \"target\": \"func_0x47573C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_shortcut_via_ishelllink__2_matches_\",\n      \"target\": \"func_0x4763AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47573C\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4763AC\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______matthew_williams_mandiant_com\",\n      \"target\": \"func_0x47573C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______matthew_williams_mandiant_com\",\n      \"target\": \"func_0x4763AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47573C\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4763AC\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-05-15 14:32:59.377830\",\n    \"total_functions\": \"2043\",\n    \"total_features\": \"120247\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-05-15 14:33:03"}
{"_id":{"$oid":"69edf02059a6632dae07de43"},"sha256":"02aa8cabeea2a0120a31adbf0886f821d10953fc6d4d9cd1959568093c48b04d","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_w6xzywcd/secondary_sample_try_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_w6xzywcd/secondary_sample_try_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_w6xzywcd/secondary_sample_try_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 74bb3514f737d1386b7ced741ec1e098                                  │\n│ sha1     │ 25de16039754b3870676911b146a956d30b2e8fa                          │\n│ sha256   │ 02aa8cabeea2a0120a31adbf0886f821d10953fc6d4d9cd1959568093c48b04d  │\n│ analysis │ static                                                            │\n│ os       │ any                                                               │\n│ format   │ dotnet                                                            │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/secondary_sample… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Archive Collected Data::Archive via Library           │\n│                      │ [T1560.002]                                           │\n│ DEFENSE EVASION      │ Deobfuscate/Decode Files or Information [T1140]       │\n│                      │ Indicator Removal::File Deletion [T1070.004]          │\n│                      │ Modify Registry [T1112]                               │\n│                      │ Obfuscated Files or Information [T1027]               │\n│                      │ Reflective Code Loading [T1620]                       │\n│                      │ Virtualization/Sandbox Evasion::System Checks         │\n│                      │ [T1497.001]                                           │\n│ DISCOVERY            │ Account Discovery [T1087]                             │\n│                      │ File and Directory Discovery [T1083]                  │\n│                      │ Process Discovery [T1057]                             │\n│                      │ Query Registry [T1012]                                │\n│                      │ Software Discovery [T1518]                            │\n│                      │ System Information Discovery [T1082]                  │\n│                      │ System Owner/User Discovery [T1033]                   │\n│ EXECUTION            │ Windows Management Instrumentation [T1047]            │\n│ PERSISTENCE          │ Scheduled Task/Job::Scheduled Task [T1053.005]        │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Debugger Detection::CheckRemoteDebuggerPresent    │\n│                          │ [B0001.002]                                       │\n│                          │ Debugger Detection::WudfIsAnyDebuggerPresent      │\n│                          │ [B0001.031]                                       │\n│                          │ Sandbox Detection [B0007]                         │\n│                          │ Virtual Machine Detection [B0009]                 │\n│ COMMAND AND CONTROL      │ C2 Communication::Receive Data [B0030.002]        │\n│ COMMUNICATION            │ DNS Communication::Resolve [C0011.001]            │\n│                          │ HTTP Communication::Get Response [C0002.017]      │\n│                          │ Socket Communication::Create TCP Socket           │\n│                          │ [C0001.011]                                       │\n│                          │ Socket Communication::Create UDP Socket           │\n│                          │ [C0001.010]                                       │\n│ CRYPTOGRAPHY             │ Cryptographic Hash::MD5 [C0029.001]               │\n│                          │ Cryptographic Hash::SHA256 [C0029.003]            │\n│                          │ Generate Pseudo-random Sequence::Use API          │\n│                          │ [C0021.003]                                       │\n│ DATA                     │ Compress Data [C0024]                             │\n│                          │ Decode Data::Base64 [C0053.001]                   │\n│                          │ Encode Data::Base64 [C0026.001]                   │\n│ DEFENSE EVASION          │ Obfuscated Files or                               │\n│                          │ Information::Encoding-Standard Algorithm          │\n│                          │ [E1027.m02]                                       │\n│                          │ Self Deletion::COMSPEC Environment Variable       │\n│                          │ [F0007.001]                                       │\n│ DISCOVERY                │ Application Window Discovery [E1010]              │\n│                          │ File and Directory Discovery [E1083]              │\n│                          │ System Information Discovery [E1082]              │\n│ FILE SYSTEM              │ Delete File [C0047]                               │\n│                          │ Read File [C0051]                                 │\n│ OPERATING SYSTEM         │ Registry::Delete Registry Key [C0036.002]         │\n│                          │ Registry::Delete Registry Value [C0036.007]       │\n│                          │ Registry::Query Registry Key [C0036.005]          │\n│                          │ Registry::Query Registry Value [C0036.006]        │\n│                          │ Registry::Set Registry Key [C0036.001]            │\n│ PROCESS                  │ Create Mutex [C0042]                              │\n│                          │ Create Process [C0017]                            │\n│                          │ Create Thread [C0038]                             │\n│                          │ Suspend Thread [C0055]                            │\n│                          │ Terminate Process [C0018]                         │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ check for sandbox and av modules      │ anti-analysis/anti-av                │\n│ check for debugger via API            │ anti-analysis/anti-debugging/debugg… │\n│ self delete (2 matches)               │ anti-analysis/anti-forensic/self-de… │\n│ reference anti-VM strings targeting   │ anti-analysis/anti-vm/vm-detection   │\n│ VMWare                                │                                      │\n│ reference anti-VM strings targeting   │ anti-analysis/anti-vm/vm-detection   │\n│ VirtualBox                            │                                      │\n│ receive data                          │ communication                        │\n│ manipulate network credentials in     │ communication/authentication         │\n│ .NET                                  │                                      │\n│ resolve DNS                           │ communication/dns                    │\n│ create TCP socket                     │ communication/socket/tcp             │\n│ create UDP socket                     │ communication/socket/udp/send        │\n│ compress data using GZip in .NET (2   │ data-manipulation/compression        │\n│ matches)                              │                                      │\n│ decode data using Base64 in .NET (3   │ data-manipulation/encoding/base64    │\n│ matches)                              │                                      │\n│ encode data using Base64              │ data-manipulation/encoding/base64    │\n│ hash data with MD5                    │ data-manipulation/hashing/md5        │\n│ hash data using SHA256 (2 matches)    │ data-manipulation/hashing/sha256     │\n│ generate random numbers in .NET       │ data-manipulation/prng               │\n│ query environment variable            │ host-interaction/environment-variab… │\n│ generate random filename in .NET      │ host-interaction/file-system         │\n│ get common file path (2 matches)      │ host-interaction/file-system         │\n│ delete file                           │ host-interaction/file-system/delete  │\n│ check if file exists (2 matches)      │ host-interaction/file-system/exists  │\n│ read file on Windows                  │ host-interaction/file-system/read    │\n│ get graphical window text             │ host-interaction/gui/window/get-text │\n│ get number of processors              │ host-interaction/hardware/cpu        │\n│ get disk size (2 matches)             │ host-interaction/hardware/storage    │\n│ create or open mutex on Windows       │ host-interaction/mutex               │\n│ get hostname (2 matches)              │ host-interaction/os/hostname         │\n│ get OS version in .NET (3 matches)    │ host-interaction/os/version          │\n│ get process image filename            │ host-interaction/process             │\n│ create a process with modified I/O    │ host-interaction/process/create      │\n│ handles and window                    │                                      │\n│ create process on Windows             │ host-interaction/process/create      │\n│ enumerate processes                   │ host-interaction/process/list        │\n│ enter debug mode in .NET              │ host-interaction/process/modify      │\n│ terminate process (2 matches)         │ host-interaction/process/terminate   │\n│ query or enumerate registry key (2    │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ query or enumerate registry value     │ host-interaction/registry            │\n│ set registry value (3 matches)        │ host-interaction/registry/create     │\n│ delete registry key                   │ host-interaction/registry/delete     │\n│ delete registry value                 │ host-interaction/registry/delete     │\n│ get session integrity level           │ host-interaction/session             │\n│ get session user name (3 matches)     │ host-interaction/session             │\n│ create thread                         │ host-interaction/thread/create       │\n│ suspend thread (4 matches)            │ host-interaction/thread/suspend      │\n│ execute via timer in .NET             │ host-interaction/thread/timer        │\n│ access WMI data in .NET (2 matches)   │ host-interaction/wmi                 │\n│ load .NET assembly                    │ load-code/dotnet                     │\n│ schedule task via schtasks (4         │ persistence/scheduled-tasks          │\n│ matches)                              │                                      │\n│ unmanaged call (6 matches)            │ runtime                              │\n│ compiled to the .NET platform         │ runtime/dotnet                       │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     74bb3514f737d1386b7ced741ec1e098                        \nsha1                    25de16039754b3870676911b146a956d30b2e8fa                \nsha256                  02aa8cabeea2a0120a31adbf0886f821d10953fc6d4d9cd19595680…\npath                    /home/apogean/projects/malware/windows/all_runs/seconda…\ntimestamp               2026-04-29 18:18:25.046336                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEI30NzcH/rules                                   \nfunction count          157                                                     \nlibrary function count  0                                                       \ntotal feature count     4647                                                    \n\ncheck for sandbox and av modules\nnamespace  anti-analysis/anti-av\nscope      basic block          \nmatches    token(0x600002B)     \n\ncheck for debugger via API\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    token(0x600002A)                               \n\nself delete (2 matches)\nnamespace  anti-analysis/anti-forensic/self-deletion\nscope      function                                 \nmatches    token(0x6000024)                         \n           token(0x6000024)                         \n\nreference anti-VM strings targeting VMWare\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nreference anti-VM strings targeting VirtualBox\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nreceive data\nnamespace    communication                                                     \ndescription  all known techniques for receiving data from a potential C2 server\nscope        function                                                          \nmatches      token(0x600001B)                                                  \n\nmanipulate network credentials in .NET\nnamespace  communication/authentication\nscope      function                    \nmatches    token(0x600001B)            \n\nresolve DNS\nnamespace  communication/dns\nscope      function         \nmatches    token(0x600001B) \n\nread data from Internet\nnamespace  communication/http/client\nscope      function                 \nmatches    token(0x600001B)         \n\ncreate TCP socket\nnamespace  communication/socket/tcp\nscope      basic block             \nmatches    token(0x600001B)        \n\ncreate UDP socket\nnamespace  communication/socket/udp/send\nscope      basic block                  \nmatches    token(0x600001B)             \n\ncompress data using GZip in .NET (2 matches)\nnamespace  data-manipulation/compression\nscope      function                     \nmatches    token(0x60000A2)             \n           token(0x60000A3)             \n\ndecode data using Base64 in .NET (3 matches)\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    token(0x6000003)                 \n           token(0x6000004)                 \n           token(0x600004E)                 \n\nencode data using Base64\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    token(0x600004C)                 \n\nhash data with MD5\nnamespace  data-manipulation/hashing/md5\nscope      function                     \nmatches    token(0x600002E)             \n\nhash data using SHA256 (2 matches)\nnamespace  data-manipulation/hashing/sha256\nscope      function                        \nmatches    token(0x6000052)                \n           token(0x6000053)                \n\ngenerate random numbers in .NET\nnamespace  data-manipulation/prng\nscope      function              \nmatches    token(0x600001B)      \n\nquery environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    token(0x6000024)                     \n\ngenerate random filename in .NET\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x6000024)            \n\nget common file path (2 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x6000027)            \n           token(0x600002D)            \n\ndelete file\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    token(0x6000024)                   \n\ncheck if file exists (2 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x6000024)                   \n           token(0x600007D)                   \n\nread file on Windows\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    token(0x6000024)                 \n\nget graphical window text\nnamespace  host-interaction/gui/window/get-text\nscope      function                            \nmatches    token(0x6000035)                    \n\nget number of processors\nnamespace  host-interaction/hardware/cpu\nscope      function                     \nmatches    token(0x600002D)             \n\nget disk size (2 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    token(0x6000027)                 \n           token(0x600002D)                 \n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex\nscope      instruction           \nmatches    token(0x6000036)+0x8  \n\nget hostname (2 matches)\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    token(0x600002D)            \n           token(0x6000032)            \n\nget OS version in .NET (3 matches)\nnamespace  host-interaction/os/version\nscope      basic block                \nmatches    token(0x6000028)           \n           token(0x600002D)           \n           token(0x600002F)           \n\nget process image filename\nnamespace  host-interaction/process\nscope      basic block             \nmatches    token(0x6000024)        \n\ncreate a process with modified I/O handles and window\nnamespace  host-interaction/process/create\nscope      function                       \nmatches    token(0x6000024)               \n\ncreate process on Windows\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    token(0x6000024)               \n\nenumerate processes\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    token(0x6000024)             \n\nenter debug mode in .NET\nnamespace    host-interaction/process/modify                                    \ndescription  Often used by debuggers and malware to attach to and modify other  \n             processes.                                                         \nscope        basic block                                                        \nmatches      token(0x600003F)                                                   \n\nterminate process (2 matches)\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    token(0x6000001)                  \n           token(0x6000024)                  \n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    token(0x6000024)         \n           token(0x6000044)         \n\nquery or enumerate registry value\nnamespace  host-interaction/registry\nscope      function                 \nmatches    token(0x6000042)         \n\nset registry value (3 matches)\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    token(0x6000024)                \n           token(0x6000024)                \n           token(0x6000041)                \n\ndelete registry key\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    token(0x6000044)                \n\ndelete registry value\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    token(0x6000043)                \n\nget session integrity level\nnamespace  host-interaction/session\nscope      function                \nmatches    token(0x6000030)        \n\nget session user name (3 matches)\nnamespace  host-interaction/session\nscope      function                \nmatches    token(0x600002D)        \n           token(0x600002F)        \n           token(0x6000030)        \n\ncreate thread\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    token(0x600001F)              \n\nsuspend thread (4 matches)\nnamespace  host-interaction/thread/suspend\nscope      basic block                    \nmatches    token(0x6000001)               \n           token(0x6000024)               \n           token(0x6000040)               \n           token(0x6000048)               \n\nexecute via timer in .NET\nnamespace  host-interaction/thread/timer\nscope      function                     \nmatches    token(0x600001B)             \n\naccess WMI data in .NET (2 matches)\nnamespace  host-interaction/wmi\nscope      function            \nmatches    token(0x6000029)    \n           token(0x6000032)    \n\nload .NET assembly\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x6000047)\n\nschedule task via schtasks (4 matches)\nnamespace  persistence/scheduled-tasks\nscope      function                   \nmatches    token(0x6000024)           \n           token(0x6000024)           \n           token(0x6000024)           \n           token(0x6000024)           \n\nunmanaged call (6 matches)\nnamespace    runtime                                                       \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nscope        function                                                      \nmatches      token(0x600002A)                                              \n             token(0x600002B)                                              \n             token(0x6000034)                                              \n             token(0x6000035)                                              \n             token(0x600003F)                                              \n             token(0x6000040)                                              \n\ncompiled to the .NET platform\nnamespace  runtime/dotnet\nscope      file          \n\n\n\n","very_verbose":"md5                     74bb3514f737d1386b7ced741ec1e098                        \nsha1                    25de16039754b3870676911b146a956d30b2e8fa                \nsha256                  02aa8cabeea2a0120a31adbf0886f821d10953fc6d4d9cd19595680…\npath                    /home/apogean/projects/malware/windows/all_runs/seconda…\ntimestamp               2026-04-29 18:18:27.618563                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIR8q40Z/rules                                   \nfunction count          157                                                     \nlibrary function count  0                                                       \ntotal feature count     4647                                                    \n\ncontain loop (2 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ token(0x600006B)\n  or:\n    characteristic: recursive call @ token(0x600006B)\n\ncreate or open registry key (5 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ token(0x6000024) in function token(0x6000024)\n  or:\n    api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000024)+0x114\n\ncheck for sandbox and av modules\nnamespace  anti-analysis/anti-av                                                \nauthor     @_re_fox                                                             \nscope      basic block                                                          \nmbc        Anti-Behavioral Analysis::Virtual Machine Detection [B0009],         \n           Anti-Behavioral Analysis::Sandbox Detection [B0007]                  \nbasic block @ token(0x600002B) in function token(0x600002B)\n  and:\n    api: GetModuleHandle @ token(0x600002B)+0x5\n    or:\n      regex: /sbiedll\\.dll/i\n        - \"SbieDll.dll\" @ token(0x600002B)+0x0\n\ncheck for debugger via API\nnamespace   anti-analysis/anti-debugging/debugger-detection                     \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \nmbc         Anti-Behavioral Analysis::Debugger                                  \n            Detection::CheckRemoteDebuggerPresent [B0001.002], Anti-Behavioral  \n            Analysis::Debugger Detection::WudfIsAnyDebuggerPresent [B0001.031]  \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ token(0x600002A)\n  or:\n    api: CheckRemoteDebuggerPresent @ token(0x600002A)+0xE\n\nself delete (2 matches)\nnamespace  anti-analysis/anti-forensic/self-deletion                            \nauthor     michael.hunhoff@mandiant.com, @mr-tz                                 \nscope      function                                                             \natt&ck     Defense Evasion::Indicator Removal::File Deletion [T1070.004]        \nmbc        Defense Evasion::Self Deletion::COMSPEC Environment Variable         \n           [F0007.001]                                                          \nfunction @ token(0x6000024)\n  and:\n    optional:\n      regex: /\\s*>\\s*nul\\s*/i\n        - \"timeout 3 > NUL\" @ token(0x6000024)+0x1C8\n    or:\n      match: host-interaction/process/create @ token(0x6000024)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x6000024)+0xF9, token(0x6000024)+0x25E\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x6000024)+0xF9, token(0x6000024)+0x25E\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000024)+0x252\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000024)+0xEA, token(0x6000024)+0x259\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000024)+0xA1, token(0x6000024)+0x23D\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000024)+0xE2\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000024)+0xF2, token(0x6000024)+0x244\n    or:\n      regex: /(^|[\\&;\\|]\\s*)del(\\s.*)?/i\n        - \"DEL \\\"\" @ token(0x6000024)+0x206\nfunction @ token(0x6000024)\n  and:\n    optional:\n      regex: /\\s*>\\s*nul\\s*/i\n        - \"timeout 3 > NUL\" @ token(0x6000024)+0x1C8\n    or:\n      match: host-interaction/process/create @ token(0x6000024)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x6000024)+0xF9, token(0x6000024)+0x25E\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x6000024)+0xF9, token(0x6000024)+0x25E\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000024)+0x252\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000024)+0xEA, token(0x6000024)+0x259\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000024)+0xA1, token(0x6000024)+0x23D\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000024)+0xE2\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000024)+0xF2, token(0x6000024)+0x244\n    or:\n      regex: /(^|[\\&;\\|]\\s*)del(\\s.*)?/i\n        - \"DEL \\\"\" @ token(0x6000024)+0x206\n\nreference anti-VM strings targeting VMWare\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com, @johnk3r                              \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /VMWare/i\n    - \"vmware\" @ file+0x9B51\n\nreference anti-VM strings targeting VirtualBox\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /VirtualBox/i\n    - \"VirtualBox\" @ file+0x9B5F\n\nreceive data\nnamespace    communication                                                     \nauthor       william.ballenthin@mandiant.com                                   \nscope        function                                                          \nmbc          Command and Control::C2 Communication::Receive Data [B0030.002]   \ndescription  all known techniques for receiving data from a potential C2 server\nfunction @ token(0x600001B)\n  or:\n    match: read data from Internet @ token(0x600001B)\n      and:\n        or:\n          api: System.Net.WebClient::DownloadString @ token(0x600001B)+0x142\n\nmanipulate network credentials in .NET\nnamespace  communication/authentication\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x600001B)\n  and:\n    api: System.Net.NetworkCredential::ctor @ token(0x600001B)+0x12B\n\nresolve DNS\nnamespace  communication/dns                                                    \nauthor     william.ballenthin@mandiant.com, johnk3r, joakim@intezer.com,        \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::DNS Communication::Resolve [C0011.001]                \nfunction @ token(0x600001B)\n  or:\n    api: System.Net.Dns::GetHostAddresses @ token(0x600001B)+0xB8\n\nread data from Internet\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Get Response [C0002.017]  \nfunction @ token(0x600001B)\n  and:\n    or:\n      api: System.Net.WebClient::DownloadString @ token(0x600001B)+0x142\n\ncreate TCP socket\nnamespace   communication/socket/tcp                                            \nauthor      william.ballenthin@mandiant.com, joakim@intezer.com,                \n            anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com       \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create TCP Socket [C0001.011]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ token(0x600001B) in function token(0x600001B)\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ token(0x600001B)+0x43, token(0x600001B)+0x5D, token(0x600001B)+0x7B, \ntoken(0x600001B)+0x95, and 13 more...\n        number: 0x6 = IPPROTO_TCP @ token(0x600001B)+0x2\n      number: 0x1 = SOCK_STREAM @ token(0x600001B)+0x1, token(0x600001B)+0x3C, token(0x600001B)+0x56, \ntoken(0x600001B)+0x74, and 9 more...\n      number: 0x2 = AF_INET @ token(0x600001B)+0x0\n      or:\n        api: System.Net.Sockets.Socket::ctor @ token(0x600001B)+0x3\n\ncreate UDP socket\nnamespace   communication/socket/udp/send                                       \nauthor      moritz.raabe@mandiant.com, joakim@intezer.com,                      \n            michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create UDP Socket [C0001.010]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ token(0x600001B) in function token(0x600001B)\n  or:\n    and:\n      number: 0x2 = AF_INET @ token(0x600001B)+0x0\n      or:\n        number: 0x0 = protocol (default) @ token(0x600001B)+0x43, token(0x600001B)+0x5D, token(0x600001B)+0x7B, \ntoken(0x600001B)+0x95, and 13 more...\n      or:\n        api: System.Net.Sockets.Socket::ctor @ token(0x600001B)+0x3\n\ncompress data using GZip in .NET (2 matches)\nnamespace  data-manipulation/compression                                      \nauthor     michael.hunhoff@mandiant.com                                       \nscope      function                                                           \natt&ck     Collection::Archive Collected Data::Archive via Library [T1560.002]\nmbc        Data::Compress Data [C0024]                                        \nfunction @ token(0x60000A2)\n  or:\n    api: System.IO.Compression.GZipStream::ctor @ token(0x60000A2)+0x22\nfunction @ token(0x60000A3)\n  or:\n    api: System.IO.Compression.GZipStream::ctor @ token(0x60000A3)+0x1A\n\ndecode data using Base64 in .NET (3 matches)\nnamespace  data-manipulation/encoding/base64                               \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \natt&ck     Defense Evasion::Deobfuscate/Decode Files or Information [T1140]\nmbc        Data::Decode Data::Base64 [C0053.001]                           \nfunction @ token(0x6000003)\n  or:\n    api: System.Convert::FromBase64String @ token(0x6000003)+0xA, token(0x6000003)+0x109\nfunction @ token(0x6000004)\n  or:\n    api: System.Convert::FromBase64String @ token(0x6000004)+0x37\nfunction @ token(0x600004E)\n  or:\n    api: System.Convert::FromBase64String @ token(0x600004E)+0x7\n\nencode data using Base64\nnamespace  data-manipulation/encoding/base64                                    \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::Base64 [C0026.001]         \nfunction @ token(0x600004C)\n  or:\n    api: System.Convert::ToBase64String @ token(0x600004C)+0x11\n\nhash data with MD5\nnamespace   data-manipulation/hashing/md5                                       \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,         \n            michael.hunhoff@mandiant.com                                        \nscope       function                                                            \nmbc         Cryptography::Cryptographic Hash::MD5 [C0029.001]                   \nreferences  https://github.com/rwfpl/rewolf-x86-virtualizer/blob/master/src/tes…\nfunction @ token(0x600002E)\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Security.Cryptography.MD5CryptoServiceProvider::ctor @ token(0x600002E)+0x0\n      optional:\n        api: System.Security.Cryptography.HashAlgorithm::ComputeHash @ token(0x600002E)+0x12\n\nhash data using SHA256 (2 matches)\nnamespace   data-manipulation/hashing/sha256                                    \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,         \n            william.ballenthin@mandiant.com                                     \nscope       function                                                            \nmbc         Cryptography::Cryptographic Hash::SHA256 [C0029.003]                \nreferences  https://www.rfc-editor.org/rfc/rfc6234                              \nfunction @ token(0x6000052)\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Security.Cryptography.SHA256Managed::ctor @ token(0x6000052)+0xC\n      api: System.Security.Cryptography.HashAlgorithm::ComputeHash @ token(0x6000052)+0x14\nfunction @ token(0x6000053)\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Security.Cryptography.SHA256Managed::ctor @ token(0x6000053)+0x0\n      api: System.Security.Cryptography.HashAlgorithm::ComputeHash @ token(0x6000053)+0x8\n\ngenerate random numbers in .NET\nnamespace  data-manipulation/prng                                            \nauthor     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com     \nscope      function                                                          \nmbc        Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\nfunction @ token(0x600001B)\n  or:\n    api: System.Random::Next @ token(0x600001B)+0x68, token(0x600001B)+0xA0, token(0x600001B)+0x176, \ntoken(0x600001B)+0x26F, and 1 more...\n\nquery environment variable\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ token(0x6000024)\n  or:\n    api: System.Environment::ExpandEnvironmentVariables @ token(0x6000024)+0x5\n\ngenerate random filename in .NET\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x6000024)\n  or:\n    api: System.IO.Path::GetTempFileName @ token(0x6000024)+0x1A0\n\nget common file path (2 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ token(0x6000027)\n  or:\n    property/read: System.Environment::SystemDirectory @ token(0x6000027)+0xA\nfunction @ token(0x600002D)\n  or:\n    property/read: System.Environment::SystemDirectory @ token(0x600002D)+0x2D\n\ndelete file\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ token(0x6000024)\n  or:\n    api: System.IO.File::Delete @ token(0x6000024)+0x16C\n\ncheck if file exists (2 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ token(0x6000024)\n  or:\n    api: System.IO.File::Exists @ token(0x6000024)+0x15C\nfunction @ token(0x600007D)\n  or:\n    api: System.IO.File::Exists @ token(0x600007D)+0x1\n\nread file on Windows\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ token(0x6000024)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x6000024)+0x188\n\nget graphical window text\nnamespace  host-interaction/gui/window/get-text           \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \nmbc        Discovery::Application Window Discovery [E1010]\nfunction @ token(0x6000035)\n  or:\n    and:\n      optional:\n        api: GetForegroundWindow @ token(0x6000035)+0xB\n      api: GetWindowText @ token(0x6000035)+0x16\n\nget number of processors\nnamespace   host-interaction/hardware/cpu                                       \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/bed03d2f849d9060c6…\nfunction @ token(0x600002D)\n  or:\n    property/read: System.Environment::ProcessorCount @ token(0x600002D)+0x8\n\nget disk size (2 matches)\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ token(0x6000027)\n  or:\n    property/read: System.IO.DriveInfo::TotalSize @ token(0x6000027)+0x19\nfunction @ token(0x600002D)\n  or:\n    property/read: System.IO.DriveInfo::TotalSize @ token(0x600002D)+0x3C\n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex                                               \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           mehunhoff@google.com                                                 \nscope      instruction                                                          \nmbc        Process::Create Mutex [C0042]                                        \ninstruction @ token(0x6000036)+0x8\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Threading.Mutex::ctor @ token(0x6000036)+0x8\n\nget hostname (2 matches)\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ token(0x600002D)\n  or:\n    property/read: System.Environment::MachineName @ token(0x600002D)+0x1D\nfunction @ token(0x6000032)\n  or:\n    property/read: System.Environment::MachineName @ token(0x6000032)+0x5\n\nget OS version in .NET (3 matches)\nnamespace  host-interaction/os/version                    \nauthor     michael.hunhoff@mandiant.com                   \nscope      basic block                                    \natt&ck     Discovery::System Information Discovery [T1082]\nbasic block @ token(0x6000028) in function token(0x6000028)\n  or:\n    property/read: Microsoft.VisualBasic.Devices.ComputerInfo::OSFullName @ token(0x6000028)+0x5\nbasic block @ token(0x600002D) in function token(0x600002D)\n  or:\n    property/read: System.Environment::OSVersion @ token(0x600002D)+0x25\nbasic block @ token(0x600002F) in function token(0x600002F)\n  or:\n    property/read: System.Environment::Is64BitOperatingSystem @ token(0x600002F)+0x73\n    property/read: Microsoft.VisualBasic.Devices.ComputerInfo::OSFullName @ token(0x600002F)+0x59\n\nget process image filename\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ token(0x6000024) in function token(0x6000024)\n  or:\n    and:\n      api: System.Diagnostics.Process::GetCurrentProcess @ token(0x6000024)+0x1A\n      property/read: System.Diagnostics.Process::MainModule @ token(0x6000024)+0x1F, token(0x6000024)+0x53\n      property/read: System.Diagnostics.ProcessModule::FileName @ token(0x6000024)+0x24, token(0x6000024)+0x58\n\ncreate a process with modified I/O handles and window\nnamespace   host-interaction/process/create                                     \nauthor      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com      \nscope       function                                                            \nmbc         Process::Create Process [C0017]                                     \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/processthreadsap…\nfunction @ token(0x6000024)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000024)+0xF9, token(0x6000024)+0x25E\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000024)+0x252\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000024)+0xEA, token(0x6000024)+0x259\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000024)+0xA1, token(0x6000024)+0x23D\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000024)+0xE2\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000024)+0xF2, token(0x6000024)+0x244\n\ncreate process on Windows\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ token(0x6000024) in function token(0x6000024)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000024)+0xF9, token(0x6000024)+0x25E\n\nenumerate processes\nnamespace  host-interaction/process/list                                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      function                                                             \natt&ck     Discovery::Process Discovery [T1057], Discovery::Software Discovery  \n           [T1518]                                                              \nfunction @ token(0x6000024)\n  or:\n    api: System.Diagnostics.Process::GetProcesses @ token(0x6000024)+0x3B\n\nenter debug mode in .NET\nnamespace    host-interaction/process/modify                                    \nauthor       @v1bh475u                                                          \nscope        basic block                                                        \nreferences   https://learn.microsoft.com/en-us/dotnet/api/system.diagnostics.pr…\ndescription  Often used by debuggers and malware to attach to and modify other  \n             processes.                                                         \nbasic block @ token(0x600003F) in function token(0x600003F)\n  and:\n    format: dotnet\n    api: System.Diagnostics.Process::EnterDebugMode @ token(0x600003F)+0x11\n\nterminate process (2 matches)\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ token(0x6000001)\n  or:\n    api: System.Environment::Exit @ token(0x6000001)+0x2D, token(0x6000001)+0x3E\nfunction @ token(0x6000024)\n  or:\n    api: System.Diagnostics.Process::Kill @ token(0x6000024)+0x6F\n    api: System.Environment::Exit @ token(0x6000024)+0x265\n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ token(0x6000024)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000024)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000024)+0x114\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000024)+0x114\nfunction @ token(0x6000044)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000044)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000044)+0xB\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000044)+0xB\n\nquery or enumerate registry value\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ token(0x6000042)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000042)\n        or:\n          api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x6000042)+0xA\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x6000042)+0x12\n\nset registry value (3 matches)\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ token(0x6000024)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x6000024)\n          or:\n            api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000024)+0x114\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000024)+0x13D\nfunction @ token(0x6000024)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x6000024)\n          or:\n            api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000024)+0x114\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000024)+0x13D\nfunction @ token(0x6000041)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x6000041)\n          or:\n            api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x6000041)+0xB\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000041)+0x15\n\ndelete registry key\nnamespace  host-interaction/registry/delete                                \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\nscope      function                                                        \natt&ck     Defense Evasion::Modify Registry [T1112]                        \nmbc        Operating System::Registry::Delete Registry Key [C0036.002]     \nfunction @ token(0x6000044)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000044)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000044)+0xB\n    or:\n      api: Microsoft.Win32.RegistryKey::DeleteSubKeyTree @ token(0x6000044)+0x17\n\ndelete registry value\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ token(0x6000043)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000043)\n        or:\n          api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x6000043)+0xA\n    or:\n      api: Microsoft.Win32.RegistryKey::DeleteValue @ token(0x6000043)+0x12\n\nget session integrity level\nnamespace  host-interaction/session                                     \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::System Owner/User Discovery [T1033]               \nfunction @ token(0x6000030)\n  or:\n    and:\n      api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x6000030)+0x0\n      number: 0x220 = BUILTIN\\Administrators @ token(0x6000030)+0xA\n      api: System.Security.Principal.WindowsPrincipal::IsInRole @ token(0x6000030)+0xF\n\nget session user name (3 matches)\nnamespace  host-interaction/session                                             \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope      function                                                             \natt&ck     Discovery::System Owner/User Discovery [T1033], Discovery::Account   \n           Discovery [T1087]                                                    \nfunction @ token(0x600002D)\n  or:\n    property/read: System.Environment::UserName @ token(0x600002D)+0x15\nfunction @ token(0x600002F)\n  or:\n    property/read: System.Environment::UserName @ token(0x600002F)+0x3A\nfunction @ token(0x6000030)\n  or:\n    api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x6000030)+0x0\n\ncreate thread\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ token(0x600001F) in function token(0x600001F)\n  or:\n    and:\n      api: System.Threading.Thread::Start @ token(0x600001F)+0x112\n      optional:\n        api: System.Threading.Thread::ctor @ token(0x600001F)+0x108\n\nsuspend thread (4 matches)\nnamespace  host-interaction/thread/suspend                    \nauthor     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\nscope      basic block                                        \nmbc        Process::Suspend Thread [C0055]                    \nbasic block @ token(0x6000001) in function token(0x6000001)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000001)+0xC, token(0x6000001)+0xBE\nbasic block @ token(0x6000024) in function token(0x6000024)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000024)+0x176\nbasic block @ token(0x6000040) in function token(0x6000040)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000040)+0x13\nbasic block @ token(0x6000048) in function token(0x6000048)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000048)+0x29\n\nexecute via timer in .NET\nnamespace  host-interaction/thread/timer\nauthor     michael.hunhoff@mandiant.com \nscope      function                     \nfunction @ token(0x600001B)\n  or:\n    api: System.Threading.Timer::ctor @ token(0x600001B)+0x288, token(0x600001B)+0x2A1\n\naccess WMI data in .NET (2 matches)\nnamespace  host-interaction/wmi                                 \nauthor     michael.hunhoff@mandiant.com                         \nscope      function                                             \natt&ck     Execution::Windows Management Instrumentation [T1047]\nfunction @ token(0x6000029)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000029)+0xC\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000029)+0x5\nfunction @ token(0x6000032)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000032)+0x26\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000032)+0x19\n\n(internal) .NET file limitation\nnamespace    internal/limitation/dynamic                        \nauthor       @v1bh475u                                          \nscope        file                                               \ndescription  This dynamic analysis trace describes a .NET file. \n                                                                \n             capa rules are not yet tuned for the .NET runtime, \n             so its analysis may be incomplete or misleading.   \n                                                                \nor:\n  format: dotnet\n\nload .NET assembly\nnamespace  load-code/dotnet                                \nauthor     anushka.virgaonkar@mandiant.com                 \nscope      function                                        \natt&ck     Defense Evasion::Reflective Code Loading [T1620]\nfunction @ token(0x6000047)\n  or:\n    api: System.AppDomain::Load @ token(0x6000047)+0x1F\n\nschedule task via schtasks (4 matches)\nnamespace   persistence/scheduled-tasks                                         \nauthor      0x534a@mailbox.org, j.j.vannielen@utwente.nl                        \nscope       function                                                            \natt&ck      Persistence::Scheduled Task/Job::Scheduled Task [T1053.005]         \nreferences  https://learn.microsoft.com/en-us/windows/win32/taskschd/task-sched…\n            https://stmxcsr.com/persistence/scheduled-tasks.html                \nfunction @ token(0x6000024)\n  or:\n    and:\n      match: host-interaction/process/create @ token(0x6000024)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x6000024)+0xF9, token(0x6000024)+0x25E\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x6000024)+0xF9, token(0x6000024)+0x25E\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000024)+0x252\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000024)+0xEA, token(0x6000024)+0x259\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000024)+0xA1, token(0x6000024)+0x23D\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000024)+0xE2\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000024)+0xF2, token(0x6000024)+0x244\n      or:\n        and:\n          regex: /schtasks/i\n            - \"/c schtasks /create /f /sc onlogon /rl highest /tn \\\"\" @ token(0x6000024)+0xB0\n          or:\n            regex: /\\/create/i\n              - \"/c schtasks /create /f /sc onlogon /rl highest /tn \\\"\" @ token(0x6000024)+0xB0\nfunction @ token(0x6000024)\n  or:\n    and:\n      match: host-interaction/process/create @ token(0x6000024)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x6000024)+0xF9, token(0x6000024)+0x25E\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x6000024)+0xF9, token(0x6000024)+0x25E\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000024)+0x252\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000024)+0xEA, token(0x6000024)+0x259\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000024)+0xA1, token(0x6000024)+0x23D\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000024)+0xE2\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000024)+0xF2, token(0x6000024)+0x244\n      or:\n        and:\n          regex: /schtasks/i\n            - \"/c schtasks /create /f /sc onlogon /rl highest /tn \\\"\" @ token(0x6000024)+0xB0\n          or:\n            regex: /\\/create/i\n              - \"/c schtasks /create /f /sc onlogon /rl highest /tn \\\"\" @ token(0x6000024)+0xB0\nfunction @ token(0x6000024)\n  or:\n    and:\n      match: host-interaction/process/create @ token(0x6000024)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x6000024)+0xF9, token(0x6000024)+0x25E\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x6000024)+0xF9, token(0x6000024)+0x25E\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000024)+0x252\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000024)+0xEA, token(0x6000024)+0x259\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000024)+0xA1, token(0x6000024)+0x23D\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000024)+0xE2\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000024)+0xF2, token(0x6000024)+0x244\n      or:\n        and:\n          regex: /schtasks/i\n            - \"/c schtasks /create /f /sc onlogon /rl highest /tn \\\"\" @ token(0x6000024)+0xB0\n          or:\n            regex: /\\/create/i\n              - \"/c schtasks /create /f /sc onlogon /rl highest /tn \\\"\" @ token(0x6000024)+0xB0\nfunction @ token(0x6000024)\n  or:\n    and:\n      match: host-interaction/process/create @ token(0x6000024)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x6000024)+0xF9, token(0x6000024)+0x25E\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x6000024)+0xF9, token(0x6000024)+0x25E\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000024)+0x252\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000024)+0xEA, token(0x6000024)+0x259\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000024)+0xA1, token(0x6000024)+0x23D\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000024)+0xE2\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000024)+0xF2, token(0x6000024)+0x244\n      or:\n        and:\n          regex: /schtasks/i\n            - \"/c schtasks /create /f /sc onlogon /rl highest /tn \\\"\" @ token(0x6000024)+0xB0\n          or:\n            regex: /\\/create/i\n              - \"/c schtasks /create /f /sc onlogon /rl highest /tn \\\"\" @ token(0x6000024)+0xB0\n\nunmanaged call (6 matches)\nnamespace    runtime                                                       \nauthor       michael.hunhoff@mandiant.com                                  \nscope        function                                                      \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nfunction @ token(0x600002A)\n  or:\n    characteristic: unmanaged call @ token(0x600002A)+0xE\nfunction @ token(0x600002B)\n  or:\n    characteristic: unmanaged call @ token(0x600002B)+0x5\nfunction @ token(0x6000034)\n  or:\n    characteristic: unmanaged call @ token(0x6000034)+0x5\nfunction @ token(0x6000035)\n  or:\n    characteristic: unmanaged call @ token(0x6000035)+0xB, token(0x6000035)+0x16\nfunction @ token(0x600003F)\n  or:\n    characteristic: unmanaged call @ token(0x600003F)+0x19\nfunction @ token(0x6000040)\n  or:\n    characteristic: unmanaged call @ token(0x6000040)+0x3\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  format: dotnet\n\n\n\n"},"hashes":{"md5":"74bb3514f737d1386b7ced741ec1e098","sha1":"25de16039754b3870676911b146a956d30b2e8fa","sha256":"02aa8cabeea2a0120a31adbf0886f821d10953fc6d4d9cd1959568093c48b04d"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 157</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 4647</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"seconda\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"74bb3514f737d1386b7ced741ec1e098\",\n        \"sha256\": \"02aa8cabeea2a0120a31adbf0886f821d10953fc6d4d9cd19595680\",\n        \"arch\": \"i386\",\n        \"os\": \"any\",\n        \"format\": \"dotnet\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_Microsoft\",\n      \"label\": \"Microsoft\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_check_for_sandbox_and_av_modules\",\n      \"label\": \"check for sandbox and av modules\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\",\n        \"Anti-Behavioral Analysis::Sandbox Detection [B0007]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetModuleHandle\",\n      \"label\": \"GetModuleHandle\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox\",\n      \"label\": \"author     @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\",\n        \"Anti-Behavioral Analysis::Sandbox Detection [B0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_for_debugger_via_api\",\n      \"label\": \"check for debugger via API\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger\",\n        \"Detection::CheckRemoteDebuggerPresent [B0001.002]\",\n        \"Anti-Behavioral\",\n        \"Analysis::Debugger Detection::WudfIsAnyDebuggerPresent [B0001.031]\"\n      ]\n    },\n    {\n      \"id\": \"api_CheckRemoteDebuggerPresent\",\n      \"label\": \"CheckRemoteDebuggerPresent\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger\",\n        \"Detection::CheckRemoteDebuggerPresent [B0001.002]\",\n        \"Anti-Behavioral\",\n        \"Analysis::Debugger Detection::WudfIsAnyDebuggerPresent [B0001.031]\"\n      ]\n    },\n    {\n      \"id\": \"cap_self_delete__2_matches_\",\n      \"label\": \"self delete (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_System\",\n      \"label\": \"System\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_vmware\",\n      \"label\": \"reference anti-VM strings targeting VMWare\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com___johnk3r\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, @johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_virtualbox\",\n      \"label\": \"reference anti-VM strings targeting VirtualBox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_data\",\n      \"label\": \"receive data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_manipulate_network_credentials_in__net\",\n      \"label\": \"manipulate network credentials in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_resolve_dns\",\n      \"label\": \"resolve DNS\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::DNS Communication::Resolve [C0011.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::DNS Communication::Resolve [C0011.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_data_from_internet\",\n      \"label\": \"read data from Internet\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_tcp_socket\",\n      \"label\": \"create TCP socket\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_udp_socket\",\n      \"label\": \"create UDP socket\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create UDP Socket [C0001.010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_compress_data_using_gzip_in__net__2_matches_\",\n      \"label\": \"compress data using GZip in .NET (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Compress Data [C0024]\"\n      ]\n    },\n    {\n      \"id\": \"cap_decode_data_using_base64_in__net__3_matches_\",\n      \"label\": \"decode data using Base64 in .NET (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decode Data::Base64 [C0053.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encode_data_using_base64\",\n      \"label\": \"encode data using Base64\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_with_md5\",\n      \"label\": \"hash data with MD5\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash::MD5 [C0029.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_using_sha256__2_matches_\",\n      \"label\": \"hash data using SHA256 (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash::SHA256 [C0029.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_william_ballenthin_mandiant_com\",\n      \"label\": \"william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash::SHA256 [C0029.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_in__net\",\n      \"label\": \"generate random numbers in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable\",\n      \"label\": \"query environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_filename_in__net\",\n      \"label\": \"generate random filename in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__2_matches_\",\n      \"label\": \"get common file path (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_file\",\n      \"label\": \"delete file\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__2_matches_\",\n      \"label\": \"check if file exists (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows\",\n      \"label\": \"read file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_graphical_window_text\",\n      \"label\": \"get graphical window text\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetWindowText\",\n      \"label\": \"GetWindowText\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetForegroundWindow\",\n      \"label\": \"GetForegroundWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_number_of_processors\",\n      \"label\": \"get number of processors\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_disk_size__2_matches_\",\n      \"label\": \"get disk size (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_or_open_mutex_on_windows\",\n      \"label\": \"create or open mutex on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_mehunhoff_google_com\",\n      \"label\": \"mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_hostname__2_matches_\",\n      \"label\": \"get hostname (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_os_version_in__net__3_matches_\",\n      \"label\": \"get OS version in .NET (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_process_image_filename\",\n      \"label\": \"get process image filename\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_a_process_with_modified_i_o_handles_and_window\",\n      \"label\": \"create a process with modified I/O handles and window\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows\",\n      \"label\": \"create process on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_processes\",\n      \"label\": \"enumerate processes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\",\n        \"Discovery::Software Discovery\",\n        \"[T1518]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enter_debug_mode_in__net\",\n      \"label\": \"enter debug mode in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author________v1bh475u\",\n      \"label\": \"author       @v1bh475u\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_terminate_process__2_matches_\",\n      \"label\": \"terminate process (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"label\": \"query or enumerate registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value\",\n      \"label\": \"query or enumerate registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_registry_value__3_matches_\",\n      \"label\": \"set registry value (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_key\",\n      \"label\": \"delete registry key\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_value\",\n      \"label\": \"delete registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_session_integrity_level\",\n      \"label\": \"get session integrity level\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_session_user_name__3_matches_\",\n      \"label\": \"get session user name (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\",\n        \"Discovery::Account\",\n        \"Discovery [T1087]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_thread\",\n      \"label\": \"create thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_suspend_thread__4_matches_\",\n      \"label\": \"suspend thread (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Suspend Thread [C0055]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Suspend Thread [C0055]\"\n      ]\n    },\n    {\n      \"id\": \"cap_execute_via_timer_in__net\",\n      \"label\": \"execute via timer in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_access_wmi_data_in__net__2_matches_\",\n      \"label\": \"access WMI data in .NET (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Windows Management Instrumentation [T1047]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal___net_file_limitation\",\n      \"label\": \"(internal) .NET file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_load__net_assembly\",\n      \"label\": \"load .NET assembly\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_schedule_task_via_schtasks__4_matches_\",\n      \"label\": \"schedule task via schtasks (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Scheduled Task/Job::Scheduled Task [T1053.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______0x534a_mailbox_org__j_j_vannielen_utwente_nl\",\n      \"label\": \"author      0x534a@mailbox.org, j.j.vannielen@utwente.nl\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Scheduled Task/Job::Scheduled Task [T1053.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_unmanaged_call__6_matches_\",\n      \"label\": \"unmanaged call (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"label\": \"author       michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compiled_to_the__net_platform\",\n      \"label\": \"compiled to the .NET platform\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_sandbox_and_av_modules\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_debugger_via_api\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_self_delete__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_vmware\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com___johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_virtualbox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_manipulate_network_credentials_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_dns\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_data_from_internet\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_tcp_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_udp_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compress_data_using_gzip_in__net__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decode_data_using_base64_in__net__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encode_data_using_base64\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_md5\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_sha256__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_filename_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_graphical_window_text\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_number_of_processors\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_mutex_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version_in__net__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_process_image_filename\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_a_process_with_modified_i_o_handles_and_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_processes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enter_debug_mode_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________v1bh475u\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_integrity_level\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_user_name__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_suspend_thread__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_execute_via_timer_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_wmi_data_in__net__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal___net_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_load__net_assembly\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_schedule_task_via_schtasks__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______0x534a_mailbox_org__j_j_vannielen_utwente_nl\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_unmanaged_call__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_to_the__net_platform\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-04-29 18:18:27.618563\",\n    \"total_functions\": \"157\",\n    \"total_features\": \"4647\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-04-29 18:18:28"}
{"_id":{"$oid":"69edf1b159a6632dae07de54"},"sha256":"6ba13af0263cd61f957f2ce738120c8a419e1eb157e489bc79f1d57ad8277324","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":true,"path":"/tmp/sdm_capa_618p8xof/3_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_618p8xof/3_very_verbose.txt"}},"outputs":{"normal":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"md5                     c2bf2a9e6beaff5b5321917475545ef4                        \nsha1                    7b33e010b7a815cbf97cc04b3adbfc009791b727                \nsha256                  6ba13af0263cd61f957f2ce738120c8a419e1eb157e489bc79f1d57…\npath                    /home/apogean/projects/malware/windows/all_runs/3       \ntimestamp               2026-04-27 00:05:11.323866                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x140000000                                             \nrules                   /tmp/_MEI3gMxmZ/rules                                   \nfunction count          84                                                      \nlibrary function count  16                                                      \ntotal feature count     31900                                                   \n\nreference anti-VM strings targeting Xen\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\npackaged as an IExpress self-extracting archive\nnamespace  executable/installer/iexpress\nscope      file                         \n\nextract resource via kernel32 functions (5 matches)\nnamespace  executable/resource\nscope      function           \nmatches    0x140002DB4        \n           0x140005050        \n           0x140005D90        \n           0x14000772C        \n           0x140007AC8        \n\nquery environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x14000261C                          \n\nget common file path (10 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x140001D28                 \n           0x140002244                 \n           0x140002468                 \n           0x14000261C                 \n           0x1400030EC                 \n           0x1400040C4                 \n           0x140004A60                 \n           0x1400063B8                 \n           0x1400066C4                 \n           0x140006CA4                 \n\nset current directory (3 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x1400030EC                 \n           0x1400061EC                 \n           0x140006CA4                 \n\ncreate directory (5 matches)\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x140003530                        \n           0x140005380                        \n           0x1400063B8                        \n           0x1400064E4                        \n           0x1400066C4                        \n\ndelete directory (3 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x14000204C                        \n           0x1400063B8                        \n           0x1400064E4                        \n\ndelete file (3 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x14000204C                        \n           0x1400061EC                        \n           0x1400063B8                        \n\ncheck if file exists (7 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x140001684                        \n           0x140003530                        \n           0x1400051BC                        \n           0x1400063B8                        \n           0x1400066C4                        \n           0x140006B70                        \n           0x1400079F0                        \n\nenumerate files on Windows\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x14000204C                            \n\nenumerate files recursively\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x14000204C                            \n\nget file attributes (9 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x14000184D                      \n           0x140001AEB                      \n           0x140003694                      \n           0x1400051BC                      \n           0x1400063E3                      \n           0x140006916                      \n           0x140006A16                      \n           0x140006C61                      \n           0x140007A44                      \n\nget file version info\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x140002834                      \n\nset file attributes (5 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x1400021A3                      \n           0x140005246                      \n           0x140005A06                      \n           0x140006229                      \n           0x140006A6D                      \n\nread .ini file\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x140001684                      \n\nread file on Windows\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x1400055E0                      \n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x140005690                       \n           0x1400078B0                       \n\nget disk information (2 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x1400066C4                      \n           0x140006CA4                      \n\nget disk size (2 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x1400066C4                      \n           0x140006CA4                      \n\ncheck mutex on Windows\nnamespace  host-interaction/mutex\nscope      function              \nmatches    0x140002DB4           \n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex\nscope      instruction           \nmatches    0x140002F06           \n\nshutdown system (2 matches)\nnamespace  host-interaction/os\nscope      function           \nmatches    0x140001C0C        \n           0x140002C54        \n\nget system information on Windows\nnamespace  host-interaction/os/info\nscope      function                \nmatches    0x1400064E4             \n\ncheck OS version (3 matches)\nnamespace  host-interaction/os/version\nscope      function                   \nmatches    0x140002C54                \n           0x140003BF4                \n           0x140007F04                \n\ncreate process on Windows\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x14000473C                    \n\nmodify access privileges\nnamespace  host-interaction/process/modify\nscope      instruction                    \nmatches    0x140001CB2                    \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x140008218                       \n\nquery or enumerate registry key\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x140002318              \n\nquery or enumerate registry value (5 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x140001D28              \n           0x140002318              \n           0x14000261C              \n           0x1400040C4              \n           0x140007F04              \n\nset registry value (2 matches)\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x140001D28                     \n           0x1400040C4                     \n\ndelete registry value\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x1400061EC                     \n\ncompare security identifiers\nnamespace  host-interaction/sid\nscope      basic block         \nmatches    0x140001452         \n\ncreate thread\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x140003A9B                   \n\nterminate thread\nnamespace  host-interaction/thread/terminate\nscope      basic block                      \nmatches    0x14000395B                      \n\nlink function at runtime on Windows (8 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x14000122B            \n           0x140001E90            \n           0x140002CA1            \n           0x1400031A9            \n           0x1400043AF            \n           0x140004AAA            \n           0x140004ACA            \n           0x140004AEC            \n\nparse PE header (2 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x1400080D0 \n           0x1400087BC \n\npersist via Run registry key (5 matches)\nnamespace  persistence/registry/run\nscope      function                \nmatches    0x140001D28             \n           0x140001D28             \n           0x1400040C4             \n           0x1400040C4             \n           0x1400061EC             \n\n\n\n","very_verbose":"md5                     c2bf2a9e6beaff5b5321917475545ef4                        \nsha1                    7b33e010b7a815cbf97cc04b3adbfc009791b727                \nsha256                  6ba13af0263cd61f957f2ce738120c8a419e1eb157e489bc79f1d57…\npath                    /home/apogean/projects/malware/windows/all_runs/3       \ntimestamp               2026-04-27 00:05:26.527665                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x140000000                                             \nrules                   /tmp/_MEI8zV991/rules                                   \nfunction count          84                                                      \nlibrary function count  16                                                      \ntotal feature count     31900                                                   \n\ncontain loop (37 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x1400012EC\n  or:\n    characteristic: loop @ 0x1400012EC\n\ncreate or open file (4 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x1400054C5\n  or:\n    api: CreateFile @ 0x1400054C5\n\ncreate or open registry key (7 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x140001D28 in function 0x140001D28\n  or:\n    api: RegCreateKeyEx @ 0x140001DBA\n\ndelay execution (3 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x140003B4C in function 0x140003B40\n  or:\n    and:\n      os: windows\n      or:\n        api: MsgWaitForMultipleObjects @ 0x140003B64\n\nget OS version (3 matches, only showing first match of library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x140002C54\n  or:\n    api: GetVersion @ 0x140002C69\n\nreference anti-VM strings targeting Xen\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /^Xen/i\n    - \"XeN>\" @ file+0x242553\n\npackaged as an IExpress self-extracting archive\nnamespace   executable/installer/iexpress         \nauthor      awillia2@cisco.com                    \nscope       file                                  \nreferences  https://en.wikipedia.org/wiki/IExpress\nor:\n  string: \"  <description>IExpress extraction tool</description>\" @ file+0x274D5E\n  and:\n    string: \"wextract_cleanup%d\" @ file+0xA4C0\n    string: \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\RunOnce\" @ file+0xA488\n\nextract resource via kernel32 functions (5 matches)\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x140002DB4\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x140003005\n      optional:\n        or:\n          api: FindResource @ 0x140002FEE\nfunction @ 0x140005050\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x1400050C0\n        api: LockResource @ 0x1400050CF\n      optional:\n        or:\n          api: FindResource @ 0x140005078, 0x1400050AF\n        api: SizeofResource @ 0x140005089\n        api: FreeResource @ 0x1400050FD\nfunction @ 0x140005D90\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x140005DD1\n        api: LockResource @ 0x140005DE0\n      optional:\n        or:\n          api: FindResource @ 0x140005DC0\n        api: FreeResource @ 0x140005F61\nfunction @ 0x14000772C\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x140007763\n        api: LockResource @ 0x140007772\n      optional:\n        or:\n          api: FindResource @ 0x1400077EC\n        api: FreeResource @ 0x1400077B8, 0x140007805\nfunction @ 0x140007AC8\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x140007B09\n      optional:\n        or:\n          api: FindResource @ 0x140007AF2\n        api: FreeResource @ 0x140007B51\n\nquery environment variable\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x14000261C\n  or:\n    api: ExpandEnvironmentStrings @ 0x140002782\n\nget common file path (10 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x140001D28\n  or:\n    api: GetSystemDirectory @ 0x140001E4C, 0x140001EC5\nfunction @ 0x140002244\n  or:\n    api: GetWindowsDirectory @ 0x140002271\nfunction @ 0x140002468\n  or:\n    api: GetWindowsDirectory @ 0x140002494\nfunction @ 0x14000261C\n  or:\n    api: GetSystemDirectory @ 0x1400027E5\n    api: GetWindowsDirectory @ 0x1400027CF\nfunction @ 0x1400030EC\n  or:\n    api: GetSystemDirectory @ 0x140003167\n    api: GetWindowsDirectory @ 0x1400031FD\nfunction @ 0x1400040C4\n  or:\n    api: GetSystemDirectory @ 0x14000468D\nfunction @ 0x140004A60\n  or:\n    api: GetTempPath @ 0x140004B1B\nfunction @ 0x1400063B8\n  or:\n    api: GetTempFileName @ 0x14000645B\nfunction @ 0x1400066C4\n  or:\n    api: GetTempPath @ 0x140006862\n    api: GetWindowsDirectory @ 0x140006A0A, 0x140006AE3\nfunction @ 0x140006CA4\n  or:\n    api: GetCurrentDirectory @ 0x140006CEE\n\nset current directory (3 matches)\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x1400030EC\n  or:\n    api: SetCurrentDirectory @ 0x14000327A\nfunction @ 0x1400061EC\n  or:\n    api: SetCurrentDirectory @ 0x1400062FB\nfunction @ 0x140006CA4\n  or:\n    api: SetCurrentDirectory @ 0x140006CFD, 0x140006E4A, 0x140006FDD\n\ncreate directory (5 matches)\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x140003530\n  or:\n    api: CreateDirectory @ 0x1400036D9\nfunction @ 0x140005380\n  or:\n    api: CreateDirectory @ 0x14000553A\nfunction @ 0x1400063B8\n  or:\n    api: CreateDirectory @ 0x140006484, 0x1400064BB\nfunction @ 0x1400064E4\n  or:\n    api: CreateDirectory @ 0x14000662F\nfunction @ 0x1400066C4\n  or:\n    api: CreateDirectory @ 0x140006A47\n\ndelete directory (3 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ 0x14000204C\n  or:\n    api: RemoveDirectory @ 0x140002207\nfunction @ 0x1400063B8\n  or:\n    api: RemoveDirectory @ 0x140006423\nfunction @ 0x1400064E4\n  or:\n    api: RemoveDirectory @ 0x14000666F\n\ndelete file (3 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x14000204C\n  or:\n    api: DeleteFile @ 0x1400021CD\nfunction @ 0x1400061EC\n  or:\n    api: DeleteFile @ 0x140006240\nfunction @ 0x1400063B8\n  or:\n    api: DeleteFile @ 0x140006473\n\ncheck if file exists (7 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x140001684\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x140001AF0\n        instruction:\n          and:\n            mnemonic: cmp @ 0x140001AFC\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x140001AFC\n      and:\n        api: GetFileAttributes @ 0x140001852\n        instruction:\n          and:\n            mnemonic: cmp @ 0x14000185E\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x14000185E\nfunction @ 0x140003530\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x140003697\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1400036A3\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x1400036A3\nfunction @ 0x1400051BC\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x1400051C9\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1400051D5\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x1400051D5\nfunction @ 0x1400063B8\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x140006432\n        instruction:\n          and:\n            mnemonic: cmp @ 0x14000643E\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x14000643E\nfunction @ 0x1400066C4\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x14000691B\n        instruction:\n          and:\n            mnemonic: cmp @ 0x140006927\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x140006927\n      and:\n        api: GetFileAttributes @ 0x140006A2F\n        instruction:\n          and:\n            mnemonic: cmp @ 0x140006A3B\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x140006A3B\nfunction @ 0x140006B70\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x140006C73\n        instruction:\n          and:\n            mnemonic: cmp @ 0x140006C7F\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x140006C7F\nfunction @ 0x1400079F0\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x140007A68\n        instruction:\n          and:\n            mnemonic: cmp @ 0x140007A74\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x140007A74\n\nenumerate files on Windows\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ 0x14000204C\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x1400020E5\n      or:\n        api: FindNextFile @ 0x1400021E1\n      optional:\n        api: FindClose @ 0x1400021F8\n        match: contain loop @ 0x14000204C\n          or:\n            characteristic: loop @ 0x14000204C\n            characteristic: recursive call @ 0x14000204C\n\nenumerate files recursively\nnamespace  host-interaction/file-system/files/list        \nauthor     @_re_fox, anushka.virgaonkar@mandiant.com      \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nmbc        Discovery::File and Directory Discovery [E1083]\nfunction @ 0x14000204C\n  and:\n    characteristic: recursive call @ 0x14000204C\n    or:\n      match: enumerate files on Windows @ 0x14000204C\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x1400020E5\n            or:\n              api: FindNextFile @ 0x1400021E1\n            optional:\n              api: FindClose @ 0x1400021F8\n              match: contain loop @ 0x14000204C\n                or:\n                  characteristic: loop @ 0x14000204C\n                  characteristic: recursive call @ 0x14000204C\n\nget file attributes (9 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x14000184D in function 0x140001684\n  or:\n    api: GetFileAttributes @ 0x140001852\nbasic block @ 0x140001AEB in function 0x140001684\n  or:\n    api: GetFileAttributes @ 0x140001AF0\nbasic block @ 0x140003694 in function 0x140003530\n  or:\n    api: GetFileAttributes @ 0x140003697\nbasic block @ 0x1400051BC in function 0x1400051BC\n  or:\n    api: GetFileAttributes @ 0x1400051C9\nbasic block @ 0x1400063E3 in function 0x1400063B8\n  or:\n    api: GetFileAttributes @ 0x140006432\nbasic block @ 0x140006916 in function 0x1400066C4\n  or:\n    api: GetFileAttributes @ 0x14000691B\nbasic block @ 0x140006A16 in function 0x1400066C4\n  or:\n    api: GetFileAttributes @ 0x140006A2F\nbasic block @ 0x140006C61 in function 0x140006B70\n  or:\n    api: GetFileAttributes @ 0x140006C73\nbasic block @ 0x140007A44 in function 0x1400079F0\n  or:\n    api: GetFileAttributes @ 0x140007A68\n\nget file version info\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x140002834\n  and:\n    or:\n      api: GetFileVersionInfo @ 0x14000290C\n    optional: = retrieve specified version information from the version-information resource\n      api: VerQueryValue @ 0x140002932\n      or:\n        api: GetFileVersionInfoSize @ 0x1400028AC\n\nset file attributes (5 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ 0x1400021A3 in function 0x14000204C\n  or:\n    api: SetFileAttributes @ 0x1400021BD\nbasic block @ 0x140005246 in function 0x1400051BC\n  or:\n    api: SetFileAttributes @ 0x14000524E\nbasic block @ 0x140005A06 in function 0x1400058B0\n  or:\n    api: SetFileAttributes @ 0x140005A0B\nbasic block @ 0x140006229 in function 0x1400061EC\n  or:\n    api: SetFileAttributes @ 0x140006231\nbasic block @ 0x140006A6D in function 0x1400066C4\n  or:\n    api: SetFileAttributes @ 0x140006A77\n\nread .ini file\nnamespace  host-interaction/file-system/read     \nauthor     @_re_fox, michael.hunhoff@mandiant.com\nscope      function                              \nmbc        File System::Read File [C0051]        \nfunction @ 0x140001684\n  and:\n    or:\n      api: GetPrivateProfileInt @ 0x1400018FC\n      api: GetPrivateProfileString @ 0x14000193F\n\nread file on Windows\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x1400055E0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x140005651\n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x140005690\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x1400056E4\nfunction @ 0x1400078B0\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x140007956\n            number: 0x2 = FILE_WRITE_DATA @ 0x14000794E\n            match: create or open file @ 0x14000795B\n              or:\n                api: CreateFile @ 0x14000795B\n      or:\n        api: WriteFile @ 0x140007992\n\nget disk information (2 matches)\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ 0x1400066C4\n  or:\n    api: GetDriveType @ 0x1400068FE\nfunction @ 0x140006CA4\n  or:\n    api: GetVolumeInformation @ 0x140006DD6\n\nget disk size (2 matches)\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ 0x1400066C4\n  or:\n    api: GetDiskFreeSpace @ 0x140006973\nfunction @ 0x140006CA4\n  or:\n    api: GetDiskFreeSpace @ 0x140006D6C\n\ncheck mutex on Windows\nnamespace  host-interaction/mutex                         \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      function                                       \nmbc        Process::Check Mutex [C0043]                   \nfunction @ 0x140002DB4\n  or:\n    and:\n      match: create or open mutex on Windows @ 0x140002F06\n        or:\n          api: CreateMutex @ 0x140002F06\n      or:\n        basic block:\n          and:\n            api: GetLastError @ 0x140002F22\n            or:\n              number: 0xB7 = ERROR_ALREADY_EXISTS @ 0x140002F2E\n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex                                               \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           mehunhoff@google.com                                                 \nscope      instruction                                                          \nmbc        Process::Create Mutex [C0042]                                        \ninstruction @ 0x140002F06\n  or:\n    api: CreateMutex @ 0x140002F06\n\nshutdown system (2 matches)\nnamespace  host-interaction/os                   \nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \natt&ck     Impact::System Shutdown/Reboot [T1529]\nfunction @ 0x140001C0C\n  or:\n    api: ExitWindowsEx @ 0x140001CF1\nfunction @ 0x140002C54\n  or:\n    api: ExitWindowsEx @ 0x140002D6C\n\nget system information on Windows\nnamespace  host-interaction/os/info                       \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com  \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x1400064E4\n  and:\n    os: windows\n    or:\n      api: GetSystemInfo @ 0x14000657C\n\ncheck OS version (3 matches)\nnamespace  host-interaction/os/version                    \nauthor     michael.hunhoff@mandiant.com, johnk3r          \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x140002C54\n  and:\n    match: get OS version @ 0x140002C54\n      or:\n        api: GetVersion @ 0x140002C69\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x140002D59\n            number: 0x6 = Windows Vista / Windows Server 2008 @ 0x140002D59\n          and:\n            mnemonic: cmp @ 0x140002C7B\n            number: 0x6 = Windows Vista / Windows Server 2008 @ 0x140002C7B\nfunction @ 0x140003BF4\n  and:\n    match: get OS version @ 0x140003BF4\n      or:\n        api: GetVersionEx @ 0x140003C3F\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x140003CC2\n            number: 0x5 = Windows 2000 @ 0x140003CC2\n        optional:\n          instruction:\n            and:\n              mnemonic: cmp @ 0x140003C70\n              or:\n                number: 0x1 = Windows XP @ 0x140003C70\n            and:\n              mnemonic: cmp @ 0x140003E28\n              or:\n                number: 0x2 = Windows XP 64-bit / Windows Server 2003 / Windows Server 2003 R2 @ 0x140003E28\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x140003F05\n            number: 0x6 = Windows Vista / Windows Server 2008 @ 0x140003F05\n        optional:\n          instruction:\n            and:\n              mnemonic: cmp @ 0x140003C70\n              or:\n                number: 0x1 = Windows Server 2008 R2 / Windows 7 @ 0x140003C70\n            and:\n              mnemonic: cmp @ 0x140003E28\n              or:\n                number: 0x2 = Windows Server 2012 / Windows 8 @ 0x140003E28\nfunction @ 0x140007F04\n  and:\n    match: get OS version @ 0x140007F04\n      or:\n        api: GetVersionEx @ 0x140007F59\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x140008057\n            number: 0x5 = Windows 2000 @ 0x140008057\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x140007F85\n            number: 0xA = Windows Server 2016 / Windows Server 2019 / Windows 10 @ 0x140007F85\n\ncreate process on Windows\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x14000473C in function 0x14000473C\n  or:\n    api: CreateProcess @ 0x1400047AE\n\nmodify access privileges\nnamespace  host-interaction/process/modify                        \nauthor     moritz.raabe@mandiant.com                              \nscope      instruction                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\ninstruction @ 0x140001CB2\n  and:\n    api: AdjustTokenPrivileges @ 0x140001CB2\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x140008218\n  or:\n    api: exit @ 0x1400083C9\n\nquery or enumerate registry key\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ 0x140002318\n  and:\n    optional:\n      match: create or open registry key @ 0x14000234A, 0x1400023CB\n        or:\n          api: RegOpenKeyEx @ 0x14000236D\n        or:\n          api: RegOpenKeyEx @ 0x1400023EE\n    or:\n      api: RegQueryInfoKeyA @ 0x140002436\n\nquery or enumerate registry value (5 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x140001D28\n  and:\n    optional:\n      match: create or open registry key @ 0x140001D28\n        or:\n          api: RegCreateKeyEx @ 0x140001DBA\n    or:\n      api: RegQueryValueEx @ 0x140001E0F\nfunction @ 0x140002318\n  and:\n    optional:\n      match: create or open registry key @ 0x14000234A, 0x1400023CB\n        or:\n          api: RegOpenKeyEx @ 0x14000236D\n        or:\n          api: RegOpenKeyEx @ 0x1400023EE\n    or:\n      api: RegQueryValueEx @ 0x14000239C\nfunction @ 0x14000261C\n  and:\n    optional:\n      match: create or open registry key @ 0x1400026E5\n        or:\n          api: RegOpenKeyEx @ 0x140002724\n    or:\n      api: RegQueryValueEx @ 0x14000275B\nfunction @ 0x1400040C4\n  and:\n    optional:\n      match: create or open registry key @ 0x1400045F2\n        or:\n          api: RegOpenKeyEx @ 0x140004613\n    or:\n      api: RegQueryValueEx @ 0x140004658\nfunction @ 0x140007F04\n  and:\n    optional:\n      match: create or open registry key @ 0x140007FA7\n        or:\n          api: RegOpenKeyEx @ 0x140007FC8\n    or:\n      api: RegQueryValueEx @ 0x140008003\n\nset registry value (2 matches)\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x140001D28\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x140001D28\n          or:\n            api: RegCreateKeyEx @ 0x140001DBA\n      or:\n        api: RegSetValueEx @ 0x140001FED\nfunction @ 0x1400040C4\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x1400045F2\n          or:\n            api: RegOpenKeyEx @ 0x140004613\n      or:\n        api: RegSetValueEx @ 0x140004710\n\ndelete registry value\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ 0x1400061EC\n  and:\n    optional:\n      match: create or open registry key @ 0x14000632D\n        or:\n          api: RegOpenKeyEx @ 0x14000634E\n    or:\n      api: RegDeleteValue @ 0x14000636A\n\ncompare security identifiers\nnamespace  host-interaction/sid        \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ 0x140001452 in function 0x1400012EC\n  or:\n    api: EqualSid @ 0x140001460\n\ncreate thread\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x140003A9B in function 0x140003910\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x140003AD0\n\nterminate thread\nnamespace  host-interaction/thread/terminate                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \nmbc        Process::Terminate Thread [C0039]                                    \nbasic block @ 0x14000395B in function 0x140003910\n  or:\n    api: TerminateThread @ 0x140003964\n\n(internal) installer file limitation\nnamespace    internal/limitation/static                                         \nauthor       william.ballenthin@mandiant.com                                    \nscope        file                                                               \ndescription  This sample appears to be an installer.                            \n                                                                                \n             capa cannot handle installers well. This means the results may be  \n             misleading or incomplete.                                          \n             You should try to understand the install mechanism and analyze     \n             created files with capa.                                           \n                                                                                \nor:\n  match: executable/installer @ global\n    or:\n      string: \"  <description>IExpress extraction tool</description>\" @ file+0x274D5E\n      and:\n        string: \"wextract_cleanup%d\" @ file+0xA4C0\n        string: \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\RunOnce\" @ file+0xA488\n\nlink function at runtime on Windows (8 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x14000122B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x14000122B\ninstruction @ 0x140001E90\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x140001E90\ninstruction @ 0x140002CA1\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x140002CA1\ninstruction @ 0x1400031A9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400031A9\ninstruction @ 0x1400043AF\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400043AF\ninstruction @ 0x140004AAA\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x140004AAA\ninstruction @ 0x140004ACA\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x140004ACA\ninstruction @ 0x140004AEC\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x140004AEC\n\nparse PE header (2 matches)\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x1400080D0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1400080D9, 0x1400080F7, 0x140008104, 0x14000810F, and 5 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x1400080F7\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x1400080D4\nfunction @ 0x1400087BC\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1400087C6, 0x1400087D1, 0x1400087D6, 0x1400087DB, and 1 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x1400087EF\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x1400087CC\n\npersist via Run registry key (5 matches)\nnamespace  persistence/registry/run                                             \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com                      \nscope      function                                                             \natt&ck     Persistence::Boot or Logon Autostart Execution::Registry Run Keys /  \n           Startup Folder [T1547.001]                                           \nmbc        Persistence::Registry Run Keys / Startup Folder [F0012]              \nfunction @ 0x140001D28\n  and:\n    or:\n      match: set registry value @ 0x140001D28\n        or:\n          and:\n            optional:\n              match: create or open registry key @ 0x140001D28\n                or:\n                  api: RegCreateKeyEx @ 0x140001DBA\n            or:\n              api: RegSetValueEx @ 0x140001FED\n      number: 0x80000002 = HKEY_LOCAL_MACHINE @ 0x140001DA6\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\RunOnce\" @ 0x140001D8A\nfunction @ 0x140001D28\n  and:\n    or:\n      match: set registry value @ 0x140001D28\n        or:\n          and:\n            optional:\n              match: create or open registry key @ 0x140001D28\n                or:\n                  api: RegCreateKeyEx @ 0x140001DBA\n            or:\n              api: RegSetValueEx @ 0x140001FED\n      number: 0x80000002 = HKEY_LOCAL_MACHINE @ 0x140001DA6\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\RunOnce\" @ 0x140001D8A\nfunction @ 0x1400040C4\n  and:\n    or:\n      match: set registry value @ 0x1400040C4\n        or:\n          and:\n            optional:\n              match: create or open registry key @ 0x1400045F2\n                or:\n                  api: RegOpenKeyEx @ 0x140004613\n            or:\n              api: RegSetValueEx @ 0x140004710\n      number: 0x80000002 = HKEY_LOCAL_MACHINE @ 0x14000460C\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\RunOnce\" @ 0x140004605\nfunction @ 0x1400040C4\n  and:\n    or:\n      match: set registry value @ 0x1400040C4\n        or:\n          and:\n            optional:\n              match: create or open registry key @ 0x1400045F2\n                or:\n                  api: RegOpenKeyEx @ 0x140004613\n            or:\n              api: RegSetValueEx @ 0x140004710\n      number: 0x80000002 = HKEY_LOCAL_MACHINE @ 0x14000460C\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\RunOnce\" @ 0x140004605\nfunction @ 0x1400061EC\n  and:\n    or:\n      number: 0x80000002 = HKEY_LOCAL_MACHINE @ 0x140006347\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\RunOnce\" @ 0x140006340\n\n\n\n"},"hashes":{"md5":"c2bf2a9e6beaff5b5321917475545ef4","sha1":"7b33e010b7a815cbf97cc04b3adbfc009791b727","sha256":"6ba13af0263cd61f957f2ce738120c8a419e1eb157e489bc79f1d57ad8277324"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 84</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 31900</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"3\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"c2bf2a9e6beaff5b5321917475545ef4\",\n        \"sha256\": \"6ba13af0263cd61f957f2ce738120c8a419e1eb157e489bc79f1d57\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__37_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (37 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1400012EC\",\n      \"label\": \"Function 0x1400012EC\",\n      \"type\": \"function\",\n      \"address\": \"0x1400012EC\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x140001D28\",\n      \"label\": \"Block 0x140001D28\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140001D28\"\n    },\n    {\n      \"id\": \"api_RegCreateKeyEx\",\n      \"label\": \"RegCreateKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__3_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (3 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x140003B4C\",\n      \"label\": \"Block 0x140003B4C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140003B4C\"\n    },\n    {\n      \"id\": \"api_MsgWaitForMultipleObjects\",\n      \"label\": \"MsgWaitForMultipleObjects\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_os_version__3_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"get OS version (3 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x140002C54\",\n      \"label\": \"Function 0x140002C54\",\n      \"type\": \"function\",\n      \"address\": \"0x140002C54\"\n    },\n    {\n      \"id\": \"api_GetVersion\",\n      \"label\": \"GetVersion\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"label\": \"reference anti-VM strings targeting Xen\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_packaged_as_an_iexpress_self_extracting_archive\",\n      \"label\": \"packaged as an IExpress self-extracting archive\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author______awillia2_cisco_com\",\n      \"label\": \"author      awillia2@cisco.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions__5_matches_\",\n      \"label\": \"extract resource via kernel32 functions (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x14000772C\",\n      \"label\": \"Function 0x14000772C\",\n      \"type\": \"function\",\n      \"address\": \"0x14000772C\"\n    },\n    {\n      \"id\": \"func_0x140005D90\",\n      \"label\": \"Function 0x140005D90\",\n      \"type\": \"function\",\n      \"address\": \"0x140005D90\"\n    },\n    {\n      \"id\": \"func_0x140002DB4\",\n      \"label\": \"Function 0x140002DB4\",\n      \"type\": \"function\",\n      \"address\": \"0x140002DB4\"\n    },\n    {\n      \"id\": \"func_0x140005050\",\n      \"label\": \"Function 0x140005050\",\n      \"type\": \"function\",\n      \"address\": \"0x140005050\"\n    },\n    {\n      \"id\": \"func_0x140007AC8\",\n      \"label\": \"Function 0x140007AC8\",\n      \"type\": \"function\",\n      \"address\": \"0x140007AC8\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FreeResource\",\n      \"label\": \"FreeResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_query_environment_variable\",\n      \"label\": \"query environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14000261C\",\n      \"label\": \"Function 0x14000261C\",\n      \"type\": \"function\",\n      \"address\": \"0x14000261C\"\n    },\n    {\n      \"id\": \"api_ExpandEnvironmentStrings\",\n      \"label\": \"ExpandEnvironmentStrings\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path__10_matches_\",\n      \"label\": \"get common file path (10 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400030EC\",\n      \"label\": \"Function 0x1400030EC\",\n      \"type\": \"function\",\n      \"address\": \"0x1400030EC\"\n    },\n    {\n      \"id\": \"func_0x1400040C4\",\n      \"label\": \"Function 0x1400040C4\",\n      \"type\": \"function\",\n      \"address\": \"0x1400040C4\"\n    },\n    {\n      \"id\": \"func_0x140002468\",\n      \"label\": \"Function 0x140002468\",\n      \"type\": \"function\",\n      \"address\": \"0x140002468\"\n    },\n    {\n      \"id\": \"func_0x1400063B8\",\n      \"label\": \"Function 0x1400063B8\",\n      \"type\": \"function\",\n      \"address\": \"0x1400063B8\"\n    },\n    {\n      \"id\": \"func_0x1400066C4\",\n      \"label\": \"Function 0x1400066C4\",\n      \"type\": \"function\",\n      \"address\": \"0x1400066C4\"\n    },\n    {\n      \"id\": \"func_0x140004A60\",\n      \"label\": \"Function 0x140004A60\",\n      \"type\": \"function\",\n      \"address\": \"0x140004A60\"\n    },\n    {\n      \"id\": \"func_0x140002244\",\n      \"label\": \"Function 0x140002244\",\n      \"type\": \"function\",\n      \"address\": \"0x140002244\"\n    },\n    {\n      \"id\": \"func_0x140006CA4\",\n      \"label\": \"Function 0x140006CA4\",\n      \"type\": \"function\",\n      \"address\": \"0x140006CA4\"\n    },\n    {\n      \"id\": \"func_0x140001D28\",\n      \"label\": \"Function 0x140001D28\",\n      \"type\": \"function\",\n      \"address\": \"0x140001D28\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempFileName\",\n      \"label\": \"GetTempFileName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetCurrentDirectory\",\n      \"label\": \"GetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_current_directory__3_matches_\",\n      \"label\": \"set current directory (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1400061EC\",\n      \"label\": \"Function 0x1400061EC\",\n      \"type\": \"function\",\n      \"address\": \"0x1400061EC\"\n    },\n    {\n      \"id\": \"api_SetCurrentDirectory\",\n      \"label\": \"SetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_directory__5_matches_\",\n      \"label\": \"create directory (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400064E4\",\n      \"label\": \"Function 0x1400064E4\",\n      \"type\": \"function\",\n      \"address\": \"0x1400064E4\"\n    },\n    {\n      \"id\": \"func_0x140005380\",\n      \"label\": \"Function 0x140005380\",\n      \"type\": \"function\",\n      \"address\": \"0x140005380\"\n    },\n    {\n      \"id\": \"func_0x140003530\",\n      \"label\": \"Function 0x140003530\",\n      \"type\": \"function\",\n      \"address\": \"0x140003530\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_directory__3_matches_\",\n      \"label\": \"delete directory (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14000204C\",\n      \"label\": \"Function 0x14000204C\",\n      \"type\": \"function\",\n      \"address\": \"0x14000204C\"\n    },\n    {\n      \"id\": \"api_RemoveDirectory\",\n      \"label\": \"RemoveDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_file__3_matches_\",\n      \"label\": \"delete file (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__7_matches_\",\n      \"label\": \"check if file exists (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140006B70\",\n      \"label\": \"Function 0x140006B70\",\n      \"type\": \"function\",\n      \"address\": \"0x140006B70\"\n    },\n    {\n      \"id\": \"func_0x140001684\",\n      \"label\": \"Function 0x140001684\",\n      \"type\": \"function\",\n      \"address\": \"0x140001684\"\n    },\n    {\n      \"id\": \"func_0x1400051BC\",\n      \"label\": \"Function 0x1400051BC\",\n      \"type\": \"function\",\n      \"address\": \"0x1400051BC\"\n    },\n    {\n      \"id\": \"func_0x1400079F0\",\n      \"label\": \"Function 0x1400079F0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400079F0\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_enumerate_files_on_windows\",\n      \"label\": \"enumerate files on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindClose\",\n      \"label\": \"FindClose\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindFirstFile\",\n      \"label\": \"FindFirstFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindNextFile\",\n      \"label\": \"FindNextFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_recursively\",\n      \"label\": \"enumerate files recursively\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     @_re_fox, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes__9_matches_\",\n      \"label\": \"get file attributes (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x140006916\",\n      \"label\": \"Block 0x140006916\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140006916\"\n    },\n    {\n      \"id\": \"bb_0x1400063E3\",\n      \"label\": \"Block 0x1400063E3\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400063E3\"\n    },\n    {\n      \"id\": \"bb_0x140003694\",\n      \"label\": \"Block 0x140003694\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140003694\"\n    },\n    {\n      \"id\": \"bb_0x140001AEB\",\n      \"label\": \"Block 0x140001AEB\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140001AEB\"\n    },\n    {\n      \"id\": \"bb_0x140006C61\",\n      \"label\": \"Block 0x140006C61\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140006C61\"\n    },\n    {\n      \"id\": \"bb_0x140007A44\",\n      \"label\": \"Block 0x140007A44\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140007A44\"\n    },\n    {\n      \"id\": \"bb_0x14000184D\",\n      \"label\": \"Block 0x14000184D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14000184D\"\n    },\n    {\n      \"id\": \"bb_0x1400051BC\",\n      \"label\": \"Block 0x1400051BC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400051BC\"\n    },\n    {\n      \"id\": \"bb_0x140006A16\",\n      \"label\": \"Block 0x140006A16\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140006A16\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_version_info\",\n      \"label\": \"get file version info\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140002834\",\n      \"label\": \"Function 0x140002834\",\n      \"type\": \"function\",\n      \"address\": \"0x140002834\"\n    },\n    {\n      \"id\": \"api_VerQueryValue\",\n      \"label\": \"VerQueryValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfoSize\",\n      \"label\": \"GetFileVersionInfoSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfo\",\n      \"label\": \"GetFileVersionInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_file_attributes__5_matches_\",\n      \"label\": \"set file attributes (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1400021A3\",\n      \"label\": \"Block 0x1400021A3\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400021A3\"\n    },\n    {\n      \"id\": \"bb_0x140005246\",\n      \"label\": \"Block 0x140005246\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140005246\"\n    },\n    {\n      \"id\": \"bb_0x140006A6D\",\n      \"label\": \"Block 0x140006A6D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140006A6D\"\n    },\n    {\n      \"id\": \"bb_0x140006229\",\n      \"label\": \"Block 0x140006229\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140006229\"\n    },\n    {\n      \"id\": \"bb_0x140005A06\",\n      \"label\": \"Block 0x140005A06\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140005A06\"\n    },\n    {\n      \"id\": \"api_SetFileAttributes\",\n      \"label\": \"SetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read__ini_file\",\n      \"label\": \"read .ini file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetPrivateProfileString\",\n      \"label\": \"GetPrivateProfileString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetPrivateProfileInt\",\n      \"label\": \"GetPrivateProfileInt\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows\",\n      \"label\": \"read file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400055E0\",\n      \"label\": \"Function 0x1400055E0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400055E0\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__2_matches_\",\n      \"label\": \"write file on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140005690\",\n      \"label\": \"Function 0x140005690\",\n      \"type\": \"function\",\n      \"address\": \"0x140005690\"\n    },\n    {\n      \"id\": \"func_0x1400078B0\",\n      \"label\": \"Function 0x1400078B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400078B0\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_disk_information__2_matches_\",\n      \"label\": \"get disk information (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetVolumeInformation\",\n      \"label\": \"GetVolumeInformation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetDriveType\",\n      \"label\": \"GetDriveType\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_size__2_matches_\",\n      \"label\": \"get disk size (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpace\",\n      \"label\": \"GetDiskFreeSpace\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_mutex_on_windows\",\n      \"label\": \"check mutex on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Check Mutex [C0043]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetLastError\",\n      \"label\": \"GetLastError\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateMutex\",\n      \"label\": \"CreateMutex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Check Mutex [C0043]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_or_open_mutex_on_windows\",\n      \"label\": \"create or open mutex on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_mehunhoff_google_com\",\n      \"label\": \"mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_shutdown_system__2_matches_\",\n      \"label\": \"shutdown system (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::System Shutdown/Reboot [T1529]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140001C0C\",\n      \"label\": \"Function 0x140001C0C\",\n      \"type\": \"function\",\n      \"address\": \"0x140001C0C\"\n    },\n    {\n      \"id\": \"api_ExitWindowsEx\",\n      \"label\": \"ExitWindowsEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_system_information_on_windows\",\n      \"label\": \"get system information on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetSystemInfo\",\n      \"label\": \"GetSystemInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_os_version__3_matches_\",\n      \"label\": \"check OS version (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140003BF4\",\n      \"label\": \"Function 0x140003BF4\",\n      \"type\": \"function\",\n      \"address\": \"0x140003BF4\"\n    },\n    {\n      \"id\": \"func_0x140007F04\",\n      \"label\": \"Function 0x140007F04\",\n      \"type\": \"function\",\n      \"address\": \"0x140007F04\"\n    },\n    {\n      \"id\": \"api_GetVersionEx\",\n      \"label\": \"GetVersionEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows\",\n      \"label\": \"create process on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x14000473C\",\n      \"label\": \"Block 0x14000473C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14000473C\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_modify_access_privileges\",\n      \"label\": \"modify access privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"api_AdjustTokenPrivileges\",\n      \"label\": \"AdjustTokenPrivileges\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140008218\",\n      \"label\": \"Function 0x140008218\",\n      \"type\": \"function\",\n      \"address\": \"0x140008218\"\n    },\n    {\n      \"id\": \"api_exit\",\n      \"label\": \"exit\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key\",\n      \"label\": \"query or enumerate registry key\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140002318\",\n      \"label\": \"Function 0x140002318\",\n      \"type\": \"function\",\n      \"address\": \"0x140002318\"\n    },\n    {\n      \"id\": \"api_RegQueryInfoKeyA\",\n      \"label\": \"RegQueryInfoKeyA\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"label\": \"query or enumerate registry value (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value__2_matches_\",\n      \"label\": \"set registry value (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delete_registry_value\",\n      \"label\": \"delete registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegDeleteValue\",\n      \"label\": \"RegDeleteValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_compare_security_identifiers\",\n      \"label\": \"compare security identifiers\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x140001452\",\n      \"label\": \"Block 0x140001452\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140001452\"\n    },\n    {\n      \"id\": \"api_EqualSid\",\n      \"label\": \"EqualSid\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_thread\",\n      \"label\": \"create thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x140003A9B\",\n      \"label\": \"Block 0x140003A9B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140003A9B\"\n    },\n    {\n      \"id\": \"api_CreateThread\",\n      \"label\": \"CreateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_thread\",\n      \"label\": \"terminate thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Thread [C0039]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x14000395B\",\n      \"label\": \"Block 0x14000395B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14000395B\"\n    },\n    {\n      \"id\": \"api_TerminateThread\",\n      \"label\": \"TerminateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap__internal__installer_file_limitation\",\n      \"label\": \"(internal) installer file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__8_matches_\",\n      \"label\": \"link function at runtime on Windows (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_parse_pe_header__2_matches_\",\n      \"label\": \"parse PE header (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400087BC\",\n      \"label\": \"Function 0x1400087BC\",\n      \"type\": \"function\",\n      \"address\": \"0x1400087BC\"\n    },\n    {\n      \"id\": \"func_0x1400080D0\",\n      \"label\": \"Function 0x1400080D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400080D0\"\n    },\n    {\n      \"id\": \"cap_persist_via_run_registry_key__5_matches_\",\n      \"label\": \"persist via Run registry key (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Registry Run Keys / Startup Folder [F0012]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__37_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__37_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x1400012EC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x140001D28\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__3_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__3_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x140003B4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version__3_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_os_version__3_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x140002C54\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140002C54\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_packaged_as_an_iexpress_self_extracting_archive\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______awillia2_cisco_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__5_matches_\",\n      \"target\": \"func_0x14000772C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__5_matches_\",\n      \"target\": \"func_0x140005D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__5_matches_\",\n      \"target\": \"func_0x140002DB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__5_matches_\",\n      \"target\": \"func_0x140005050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__5_matches_\",\n      \"target\": \"func_0x140007AC8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000772C\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005D90\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002DB4\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005050\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007AC8\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000772C\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005D90\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002DB4\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005050\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007AC8\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000772C\",\n      \"target\": \"api_FreeResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005D90\",\n      \"target\": \"api_FreeResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002DB4\",\n      \"target\": \"api_FreeResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005050\",\n      \"target\": \"api_FreeResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007AC8\",\n      \"target\": \"api_FreeResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000772C\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005D90\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002DB4\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005050\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007AC8\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000772C\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005D90\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002DB4\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005050\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007AC8\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x14000772C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x140005D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x140002DB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x140005050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x140007AC8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000772C\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005D90\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002DB4\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005050\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007AC8\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000772C\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005D90\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002DB4\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005050\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007AC8\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000772C\",\n      \"target\": \"api_FreeResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005D90\",\n      \"target\": \"api_FreeResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002DB4\",\n      \"target\": \"api_FreeResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005050\",\n      \"target\": \"api_FreeResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007AC8\",\n      \"target\": \"api_FreeResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000772C\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005D90\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002DB4\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005050\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007AC8\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000772C\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005D90\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002DB4\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005050\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007AC8\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable\",\n      \"target\": \"func_0x14000261C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x14000261C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__10_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__10_matches_\",\n      \"target\": \"func_0x1400030EC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__10_matches_\",\n      \"target\": \"func_0x1400040C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__10_matches_\",\n      \"target\": \"func_0x140002468\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__10_matches_\",\n      \"target\": \"func_0x1400063B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__10_matches_\",\n      \"target\": \"func_0x14000261C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__10_matches_\",\n      \"target\": \"func_0x1400066C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__10_matches_\",\n      \"target\": \"func_0x140004A60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__10_matches_\",\n      \"target\": \"func_0x140002244\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__10_matches_\",\n      \"target\": \"func_0x140006CA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__10_matches_\",\n      \"target\": \"func_0x140001D28\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400030EC\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002468\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004A60\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002244\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400030EC\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002468\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004A60\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002244\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400030EC\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002468\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004A60\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002244\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400030EC\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002468\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004A60\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002244\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400030EC\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002468\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004A60\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002244\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400030EC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400040C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140002468\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400063B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x14000261C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400066C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140004A60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140002244\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140006CA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140001D28\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400030EC\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002468\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004A60\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002244\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400030EC\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002468\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004A60\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002244\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400030EC\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002468\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004A60\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002244\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400030EC\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002468\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004A60\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002244\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400030EC\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002468\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004A60\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002244\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_current_directory__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__3_matches_\",\n      \"target\": \"func_0x1400030EC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__3_matches_\",\n      \"target\": \"func_0x140006CA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__3_matches_\",\n      \"target\": \"func_0x1400061EC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400030EC\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400061EC\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400030EC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140006CA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400061EC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400030EC\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400061EC\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory__5_matches_\",\n      \"target\": \"func_0x1400064E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__5_matches_\",\n      \"target\": \"func_0x1400063B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__5_matches_\",\n      \"target\": \"func_0x140005380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__5_matches_\",\n      \"target\": \"func_0x140003530\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__5_matches_\",\n      \"target\": \"func_0x1400066C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400064E4\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005380\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140003530\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400064E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400063B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140005380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140003530\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400066C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400064E4\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005380\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140003530\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_directory__3_matches_\",\n      \"target\": \"func_0x14000204C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_directory__3_matches_\",\n      \"target\": \"func_0x1400064E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_directory__3_matches_\",\n      \"target\": \"func_0x1400063B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000204C\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400064E4\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14000204C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400064E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400063B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000204C\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400064E4\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x14000204C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x1400061EC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x1400063B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000204C\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400061EC\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14000204C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400061EC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400063B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000204C\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400061EC\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__7_matches_\",\n      \"target\": \"func_0x140006B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__7_matches_\",\n      \"target\": \"func_0x140001684\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__7_matches_\",\n      \"target\": \"func_0x1400063B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__7_matches_\",\n      \"target\": \"func_0x1400051BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__7_matches_\",\n      \"target\": \"func_0x140003530\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__7_matches_\",\n      \"target\": \"func_0x1400079F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__7_matches_\",\n      \"target\": \"func_0x1400066C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140006B70\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001684\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400051BC\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140003530\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400079F0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140006B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140001684\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400063B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400051BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140003530\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400079F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400066C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140006B70\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001684\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400063B8\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400051BC\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140003530\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400079F0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows\",\n      \"target\": \"func_0x14000204C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000204C\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000204C\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000204C\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x14000204C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000204C\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000204C\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000204C\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_recursively\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively\",\n      \"target\": \"func_0x14000204C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000204C\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000204C\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000204C\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x14000204C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000204C\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000204C\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000204C\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__9_matches_\",\n      \"target\": \"bb_0x140006916\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__9_matches_\",\n      \"target\": \"bb_0x1400063E3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__9_matches_\",\n      \"target\": \"bb_0x140003694\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__9_matches_\",\n      \"target\": \"bb_0x140001AEB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__9_matches_\",\n      \"target\": \"bb_0x140006C61\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__9_matches_\",\n      \"target\": \"bb_0x140007A44\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__9_matches_\",\n      \"target\": \"bb_0x14000184D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__9_matches_\",\n      \"target\": \"bb_0x1400051BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__9_matches_\",\n      \"target\": \"bb_0x140006A16\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x140006916\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x1400063E3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x140003694\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x140001AEB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x140006C61\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x140007A44\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x14000184D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x1400051BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x140006A16\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_version_info\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_version_info\",\n      \"target\": \"func_0x140002834\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140002834\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002834\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002834\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140002834\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140002834\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002834\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002834\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__5_matches_\",\n      \"target\": \"bb_0x1400021A3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__5_matches_\",\n      \"target\": \"bb_0x140005246\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__5_matches_\",\n      \"target\": \"bb_0x140006A6D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__5_matches_\",\n      \"target\": \"bb_0x140006229\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__5_matches_\",\n      \"target\": \"bb_0x140005A06\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x1400021A3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x140005246\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x140006A6D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x140006229\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x140005A06\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read__ini_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read__ini_file\",\n      \"target\": \"func_0x140001684\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140001684\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001684\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140001684\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140001684\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001684\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows\",\n      \"target\": \"func_0x1400055E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400055E0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400055E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400055E0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x140005690\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x1400078B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140005690\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400078B0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005690\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400078B0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140005690\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400078B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140005690\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400078B0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005690\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400078B0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__2_matches_\",\n      \"target\": \"func_0x140006CA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__2_matches_\",\n      \"target\": \"func_0x1400066C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140006CA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400066C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_size__2_matches_\",\n      \"target\": \"func_0x140006CA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_size__2_matches_\",\n      \"target\": \"func_0x1400066C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140006CA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400066C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140006CA4\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400066C4\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_mutex_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_mutex_on_windows\",\n      \"target\": \"func_0x140002DB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140002DB4\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002DB4\",\n      \"target\": \"api_CreateMutex\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x140002DB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140002DB4\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002DB4\",\n      \"target\": \"api_CreateMutex\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_mutex_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_shutdown_system__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_shutdown_system__2_matches_\",\n      \"target\": \"func_0x140001C0C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_shutdown_system__2_matches_\",\n      \"target\": \"func_0x140002C54\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140001C0C\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002C54\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140001C0C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140002C54\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140001C0C\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002C54\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_system_information_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_system_information_on_windows\",\n      \"target\": \"func_0x1400064E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400064E4\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x1400064E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400064E4\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_os_version__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_os_version__3_matches_\",\n      \"target\": \"func_0x140002C54\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_os_version__3_matches_\",\n      \"target\": \"func_0x140003BF4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_os_version__3_matches_\",\n      \"target\": \"func_0x140007F04\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140002C54\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140003BF4\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007F04\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002C54\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140003BF4\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007F04\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x140002C54\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x140003BF4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x140007F04\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140002C54\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140003BF4\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007F04\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002C54\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140003BF4\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007F04\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows\",\n      \"target\": \"bb_0x14000473C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x14000473C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_modify_access_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x140008218\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140008218\",\n      \"target\": \"api_exit\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140008218\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140008218\",\n      \"target\": \"api_exit\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key\",\n      \"target\": \"func_0x140002318\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140002318\",\n      \"target\": \"api_RegQueryInfoKeyA\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002318\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140002318\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140002318\",\n      \"target\": \"api_RegQueryInfoKeyA\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002318\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x1400040C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x140002318\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x14000261C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x140001D28\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x140007F04\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002318\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007F04\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002318\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007F04\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002318\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007F04\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400040C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140002318\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x14000261C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140001D28\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140007F04\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002318\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007F04\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002318\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007F04\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140002318\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000261C\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140007F04\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__2_matches_\",\n      \"target\": \"func_0x1400040C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__2_matches_\",\n      \"target\": \"func_0x140001D28\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400040C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140001D28\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value\",\n      \"target\": \"func_0x1400061EC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400061EC\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400061EC\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400061EC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400061EC\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400061EC\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compare_security_identifiers\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_compare_security_identifiers\",\n      \"target\": \"bb_0x140001452\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x140001452\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread\",\n      \"target\": \"bb_0x140003A9B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x140003A9B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_thread\",\n      \"target\": \"bb_0x14000395B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x14000395B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal__installer_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__2_matches_\",\n      \"target\": \"func_0x1400087BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__2_matches_\",\n      \"target\": \"func_0x1400080D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400087BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400080D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_persist_via_run_registry_key__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_persist_via_run_registry_key__5_matches_\",\n      \"target\": \"func_0x1400040C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_persist_via_run_registry_key__5_matches_\",\n      \"target\": \"func_0x140001D28\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_persist_via_run_registry_key__5_matches_\",\n      \"target\": \"func_0x1400061EC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400061EC\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400061EC\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400061EC\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x1400040C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x140001D28\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x1400061EC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400061EC\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400061EC\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400040C4\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140001D28\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400061EC\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-04-27 00:05:26.527665\",\n    \"total_functions\": \"84\",\n    \"total_features\": \"31900\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-04-27 00:05:27"}
{"_id":{"$oid":"69f0fc1c59a6632dae07de68"},"sha256":"c5ae6f6ec23fd8d5ba1343e49bf805bbc016545715a413227bd5afe9c795002e","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         compiled with AutoIt.                                                  \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  AutoIt is a freeware BASIC-like common.py:90\n         scripting language designed for automating the Windows                 \n         GUI.                                                                   \nWARNING  capa.capabilities.common:  capa cannot handle AutoIt       common.py:90\n         scripts. This means that the results will be misleading or             \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You may have to analyze the     common.py:90\n         file manually, using a tool like the AutoIt decompiler                 \n         MyAut2Exe.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         autoit file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":true,"path":"/tmp/sdm_capa_kqguzd4a/c5ae6f6ec23fd8d5ba1343e49bf805bbc016545715a413227bd5afe9c795002e-019f7c1a0e677960bfb1f850c5b3a274.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_kqguzd4a/c5ae6f6ec23fd8d5ba1343e49bf805bbc016545715a413227bd5afe9c795002e-019f7c1a0e677960bfb1f850c5b3a274.exe_very_verbose.txt"}},"outputs":{"normal":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         compiled with AutoIt.                                                  \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  AutoIt is a freeware BASIC-like common.py:90\n         scripting language designed for automating the Windows                 \n         GUI.                                                                   \nWARNING  capa.capabilities.common:  capa cannot handle AutoIt       common.py:90\n         scripts. This means that the results will be misleading or             \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You may have to analyze the     common.py:90\n         file manually, using a tool like the AutoIt decompiler                 \n         MyAut2Exe.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         autoit file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         compiled with AutoIt.                                                  \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  AutoIt is a freeware BASIC-like common.py:90\n         scripting language designed for automating the Windows                 \n         GUI.                                                                   \nWARNING  capa.capabilities.common:  capa cannot handle AutoIt       common.py:90\n         scripts. This means that the results will be misleading or             \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You may have to analyze the     common.py:90\n         file manually, using a tool like the AutoIt decompiler                 \n         MyAut2Exe.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         autoit file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"md5                     9743b958d41813a0a3f62920f90a25c8                        \nsha1                    fec4f7eea0ac8e7935081d865a2f8fee6839641b                \nsha256                  c5ae6f6ec23fd8d5ba1343e49bf805bbc016545715a413227bd5afe…\npath                    /home/apogean/projects/malware/windows/all_runs/c5ae6f6…\ntimestamp               2026-07-20 02:12:43.216426                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIRbnDSM/rules                                   \nfunction count          2043                                                    \nlibrary function count  714                                                     \ntotal feature count     119213                                                  \n\ncheck for time delay via QueryPerformanceCounter (4 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    0x469B67                                       \n           0x469B7E                                       \n           0x46AFC6                                       \n           0x46E899                                       \n\ncheck for unmoving mouse cursor (2 matches)\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      function                          \nmatches    0x498EBB                          \n           0x499468                          \n\nlog keystrokes (9 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    0x4034CE         \n           0x41EFAD         \n           0x4624E6         \n           0x462CEB         \n           0x463985         \n           0x46A90B         \n           0x46B04D         \n           0x46B198         \n           0x46B1FD         \n\nlog keystrokes via polling (11 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    0x4028C0         \n           0x41EA9A         \n           0x469B97         \n           0x469EAF         \n           0x46A90B         \n           0x46A975         \n           0x46AABA         \n           0x46ABF8         \n           0x46ADD8         \n           0x46B198         \n           0x499468         \n\ncapture screenshot\nnamespace  collection/screenshot\nscope      function             \nmatches    0x482483             \n\nquery remote server for available data\nnamespace  communication\nscope      basic block  \nmatches    0x47CE38     \n\nreceive data (4 matches)\nnamespace    communication                                                     \ndescription  all known techniques for receiving data from a potential C2 server\nscope        function                                                          \nmatches      0x47CD62                                                          \n             0x47CE38                                                          \n             0x48135A                                                          \n             0x481B87                                                          \n\nsend data (3 matches)\nnamespace    communication                                                 \ndescription  all known techniques for sending data to a potential C2 server\nscope        function                                                      \nmatches      0x47C394                                                      \n             0x4814F1                                                      \n             0x481F24                                                      \n\nreceive and write data from server to client\nnamespace  communication/c2/file-transfer\nscope      function                      \nmatches    0x47CD62                      \n\nresolve DNS (3 matches)\nnamespace  communication/dns\nscope      function         \nmatches    0x46DD45         \n           0x480482         \n           0x481288         \n\nconnect network resource\nnamespace    communication/http               \ndescription  connect to disk or print resource\nscope        function                         \nmatches      0x4605C7                         \n\nparse URL\nnamespace  communication/http\nscope      basic block       \nmatches    0x47D012          \n\nconnect to HTTP server (2 matches)\nnamespace  communication/http/client\nscope      function                 \nmatches    0x47C061                 \n           0x47C394                 \n\nconnect to URL\nnamespace  communication/http/client\nscope      instruction              \nmatches    0x47C190                 \n\ncreate HTTP request\nnamespace  communication/http/client\nscope      function                 \nmatches    0x47CC3C                 \n\nread data from Internet (2 matches)\nnamespace  communication/http/client\nscope      function                 \nmatches    0x47CD62                 \n           0x47CE38                 \n\nsend HTTP request\nnamespace  communication/http/client\nscope      function                 \nmatches    0x47C394                 \n\nsend ICMP echo request\nnamespace  communication/icmp\nscope      function          \nmatches    0x480482          \n\ncreate pipe (2 matches)\nnamespace  communication/named-pipe/create\nscope      function                       \nmatches    0x4703F0                       \n           0x4704C5                       \n\nconnect socket\nnamespace    communication/socket                                               \ndescription  Detects socket connection attempts using common APIs or ConnectEx  \n             setup.                                                             \nscope        basic block                                                        \nmatches      0x4810AF                                                           \n\nget socket status\nnamespace  communication/socket\nscope      function            \nmatches    0x483070            \n\ninitialize Winsock library (3 matches)\nnamespace  communication/socket\nscope      function            \nmatches    0x46DD45            \n           0x480482            \n           0x4815DA            \n\nset socket configuration (3 matches)\nnamespace  communication/socket\nscope      function            \nmatches    0x480482            \n           0x4819FD            \n           0x482F75            \n\nreceive data on socket (2 matches)\nnamespace  communication/socket/receive\nscope      function                    \nmatches    0x48135A                    \n           0x481B87                    \n\nsend data on socket (2 matches)\nnamespace  communication/socket/send\nscope      function                 \nmatches    0x4814F1                 \n           0x481F24                 \n\nconnect TCP socket\nnamespace  communication/socket/tcp\nscope      function                \nmatches    0x480FDF                \n\ncreate TCP socket (2 matches)\nnamespace  communication/socket/tcp\nscope      basic block             \nmatches    0x481033                \n           0x481197                \n\ncreate UDP socket (2 matches)\nnamespace  communication/socket/udp/send\nscope      basic block                  \nmatches    0x48177E                     \n           0x4819FD                     \n\nact as TCP client\nnamespace  communication/tcp/client\nscope      function                \nmatches    0x480FDF                \n\ncompiled with AutoIt\nnamespace  compiler/autoit\nscope      file           \n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32\nscope      function                        \nmatches    0x4823E8                        \n\nencode data using Base64\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    0x41BEAD                         \n\nencode data using XOR (7 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x4695EE                      \n           0x471F30                      \n           0x471F9C                      \n           0x471FD6                      \n           0x47284B                      \n           0x472ABF                      \n           0x47D73F                      \n\nhash data using djb2\nnamespace  data-manipulation/hashing/djb2\nscope      function                      \nmatches    0x408273                      \n\nauthenticate HMAC\nnamespace  data-manipulation/hmac\nscope      function              \nmatches    0x41BEAD              \n\ngenerate random numbers using a Mersenne Twister (4 matches)\nnamespace  data-manipulation/prng/mersenne\nscope      function                       \nmatches    0x471E7A                       \n           0x471EC0                       \n           0x471F24                       \n           0x471F64                       \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x406122           \n\nlist drag and drop files\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x47EA26                  \n\nopen clipboard (2 matches)\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x47EA26                  \n           0x47EC91                  \n\nread clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x47EA26                  \n\nwrite clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x47EC91                  \n\ninteract with driver via IOCTL (4 matches)\nnamespace  host-interaction/driver\nscope      instruction            \nmatches    0x46D563               \n           0x46D5DD               \n           0x46D690               \n           0x473D73               \n\nget COMSPEC environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x41D70E                             \n\nquery environment variable (3 matches)\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x41D70E                             \n           0x47EE14                             \n           0x487559                             \n\nset environment variable (2 matches)\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x43D170                             \n           0x47EE84                             \n\nget common file path (9 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x40445D                    \n           0x41D70E                    \n           0x41F962                    \n           0x46DE45                    \n           0x472F35                    \n           0x4779B4                    \n           0x477D0E                    \n           0x4780B3                    \n           0x48AF20                    \n\nset current directory (7 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x40445D                    \n           0x40AD7C                    \n           0x4753D4                    \n           0x477D0E                    \n           0x4780B3                    \n           0x479560                    \n           0x4796BB                    \n\ncopy file (3 matches)\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    0x46CE1E                         \n           0x46D1BA                         \n           0x472865                         \n\ncreate directory (2 matches)\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x46D1DF                           \n           0x473C3C                           \n\ndelete directory (2 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x46E77B                           \n           0x473C3C                           \n\ndelete file (6 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x46CF94                           \n           0x46D2C7                           \n           0x46E77B                           \n           0x472865                           \n           0x4755F7                           \n           0x4778BA                           \n\ncheck if file exists (3 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x46D1DF                           \n           0x46DADC                           \n           0x46E0B7                           \n\nenumerate files on Windows (6 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x46CF94                               \n           0x46D2C7                               \n           0x475BB5                               \n           0x479560                               \n           0x4796BB                               \n           0x479A49                               \n\nenumerate files recursively (3 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x479560                               \n           0x4796BB                               \n           0x479A49                               \n\nget file attributes (5 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x46D1DF                         \n           0x46DAFA                         \n           0x46E0B7                         \n           0x477F04                         \n           0x4795B8                         \n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x482A05                         \n           0x498461                         \n\nget file version info\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x46DB2C                         \n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x477F04                         \n           0x4795B8                         \n\nmove file (3 matches)\nnamespace  host-interaction/file-system/move\nscope      function                         \nmatches    0x46CE1E                         \n           0x46CF94                         \n           0x46E319                         \n\nread .ini file (4 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x4783FD                         \n           0x4784BF                         \n           0x4787FC                         \n           0x478A19                         \n\nread file on Windows (9 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x406A95                         \n           0x40B230                         \n           0x40B3B0                         \n           0x43921B                         \n           0x47070D                         \n           0x472475                         \n           0x4725B1                         \n           0x482A05                         \n           0x498461                         \n\nclear file content\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x477FD5                          \n\nwrite file on Windows (7 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x41F5B3                          \n           0x46CC1D                          \n           0x470633                          \n           0x4725F5                          \n           0x472642                          \n           0x472865                          \n           0x47CD62                          \n\nenumerate gui resources\nnamespace  host-interaction/gui\nscope      function            \nmatches    0x464144            \n\nfind taskbar (3 matches)\nnamespace  host-interaction/gui/taskbar/find\nscope      basic block                      \nmatches    0x41EFCE                         \n           0x492255                         \n           0x492289                         \n\nfind graphical window (4 matches)\nnamespace  host-interaction/gui/window/find\nscope      instruction                     \nmatches    0x41EFD4                        \n           0x46E645                        \n           0x49225F                        \n           0x49229F                        \n\nget graphical window text (11 matches)\nnamespace  host-interaction/gui/window/get-text\nscope      function                            \nmatches    0x461A70                            \n           0x46359E                            \n           0x463B0C                            \n           0x46489C                            \n           0x464BD3                            \n           0x465B9A                            \n           0x47E8F7                            \n           0x491E0D                            \n           0x4947A8                            \n           0x496FA4                            \n           0x4972B7                            \n\nhide graphical window (8 matches)\nnamespace  host-interaction/gui/window/hide\nscope      basic block                     \nmatches    0x45F0F9                        \n           0x4827C2                        \n           0x49015D                        \n           0x4950F2                        \n           0x496B61                        \n           0x49813A                        \n           0x4981BF                        \n           0x49A198                        \n\nget keyboard layout\nnamespace  host-interaction/hardware/keyboard\nscope      function                          \nmatches    0x41D70E                          \n\nget memory capacity\nnamespace  host-interaction/hardware/memory\nscope      function                        \nmatches    0x41F370                        \n\nget disk information (6 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x473D97                         \n           0x4743DE                         \n           0x474776                         \n           0x474844                         \n           0x474912                         \n           0x4749FD                         \n\nget disk size (3 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x4750EB                         \n           0x4751CE                         \n           0x4752B1                         \n\nget storage device properties (2 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x46D509                         \n           0x46D588                         \n\nprint debug messages\nnamespace  host-interaction/log/debug/write-event\nscope      function                              \nmatches    0x41F5B3                              \n\nshutdown system\nnamespace  host-interaction/os\nscope      function           \nmatches    0x46E814           \n\nget hostname (2 matches)\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    0x41D70E                    \n           0x46DD45                    \n\nget system information on Windows\nnamespace  host-interaction/os/info\nscope      function                \nmatches    0x40615E                \n\ncreate process on Windows (6 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x4437E0                       \n           0x46134A                       \n           0x461472                       \n           0x48AD7A                       \n           0x48B2C1                       \n           0x498064                       \n\nallocate or change RWX memory\nnamespace  host-interaction/process/inject\nscope      basic block                    \nmatches    0x489881                       \n\nenumerate processes (2 matches)\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    0x46D3FA                     \n           0x48A5A3                     \n\nacquire debug privileges\nnamespace  host-interaction/process/modify\nscope      basic block                    \nmatches    0x48A0B6                       \n\nmodify access privileges (2 matches)\nnamespace  host-interaction/process/modify\nscope      instruction                    \nmatches    0x461018                       \n           0x46167E                       \n\nterminate process (3 matches)\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x46EA3E                          \n           0x487E80                          \n           0x48A009                          \n\nempty the recycle bin\nnamespace  host-interaction/recycle-bin\nscope      function                    \nmatches    0x477953                    \n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x48B8F0                 \n           0x48CB5B                 \n\nquery or enumerate registry value (5 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x40533E                 \n           0x4059A7                 \n           0x4605C7                 \n           0x48BB02                 \n           0x48BD6B                 \n\nset registry value\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x48C2DE                        \n\ndelete registry key (2 matches)\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x48B535                        \n           0x48CB5B                        \n\ndelete registry value\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x48B535                        \n\nget session user name\nnamespace  host-interaction/session\nscope      function                \nmatches    0x41D70E                \n\nget token membership\nnamespace  host-interaction/session\nscope      function                \nmatches    0x4615A7                \n\nget token privileges\nnamespace  host-interaction/session\nscope      function                \nmatches    0x460F58                \n\ncreate thread (5 matches)\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x461747                      \n           0x46E114                      \n           0x470870                      \n           0x470870                      \n           0x47D13B                      \n\nterminate thread\nnamespace  host-interaction/thread/terminate\nscope      basic block                      \nmatches    0x4708A6                         \n\nimpersonate user\nnamespace  host-interaction/user\nscope      function             \nmatches    0x461145             \n\nlink function at runtime on Windows (13 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x4062E6               \n           0x406816               \n           0x406850               \n           0x45DB5B               \n           0x432FC7               \n           0x432FC7               \n           0x4671A3               \n           0x483FF4               \n           0x488EF7               \n           0x488F13               \n           0x488F59               \n           0x48B82B               \n           0x48CBF6               \n\nparse PE header\nnamespace  load-code/pe\nscope      function    \nmatches    0x40B7E0    \n\nresolve function by parsing PE exports (15 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x401641    \n           0x408BAA    \n           0x4095C0    \n           0x40A180    \n           0x40AD7C    \n           0x40D840    \n           0x410540    \n           0x41BEAD    \n           0x466502    \n           0x4681EE    \n           0x4763AC    \n           0x476E0F    \n           0x47902A    \n           0x487E80    \n           0x490F26    \n\nexecute shellcode via indirect call\nnamespace  load-code/shellcode\nscope      function           \nmatches    0x4895BB           \n\ncreate shortcut via IShellLink (2 matches)\nnamespace  persistence\nscope      function   \nmatches    0x47573C   \n           0x4763AC   \n\n\n\n","very_verbose":"md5                     9743b958d41813a0a3f62920f90a25c8                        \nsha1                    fec4f7eea0ac8e7935081d865a2f8fee6839641b                \nsha256                  c5ae6f6ec23fd8d5ba1343e49bf805bbc016545715a413227bd5afe…\npath                    /home/apogean/projects/malware/windows/all_runs/c5ae6f6…\ntimestamp               2026-07-20 02:13:43.625297                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEI32z4wx/rules                                   \nfunction count          2043                                                    \nlibrary function count  714                                                     \ntotal feature count     119213                                                  \n\nallocate memory (2 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x46B26C in function 0x46B248\n  or:\n    api: VirtualAllocEx @ 0x46B299\n\nallocate or change RW memory (library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x46B26C in function 0x46B248\n  and:\n    or:\n      match: allocate memory @ 0x46B26C\n        or:\n          api: VirtualAllocEx @ 0x46B299\n    or:\n      number: 0x4 = PAGE_READWRITE @ 0x46B289\n\ncalculate modulo 256 via x86 assembly (9 matches, only showing first match of \nlibrary rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x436DAA\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x436DAA\n    or:\n      number: 0xFF @ 0x436DAA\n\ncontain loop (489 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401202\n  or:\n    characteristic: loop @ 0x401202\n\ncreate or open file (13 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x407113\n  or:\n    api: CreateFile @ 0x407113\n\ncreate or open registry key (9 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x40533E in function 0x40533E\n  or:\n    api: RegOpenKeyEx @ 0x40545B\n\ndelay execution (37 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x40F4AF in function 0x40F060\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x40F4B1\n\nget OS version (library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x40615E\n  or:\n    api: GetVersionEx @ 0x40618D\n\nopen process (7 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org           \nscope   basic block                  \nmbc     Process::Open Process [C0065]\nbasic block @ 0x46B26C in function 0x46B248\n  or:\n    api: OpenProcess @ 0x46B283\n\nwrite process memory (library rule)\nauthor  moritz.raabe@mandiant.com                 \nscope   instruction                               \natt&ck  Defense Evasion::Process Injection [T1055]\ninstruction @ 0x46B34B\n  or:\n    api: WriteProcessMemory @ 0x46B34B\n\ncheck for time delay via QueryPerformanceCounter (4 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection                      \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check     \n           QueryPerformanceCounter [B0001.033]                                  \nfunction @ 0x469B67\n  and:\n    count(api(QueryPerformanceCounter)): 2 or more @ 0x46AFE2, 0x46B011\nfunction @ 0x469B7E\n  and:\n    count(api(QueryPerformanceCounter)): 2 or more @ 0x46AFE2, 0x46B011\nfunction @ 0x46AFC6\n  and:\n    count(api(QueryPerformanceCounter)): 2 or more @ 0x46AFE2, 0x46B011\nfunction @ 0x46E899\n  and:\n    count(api(QueryPerformanceCounter)): 2 or more @ 0x46E8B5, 0x46E8D5\n\ncheck for unmoving mouse cursor (2 matches)\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      BitsOfBinary                                                        \nscope       function                                                            \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::User Activity Based\n            Checks [T1497.002]                                                  \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection::Human User     \n            Check [B0009.012]                                                   \nreferences  https://www.joesecurity.org/blog/5852460122427342172                \nfunction @ 0x498EBB\n  and:\n    count(api(GetCursorPos)): 2 or more @ 0x498EF3, 0x498F50\nfunction @ 0x499468\n  and:\n    count(api(GetCursorPos)): 2 or more @ 0x49990B, 0x499A5A\n\nlog keystrokes (9 matches)\nnamespace  collection/keylog                                \nauthor     moritz.raabe@mandiant.com                        \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nfunction @ 0x4034CE\n  or:\n    api: MapVirtualKey @ 0x4034FF, 0x403507, 0x403512, 0x40351D, and 2 more...\nfunction @ 0x41EFAD\n  or:\n    api: AttachThreadInput @ 0x41F029, 0x41F031, 0x41F039, 0x41F0AD, and 2 more...\n    api: MapVirtualKey @ 0x41F055, 0x41F06A, 0x41F078, 0x41F087\nfunction @ 0x4624E6\n  or:\n    api: MapVirtualKey @ 0x462501, 0x46252D, 0x462553\nfunction @ 0x462CEB\n  or:\n    api: AttachThreadInput @ 0x462D28\nfunction @ 0x463985\n  or:\n    api: AttachThreadInput @ 0x4639AD\nfunction @ 0x46A90B\n  or:\n    api: MapVirtualKey @ 0x46A93A, 0x46A956\nfunction @ 0x46B04D\n  or:\n    api: AttachThreadInput @ 0x46B099, 0x46B0C4, 0x46B0D6, 0x46B11B, and 2 more...\nfunction @ 0x46B198\n  or:\n    api: MapVirtualKey @ 0x46B1CD\nfunction @ 0x46B1FD\n  or:\n    api: MapVirtualKey @ 0x46B21B\n\nlog keystrokes via polling (11 matches)\nnamespace  collection/keylog                                \nauthor     michael.hunhoff@mandiant.com                     \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nmbc        Collection::Keylogging::Polling [F0002.002]      \nfunction @ 0x4028C0\n  or:\n    api: VkKeyScan @ 0x442F79, 0x442F89, 0x442FD2\nfunction @ 0x41EA9A\n  or:\n    api: GetAsyncKeyState @ 0x41EB02, 0x41EB1C\nfunction @ 0x469B97\n  or:\n    api: GetAsyncKeyState @ 0x469C40, 0x469C75, 0x469CA2, 0x469CCC, and 1 more...\n    api: GetKeyState @ 0x469C5B, 0x469C8A, 0x469CB4, 0x469CDE, and 1 more...\n    api: GetKeyboardState @ 0x469BBF\nfunction @ 0x469EAF\n  or:\n    api: GetAsyncKeyState @ 0x469FBB, 0x46A001, 0x46A03E, 0x46A075, and 1 more...\n    api: GetKeyState @ 0x469FD2, 0x46A012, 0x46A04C, 0x46A083, and 1 more...\n    api: GetKeyboardState @ 0x469F30\nfunction @ 0x46A90B\n  or:\n    api: GetKeyState @ 0x46A91B\nfunction @ 0x46A975\n  or:\n    api: GetKeyboardState @ 0x46A9CA\nfunction @ 0x46AABA\n  or:\n    api: GetKeyboardState @ 0x46AB0F\nfunction @ 0x46ABF8\n  or:\n    api: GetKeyboardState @ 0x46AC4C\nfunction @ 0x46ADD8\n  or:\n    api: GetKeyboardState @ 0x46AE2C\nfunction @ 0x46B198\n  or:\n    api: VkKeyScan @ 0x46B1B0\nfunction @ 0x499468\n  or:\n    api: GetKeyState @ 0x49967D, 0x49968A, 0x4996AA\n\ncapture screenshot\nnamespace  collection/screenshot                                            \nauthor     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\nscope      function                                                         \natt&ck     Collection::Screen Capture [T1113]                               \nmbc        Collection::Screen Capture::WinAPI [E1113.m01]                   \nfunction @ 0x482483\n  or:\n    and:\n      or:\n        api: GetDC @ 0x4824FF\n      or:\n        api: GetDIBits @ 0x4825D3, 0x4825F7\n      api: CreateCompatibleDC @ 0x48251B\n      api: CreateCompatibleBitmap @ 0x48250F\n\nquery remote server for available data\nnamespace  communication               \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ 0x47CE38 in function 0x47CE38\n  or:\n    api: InternetQueryDataAvailable @ 0x47CE56\n\nreceive data (4 matches)\nnamespace    communication                                                     \nauthor       william.ballenthin@mandiant.com                                   \nscope        function                                                          \nmbc          Command and Control::C2 Communication::Receive Data [B0030.002]   \ndescription  all known techniques for receiving data from a potential C2 server\nfunction @ 0x47CD62\n  or:\n    match: read data from Internet @ 0x47CD62\n      and:\n        or:\n          api: InternetReadFile @ 0x47CDA7\nfunction @ 0x47CE38\n  or:\n    match: read data from Internet @ 0x47CE38\n      and:\n        or:\n          api: InternetReadFile @ 0x47CE8D\nfunction @ 0x48135A\n  or:\n    match: receive data on socket @ 0x48135A\n      or:\n        api: recv @ 0x481403\nfunction @ 0x481B87\n  or:\n    match: receive data on socket @ 0x481B87\n      or:\n        api: recvfrom @ 0x481D08\n\nsend data (3 matches)\nnamespace    communication                                                 \nauthor       william.ballenthin@mandiant.com, joakim@intezer.com           \nscope        function                                                      \nmbc          Command and Control::C2 Communication::Send Data [B0030.001]  \ndescription  all known techniques for sending data to a potential C2 server\nfunction @ 0x47C394\n  or:\n    and:\n      os: windows\n      or:\n        match: send HTTP request @ 0x47C394\n          or:\n            and:\n              or:\n                api: HttpOpenRequest @ 0x47C40E\n                api: InternetConnect @ 0x47C3CE\n              or:\n                api: HttpSendRequest @ 0x47C472\nfunction @ 0x4814F1\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x4814F1\n          or:\n            api: send @ 0x481525\nfunction @ 0x481F24\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x481F24\n          or:\n            api: sendto @ 0x482063\n\ndownload and write a file\nnamespace              communication/c2/file-transfer                           \nmaec/malware-category  downloader                                               \nauthor                 moritz.raabe@mandiant.com                                \nscope                  function                                                 \natt&ck                 Command and Control::Ingress Tool Transfer [T1105]       \nmbc                    Command and Control::C2 Communication::Server to Client  \n                       File Transfer [B0030.003]                                \nfunction @ 0x47CD62\n  and:\n    match: receive data @ 0x47CD62\n      or:\n        match: read data from Internet @ 0x47CD62\n          and:\n            or:\n              api: InternetReadFile @ 0x47CDA7\n    match: host-interaction/file-system/write @ 0x47CD62\n      or:\n        and:\n          os: windows\n          or:\n            api: _fwrite @ 0x47CDC3\n            api: fwrite @ 0x47CDC3\n\nreceive and write data from server to client\nnamespace  communication/c2/file-transfer \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x47CD62\n  and:\n    match: receive data @ 0x47CD62\n      or:\n        match: read data from Internet @ 0x47CD62\n          and:\n            or:\n              api: InternetReadFile @ 0x47CDA7\n    match: host-interaction/file-system/write @ 0x47CD62\n      or:\n        and:\n          os: windows\n          or:\n            api: _fwrite @ 0x47CDC3\n            api: fwrite @ 0x47CDC3\n\nresolve DNS (3 matches)\nnamespace  communication/dns                                                    \nauthor     william.ballenthin@mandiant.com, johnk3r, joakim@intezer.com,        \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::DNS Communication::Resolve [C0011.001]                \nfunction @ 0x46DD45\n  or:\n    api: gethostbyname @ 0x46DD87\nfunction @ 0x480482\n  or:\n    api: gethostbyname @ 0x48054F\nfunction @ 0x481288\n  or:\n    api: gethostbyname @ 0x4812B7\n\nconnect network resource\nnamespace    communication/http               \nauthor       michael.hunhoff@mandiant.com     \nscope        function                         \ndescription  connect to disk or print resource\nfunction @ 0x4605C7\n  and:\n    or:\n      api: WNetAddConnection2 @ 0x46068B\n\nparse URL\nnamespace  communication/http          \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ 0x47D012 in function 0x47D012\n  or:\n    api: InternetCrackUrl @ 0x47D058\n\nconnect to HTTP server (2 matches)\nnamespace  communication/http/client                                       \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \nmbc        Communication::HTTP Communication::Connect to Server [C0002.009]\nfunction @ 0x47C061\n  and:\n    api: InternetConnect @ 0x47C0A0\nfunction @ 0x47C394\n  and:\n    api: InternetConnect @ 0x47C3CE\n\nconnect to URL\nnamespace  communication/http/client                              \nauthor     michael.hunhoff@mandiant.com                           \nscope      instruction                                            \nmbc        Communication::HTTP Communication::Open URL [C0002.004]\ninstruction @ 0x47C190\n  and:\n    api: InternetOpenUrl @ 0x47C190\n\ncreate HTTP request\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Create Request [C0002.012]\nfunction @ 0x47CC3C\n  and:\n    or:\n      api: InternetOpen @ 0x47CC9B\n\nread data from Internet (2 matches)\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Get Response [C0002.017]  \nfunction @ 0x47CD62\n  and:\n    or:\n      api: InternetReadFile @ 0x47CDA7\nfunction @ 0x47CE38\n  and:\n    or:\n      api: InternetReadFile @ 0x47CE8D\n\nsend HTTP request\nnamespace  communication/http/client                                  \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com    \nscope      function                                                   \nmbc        Communication::HTTP Communication::Send Request [C0002.003]\nfunction @ 0x47C394\n  or:\n    and:\n      or:\n        api: HttpOpenRequest @ 0x47C40E\n        api: InternetConnect @ 0x47C3CE\n      or:\n        api: HttpSendRequest @ 0x47C472\n\nsend ICMP echo request\nnamespace   communication/icmp                                         \nauthor      michael.hunhoff@mandiant.com                               \nscope       function                                                   \nmbc         Communication::ICMP Communication::Echo Request [C0014.002]\nreferences  https://docs.microsoft.com/en-us/windows/win32/api/icmpapi/\nfunction @ 0x480482\n  and:\n    or:\n      api: IcmpSendEcho @ 0x4805ED, 0x48060C\n    optional:\n      or:\n        api: IcmpCreateFile @ 0x48055D\n      api: IcmpCloseHandle @ 0x4806E0\n\ncreate pipe (2 matches)\nnamespace  communication/named-pipe/create                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com           \nscope      function                                                          \nmbc        Communication::Interprocess Communication::Create Pipe [C0003.001]\nfunction @ 0x4703F0\n  or:\n    api: CreatePipe @ 0x47044C\nfunction @ 0x4704C5\n  or:\n    api: CreatePipe @ 0x47051F\n\nconnect socket\nnamespace    communication/socket                                               \nauthor       moritz.raabe@mandiant.com, joakim@intezer.com,                     \n             mrhafizfarhad@gmail.com                                            \nscope        basic block                                                        \ndescription  Detects socket connection attempts using common APIs or ConnectEx  \n             setup.                                                             \nbasic block @ 0x4810AF in function 0x480FDF\n  or:\n    api: connect @ 0x4810B6\n\nget socket status\nnamespace  communication/socket                                              \nauthor     michael.hunhoff@mandiant.com                                      \nscope      function                                                          \natt&ck     Discovery::System Network Configuration Discovery [T1016]         \nmbc        Communication::Socket Communication::Get Socket Status [C0001.012]\nfunction @ 0x483070\n  or:\n    api: select @ 0x4830BC\n\ninitialize Winsock library (3 matches)\nnamespace  communication/socket                                                 \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Initialize Winsock Library      \n           [C0001.009]                                                          \nfunction @ 0x46DD45\n  or:\n    api: WSAStartup @ 0x46DD60\nfunction @ 0x480482\n  or:\n    api: WSAStartup @ 0x4804E3\nfunction @ 0x4815DA\n  or:\n    api: WSAStartup @ 0x4815F5\n\nset socket configuration (3 matches)\nnamespace  communication/socket                                              \nauthor     michael.hunhoff@mandiant.com                                      \nscope      function                                                          \nmbc        Communication::Socket Communication::Set Socket Config [C0001.001]\nfunction @ 0x480482\n  or:\n    api: ioctlsocket @ 0x480543\nfunction @ 0x4819FD\n  or:\n    api: setsockopt @ 0x481AB1\nfunction @ 0x482F75\n  or:\n    api: ioctlsocket @ 0x482FA1\n\nreceive data on socket (2 matches)\nnamespace  communication/socket/receive                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Receive Data [C0001.006]        \nfunction @ 0x48135A\n  or:\n    api: recv @ 0x481403\nfunction @ 0x481B87\n  or:\n    api: recvfrom @ 0x481D08\n\nsend data on socket (2 matches)\nnamespace  communication/socket/send                                            \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Communication::Socket Communication::Send Data [C0001.007]           \nfunction @ 0x4814F1\n  or:\n    api: send @ 0x481525\nfunction @ 0x481F24\n  or:\n    api: sendto @ 0x482063\n\nconnect TCP socket\nnamespace  communication/socket/tcp                                             \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           mrhafizfarhad@gmail.com                                              \nscope      function                                                             \nmbc        Communication::Socket Communication::Connect Socket [C0001.004]      \nfunction @ 0x480FDF\n  and:\n    match: create TCP socket @ 0x481033\n      or:\n        and:\n          or:\n            number: 0x6 = IPPROTO_TCP @ 0x481033\n          number: 0x1 = SOCK_STREAM @ 0x481035\n          number: 0x2 = AF_INET @ 0x481037\n          or:\n            api: socket @ 0x481039\n    match: connect socket @ 0x4810AF\n      or:\n        api: connect @ 0x4810B6\n\ncreate TCP socket (2 matches)\nnamespace   communication/socket/tcp                                            \nauthor      william.ballenthin@mandiant.com, joakim@intezer.com,                \n            anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com       \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create TCP Socket [C0001.011]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ 0x481033 in function 0x480FDF\n  or:\n    and:\n      or:\n        number: 0x6 = IPPROTO_TCP @ 0x481033\n      number: 0x1 = SOCK_STREAM @ 0x481035\n      number: 0x2 = AF_INET @ 0x481037\n      or:\n        api: socket @ 0x481039\nbasic block @ 0x481197 in function 0x48112B\n  or:\n    and:\n      or:\n        number: 0x6 = IPPROTO_TCP @ 0x481197\n      number: 0x1 = SOCK_STREAM @ 0x481199\n      number: 0x2 = AF_INET @ 0x48119B\n      or:\n        api: socket @ 0x48119D\n\ncreate UDP socket (2 matches)\nnamespace   communication/socket/udp/send                                       \nauthor      moritz.raabe@mandiant.com, joakim@intezer.com,                      \n            michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create UDP Socket [C0001.010]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ 0x48177E in function 0x48172D\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x481780, 0x481782\n      or:\n        number: 0x11 = IPPROTO_UDP @ 0x48177E\n      or:\n        api: socket @ 0x481784\nbasic block @ 0x4819FD in function 0x4819FD\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x481A20, 0x481A22\n      or:\n        number: 0x11 = IPPROTO_UDP @ 0x481A1E\n      or:\n        api: socket @ 0x481A24\n\nact as TCP client\nnamespace  communication/tcp/client                                     \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                                     \nmbc        Communication::Socket Communication::TCP Client [C0001.008]  \nfunction @ 0x480FDF\n  or:\n    match: connect TCP socket @ 0x480FDF\n      and:\n        match: create TCP socket @ 0x481033\n          or:\n            and:\n              or:\n                number: 0x6 = IPPROTO_TCP @ 0x481033\n              number: 0x1 = SOCK_STREAM @ 0x481035\n              number: 0x2 = AF_INET @ 0x481037\n              or:\n                api: socket @ 0x481039\n        match: connect socket @ 0x4810AF\n          or:\n            api: connect @ 0x4810B6\n\ncompiled with AutoIt\nnamespace   compiler/autoit                                                     \nauthor      william.ballenthin@mandiant.com                                     \nscope       file                                                                \natt&ck      Execution::Command and Scripting Interpreter [T1059]                \nreferences  https://fumik0.com/2019/03/25/lets-play-with-qulab-an-exotic-malwar…\nor:\n  string: \"AutoIt Error\" @ file+0xD5910\n  string: \">>>AUTOIT NO CMDEXECUTE<<<\" @ file+0x9BF64\n  string: \"#requireadmin\" @ file+0x9EB28\n  string: \"#OnAutoItStartRegister\" @ file+0x9EAD8\n  substring: >>>AUTOIT SCRIPT<<<\n    - \">>>AUTOIT SCRIPT<<<\" @ file+0xC5640\n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32 \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \nmbc        Data::Checksum::CRC32 [C0032.001]\nfunction @ 0x4823E8\n  or:\n    bytes: 00000000963007772c610eeeba51099919c46d078ff46a7035a563e9a395649e = crc32_tab @ 0x48242B, 0x48243F, 0x48244E\n\nencode data using Base64\nnamespace  data-manipulation/encoding/base64                                    \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::Base64 [C0026.001]         \nfunction @ 0x41BEAD\n  or:\n    and:\n      mnemonic: shl @ 0x41C098, 0x45B1BE, 0x45B245, 0x45B424, and 3 more...\n      mnemonic: shr @ 0x41BEE6, 0x41C310, 0x41C500\n      number: 0x3F = modulo 64 @ 0x41C25B, 0x41C296, 0x41C3BA, 0x41C403, and 6 more...\n      or:\n        number: 0x3D = '=' @ 0x41C5C2, 0x459581, 0x45959D, 0x459A4A, and 4 more...\n      match: contain loop @ 0x41BEAD\n        or:\n          characteristic: loop @ 0x41BEAD\n          characteristic: tight loop @ 0x41C0D3, 0x45A209, 0x45A37A, 0x45AD30, and 12 more...\n      optional:\n        number: 0x2 @ 0x41C049, 0x41C14F, 0x41C310, 0x41C32B, and 152 more...\n        number: 0x3 @ 0x41C2DC, 0x459353, 0x459429, 0x459538, and 4 more...\n        number: 0x4 @ 0x41C2BC, 0x41CC04, 0x458FD9, 0x4591CC, and 24 more...\n        number: 0x6 @ 0x41C55C, 0x41C57C, 0x41C604, 0x4590F1, and 8 more...\n        number: 0xF @ 0x41C91D, 0x41CBE2, 0x45A926, 0x45B30B, and 3 more...\n\nencode data using XOR (7 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x4695EE in function 0x46959C\n  and:\n    characteristic: tight loop @ 0x4695EE\n    characteristic: nzxor @ 0x4695EE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x471F30 in function 0x471F24\n  and:\n    characteristic: tight loop @ 0x471F30\n    characteristic: nzxor @ 0x471F3C\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x471F9C in function 0x471F64\n  and:\n    characteristic: tight loop @ 0x471F9C\n    characteristic: nzxor @ 0x471FA1, 0x471FAE, 0x471FBB, 0x471FBD\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x471FD6 in function 0x471F64\n  and:\n    characteristic: tight loop @ 0x471FD6\n    characteristic: nzxor @ 0x471FDB, 0x471FE3, 0x471FF7, 0x471FFB\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x47284B in function 0x47281C\n  and:\n    characteristic: tight loop @ 0x47284B\n    characteristic: nzxor @ 0x472858\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x472ABF in function 0x472865\n  and:\n    characteristic: tight loop @ 0x472ABF\n    characteristic: nzxor @ 0x472ACC\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x47D73F in function 0x47D71C\n  and:\n    characteristic: tight loop @ 0x47D73F\n    characteristic: nzxor @ 0x47D74A\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nhash data using djb2\nnamespace   data-manipulation/hashing/djb2                                      \nauthor      awillia2@cisco.com, still@teamt5.org                                \nscope       function                                                            \nmbc         Data::Non-Cryptographic Hash::djb2 [C0030.006]                      \nreferences  https://twitter.com/r3c0nst/status/1392405576131436546,             \n            http://www.cse.yorku.ca/~oz/hash.html                               \nfunction @ 0x408273\n  and:\n    instruction:\n      and:\n        mnemonic: mov @ 0x408284\n        number: 0x1505 @ 0x408284\n    or:\n      instruction:\n        and:\n          number: 0x21 @ 0x408291\n          or:\n            mnemonic: imul @ 0x408291\n\nauthenticate HMAC\nnamespace   data-manipulation/hmac                                              \nauthor      moritz.raabe@mandiant.com                                           \nscope       function                                                            \nmbc         Cryptography::Hashed Message Authentication Code [C0061]            \nreferences  https://tools.ietf.org/html/rfc2104,                                \n            https://tools.ietf.org/html/rfc4634, https://github.com/ogay/hmac   \nfunction @ 0x41BEAD\n  and:\n    number: 0x36 = inner padding byte value @ 0x45A89F, 0x45BF8B\n    number: 0x5C = outer padding byte value @ 0x41C20E, 0x41C5D0, 0x41C691, 0x41C6A4, and 8 more...\n    match: contain loop @ 0x41BEAD\n      or:\n        characteristic: loop @ 0x41BEAD\n        characteristic: tight loop @ 0x41C0D3, 0x45A209, 0x45A37A, 0x45AD30, and 12 more...\n    count(characteristic(nzxor)): 2 or more @ 0x41BEFA, 0x41C50E\n    optional: = block size\n      number: 0x40 = MD5, SHA-1, SHA-224, or SHA-256 @ 0x45AA0A, 0x45AC60, 0x45B980\n      number: 0x80 = SHA-384 or SHA-512 @ 0x41C089, 0x41C9F5, 0x41CA50, 0x41CAC2, and 2 more...\n\ngenerate random numbers using a Mersenne Twister (4 matches)\nnamespace  data-manipulation/prng/mersenne                      \nauthor     moritz.raabe@mandiant.com                            \nscope      function                                             \nmbc        Cryptography::Generate Pseudo-random Sequence [C0021]\nfunction @ 0x471E7A\n  or:\n    number: 0xFF3A58AD @ 0x471EA0\nfunction @ 0x471EC0\n  or:\n    number: 0xFF3A58AD @ 0x471EEB\nfunction @ 0x471F24\n  or:\n    number: 0x6C078965 @ 0x471F3E\nfunction @ 0x471F64\n  or:\n    number: 0x9908B0DF @ 0x471FB6, 0x471FF2, 0x472029\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x406122\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x4442F5\n        api: LockResource @ 0x44431D\n      optional:\n        or:\n          api: FindResourceEx @ 0x406149\n        api: SizeofResource @ 0x44430A\n\nlist drag and drop files\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ 0x47EA26\n  and:\n    api: DragQueryFile @ 0x47EB9E, 0x47EBBB, 0x47EBF9\n    and:\n      api: GetClipboardData @ 0x47EA6A, 0x47EAF8, 0x47EB6B\n      number: 0xF = HDROP @ 0x47EB5D, 0x47EB69\n\nopen clipboard (2 matches)\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ 0x47EA26\n  and:\n    api: OpenClipboard @ 0x47EA50\n    optional:\n      api: CloseClipboard @ 0x47EA76, 0x47EAB8, 0x47EAE9, 0x47EB58, and 2 more...\nfunction @ 0x47EC91\n  and:\n    api: OpenClipboard @ 0x47ECB8, 0x47ED76\n    optional:\n      api: CloseClipboard @ 0x47ECC4, 0x47EDCA\n\nread clipboard data\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Collection::Clipboard Data [T1115]                                  \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ 0x47EA26\n  and:\n    optional:\n      match: open clipboard @ 0x47EA26\n        and:\n          api: OpenClipboard @ 0x47EA50\n          optional:\n            api: CloseClipboard @ 0x47EA76, 0x47EAB8, 0x47EAE9, 0x47EB58, and 2 more...\n      match: contain loop @ 0x47EA26\n        or:\n          characteristic: tight loop @ 0x47EBAF\n      api: GlobalLock @ 0x47EAAE, 0x47EB09, 0x47EB7C\n      api: GlobalUnlock @ 0x47EAE3, 0x47EB49, 0x47EC1A\n    or:\n      basic block:\n        and:\n          api: GetClipboardData @ 0x47EA6A\n          optional:\n            number: 0xD = CF_UNICODETEXT @ 0x47EA68\n        and:\n          api: GetClipboardData @ 0x47EB6B\n        and:\n          api: GetClipboardData @ 0x47EAF8\n          optional:\n            number: 0x1 = CF_TEXT @ 0x47EAF6\n\nwrite clipboard data\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \nmbc         Impact::Clipboard Modification [E1510]                              \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ 0x47EC91\n  and:\n    optional:\n      match: open clipboard @ 0x47EC91\n        and:\n          api: OpenClipboard @ 0x47ECB8, 0x47ED76\n          optional:\n            api: CloseClipboard @ 0x47ECC4, 0x47EDCA\n      api: EmptyClipboard @ 0x47ECBE, 0x47ED7C\n    or:\n      api: SetClipboardData @ 0x47ED85\n\ninteract with driver via IOCTL (4 matches)\nnamespace  host-interaction/driver  \nauthor     moritz.raabe@mandiant.com\nscope      instruction              \ninstruction @ 0x46D563\n  or:\n    api: DeviceIoControl @ 0x46D563\ninstruction @ 0x46D5DD\n  or:\n    api: DeviceIoControl @ 0x46D5DD\ninstruction @ 0x46D690\n  or:\n    api: DeviceIoControl @ 0x46D690\ninstruction @ 0x473D73\n  or:\n    api: DeviceIoControl @ 0x473D73\n\nget COMSPEC environment variable\nnamespace  host-interaction/environment-variable          \nauthor     matthew.williams@mandiant.com                  \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Operating System::Environment Variable [C0034] \nfunction @ 0x41D70E\n  and:\n    match: query environment variable @ 0x41D70E\n      or:\n        api: GetEnvironmentVariable @ 0x45E05B, 0x45E06E, 0x45E0CA, 0x45E0DD, and 4 more...\n    or:\n      string: \"COMSPEC\" @ 0x45E056\n\nquery environment variable (3 matches)\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x41D70E\n  or:\n    api: GetEnvironmentVariable @ 0x45E05B, 0x45E06E, 0x45E0CA, 0x45E0DD, and 4 more...\nfunction @ 0x47EE14\n  or:\n    api: GetEnvironmentVariable @ 0x47EE51\nfunction @ 0x487559\n  or:\n    api: GetEnvironmentVariable @ 0x4875FD\n\nset environment variable (2 matches)\nnamespace  host-interaction/environment-variable                           \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \nmbc        Operating System::Environment Variable::Set Variable [C0034.001]\nfunction @ 0x43D170\n  or:\n    api: SetEnvironmentVariable @ 0x43D03C\nfunction @ 0x47EE84\n  or:\n    api: SetEnvironmentVariable @ 0x47EEC4\n\nget common file path (9 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x40445D\n  or:\n    api: GetCurrentDirectory @ 0x40448D\nfunction @ 0x41D70E\n  or:\n    api: GetTempPath @ 0x45E085\n    api: GetSystemDirectory @ 0x45DB98\n    api: GetWindowsDirectory @ 0x45DB28\n    api: GetCurrentDirectory @ 0x45DD7F\nfunction @ 0x41F962\n  or:\n    api: GetCurrentDirectory @ 0x41F97E\nfunction @ 0x46DE45\n  or:\n    api: SHGetFolderPath @ 0x46DE5E\nfunction @ 0x472F35\n  or:\n    api: GetTempPath @ 0x472F4D\n    api: GetTempFileName @ 0x472F62\nfunction @ 0x4779B4\n  or:\n    api: SHGetSpecialFolderLocation @ 0x477AAD\nfunction @ 0x477D0E\n  or:\n    api: GetCurrentDirectory @ 0x477ECB\nfunction @ 0x4780B3\n  or:\n    api: GetCurrentDirectory @ 0x47822E\nfunction @ 0x48AF20\n  or:\n    api: GetSystemDirectory @ 0x48B0D7, 0x48B0FB\n    api: GetCurrentDirectory @ 0x48B13B, 0x48B15D\n\nset current directory (7 matches)\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x40445D\n  or:\n    api: SetCurrentDirectory @ 0x404596, 0x443769\nfunction @ 0x40AD7C\n  or:\n    api: SetCurrentDirectory @ 0x40AEF0, 0x40B045\nfunction @ 0x4753D4\n  or:\n    api: SetCurrentDirectory @ 0x4753EC\nfunction @ 0x477D0E\n  or:\n    api: SetCurrentDirectory @ 0x477EDF, 0x477F35, 0x477F7E, 0x477FCE\nfunction @ 0x4780B3\n  or:\n    api: SetCurrentDirectory @ 0x478242, 0x478274, 0x4782AA, 0x4782B3\nfunction @ 0x479560\n  or:\n    api: SetCurrentDirectory @ 0x479668, 0x479686\nfunction @ 0x4796BB\n  or:\n    api: SetCurrentDirectory @ 0x4797AE, 0x4797CC\n\ncopy file (3 matches)\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ 0x46CE1E\n  or:\n    basic block:\n      and:\n        number: 0x2 = FO_COPY @ 0x46CF40\n        or:\n          api: SHFileOperation @ 0x46CF7F\nfunction @ 0x46D1BA\n  or:\n    api: CopyFileEx @ 0x46D1D0\nfunction @ 0x472865\n  or:\n    api: CopyFile @ 0x472BBB\n\ncreate directory (2 matches)\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x46D1DF\n  or:\n    api: CreateDirectory @ 0x46D237, 0x46D294\nfunction @ 0x473C3C\n  or:\n    api: CreateDirectory @ 0x473CBB\n\ndelete directory (2 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ 0x46E77B\n  or:\n    api: RemoveDirectory @ 0x46E7B9\nfunction @ 0x473C3C\n  or:\n    api: RemoveDirectory @ 0x473CEC\n\ndelete file (6 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x46CF94\n  or:\n    api: DeleteFile @ 0x46D0FB, 0x46D12B\nfunction @ 0x46D2C7\n  or:\n    api: DeleteFile @ 0x46D38E\nfunction @ 0x46E77B\n  or:\n    basic block:\n      and:\n        number: 0x3 = FO_DELETE @ 0x46E7D0\n        or:\n          api: SHFileOperation @ 0x46E806\nfunction @ 0x472865\n  or:\n    api: DeleteFile @ 0x472B23, 0x472BA5, 0x472BCC, 0x472BDE\nfunction @ 0x4755F7\n  or:\n    api: DeleteFile @ 0x4756EC\nfunction @ 0x4778BA\n  or:\n    basic block:\n      and:\n        number: 0x3 = FO_DELETE @ 0x4778FA\n        or:\n          api: SHFileOperation @ 0x47792E\n\ncheck if file exists (3 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x46D1DF\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x46D219\n        instruction:\n          and:\n            mnemonic: cmp @ 0x46D21F\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x46D21F\n    basic block:\n      and:\n        api: GetLastError @ 0x46D228\n        instruction:\n          and:\n            mnemonic: cmp @ 0x46D230\n            number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x46D230\nfunction @ 0x46DADC\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x46DAFB\n        instruction:\n          and:\n            mnemonic: cmp @ 0x46DB01\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x46DB01\nfunction @ 0x46E0B7\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x46E0B8\n        instruction:\n          and:\n            mnemonic: cmp @ 0x46E0BE\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x46E0BE\n\nenumerate files on Windows (6 matches)\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ 0x46CF94\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x46D040\n      or:\n        api: FindNextFile @ 0x46D155\n      optional:\n        api: FindClose @ 0x46D171, 0x46D182\n        match: contain loop @ 0x46CF94\n          or:\n            characteristic: loop @ 0x46CF94\nfunction @ 0x46D2C7\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x46D33E\n      or:\n        api: FindNextFile @ 0x46D39F\n      optional:\n        api: FindClose @ 0x46D3B6, 0x46D3BF\n        match: contain loop @ 0x46D2C7\n          or:\n            characteristic: loop @ 0x46D2C7\nfunction @ 0x475BB5\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x475BDF\n      or:\n        api: FindNextFile @ 0x475C35\n      optional:\n        api: FindClose @ 0x475C7D\n        match: contain loop @ 0x475BB5\n          or:\n            characteristic: loop @ 0x475BB5\nfunction @ 0x479560\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x479581, 0x479618\n      or:\n        api: FindNextFile @ 0x4795F1, 0x479690\n      optional:\n        api: FindClose @ 0x4795FC, 0x47969D, 0x4796AD\n        match: contain loop @ 0x479560\n          or:\n            characteristic: loop @ 0x479560\n            characteristic: recursive call @ 0x479560\nfunction @ 0x4796BB\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x4796DC, 0x47975E\n      or:\n        api: FindNextFile @ 0x479737, 0x4797D6\n      optional:\n        api: FindClose @ 0x479742, 0x4797E3, 0x4797F3\n        match: contain loop @ 0x4796BB\n          or:\n            characteristic: loop @ 0x4796BB\n            characteristic: recursive call @ 0x4796BB\nfunction @ 0x479A49\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x479A96\n      or:\n        api: FindNextFile @ 0x479B93\n      optional:\n        api: FindClose @ 0x479BA9\n        match: contain loop @ 0x479A49\n          or:\n            characteristic: loop @ 0x479A49\n            characteristic: recursive call @ 0x479A49\n\nenumerate files recursively (3 matches)\nnamespace  host-interaction/file-system/files/list        \nauthor     @_re_fox, anushka.virgaonkar@mandiant.com      \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nmbc        Discovery::File and Directory Discovery [E1083]\nfunction @ 0x479560\n  and:\n    characteristic: recursive call @ 0x479560\n    or:\n      match: enumerate files on Windows @ 0x479560\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x479581, 0x479618\n            or:\n              api: FindNextFile @ 0x4795F1, 0x479690\n            optional:\n              api: FindClose @ 0x4795FC, 0x47969D, 0x4796AD\n              match: contain loop @ 0x479560\n                or:\n                  characteristic: loop @ 0x479560\n                  characteristic: recursive call @ 0x479560\nfunction @ 0x4796BB\n  and:\n    characteristic: recursive call @ 0x4796BB\n    or:\n      match: enumerate files on Windows @ 0x4796BB\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x4796DC, 0x47975E\n            or:\n              api: FindNextFile @ 0x479737, 0x4797D6\n            optional:\n              api: FindClose @ 0x479742, 0x4797E3, 0x4797F3\n              match: contain loop @ 0x4796BB\n                or:\n                  characteristic: loop @ 0x4796BB\n                  characteristic: recursive call @ 0x4796BB\nfunction @ 0x479A49\n  and:\n    characteristic: recursive call @ 0x479A49\n    or:\n      match: enumerate files on Windows @ 0x479A49\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x479A96\n            or:\n              api: FindNextFile @ 0x479B93\n            optional:\n              api: FindClose @ 0x479BA9\n              match: contain loop @ 0x479A49\n                or:\n                  characteristic: loop @ 0x479A49\n                  characteristic: recursive call @ 0x479A49\n\nget file attributes (5 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x46D1DF in function 0x46D1DF\n  or:\n    api: GetFileAttributes @ 0x46D219\nbasic block @ 0x46DAFA in function 0x46DADC\n  or:\n    api: GetFileAttributes @ 0x46DAFB\nbasic block @ 0x46E0B7 in function 0x46E0B7\n  or:\n    api: GetFileAttributes @ 0x46E0B8\nbasic block @ 0x477F04 in function 0x477D0E\n  or:\n    api: GetFileAttributes @ 0x477F09\nbasic block @ 0x4795B8 in function 0x479560\n  or:\n    api: GetFileAttributes @ 0x4795BF\n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x482A05\n  or:\n    api: GetFileSize @ 0x482C9C\nfunction @ 0x498461\n  or:\n    api: GetFileSize @ 0x498494\n\nget file version info\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x46DB2C\n  and:\n    or:\n      api: GetFileVersionInfo @ 0x46DB64\n    optional: = retrieve specified version information from the version-information resource\n      api: VerQueryValue @ 0x46DBDA, 0x46DC84\n      or:\n        api: GetFileVersionInfoSize @ 0x46DB3E\n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ 0x477F04 in function 0x477D0E\n  or:\n    api: SetFileAttributes @ 0x477F23\nbasic block @ 0x4795B8 in function 0x479560\n  or:\n    api: SetFileAttributes @ 0x4795D9\n\nmove file (3 matches)\nnamespace  host-interaction/file-system/move                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Move File [C0063]                         \nfunction @ 0x46CE1E\n  or:\n    api: MoveFile @ 0x46CE9D\nfunction @ 0x46CF94\n  or:\n    api: MoveFile @ 0x46D10E\nfunction @ 0x46E319\n  or:\n    api: MoveFile @ 0x46E3CA\n    basic block:\n      and:\n        number: 0x1 = FO_MOVE @ 0x46E566\n        or:\n          api: SHFileOperation @ 0x46E56E\n\nread .ini file (4 matches)\nnamespace  host-interaction/file-system/read     \nauthor     @_re_fox, michael.hunhoff@mandiant.com\nscope      function                              \nmbc        File System::Read File [C0051]        \nfunction @ 0x4783FD\n  and:\n    or:\n      api: GetPrivateProfileString @ 0x478482\nfunction @ 0x4784BF\n  and:\n    or:\n      api: GetPrivateProfileSection @ 0x47852A\nfunction @ 0x4787FC\n  and:\n    or:\n      api: GetPrivateProfileSectionNames @ 0x478858\nfunction @ 0x478A19\n  and:\n    or:\n      api: GetPrivateProfileSection @ 0x478ACC, 0x478AF8\n\nread file on Windows (9 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x406A95\n  or:\n    and:\n      os: windows\n      or:\n        api: fread @ 0x406AB3\nfunction @ 0x40B230\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x40B35C\nfunction @ 0x40B3B0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x40B40C\nfunction @ 0x43921B\n  or:\n    and:\n      os: windows\n      or:\n        api: _read @ 0x439134\nfunction @ 0x47070D\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x470765, 0x470811\nfunction @ 0x472475\n  or:\n    and:\n      os: windows\n      or:\n        api: fread @ 0x4724A5\nfunction @ 0x4725B1\n  or:\n    and:\n      os: windows\n      or:\n        api: fread @ 0x4725D3\nfunction @ 0x482A05\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x482C82\n          match: create or open file @ 0x482C89\n            or:\n              api: CreateFile @ 0x482C89\n      or:\n        api: ReadFile @ 0x482CBF\nfunction @ 0x498461\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x49847E\n          match: create or open file @ 0x498484\n            or:\n              api: CreateFile @ 0x498484\n      or:\n        api: ReadFile @ 0x4984C9\n\nclear file content\nnamespace  host-interaction/file-system/write\nauthor     jakeperalta7                      \nscope      function                          \nmbc        File System::Writes File [C0052]  \nfunction @ 0x477FD5\n  and:\n    api: SetEndOfFile @ 0x478019\n    not:\n      api: SetFilePointer\n\nwrite file on Windows (7 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x41F5B3\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x45F3C6\n        api: fwrite @ 0x45F3C6\nfunction @ 0x46CC1D\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x46CC44\nfunction @ 0x470633\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x470664\nfunction @ 0x4725F5\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x47262D\n        api: fwrite @ 0x47262D\nfunction @ 0x472642\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x47265B\n        api: fwrite @ 0x47265B\nfunction @ 0x472865\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x472AF5\n        api: fwrite @ 0x472AF5\nfunction @ 0x47CD62\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x47CDC3\n        api: fwrite @ 0x47CDC3\n\nenumerate gui resources\nnamespace  host-interaction/gui                           \nauthor     johnk3r, anushka.virgaonkar@mandiant.com       \nscope      function                                       \natt&ck     Discovery::Application Window Discovery [T1010]\nfunction @ 0x464144\n  or:\n    api: EnumWindows @ 0x464832\n\nfind taskbar (3 matches)\nnamespace  host-interaction/gui/taskbar/find   \nauthor     moritz.raabe@mandiant.com           \nscope      basic block                         \nmbc        Discovery::Taskbar Discovery [B0043]\nbasic block @ 0x41EFCE in function 0x41EFAD\n  and:\n    string: \"Shell_TrayWnd\" @ 0x41EFCF\n    match: find graphical window @ 0x41EFD4\n      or:\n        api: FindWindow @ 0x41EFD4\nbasic block @ 0x492255 in function 0x492255\n  and:\n    string: \"Shell_TrayWnd\" @ 0x492258\n    match: find graphical window @ 0x49225F\n      or:\n        api: FindWindow @ 0x49225F\nbasic block @ 0x492289 in function 0x492289\n  and:\n    string: \"Shell_TrayWnd\" @ 0x492298\n    match: find graphical window @ 0x49229F\n      or:\n        api: FindWindow @ 0x49229F\n\nfind graphical window (4 matches)\nnamespace  host-interaction/gui/window/find               \nauthor     moritz.raabe@mandiant.com                      \nscope      instruction                                    \natt&ck     Discovery::Application Window Discovery [T1010]\ninstruction @ 0x41EFD4\n  or:\n    api: FindWindow @ 0x41EFD4\ninstruction @ 0x46E645\n  or:\n    api: FindWindowEx @ 0x46E645\ninstruction @ 0x49225F\n  or:\n    api: FindWindow @ 0x49225F\ninstruction @ 0x49229F\n  or:\n    api: FindWindow @ 0x49229F\n\nget graphical window text (11 matches)\nnamespace  host-interaction/gui/window/get-text           \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \nmbc        Discovery::Application Window Discovery [E1010]\nfunction @ 0x461A70\n  or:\n    and:\n      or:\n        basic block:\n          and:\n            number: 0xD = WM_GETTEXT @ 0x461AD9\n            api: SendMessage @ 0x461ADD\nfunction @ 0x46359E\n  or:\n    and:\n      api: GetWindowText @ 0x4638A5\nfunction @ 0x463B0C\n  or:\n    and:\n      or:\n        basic block:\n          and:\n            number: 0xD = WM_GETTEXT @ 0x463B66\n            api: SendMessage @ 0x463B6B\nfunction @ 0x46489C\n  or:\n    and:\n      api: GetWindowText @ 0x464922, 0x4649E9\nfunction @ 0x464BD3\n  or:\n    and:\n      optional:\n        api: IsWindowVisible @ 0x464BEB\n      or:\n        basic block:\n          and:\n            number: 0xD = WM_GETTEXT @ 0x464C3B\n            api: SendMessage @ 0x464C40\nfunction @ 0x465B9A\n  or:\n    and:\n      api: GetWindowText @ 0x465BC5\nfunction @ 0x47E8F7\n  or:\n    and:\n      api: GetWindowText @ 0x47E91E\nfunction @ 0x491E0D\n  or:\n    and:\n      api: GetWindowText @ 0x491F76\nfunction @ 0x4947A8\n  or:\n    and:\n      api: GetWindowText @ 0x494C26, 0x494C8F\nfunction @ 0x496FA4\n  or:\n    and:\n      api: GetWindowText @ 0x4971C3\nfunction @ 0x4972B7\n  or:\n    and:\n      api: GetWindowText @ 0x497423\n\nhide graphical window (8 matches)\nnamespace  host-interaction/gui/window/hide                          \nauthor     michael.hunhoff@mandiant.com                              \nscope      basic block                                               \natt&ck     Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\nbasic block @ 0x45F0F9 in function 0x41EEF7\n  and:\n    number: 0x0 = SW_HIDE @ 0x45F101\n    api: ShowWindow @ 0x45F0FB\nbasic block @ 0x4827C2 in function 0x482638\n  and:\n    number: 0x0 = SW_HIDE @ 0x48294B, 0x48295A\n    api: ShowWindow @ 0x4829BE\nbasic block @ 0x49015D in function 0x490135\n  and:\n    number: 0x0 = SW_HIDE @ 0x490163\n    api: ShowWindow @ 0x490167\nbasic block @ 0x4950F2 in function 0x495009\n  and:\n    number: 0x0 = SW_HIDE @ 0x4950F8\n    api: ShowWindow @ 0x4950FC, 0x495102\nbasic block @ 0x496B61 in function 0x496A44\n  and:\n    number: 0x0 = SW_HIDE @ 0x496B61\n    api: ShowWindow @ 0x496B66\nbasic block @ 0x49813A in function 0x4980CD\n  and:\n    number: 0x0 = SW_HIDE @ 0x49813A\n    api: ShowWindow @ 0x49813E\nbasic block @ 0x4981BF in function 0x4980CD\n  and:\n    number: 0x0 = SW_HIDE @ 0x4981BF\n    api: ShowWindow @ 0x4981C3, 0x4981D7\nbasic block @ 0x49A198 in function 0x499E78\n  and:\n    number: 0x0 = SW_HIDE @ 0x49A198\n    api: ShowWindow @ 0x49A19C\n\nget keyboard layout\nnamespace  host-interaction/hardware/keyboard                                   \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Discovery::System Location Discovery::System Language Discovery      \n           [T1614.001]                                                          \nfunction @ 0x41D70E\n  and:\n    or:\n      api: GetKeyboardLayoutName @ 0x45DF94\n\nget memory capacity\nnamespace  host-interaction/hardware/memory               \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x41F370\n  or:\n    api: GlobalMemoryStatusEx @ 0x41F39A\n\nget disk information (6 matches)\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ 0x473D97\n  or:\n    api: GetDriveType @ 0x473EF4\nfunction @ 0x4743DE\n  or:\n    api: GetDriveType @ 0x474661\nfunction @ 0x474776\n  or:\n    api: GetVolumeInformation @ 0x4747DB\nfunction @ 0x474844\n  or:\n    api: GetVolumeInformation @ 0x4748A9\nfunction @ 0x474912\n  or:\n    api: GetVolumeInformation @ 0x47497A\nfunction @ 0x4749FD\n  or:\n    api: GetDriveType @ 0x474AE8\n\nget disk size (3 matches)\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ 0x4750EB\n  or:\n    api: GetDiskFreeSpaceEx @ 0x475156\nfunction @ 0x4751CE\n  or:\n    api: GetDiskFreeSpaceEx @ 0x475239\nfunction @ 0x4752B1\n  or:\n    api: GetDiskFreeSpace @ 0x475334\n\nget storage device properties (2 matches)\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com                                        \nscope       function                                                            \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/winioctl/ni-wini…\nfunction @ 0x46D509\n  and:\n    number: 0x2D1400 = IOCTL_STORAGE_QUERY_PROPERTY @ 0x46D55D\n    or:\n      match: interact with driver via IOCTL @ 0x46D563\n        or:\n          api: DeviceIoControl @ 0x46D563\nfunction @ 0x46D588\n  and:\n    number: 0x2D1400 = IOCTL_STORAGE_QUERY_PROPERTY @ 0x46D5D7\n    or:\n      match: interact with driver via IOCTL @ 0x46D5DD\n        or:\n          api: DeviceIoControl @ 0x46D5DD\n\nprint debug messages\nnamespace  host-interaction/log/debug/write-event\nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \nfunction @ 0x41F5B3\n  or:\n    api: OutputDebugString @ 0x45F3E1\n\nshutdown system\nnamespace  host-interaction/os                   \nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \natt&ck     Impact::System Shutdown/Reboot [T1529]\nfunction @ 0x46E814\n  or:\n    api: ExitWindowsEx @ 0x46E850\n    api: InitiateSystemShutdownEx @ 0x46E870\n\nget hostname (2 matches)\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ 0x41D70E\n  or:\n    api: GetComputerName @ 0x45DB11\nfunction @ 0x46DD45\n  or:\n    api: gethostname @ 0x46DD7A\n\nget system information on Windows\nnamespace  host-interaction/os/info                       \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com  \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x40615E\n  and:\n    os: windows\n    or:\n      api: GetSystemInfo @ 0x406320, 0x44455F\n\ncreate process on Windows (6 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x4437E0 in function 0x40445D\n  or:\n    api: ShellExecute @ 0x4437F9\nbasic block @ 0x46134A in function 0x461145\n  or:\n    api: CreateProcessAsUser @ 0x46136D\nbasic block @ 0x461472 in function 0x461412\n  or:\n    api: CreateProcessWithLogon @ 0x461493\nbasic block @ 0x48AD7A in function 0x48AC8B\n  or:\n    api: ShellExecuteEx @ 0x48ADCA\nbasic block @ 0x48B2C1 in function 0x48AF20\n  or:\n    api: CreateProcess @ 0x48B2DD\nbasic block @ 0x498064 in function 0x498064\n  or:\n    api: CreateProcess @ 0x4980B1\n\nallocate or change RWX memory\nnamespace  host-interaction/process/inject\nauthor     @mr-tz, mehunhoff@google.com   \nscope      basic block                    \nmbc        Memory::Allocate Memory [C0007]\nbasic block @ 0x489881 in function 0x4895BB\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x489881\n            or:\n              api: VirtualAlloc @ 0x489895\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x489881\n\nenumerate processes (2 matches)\nnamespace  host-interaction/process/list                                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      function                                                             \natt&ck     Discovery::Process Discovery [T1057], Discovery::Software Discovery  \n           [T1518]                                                              \nfunction @ 0x46D3FA\n  or:\n    and:\n      api: Process32First @ 0x46D42D\n      api: Process32Next @ 0x46D44D\n      optional:\n        basic block:\n          and:\n            api: CreateToolhelp32Snapshot @ 0x46D41F\n            or:\n              number: 0x2 = TH32CS_SNAPPROCESS @ 0x46D411\nfunction @ 0x48A5A3\n  or:\n    and:\n      api: Process32First @ 0x48A5E1\n      api: Process32Next @ 0x48A6C3\n      optional:\n        basic block:\n          and:\n            api: CreateToolhelp32Snapshot @ 0x48A5D3\n            or:\n              number: 0x2 = TH32CS_SNAPPROCESS @ 0x48A5BD\n\nacquire debug privileges\nnamespace  host-interaction/process/modify                        \nauthor     william.ballenthin@mandiant.com                        \nscope      basic block                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\nbasic block @ 0x48A0B6 in function 0x48A009\n  and:\n    string: \"SeDebugPrivilege\" @ 0x48A0B6\n\nmodify access privileges (2 matches)\nnamespace  host-interaction/process/modify                        \nauthor     moritz.raabe@mandiant.com                              \nscope      instruction                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\ninstruction @ 0x461018\n  and:\n    api: AdjustTokenPrivileges @ 0x461018\ninstruction @ 0x46167E\n  and:\n    api: AdjustTokenPrivileges @ 0x46167E\n\nterminate process (3 matches)\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x46EA3E\n  or:\n    and:\n      optional:\n        match: open process @ 0x46EA6E\n          or:\n            api: OpenProcess @ 0x46EA82\n      or:\n        api: TerminateProcess @ 0x46EA8C\nfunction @ 0x487E80\n  or:\n    and:\n      or:\n        api: TerminateProcess @ 0x488223\nfunction @ 0x48A009\n  or:\n    and:\n      optional:\n        match: open process @ 0x48A08D, 0x48A0D2\n          or:\n            api: OpenProcess @ 0x48A0DA\n          or:\n            api: OpenProcess @ 0x48A094\n      or:\n        api: TerminateProcess @ 0x48A18F\n\nempty the recycle bin\nnamespace  host-interaction/recycle-bin\nauthor     moritz.raabe@mandiant.com   \nscope      function                    \nfunction @ 0x477953\n  or:\n    api: SHEmptyRecycleBin @ 0x477977\n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ 0x48B8F0\n  and:\n    optional:\n      match: create or open registry key @ 0x48BA11\n        or:\n          api: RegOpenKeyEx @ 0x48BA27\n    or:\n      api: RegEnumKeyEx @ 0x48BA8A\nfunction @ 0x48CB5B\n  and:\n    optional:\n      match: create or open registry key @ 0x48CBA6\n        or:\n          api: RegOpenKeyEx @ 0x48CBB4\n    or:\n      api: RegEnumKeyEx @ 0x48CB8B, 0x48CC4F\n\nquery or enumerate registry value (5 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x40533E\n  and:\n    optional:\n      match: create or open registry key @ 0x40533E\n        or:\n          api: RegOpenKeyEx @ 0x40545B\n    or:\n      api: RegQueryValueEx @ 0x443EEC, 0x443F2D\nfunction @ 0x4059A7\n  and:\n    optional:\n      match: create or open registry key @ 0x4059BB\n        or:\n          api: RegOpenKeyEx @ 0x4059CB\n    or:\n      api: RegQueryValueEx @ 0x4059EC\nfunction @ 0x4605C7\n  and:\n    optional:\n      match: create or open registry key @ 0x4606B3\n        or:\n          api: RegOpenKeyEx @ 0x4606C3\n    or:\n      api: RegQueryValueEx @ 0x4606ED\nfunction @ 0x48BB02\n  and:\n    optional:\n      match: create or open registry key @ 0x48BC36\n        or:\n          api: RegOpenKeyEx @ 0x48BC4C\n    or:\n      api: RegEnumValue @ 0x48BCC0\nfunction @ 0x48BD6B\n  and:\n    optional:\n      match: create or open registry key @ 0x48BEB9\n        or:\n          api: RegOpenKeyEx @ 0x48BED0\n    or:\n      api: RegQueryValueEx @ 0x48BF53, 0x48C00E, 0x48C07B, 0x48C110, and 2 more...\n\nset registry value\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x48C2DE\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x48C448\n          or:\n            api: RegCreateKeyEx @ 0x48C46B\n      or:\n        api: RegSetValueEx @ 0x48C5D9, 0x48C6E8, 0x48C774, 0x48C887\n\ndelete registry key (2 matches)\nnamespace  host-interaction/registry/delete                                \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\nscope      function                                                        \natt&ck     Defense Evasion::Modify Registry [T1112]                        \nmbc        Operating System::Registry::Delete Registry Key [C0036.002]     \nfunction @ 0x48B535\n  and:\n    optional:\n      match: create or open registry key @ 0x48B683\n        or:\n          api: RegOpenKeyEx @ 0x48B699\n    or:\n      api: RegDeleteKey @ 0x48B849\nfunction @ 0x48CB5B\n  and:\n    optional:\n      match: create or open registry key @ 0x48CBA6\n        or:\n          api: RegOpenKeyEx @ 0x48CBB4\n    or:\n      api: RegDeleteKey @ 0x48CC1A\n\ndelete registry value\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ 0x48B535\n  and:\n    optional:\n      match: create or open registry key @ 0x48B683\n        or:\n          api: RegOpenKeyEx @ 0x48B699\n    or:\n      api: RegDeleteValue @ 0x48B731\n\nget session user name\nnamespace  host-interaction/session                                             \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope      function                                                             \natt&ck     Discovery::System Owner/User Discovery [T1033], Discovery::Account   \n           Discovery [T1087]                                                    \nfunction @ 0x41D70E\n  or:\n    api: GetUserName @ 0x45DA28\n\nget token membership\nnamespace  host-interaction/session                      \nauthor     michael.hunhoff@mandiant.com                  \nscope      function                                      \natt&ck     Discovery::System Owner/User Discovery [T1033]\nfunction @ 0x4615A7\n  and:\n    api: CheckTokenMembership @ 0x4615E5\n    optional:\n      api: AllocateAndInitializeSid @ 0x4615D0\n      api: FreeSid @ 0x4615F5\n\nget token privileges\nnamespace  host-interaction/session    \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x460F58\n  and:\n    or:\n      basic block:\n        and:\n          api: GetTokenInformation @ 0x460F6E\n          number: 0x3 = TokenPrivileges @ 0x460F6B\n        and:\n          api: GetTokenInformation @ 0x460FA6\n          number: 0x3 = TokenPrivileges @ 0x460FA3\n\ncreate thread (5 matches)\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x461747 in function 0x461747\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x4617AC\nbasic block @ 0x46E114 in function 0x46E0F4\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthreadex @ 0x46E139\nbasic block @ 0x470870 in function 0x4708F7\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x47087D\nbasic block @ 0x470870 in function 0x4708F7\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x47087D\nbasic block @ 0x47D13B in function 0x47D126\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthread @ 0x47D151\n\nterminate thread\nnamespace  host-interaction/thread/terminate                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \nmbc        Process::Terminate Thread [C0039]                                    \nbasic block @ 0x4708A6 in function 0x470889\n  or:\n    api: TerminateThread @ 0x4708B9\n\nimpersonate user\nnamespace  host-interaction/user                                                \nauthor     michael.hunhoff@mandiant.com, 99.elad.levi@gmail.com                 \nscope      function                                                             \natt&ck     Privilege Escalation::Access Token Manipulation::Token               \n           Impersonation/Theft [T1134.001]                                      \nfunction @ 0x461145\n  or:\n    api: LogonUser @ 0x4611CA\n    and:\n      api: LoadUserProfile @ 0x461327\n\n(internal) autoit file limitation\nnamespace    internal/limitation/static                                         \nauthor       william.ballenthin@mandiant.com                                    \nscope        file                                                               \ndescription  This sample appears to be compiled with AutoIt.                    \n                                                                                \n             AutoIt is a freeware BASIC-like scripting language designed for    \n             automating the Windows GUI.                                        \n             capa cannot handle AutoIt scripts. This means that the results will\n             be misleading or incomplete.                                       \n             You may have to analyze the file manually, using a tool like the   \n             AutoIt decompiler MyAut2Exe.                                       \n                                                                                \nor:\n  match: compiler/autoit @ global\n    or:\n      string: \"AutoIt Error\" @ file+0xD5910\n      string: \">>>AUTOIT NO CMDEXECUTE<<<\" @ file+0x9BF64\n      string: \"#requireadmin\" @ file+0x9EB28\n      string: \"#OnAutoItStartRegister\" @ file+0x9EAD8\n      substring: >>>AUTOIT SCRIPT<<<\n        - \">>>AUTOIT SCRIPT<<<\" @ file+0xC5640\n\nlink function at runtime on Windows (13 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x4062E6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4062E6\ninstruction @ 0x406816\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x406816\ninstruction @ 0x406850\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x406850\ninstruction @ 0x432FC7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x432FC7\ninstruction @ 0x432FC7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x432FC7\ninstruction @ 0x45DB5B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x45DB5B\ninstruction @ 0x4671A3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4671A3\ninstruction @ 0x483FF4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x483FF4\ninstruction @ 0x488EF7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x488EF7\ninstruction @ 0x488F13\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x488F13\ninstruction @ 0x488F59\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x488F59\ninstruction @ 0x48B82B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x48B82B\ninstruction @ 0x48CBF6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x48CBF6\n\nparse PE header\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x40B7E0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x40B810, 0x40B824, 0x40B82D, 0x40B84F, and 43 more...\n      or:\n        and:\n          number: 0x50 @ 0x450313\n          number: 0x45 @ 0x40BC73\n      or:\n        and:\n          number: 0x4D @ 0x40BB79\n          number: 0x5A @ 0x40B92F, 0x40B973, 0x40BCA4\n\nresolve function by parsing PE exports (15 matches)\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x401641\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x401641\n      mnemonic: movzx @ 0x401B19, 0x401B67, 0x401BA4, 0x401BEE, and 2 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x401AB7, 0x401AF7, 0x442A22\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x401760\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x401B05, 0x401B29, 0x401B5B, 0x401B63, and 11 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x40165B, 0x401679, 0x401A7C, 0x401BB7, and 8 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x401A6C, 0x401A9E, 0x401ADE, 0x401B15, and 8 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x401AB3, 0x401AC0, 0x401AF0, 0x401B25, and 12 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x401AA2, 0x401AD4, 0x401BD5, 0x4425C7, and 11 more...\nfunction @ 0x408BAA\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x408BAA\n      mnemonic: movzx @ 0x445922, 0x445B7A\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x408D85, 0x408DDB\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x445A85, 0x445B3F\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x408C7B, 0x408CD7, 0x408D0F, 0x408D4C, and 9 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x408BB8, 0x408CBE, 0x408DC2, 0x408DD1, and 7 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x408BF6, 0x408C12, 0x408C87, 0x408D89\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x408D20, 0x445980, 0x445A4F, 0x445AB4, and 2 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x408CA5, 0x408CD3, 0x408DAF, 0x408E24, and 2 more...\nfunction @ 0x4095C0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x4095C0\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x4096AC, 0x409887, 0x4098DD, 0x4099C7\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x4463CA, 0x446461, 0x4465C9, 0x44661E, and 1 more...\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x409653, 0x409864, 0x446280, 0x4462A5, and 9 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x4096B0, 0x4098EC, 0x4465C1\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x4096BC, 0x40988B, 0x40989D, 0x4098AE, and 6 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x4096A4, 0x409963, 0x40996D, 0x409971, and 7 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x4096B8, 0x4097D8, 0x409909, 0x409931, and 6 more...\nfunction @ 0x40A180\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x40A180\n      mnemonic: movzx @ 0x40A1DD, 0x40A1FF, 0x40A20D, 0x40A21F, and 490 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x40A558, 0x449751, 0x44976C\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x40A670, 0x40A8C8, 0x44738C, 0x447398, and 18 more...\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x40A647, 0x40A887, 0x447695, 0x447A2F, and 1 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x4474A1, 0x4474D4, 0x447577, 0x4475AA, and 2 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x40A7ED, 0x447F8A, 0x448031, 0x44806F, and 14 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x40A7FB, 0x447F9C, 0x447FBA, 0x44803B, and 23 more...\nfunction @ 0x40AD7C\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x40AD7C\n      mnemonic: movzx @ 0x40AF89, 0x44FB38\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x44FAEE, 0x44FAFC, 0x44FB1F, 0x44FCE1\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x40ADD7, 0x40B08A\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x40AD92, 0x40AF43, 0x40B0D0, 0x44FAA7, and 6 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x40ADBC, 0x40AE73, 0x44FBCB, 0x44FC8B, and 1 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x40AFA8, 0x40B019, 0x40B02B, 0x44FBCF, and 2 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x40ADB8, 0x40AF21, 0x40AF49, 0x40B0CC, and 6 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x40AF4D, 0x40AFCD, 0x40B011, 0x44FC5F, and 2 more...\nfunction @ 0x40D840\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x40D840\n      mnemonic: movzx @ 0x40DD22, 0x40DEE0, 0x40DEE7, 0x40DEF0, and 4 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x40D863, 0x40D996, 0x40DD88, 0x40DE6E, and 8 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x40D8C7\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x40D92B, 0x40D989, 0x40D9C0, 0x40DA03, and 9 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x40D8E3, 0x40DC92, 0x40DCC7, 0x40DFCA, and 8 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x40D8CB, 0x40D927, 0x40DAB6, 0x40DBBC, and 14 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x40D9B7, 0x40DA33, 0x40DAC0, 0x40DB79, and 20 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x40D85D, 0x40D922, 0x40D98E, 0x40DE85, and 11 more...\nfunction @ 0x410540\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x410540\n      mnemonic: movzx @ 0x410600, 0x41062B, 0x41066B, 0x4107F2, and 29 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x410592\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x410876, 0x410AAA, 0x410BFC, 0x410C2C, and 7 more...\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x41059A, 0x4105D1, 0x410652, 0x4106C4, and 22 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x410A1F, 0x411150, 0x411166, 0x4112C1, and 9 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x41058A, 0x4105B5, 0x41065A, 0x410A26, and 14 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x410552, 0x4108D8, 0x41092E, 0x410938, and 23 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x410691, 0x410842, 0x4108BB, 0x4108C4, and 27 more...\nfunction @ 0x41BEAD\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x41BEAD\n      mnemonic: movzx @ 0x41C06A, 0x41C091, 0x41C0A0, 0x41C0A8, and 128 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x41C16F, 0x45A1E8, 0x45A34E, 0x45B07F\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x459C84, 0x45B005\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x459F7A, 0x45B03F, 0x45B060, 0x45B07C, and 2 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x45933F, 0x45AF58, 0x45B1CB, 0x45B252\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x41C052, 0x41C302, 0x41C338, 0x41C408, and 23 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x458F91, 0x458FCD, 0x459172, 0x4591C1, and 1 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x459046, 0x459E17\nfunction @ 0x466502\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x466502\n      mnemonic: movzx @ 0x4666E8, 0x4667E7, 0x4669E6, 0x4669EC\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x46656E, 0x46659F, 0x466602, 0x46674E, and 7 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x46661E\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x466641, 0x466652, 0x466662, 0x466686, and 11 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x466554, 0x466571, 0x46657B, 0x46682E, and 7 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x466596, 0x4665CF, 0x466616, 0x4667A9, and 3 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x4665C4, 0x46665B, 0x4667AD, 0x46683F, and 1 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x46671D, 0x466769, 0x4667B1, 0x4667CC, and 2 more...\nfunction @ 0x4681EE\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x4681EE\n      mnemonic: movzx @ 0x468256, 0x46826B, 0x4682A7, 0x4682F8, and 8 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x4684CE\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x46852F\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x4683DF, 0x4686B0\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x468378, 0x468407, 0x468439\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x468401\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x4683E5, 0x468612\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x4683FB, 0x4687AF\nfunction @ 0x4763AC\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x4763AC\n      mnemonic: movzx @ 0x47645E, 0x476474, 0x476480, 0x476489\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x476405, 0x476580, 0x476597, 0x4767DE\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x476707\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x47652F, 0x4765A3, 0x4765EC, 0x476638, and 4 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x4763D3, 0x47642F, 0x4764C2, 0x4764C7, and 3 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x476626\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x476542, 0x4765C2, 0x4765F9, 0x476645, and 9 more...\nfunction @ 0x476E0F\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x476E0F\n      mnemonic: movzx @ 0x476EA3, 0x476EA6\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x476E8F\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x477044, 0x4770D8, 0x4771A4\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x476E7D, 0x476E9B, 0x476EAA, 0x476FA1, and 1 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x476E26, 0x476EE6, 0x476EFE, 0x476F13, and 4 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x476F24, 0x476F3C, 0x47706B, 0x4770B0\nfunction @ 0x47902A\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x47902A\n      mnemonic: movzx @ 0x47912D, 0x47913D, 0x47916B, 0x479184\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x4790E8, 0x479508\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x479080\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x479131, 0x479174, 0x479266, 0x47929D, and 3 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x4791BC, 0x4791CA, 0x4791F4, 0x479225, and 4 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x479051, 0x4790B8, 0x479202, 0x47930A, and 1 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x47916F, 0x47927E, 0x4792D5, 0x4794E8, and 1 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x47926E, 0x4794FC\nfunction @ 0x487E80\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x487E80\n      mnemonic: movzx @ 0x487E8C\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x487FF3, 0x48829E\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x487F41, 0x4881C4, 0x488201\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x487EF1, 0x487F23, 0x487F9A, 0x487FDB, and 7 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x488092, 0x488118, 0x488136\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x487FBF, 0x488192, 0x488197, 0x4881DA, and 3 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x487F38, 0x487FAF, 0x487FEA, 0x488018, and 7 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x487FE6, 0x487FF8, 0x488004, 0x48808E, and 2 more...\nfunction @ 0x490F26\n  and:\n    os: windows\n    or:\n      mnemonic: movzx @ 0x49110E, 0x4912C4, 0x4912CA\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x491140, 0x491288\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x491028\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x490FB0, 0x490FC8, 0x490FDA, 0x490FED, and 6 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x490F4B, 0x490FD6, 0x4910C5\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x490F43, 0x49107D, 0x4912B0\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x49106A, 0x4910BB, 0x491298, 0x4912A6, and 1 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x490F57, 0x490FC4, 0x4910E2, 0x491184, and 2 more...\n\nexecute shellcode via indirect call\nnamespace  load-code/shellcode            \nauthor     ronnie.salomonsen@mandiant.com \nscope      function                       \nmbc        Memory::Allocate Memory [C0007]\nfunction @ 0x4895BB\n  and:\n    match: allocate or change RWX memory @ 0x489881\n      or:\n        basic block:\n          and:\n            or:\n              match: allocate memory @ 0x489881\n                or:\n                  api: VirtualAlloc @ 0x489895\n            or:\n              number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x489881\n    or:\n      characteristic: indirect call @ 0x48963F, 0x489682\n\ncreate shortcut via IShellLink (2 matches)\nnamespace   persistence                                                         \nauthor      matthew.williams@mandiant.com                                       \nscope       function                                                            \natt&ck      Persistence::Boot or Logon Autostart Execution::Shortcut            \n            Modification [T1547.009]                                            \nreferences  https://docs.microsoft.com/en-us/windows/win32/shell/links#creating…\nfunction @ 0x47573C\n  and:\n    offset: 0x50 = psl->SetPath @ 0x475910, 0x4759CE, 0x4759FC\n    offset: 0x18 = ppf->Save @ 0x475790, 0x4757C8, 0x47585F, 0x475864, and 4 more...\n    api: CoCreateInstance @ 0x4758CC\n    bytes: 0114020000000000c000000000000046 = CLSID_ShellLink @ 0x4758C7\n    bytes: 0b01000000000000c000000000000046 = IID_IPersistFile @ 0x475AB3\n    or:\n      bytes: f914020000000000c000000000000046 = IID_IShellLinkW @ 0x4758BE\nfunction @ 0x4763AC\n  and:\n    offset: 0x50 = psl->SetPath @ 0x4763F4, 0x476610, 0x47665C, 0x4766A8, and 2 more...\n    offset: 0x18 = ppf->Save @ 0x476542, 0x4765C2, 0x4765F9, 0x476645, and 9 more...\n    api: CoCreateInstance @ 0x47656E\n    bytes: 0114020000000000c000000000000046 = CLSID_ShellLink @ 0x476569\n    bytes: 0b01000000000000c000000000000046 = IID_IPersistFile @ 0x476585\n    or:\n      bytes: f914020000000000c000000000000046 = IID_IShellLinkW @ 0x476562\n\n\n\n"},"hashes":{"md5":"9743b958d41813a0a3f62920f90a25c8","sha1":"fec4f7eea0ac8e7935081d865a2f8fee6839641b","sha256":"c5ae6f6ec23fd8d5ba1343e49bf805bbc016545715a413227bd5afe9c795002e"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 2043</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 119213</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"c5ae6f6\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"9743b958d41813a0a3f62920f90a25c8\",\n        \"sha256\": \"c5ae6f6ec23fd8d5ba1343e49bf805bbc016545715a413227bd5afe\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_allocate_memory__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"allocate memory (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x46B26C\",\n      \"label\": \"Block 0x46B26C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46B26C\"\n    },\n    {\n      \"id\": \"api_VirtualAllocEx\",\n      \"label\": \"VirtualAllocEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_library_rule_\",\n      \"label\": \"library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Modulo [C0058]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_loop__489_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (489 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401202\",\n      \"label\": \"Function 0x401202\",\n      \"type\": \"function\",\n      \"address\": \"0x401202\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__13_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (13 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40533E\",\n      \"label\": \"Block 0x40533E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40533E\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__37_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (37 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40F4AF\",\n      \"label\": \"Block 0x40F4AF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40F4AF\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_open_process__7_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"open process (7 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Open Process [C0065]\"\n      ]\n    },\n    {\n      \"id\": \"api_OpenProcess\",\n      \"label\": \"OpenProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"label\": \"check for time delay via QueryPerformanceCounter (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"QueryPerformanceCounter [B0001.033]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x469B67\",\n      \"label\": \"Function 0x469B67\",\n      \"type\": \"function\",\n      \"address\": \"0x469B67\"\n    },\n    {\n      \"id\": \"func_0x46AFC6\",\n      \"label\": \"Function 0x46AFC6\",\n      \"type\": \"function\",\n      \"address\": \"0x46AFC6\"\n    },\n    {\n      \"id\": \"func_0x46E899\",\n      \"label\": \"Function 0x46E899\",\n      \"type\": \"function\",\n      \"address\": \"0x46E899\"\n    },\n    {\n      \"id\": \"func_0x469B7E\",\n      \"label\": \"Function 0x469B7E\",\n      \"type\": \"function\",\n      \"address\": \"0x469B7E\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"QueryPerformanceCounter [B0001.033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_for_unmoving_mouse_cursor__2_matches_\",\n      \"label\": \"check for unmoving mouse cursor (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection::Human User\",\n        \"Check [B0009.012]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x498EBB\",\n      \"label\": \"Function 0x498EBB\",\n      \"type\": \"function\",\n      \"address\": \"0x498EBB\"\n    },\n    {\n      \"id\": \"func_0x499468\",\n      \"label\": \"Function 0x499468\",\n      \"type\": \"function\",\n      \"address\": \"0x499468\"\n    },\n    {\n      \"id\": \"cap_author______bitsofbinary\",\n      \"label\": \"author      BitsOfBinary\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection::Human User\",\n        \"Check [B0009.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes__9_matches_\",\n      \"label\": \"log keystrokes (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46B1FD\",\n      \"label\": \"Function 0x46B1FD\",\n      \"type\": \"function\",\n      \"address\": \"0x46B1FD\"\n    },\n    {\n      \"id\": \"func_0x463985\",\n      \"label\": \"Function 0x463985\",\n      \"type\": \"function\",\n      \"address\": \"0x463985\"\n    },\n    {\n      \"id\": \"func_0x46A90B\",\n      \"label\": \"Function 0x46A90B\",\n      \"type\": \"function\",\n      \"address\": \"0x46A90B\"\n    },\n    {\n      \"id\": \"func_0x4624E6\",\n      \"label\": \"Function 0x4624E6\",\n      \"type\": \"function\",\n      \"address\": \"0x4624E6\"\n    },\n    {\n      \"id\": \"func_0x4034CE\",\n      \"label\": \"Function 0x4034CE\",\n      \"type\": \"function\",\n      \"address\": \"0x4034CE\"\n    },\n    {\n      \"id\": \"func_0x46B198\",\n      \"label\": \"Function 0x46B198\",\n      \"type\": \"function\",\n      \"address\": \"0x46B198\"\n    },\n    {\n      \"id\": \"func_0x46B04D\",\n      \"label\": \"Function 0x46B04D\",\n      \"type\": \"function\",\n      \"address\": \"0x46B04D\"\n    },\n    {\n      \"id\": \"func_0x462CEB\",\n      \"label\": \"Function 0x462CEB\",\n      \"type\": \"function\",\n      \"address\": \"0x462CEB\"\n    },\n    {\n      \"id\": \"func_0x41EFAD\",\n      \"label\": \"Function 0x41EFAD\",\n      \"type\": \"function\",\n      \"address\": \"0x41EFAD\"\n    },\n    {\n      \"id\": \"api_AttachThreadInput\",\n      \"label\": \"AttachThreadInput\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_MapVirtualKey\",\n      \"label\": \"MapVirtualKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"label\": \"log keystrokes via polling (11 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46ABF8\",\n      \"label\": \"Function 0x46ABF8\",\n      \"type\": \"function\",\n      \"address\": \"0x46ABF8\"\n    },\n    {\n      \"id\": \"func_0x41EA9A\",\n      \"label\": \"Function 0x41EA9A\",\n      \"type\": \"function\",\n      \"address\": \"0x41EA9A\"\n    },\n    {\n      \"id\": \"func_0x46AABA\",\n      \"label\": \"Function 0x46AABA\",\n      \"type\": \"function\",\n      \"address\": \"0x46AABA\"\n    },\n    {\n      \"id\": \"func_0x4028C0\",\n      \"label\": \"Function 0x4028C0\",\n      \"type\": \"function\",\n      \"address\": \"0x4028C0\"\n    },\n    {\n      \"id\": \"func_0x46ADD8\",\n      \"label\": \"Function 0x46ADD8\",\n      \"type\": \"function\",\n      \"address\": \"0x46ADD8\"\n    },\n    {\n      \"id\": \"func_0x469B97\",\n      \"label\": \"Function 0x469B97\",\n      \"type\": \"function\",\n      \"address\": \"0x469B97\"\n    },\n    {\n      \"id\": \"func_0x46A975\",\n      \"label\": \"Function 0x46A975\",\n      \"type\": \"function\",\n      \"address\": \"0x46A975\"\n    },\n    {\n      \"id\": \"func_0x469EAF\",\n      \"label\": \"Function 0x469EAF\",\n      \"type\": \"function\",\n      \"address\": \"0x469EAF\"\n    },\n    {\n      \"id\": \"api_GetAsyncKeyState\",\n      \"label\": \"GetAsyncKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetKeyState\",\n      \"label\": \"GetKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_VkKeyScan\",\n      \"label\": \"VkKeyScan\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetKeyboardState\",\n      \"label\": \"GetKeyboardState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_capture_screenshot\",\n      \"label\": \"capture screenshot\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x482483\",\n      \"label\": \"Function 0x482483\",\n      \"type\": \"function\",\n      \"address\": \"0x482483\"\n    },\n    {\n      \"id\": \"api_GetDC\",\n      \"label\": \"GetDC\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateCompatibleDC\",\n      \"label\": \"CreateCompatibleDC\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetDIBits\",\n      \"label\": \"GetDIBits\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateCompatibleBitmap\",\n      \"label\": \"CreateCompatibleBitmap\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_remote_server_for_available_data\",\n      \"label\": \"query remote server for available data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x47CE38\",\n      \"label\": \"Block 0x47CE38\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x47CE38\"\n    },\n    {\n      \"id\": \"api_InternetQueryDataAvailable\",\n      \"label\": \"InternetQueryDataAvailable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_receive_data__4_matches_\",\n      \"label\": \"receive data (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47CE38\",\n      \"label\": \"Function 0x47CE38\",\n      \"type\": \"function\",\n      \"address\": \"0x47CE38\"\n    },\n    {\n      \"id\": \"func_0x47CD62\",\n      \"label\": \"Function 0x47CD62\",\n      \"type\": \"function\",\n      \"address\": \"0x47CD62\"\n    },\n    {\n      \"id\": \"func_0x48135A\",\n      \"label\": \"Function 0x48135A\",\n      \"type\": \"function\",\n      \"address\": \"0x48135A\"\n    },\n    {\n      \"id\": \"func_0x481B87\",\n      \"label\": \"Function 0x481B87\",\n      \"type\": \"function\",\n      \"address\": \"0x481B87\"\n    },\n    {\n      \"id\": \"api_InternetReadFile\",\n      \"label\": \"InternetReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_recvfrom\",\n      \"label\": \"recvfrom\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"api_recv\",\n      \"label\": \"recv\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data__3_matches_\",\n      \"label\": \"send data (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47C394\",\n      \"label\": \"Function 0x47C394\",\n      \"type\": \"function\",\n      \"address\": \"0x47C394\"\n    },\n    {\n      \"id\": \"func_0x481F24\",\n      \"label\": \"Function 0x481F24\",\n      \"type\": \"function\",\n      \"address\": \"0x481F24\"\n    },\n    {\n      \"id\": \"func_0x4814F1\",\n      \"label\": \"Function 0x4814F1\",\n      \"type\": \"function\",\n      \"address\": \"0x4814F1\"\n    },\n    {\n      \"id\": \"api_InternetConnect\",\n      \"label\": \"InternetConnect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_sendto\",\n      \"label\": \"sendto\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"api_HttpSendRequest\",\n      \"label\": \"HttpSendRequest\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"api_send\",\n      \"label\": \"send\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"api_HttpOpenRequest\",\n      \"label\": \"HttpOpenRequest\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_download_and_write_a_file\",\n      \"label\": \"download and write a file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"downloader\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Server to Client\",\n        \"File Transfer [B0030.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_fwrite\",\n      \"label\": \"fwrite\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api__fwrite\",\n      \"label\": \"_fwrite\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_maec_malware_category__downloader\",\n      \"label\": \"maec/malware-category  downloader\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"downloader\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Server to Client\",\n        \"File Transfer [B0030.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_and_write_data_from_server_to_client\",\n      \"label\": \"receive and write data from server to client\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_resolve_dns__3_matches_\",\n      \"label\": \"resolve DNS (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::DNS Communication::Resolve [C0011.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x481288\",\n      \"label\": \"Function 0x481288\",\n      \"type\": \"function\",\n      \"address\": \"0x481288\"\n    },\n    {\n      \"id\": \"func_0x480482\",\n      \"label\": \"Function 0x480482\",\n      \"type\": \"function\",\n      \"address\": \"0x480482\"\n    },\n    {\n      \"id\": \"func_0x46DD45\",\n      \"label\": \"Function 0x46DD45\",\n      \"type\": \"function\",\n      \"address\": \"0x46DD45\"\n    },\n    {\n      \"id\": \"api_gethostbyname\",\n      \"label\": \"gethostbyname\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::DNS Communication::Resolve [C0011.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_network_resource\",\n      \"label\": \"connect network resource\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x4605C7\",\n      \"label\": \"Function 0x4605C7\",\n      \"type\": \"function\",\n      \"address\": \"0x4605C7\"\n    },\n    {\n      \"id\": \"api_WNetAddConnection2\",\n      \"label\": \"WNetAddConnection2\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"label\": \"author       michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_parse_url\",\n      \"label\": \"parse URL\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x47D012\",\n      \"label\": \"Block 0x47D012\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x47D012\"\n    },\n    {\n      \"id\": \"api_InternetCrackUrl\",\n      \"label\": \"InternetCrackUrl\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_connect_to_http_server__2_matches_\",\n      \"label\": \"connect to HTTP server (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Connect to Server [C0002.009]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47C061\",\n      \"label\": \"Function 0x47C061\",\n      \"type\": \"function\",\n      \"address\": \"0x47C061\"\n    },\n    {\n      \"id\": \"cap_connect_to_url\",\n      \"label\": \"connect to URL\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Open URL [C0002.004]\"\n      ]\n    },\n    {\n      \"id\": \"api_InternetOpenUrl\",\n      \"label\": \"InternetOpenUrl\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_create_http_request\",\n      \"label\": \"create HTTP request\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47CC3C\",\n      \"label\": \"Function 0x47CC3C\",\n      \"type\": \"function\",\n      \"address\": \"0x47CC3C\"\n    },\n    {\n      \"id\": \"api_InternetOpen\",\n      \"label\": \"InternetOpen\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_data_from_internet__2_matches_\",\n      \"label\": \"read data from Internet (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_http_request\",\n      \"label\": \"send HTTP request\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Send Request [C0002.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Send Request [C0002.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_icmp_echo_request\",\n      \"label\": \"send ICMP echo request\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::ICMP Communication::Echo Request [C0014.002]\"\n      ]\n    },\n    {\n      \"id\": \"api_IcmpSendEcho\",\n      \"label\": \"IcmpSendEcho\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_IcmpCreateFile\",\n      \"label\": \"IcmpCreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_IcmpCloseHandle\",\n      \"label\": \"IcmpCloseHandle\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::ICMP Communication::Echo Request [C0014.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_pipe__2_matches_\",\n      \"label\": \"create pipe (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Interprocess Communication::Create Pipe [C0003.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4704C5\",\n      \"label\": \"Function 0x4704C5\",\n      \"type\": \"function\",\n      \"address\": \"0x4704C5\"\n    },\n    {\n      \"id\": \"func_0x4703F0\",\n      \"label\": \"Function 0x4703F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4703F0\"\n    },\n    {\n      \"id\": \"api_CreatePipe\",\n      \"label\": \"CreatePipe\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_connect_socket\",\n      \"label\": \"connect socket\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x4810AF\",\n      \"label\": \"Block 0x4810AF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4810AF\"\n    },\n    {\n      \"id\": \"api_connect\",\n      \"label\": \"connect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_mrhafizfarhad_gmail_com\",\n      \"label\": \"mrhafizfarhad@gmail.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_socket_status\",\n      \"label\": \"get socket status\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Get Socket Status [C0001.012]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x483070\",\n      \"label\": \"Function 0x483070\",\n      \"type\": \"function\",\n      \"address\": \"0x483070\"\n    },\n    {\n      \"id\": \"api_select\",\n      \"label\": \"select\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_initialize_winsock_library__3_matches_\",\n      \"label\": \"initialize Winsock library (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Initialize Winsock Library\",\n        \"[C0001.009]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4815DA\",\n      \"label\": \"Function 0x4815DA\",\n      \"type\": \"function\",\n      \"address\": \"0x4815DA\"\n    },\n    {\n      \"id\": \"api_WSAStartup\",\n      \"label\": \"WSAStartup\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_socket_configuration__3_matches_\",\n      \"label\": \"set socket configuration (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Set Socket Config [C0001.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x482F75\",\n      \"label\": \"Function 0x482F75\",\n      \"type\": \"function\",\n      \"address\": \"0x482F75\"\n    },\n    {\n      \"id\": \"func_0x4819FD\",\n      \"label\": \"Function 0x4819FD\",\n      \"type\": \"function\",\n      \"address\": \"0x4819FD\"\n    },\n    {\n      \"id\": \"api_setsockopt\",\n      \"label\": \"setsockopt\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_ioctlsocket\",\n      \"label\": \"ioctlsocket\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_receive_data_on_socket__2_matches_\",\n      \"label\": \"receive data on socket (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Receive Data [C0001.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data_on_socket__2_matches_\",\n      \"label\": \"send data on socket (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_tcp_socket\",\n      \"label\": \"connect TCP socket\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Connect Socket [C0001.004]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x480FDF\",\n      \"label\": \"Function 0x480FDF\",\n      \"type\": \"function\",\n      \"address\": \"0x480FDF\"\n    },\n    {\n      \"id\": \"api_socket\",\n      \"label\": \"socket\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_tcp_socket__2_matches_\",\n      \"label\": \"create TCP socket (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x481197\",\n      \"label\": \"Block 0x481197\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x481197\"\n    },\n    {\n      \"id\": \"bb_0x481033\",\n      \"label\": \"Block 0x481033\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x481033\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_udp_socket__2_matches_\",\n      \"label\": \"create UDP socket (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create UDP Socket [C0001.010]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x48177E\",\n      \"label\": \"Block 0x48177E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x48177E\"\n    },\n    {\n      \"id\": \"bb_0x4819FD\",\n      \"label\": \"Block 0x4819FD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4819FD\"\n    },\n    {\n      \"id\": \"cap_act_as_tcp_client\",\n      \"label\": \"act as TCP client\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_compiled_with_autoit\",\n      \"label\": \"compiled with AutoIt\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [T1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [T1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_with_crc32\",\n      \"label\": \"hash data with CRC32\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4823E8\",\n      \"label\": \"Function 0x4823E8\",\n      \"type\": \"function\",\n      \"address\": \"0x4823E8\"\n    },\n    {\n      \"id\": \"cap_encode_data_using_base64\",\n      \"label\": \"encode data using Base64\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x41BEAD\",\n      \"label\": \"Function 0x41BEAD\",\n      \"type\": \"function\",\n      \"address\": \"0x41BEAD\"\n    },\n    {\n      \"id\": \"cap_hash_data_using_djb2\",\n      \"label\": \"hash data using djb2\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::djb2 [C0030.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408273\",\n      \"label\": \"Function 0x408273\",\n      \"type\": \"function\",\n      \"address\": \"0x408273\"\n    },\n    {\n      \"id\": \"cap_author______awillia2_cisco_com__still_teamt5_org\",\n      \"label\": \"author      awillia2@cisco.com, still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::djb2 [C0030.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_authenticate_hmac\",\n      \"label\": \"authenticate HMAC\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Hashed Message Authentication Code [C0061]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Hashed Message Authentication Code [C0061]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"label\": \"generate random numbers using a Mersenne Twister (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence [C0021]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x471F64\",\n      \"label\": \"Function 0x471F64\",\n      \"type\": \"function\",\n      \"address\": \"0x471F64\"\n    },\n    {\n      \"id\": \"func_0x471E7A\",\n      \"label\": \"Function 0x471E7A\",\n      \"type\": \"function\",\n      \"address\": \"0x471E7A\"\n    },\n    {\n      \"id\": \"func_0x471EC0\",\n      \"label\": \"Function 0x471EC0\",\n      \"type\": \"function\",\n      \"address\": \"0x471EC0\"\n    },\n    {\n      \"id\": \"func_0x471F24\",\n      \"label\": \"Function 0x471F24\",\n      \"type\": \"function\",\n      \"address\": \"0x471F24\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x406122\",\n      \"label\": \"Function 0x406122\",\n      \"type\": \"function\",\n      \"address\": \"0x406122\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResourceEx\",\n      \"label\": \"FindResourceEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_list_drag_and_drop_files\",\n      \"label\": \"list drag and drop files\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47EA26\",\n      \"label\": \"Function 0x47EA26\",\n      \"type\": \"function\",\n      \"address\": \"0x47EA26\"\n    },\n    {\n      \"id\": \"api_DragQueryFile\",\n      \"label\": \"DragQueryFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetClipboardData\",\n      \"label\": \"GetClipboardData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_open_clipboard__2_matches_\",\n      \"label\": \"open clipboard (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47EC91\",\n      \"label\": \"Function 0x47EC91\",\n      \"type\": \"function\",\n      \"address\": \"0x47EC91\"\n    },\n    {\n      \"id\": \"api_CloseClipboard\",\n      \"label\": \"CloseClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_OpenClipboard\",\n      \"label\": \"OpenClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_clipboard_data\",\n      \"label\": \"read clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"api_GlobalLock\",\n      \"label\": \"GlobalLock\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GlobalUnlock\",\n      \"label\": \"GlobalUnlock\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_clipboard_data\",\n      \"label\": \"write clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"api_EmptyClipboard\",\n      \"label\": \"EmptyClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SetClipboardData\",\n      \"label\": \"SetClipboardData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_interact_with_driver_via_ioctl__4_matches_\",\n      \"label\": \"interact with driver via IOCTL (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_DeviceIoControl\",\n      \"label\": \"DeviceIoControl\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_comspec_environment_variable\",\n      \"label\": \"get COMSPEC environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable [C0034]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x41D70E\",\n      \"label\": \"Function 0x41D70E\",\n      \"type\": \"function\",\n      \"address\": \"0x41D70E\"\n    },\n    {\n      \"id\": \"api_GetEnvironmentVariable\",\n      \"label\": \"GetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"label\": \"author     matthew.williams@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable [C0034]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable__3_matches_\",\n      \"label\": \"query environment variable (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47EE14\",\n      \"label\": \"Function 0x47EE14\",\n      \"type\": \"function\",\n      \"address\": \"0x47EE14\"\n    },\n    {\n      \"id\": \"func_0x487559\",\n      \"label\": \"Function 0x487559\",\n      \"type\": \"function\",\n      \"address\": \"0x487559\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_environment_variable__2_matches_\",\n      \"label\": \"set environment variable (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable::Set Variable [C0034.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47EE84\",\n      \"label\": \"Function 0x47EE84\",\n      \"type\": \"function\",\n      \"address\": \"0x47EE84\"\n    },\n    {\n      \"id\": \"func_0x43D170\",\n      \"label\": \"Function 0x43D170\",\n      \"type\": \"function\",\n      \"address\": \"0x43D170\"\n    },\n    {\n      \"id\": \"api_SetEnvironmentVariable\",\n      \"label\": \"SetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__9_matches_\",\n      \"label\": \"get common file path (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x477D0E\",\n      \"label\": \"Function 0x477D0E\",\n      \"type\": \"function\",\n      \"address\": \"0x477D0E\"\n    },\n    {\n      \"id\": \"func_0x4780B3\",\n      \"label\": \"Function 0x4780B3\",\n      \"type\": \"function\",\n      \"address\": \"0x4780B3\"\n    },\n    {\n      \"id\": \"func_0x46DE45\",\n      \"label\": \"Function 0x46DE45\",\n      \"type\": \"function\",\n      \"address\": \"0x46DE45\"\n    },\n    {\n      \"id\": \"func_0x41F962\",\n      \"label\": \"Function 0x41F962\",\n      \"type\": \"function\",\n      \"address\": \"0x41F962\"\n    },\n    {\n      \"id\": \"func_0x48AF20\",\n      \"label\": \"Function 0x48AF20\",\n      \"type\": \"function\",\n      \"address\": \"0x48AF20\"\n    },\n    {\n      \"id\": \"func_0x472F35\",\n      \"label\": \"Function 0x472F35\",\n      \"type\": \"function\",\n      \"address\": \"0x472F35\"\n    },\n    {\n      \"id\": \"func_0x40445D\",\n      \"label\": \"Function 0x40445D\",\n      \"type\": \"function\",\n      \"address\": \"0x40445D\"\n    },\n    {\n      \"id\": \"func_0x4779B4\",\n      \"label\": \"Function 0x4779B4\",\n      \"type\": \"function\",\n      \"address\": \"0x4779B4\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempFileName\",\n      \"label\": \"GetTempFileName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetCurrentDirectory\",\n      \"label\": \"GetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHGetSpecialFolderLocation\",\n      \"label\": \"SHGetSpecialFolderLocation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHGetFolderPath\",\n      \"label\": \"SHGetFolderPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_current_directory__7_matches_\",\n      \"label\": \"set current directory (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x4796BB\",\n      \"label\": \"Function 0x4796BB\",\n      \"type\": \"function\",\n      \"address\": \"0x4796BB\"\n    },\n    {\n      \"id\": \"func_0x479560\",\n      \"label\": \"Function 0x479560\",\n      \"type\": \"function\",\n      \"address\": \"0x479560\"\n    },\n    {\n      \"id\": \"func_0x4753D4\",\n      \"label\": \"Function 0x4753D4\",\n      \"type\": \"function\",\n      \"address\": \"0x4753D4\"\n    },\n    {\n      \"id\": \"func_0x40AD7C\",\n      \"label\": \"Function 0x40AD7C\",\n      \"type\": \"function\",\n      \"address\": \"0x40AD7C\"\n    },\n    {\n      \"id\": \"api_SetCurrentDirectory\",\n      \"label\": \"SetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_copy_file__3_matches_\",\n      \"label\": \"copy file (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46CE1E\",\n      \"label\": \"Function 0x46CE1E\",\n      \"type\": \"function\",\n      \"address\": \"0x46CE1E\"\n    },\n    {\n      \"id\": \"func_0x46D1BA\",\n      \"label\": \"Function 0x46D1BA\",\n      \"type\": \"function\",\n      \"address\": \"0x46D1BA\"\n    },\n    {\n      \"id\": \"func_0x472865\",\n      \"label\": \"Function 0x472865\",\n      \"type\": \"function\",\n      \"address\": \"0x472865\"\n    },\n    {\n      \"id\": \"api_SHFileOperation\",\n      \"label\": \"SHFileOperation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CopyFile\",\n      \"label\": \"CopyFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CopyFileEx\",\n      \"label\": \"CopyFileEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_directory__2_matches_\",\n      \"label\": \"create directory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x473C3C\",\n      \"label\": \"Function 0x473C3C\",\n      \"type\": \"function\",\n      \"address\": \"0x473C3C\"\n    },\n    {\n      \"id\": \"func_0x46D1DF\",\n      \"label\": \"Function 0x46D1DF\",\n      \"type\": \"function\",\n      \"address\": \"0x46D1DF\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_delete_directory__2_matches_\",\n      \"label\": \"delete directory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46E77B\",\n      \"label\": \"Function 0x46E77B\",\n      \"type\": \"function\",\n      \"address\": \"0x46E77B\"\n    },\n    {\n      \"id\": \"api_RemoveDirectory\",\n      \"label\": \"RemoveDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_file__6_matches_\",\n      \"label\": \"delete file (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4755F7\",\n      \"label\": \"Function 0x4755F7\",\n      \"type\": \"function\",\n      \"address\": \"0x4755F7\"\n    },\n    {\n      \"id\": \"func_0x4778BA\",\n      \"label\": \"Function 0x4778BA\",\n      \"type\": \"function\",\n      \"address\": \"0x4778BA\"\n    },\n    {\n      \"id\": \"func_0x46D2C7\",\n      \"label\": \"Function 0x46D2C7\",\n      \"type\": \"function\",\n      \"address\": \"0x46D2C7\"\n    },\n    {\n      \"id\": \"func_0x46CF94\",\n      \"label\": \"Function 0x46CF94\",\n      \"type\": \"function\",\n      \"address\": \"0x46CF94\"\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__3_matches_\",\n      \"label\": \"check if file exists (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46E0B7\",\n      \"label\": \"Function 0x46E0B7\",\n      \"type\": \"function\",\n      \"address\": \"0x46E0B7\"\n    },\n    {\n      \"id\": \"func_0x46DADC\",\n      \"label\": \"Function 0x46DADC\",\n      \"type\": \"function\",\n      \"address\": \"0x46DADC\"\n    },\n    {\n      \"id\": \"api_GetLastError\",\n      \"label\": \"GetLastError\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"label\": \"enumerate files on Windows (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x479A49\",\n      \"label\": \"Function 0x479A49\",\n      \"type\": \"function\",\n      \"address\": \"0x479A49\"\n    },\n    {\n      \"id\": \"func_0x475BB5\",\n      \"label\": \"Function 0x475BB5\",\n      \"type\": \"function\",\n      \"address\": \"0x475BB5\"\n    },\n    {\n      \"id\": \"api_FindFirstFile\",\n      \"label\": \"FindFirstFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindClose\",\n      \"label\": \"FindClose\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindNextFile\",\n      \"label\": \"FindNextFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_recursively__3_matches_\",\n      \"label\": \"enumerate files recursively (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     @_re_fox, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes__5_matches_\",\n      \"label\": \"get file attributes (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4795B8\",\n      \"label\": \"Block 0x4795B8\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4795B8\"\n    },\n    {\n      \"id\": \"bb_0x46D1DF\",\n      \"label\": \"Block 0x46D1DF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46D1DF\"\n    },\n    {\n      \"id\": \"bb_0x46DAFA\",\n      \"label\": \"Block 0x46DAFA\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46DAFA\"\n    },\n    {\n      \"id\": \"bb_0x46E0B7\",\n      \"label\": \"Block 0x46E0B7\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46E0B7\"\n    },\n    {\n      \"id\": \"bb_0x477F04\",\n      \"label\": \"Block 0x477F04\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x477F04\"\n    },\n    {\n      \"id\": \"cap_get_file_size__2_matches_\",\n      \"label\": \"get file size (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x482A05\",\n      \"label\": \"Function 0x482A05\",\n      \"type\": \"function\",\n      \"address\": \"0x482A05\"\n    },\n    {\n      \"id\": \"func_0x498461\",\n      \"label\": \"Function 0x498461\",\n      \"type\": \"function\",\n      \"address\": \"0x498461\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_file_version_info\",\n      \"label\": \"get file version info\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46DB2C\",\n      \"label\": \"Function 0x46DB2C\",\n      \"type\": \"function\",\n      \"address\": \"0x46DB2C\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfo\",\n      \"label\": \"GetFileVersionInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_VerQueryValue\",\n      \"label\": \"VerQueryValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfoSize\",\n      \"label\": \"GetFileVersionInfoSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_file_attributes__2_matches_\",\n      \"label\": \"set file attributes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"api_SetFileAttributes\",\n      \"label\": \"SetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_move_file__3_matches_\",\n      \"label\": \"move file (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46E319\",\n      \"label\": \"Function 0x46E319\",\n      \"type\": \"function\",\n      \"address\": \"0x46E319\"\n    },\n    {\n      \"id\": \"api_MoveFile\",\n      \"label\": \"MoveFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read__ini_file__4_matches_\",\n      \"label\": \"read .ini file (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4783FD\",\n      \"label\": \"Function 0x4783FD\",\n      \"type\": \"function\",\n      \"address\": \"0x4783FD\"\n    },\n    {\n      \"id\": \"func_0x4787FC\",\n      \"label\": \"Function 0x4787FC\",\n      \"type\": \"function\",\n      \"address\": \"0x4787FC\"\n    },\n    {\n      \"id\": \"func_0x478A19\",\n      \"label\": \"Function 0x478A19\",\n      \"type\": \"function\",\n      \"address\": \"0x478A19\"\n    },\n    {\n      \"id\": \"func_0x4784BF\",\n      \"label\": \"Function 0x4784BF\",\n      \"type\": \"function\",\n      \"address\": \"0x4784BF\"\n    },\n    {\n      \"id\": \"api_GetPrivateProfileSection\",\n      \"label\": \"GetPrivateProfileSection\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetPrivateProfileSectionNames\",\n      \"label\": \"GetPrivateProfileSectionNames\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetPrivateProfileString\",\n      \"label\": \"GetPrivateProfileString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__9_matches_\",\n      \"label\": \"read file on Windows (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x406A95\",\n      \"label\": \"Function 0x406A95\",\n      \"type\": \"function\",\n      \"address\": \"0x406A95\"\n    },\n    {\n      \"id\": \"func_0x472475\",\n      \"label\": \"Function 0x472475\",\n      \"type\": \"function\",\n      \"address\": \"0x472475\"\n    },\n    {\n      \"id\": \"func_0x4725B1\",\n      \"label\": \"Function 0x4725B1\",\n      \"type\": \"function\",\n      \"address\": \"0x4725B1\"\n    },\n    {\n      \"id\": \"func_0x47070D\",\n      \"label\": \"Function 0x47070D\",\n      \"type\": \"function\",\n      \"address\": \"0x47070D\"\n    },\n    {\n      \"id\": \"func_0x40B230\",\n      \"label\": \"Function 0x40B230\",\n      \"type\": \"function\",\n      \"address\": \"0x40B230\"\n    },\n    {\n      \"id\": \"func_0x43921B\",\n      \"label\": \"Function 0x43921B\",\n      \"type\": \"function\",\n      \"address\": \"0x43921B\"\n    },\n    {\n      \"id\": \"func_0x40B3B0\",\n      \"label\": \"Function 0x40B3B0\",\n      \"type\": \"function\",\n      \"address\": \"0x40B3B0\"\n    },\n    {\n      \"id\": \"api_fread\",\n      \"label\": \"fread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api__read\",\n      \"label\": \"_read\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_clear_file_content\",\n      \"label\": \"clear file content\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x477FD5\",\n      \"label\": \"Function 0x477FD5\",\n      \"type\": \"function\",\n      \"address\": \"0x477FD5\"\n    },\n    {\n      \"id\": \"api_SetFilePointer\",\n      \"label\": \"SetFilePointer\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SetEndOfFile\",\n      \"label\": \"SetEndOfFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____jakeperalta7\",\n      \"label\": \"author     jakeperalta7\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__7_matches_\",\n      \"label\": \"write file on Windows (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x472642\",\n      \"label\": \"Function 0x472642\",\n      \"type\": \"function\",\n      \"address\": \"0x472642\"\n    },\n    {\n      \"id\": \"func_0x4725F5\",\n      \"label\": \"Function 0x4725F5\",\n      \"type\": \"function\",\n      \"address\": \"0x4725F5\"\n    },\n    {\n      \"id\": \"func_0x41F5B3\",\n      \"label\": \"Function 0x41F5B3\",\n      \"type\": \"function\",\n      \"address\": \"0x41F5B3\"\n    },\n    {\n      \"id\": \"func_0x46CC1D\",\n      \"label\": \"Function 0x46CC1D\",\n      \"type\": \"function\",\n      \"address\": \"0x46CC1D\"\n    },\n    {\n      \"id\": \"func_0x470633\",\n      \"label\": \"Function 0x470633\",\n      \"type\": \"function\",\n      \"address\": \"0x470633\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_gui_resources\",\n      \"label\": \"enumerate gui resources\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x464144\",\n      \"label\": \"Function 0x464144\",\n      \"type\": \"function\",\n      \"address\": \"0x464144\"\n    },\n    {\n      \"id\": \"api_EnumWindows\",\n      \"label\": \"EnumWindows\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     johnk3r, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_taskbar__3_matches_\",\n      \"label\": \"find taskbar (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Taskbar Discovery [B0043]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x492255\",\n      \"label\": \"Block 0x492255\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x492255\"\n    },\n    {\n      \"id\": \"bb_0x492289\",\n      \"label\": \"Block 0x492289\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x492289\"\n    },\n    {\n      \"id\": \"bb_0x41EFCE\",\n      \"label\": \"Block 0x41EFCE\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x41EFCE\"\n    },\n    {\n      \"id\": \"api_FindWindow\",\n      \"label\": \"FindWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_find_graphical_window__4_matches_\",\n      \"label\": \"find graphical window (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindWindowEx\",\n      \"label\": \"FindWindowEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_graphical_window_text__11_matches_\",\n      \"label\": \"get graphical window text (11 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4947A8\",\n      \"label\": \"Function 0x4947A8\",\n      \"type\": \"function\",\n      \"address\": \"0x4947A8\"\n    },\n    {\n      \"id\": \"func_0x463B0C\",\n      \"label\": \"Function 0x463B0C\",\n      \"type\": \"function\",\n      \"address\": \"0x463B0C\"\n    },\n    {\n      \"id\": \"func_0x47E8F7\",\n      \"label\": \"Function 0x47E8F7\",\n      \"type\": \"function\",\n      \"address\": \"0x47E8F7\"\n    },\n    {\n      \"id\": \"func_0x496FA4\",\n      \"label\": \"Function 0x496FA4\",\n      \"type\": \"function\",\n      \"address\": \"0x496FA4\"\n    },\n    {\n      \"id\": \"func_0x46489C\",\n      \"label\": \"Function 0x46489C\",\n      \"type\": \"function\",\n      \"address\": \"0x46489C\"\n    },\n    {\n      \"id\": \"func_0x464BD3\",\n      \"label\": \"Function 0x464BD3\",\n      \"type\": \"function\",\n      \"address\": \"0x464BD3\"\n    },\n    {\n      \"id\": \"func_0x461A70\",\n      \"label\": \"Function 0x461A70\",\n      \"type\": \"function\",\n      \"address\": \"0x461A70\"\n    },\n    {\n      \"id\": \"func_0x46359E\",\n      \"label\": \"Function 0x46359E\",\n      \"type\": \"function\",\n      \"address\": \"0x46359E\"\n    },\n    {\n      \"id\": \"func_0x4972B7\",\n      \"label\": \"Function 0x4972B7\",\n      \"type\": \"function\",\n      \"address\": \"0x4972B7\"\n    },\n    {\n      \"id\": \"func_0x465B9A\",\n      \"label\": \"Function 0x465B9A\",\n      \"type\": \"function\",\n      \"address\": \"0x465B9A\"\n    },\n    {\n      \"id\": \"func_0x491E0D\",\n      \"label\": \"Function 0x491E0D\",\n      \"type\": \"function\",\n      \"address\": \"0x491E0D\"\n    },\n    {\n      \"id\": \"api_SendMessage\",\n      \"label\": \"SendMessage\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_IsWindowVisible\",\n      \"label\": \"IsWindowVisible\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetWindowText\",\n      \"label\": \"GetWindowText\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_hide_graphical_window__8_matches_\",\n      \"label\": \"hide graphical window (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x45F0F9\",\n      \"label\": \"Block 0x45F0F9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x45F0F9\"\n    },\n    {\n      \"id\": \"bb_0x49813A\",\n      \"label\": \"Block 0x49813A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x49813A\"\n    },\n    {\n      \"id\": \"bb_0x496B61\",\n      \"label\": \"Block 0x496B61\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x496B61\"\n    },\n    {\n      \"id\": \"bb_0x4827C2\",\n      \"label\": \"Block 0x4827C2\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4827C2\"\n    },\n    {\n      \"id\": \"bb_0x49A198\",\n      \"label\": \"Block 0x49A198\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x49A198\"\n    },\n    {\n      \"id\": \"bb_0x49015D\",\n      \"label\": \"Block 0x49015D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x49015D\"\n    },\n    {\n      \"id\": \"bb_0x4950F2\",\n      \"label\": \"Block 0x4950F2\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4950F2\"\n    },\n    {\n      \"id\": \"bb_0x4981BF\",\n      \"label\": \"Block 0x4981BF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4981BF\"\n    },\n    {\n      \"id\": \"api_ShowWindow\",\n      \"label\": \"ShowWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_keyboard_layout\",\n      \"label\": \"get keyboard layout\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery::System Language Discovery\",\n        \"[T1614.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetKeyboardLayoutName\",\n      \"label\": \"GetKeyboardLayoutName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_memory_capacity\",\n      \"label\": \"get memory capacity\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x41F370\",\n      \"label\": \"Function 0x41F370\",\n      \"type\": \"function\",\n      \"address\": \"0x41F370\"\n    },\n    {\n      \"id\": \"api_GlobalMemoryStatusEx\",\n      \"label\": \"GlobalMemoryStatusEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_information__6_matches_\",\n      \"label\": \"get disk information (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x474912\",\n      \"label\": \"Function 0x474912\",\n      \"type\": \"function\",\n      \"address\": \"0x474912\"\n    },\n    {\n      \"id\": \"func_0x4743DE\",\n      \"label\": \"Function 0x4743DE\",\n      \"type\": \"function\",\n      \"address\": \"0x4743DE\"\n    },\n    {\n      \"id\": \"func_0x473D97\",\n      \"label\": \"Function 0x473D97\",\n      \"type\": \"function\",\n      \"address\": \"0x473D97\"\n    },\n    {\n      \"id\": \"func_0x4749FD\",\n      \"label\": \"Function 0x4749FD\",\n      \"type\": \"function\",\n      \"address\": \"0x4749FD\"\n    },\n    {\n      \"id\": \"func_0x474776\",\n      \"label\": \"Function 0x474776\",\n      \"type\": \"function\",\n      \"address\": \"0x474776\"\n    },\n    {\n      \"id\": \"func_0x474844\",\n      \"label\": \"Function 0x474844\",\n      \"type\": \"function\",\n      \"address\": \"0x474844\"\n    },\n    {\n      \"id\": \"api_GetVolumeInformation\",\n      \"label\": \"GetVolumeInformation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetDriveType\",\n      \"label\": \"GetDriveType\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_size__3_matches_\",\n      \"label\": \"get disk size (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4750EB\",\n      \"label\": \"Function 0x4750EB\",\n      \"type\": \"function\",\n      \"address\": \"0x4750EB\"\n    },\n    {\n      \"id\": \"func_0x4751CE\",\n      \"label\": \"Function 0x4751CE\",\n      \"type\": \"function\",\n      \"address\": \"0x4751CE\"\n    },\n    {\n      \"id\": \"func_0x4752B1\",\n      \"label\": \"Function 0x4752B1\",\n      \"type\": \"function\",\n      \"address\": \"0x4752B1\"\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpaceEx\",\n      \"label\": \"GetDiskFreeSpaceEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpace\",\n      \"label\": \"GetDiskFreeSpace\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_storage_device_properties__2_matches_\",\n      \"label\": \"get storage device properties (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x46D588\",\n      \"label\": \"Function 0x46D588\",\n      \"type\": \"function\",\n      \"address\": \"0x46D588\"\n    },\n    {\n      \"id\": \"func_0x46D509\",\n      \"label\": \"Function 0x46D509\",\n      \"type\": \"function\",\n      \"address\": \"0x46D509\"\n    },\n    {\n      \"id\": \"cap_print_debug_messages\",\n      \"label\": \"print debug messages\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_OutputDebugString\",\n      \"label\": \"OutputDebugString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_shutdown_system\",\n      \"label\": \"shutdown system\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::System Shutdown/Reboot [T1529]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46E814\",\n      \"label\": \"Function 0x46E814\",\n      \"type\": \"function\",\n      \"address\": \"0x46E814\"\n    },\n    {\n      \"id\": \"api_ExitWindowsEx\",\n      \"label\": \"ExitWindowsEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_InitiateSystemShutdownEx\",\n      \"label\": \"InitiateSystemShutdownEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_hostname__2_matches_\",\n      \"label\": \"get hostname (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetComputerName\",\n      \"label\": \"GetComputerName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_gethostname\",\n      \"label\": \"gethostname\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_system_information_on_windows\",\n      \"label\": \"get system information on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40615E\",\n      \"label\": \"Function 0x40615E\",\n      \"type\": \"function\",\n      \"address\": \"0x40615E\"\n    },\n    {\n      \"id\": \"api_GetSystemInfo\",\n      \"label\": \"GetSystemInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__6_matches_\",\n      \"label\": \"create process on Windows (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x461472\",\n      \"label\": \"Block 0x461472\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x461472\"\n    },\n    {\n      \"id\": \"bb_0x4437E0\",\n      \"label\": \"Block 0x4437E0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4437E0\"\n    },\n    {\n      \"id\": \"bb_0x48B2C1\",\n      \"label\": \"Block 0x48B2C1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x48B2C1\"\n    },\n    {\n      \"id\": \"bb_0x48AD7A\",\n      \"label\": \"Block 0x48AD7A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x48AD7A\"\n    },\n    {\n      \"id\": \"bb_0x46134A\",\n      \"label\": \"Block 0x46134A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46134A\"\n    },\n    {\n      \"id\": \"bb_0x498064\",\n      \"label\": \"Block 0x498064\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x498064\"\n    },\n    {\n      \"id\": \"api_ShellExecuteEx\",\n      \"label\": \"ShellExecuteEx\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_CreateProcessAsUser\",\n      \"label\": \"CreateProcessAsUser\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_CreateProcessWithLogon\",\n      \"label\": \"CreateProcessWithLogon\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_ShellExecute\",\n      \"label\": \"ShellExecute\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_allocate_or_change_rwx_memory\",\n      \"label\": \"allocate or change RWX memory\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x489881\",\n      \"label\": \"Block 0x489881\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x489881\"\n    },\n    {\n      \"id\": \"api_VirtualAlloc\",\n      \"label\": \"VirtualAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"label\": \"author     @mr-tz, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_processes__2_matches_\",\n      \"label\": \"enumerate processes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\",\n        \"Discovery::Software Discovery\",\n        \"[T1518]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46D3FA\",\n      \"label\": \"Function 0x46D3FA\",\n      \"type\": \"function\",\n      \"address\": \"0x46D3FA\"\n    },\n    {\n      \"id\": \"func_0x48A5A3\",\n      \"label\": \"Function 0x48A5A3\",\n      \"type\": \"function\",\n      \"address\": \"0x48A5A3\"\n    },\n    {\n      \"id\": \"api_Process32Next\",\n      \"label\": \"Process32Next\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_Process32First\",\n      \"label\": \"Process32First\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateToolhelp32Snapshot\",\n      \"label\": \"CreateToolhelp32Snapshot\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_acquire_debug_privileges\",\n      \"label\": \"acquire debug privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x48A0B6\",\n      \"label\": \"Block 0x48A0B6\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x48A0B6\"\n    },\n    {\n      \"id\": \"cap_modify_access_privileges__2_matches_\",\n      \"label\": \"modify access privileges (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"api_AdjustTokenPrivileges\",\n      \"label\": \"AdjustTokenPrivileges\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_terminate_process__3_matches_\",\n      \"label\": \"terminate process (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x48A009\",\n      \"label\": \"Function 0x48A009\",\n      \"type\": \"function\",\n      \"address\": \"0x48A009\"\n    },\n    {\n      \"id\": \"func_0x487E80\",\n      \"label\": \"Function 0x487E80\",\n      \"type\": \"function\",\n      \"address\": \"0x487E80\"\n    },\n    {\n      \"id\": \"func_0x46EA3E\",\n      \"label\": \"Function 0x46EA3E\",\n      \"type\": \"function\",\n      \"address\": \"0x46EA3E\"\n    },\n    {\n      \"id\": \"api_TerminateProcess\",\n      \"label\": \"TerminateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_empty_the_recycle_bin\",\n      \"label\": \"empty the recycle bin\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x477953\",\n      \"label\": \"Function 0x477953\",\n      \"type\": \"function\",\n      \"address\": \"0x477953\"\n    },\n    {\n      \"id\": \"api_SHEmptyRecycleBin\",\n      \"label\": \"SHEmptyRecycleBin\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"label\": \"query or enumerate registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x48CB5B\",\n      \"label\": \"Function 0x48CB5B\",\n      \"type\": \"function\",\n      \"address\": \"0x48CB5B\"\n    },\n    {\n      \"id\": \"func_0x48B8F0\",\n      \"label\": \"Function 0x48B8F0\",\n      \"type\": \"function\",\n      \"address\": \"0x48B8F0\"\n    },\n    {\n      \"id\": \"api_RegEnumKeyEx\",\n      \"label\": \"RegEnumKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"label\": \"query or enumerate registry value (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x48BB02\",\n      \"label\": \"Function 0x48BB02\",\n      \"type\": \"function\",\n      \"address\": \"0x48BB02\"\n    },\n    {\n      \"id\": \"func_0x40533E\",\n      \"label\": \"Function 0x40533E\",\n      \"type\": \"function\",\n      \"address\": \"0x40533E\"\n    },\n    {\n      \"id\": \"func_0x4059A7\",\n      \"label\": \"Function 0x4059A7\",\n      \"type\": \"function\",\n      \"address\": \"0x4059A7\"\n    },\n    {\n      \"id\": \"func_0x48BD6B\",\n      \"label\": \"Function 0x48BD6B\",\n      \"type\": \"function\",\n      \"address\": \"0x48BD6B\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegEnumValue\",\n      \"label\": \"RegEnumValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value\",\n      \"label\": \"set registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x48C2DE\",\n      \"label\": \"Function 0x48C2DE\",\n      \"type\": \"function\",\n      \"address\": \"0x48C2DE\"\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"api_RegCreateKeyEx\",\n      \"label\": \"RegCreateKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delete_registry_key__2_matches_\",\n      \"label\": \"delete registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x48B535\",\n      \"label\": \"Function 0x48B535\",\n      \"type\": \"function\",\n      \"address\": \"0x48B535\"\n    },\n    {\n      \"id\": \"api_RegDeleteKey\",\n      \"label\": \"RegDeleteKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_value\",\n      \"label\": \"delete registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegDeleteValue\",\n      \"label\": \"RegDeleteValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_session_user_name\",\n      \"label\": \"get session user name\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\",\n        \"Discovery::Account\",\n        \"Discovery [T1087]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetUserName\",\n      \"label\": \"GetUserName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_token_membership\",\n      \"label\": \"get token membership\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4615A7\",\n      \"label\": \"Function 0x4615A7\",\n      \"type\": \"function\",\n      \"address\": \"0x4615A7\"\n    },\n    {\n      \"id\": \"api_AllocateAndInitializeSid\",\n      \"label\": \"AllocateAndInitializeSid\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FreeSid\",\n      \"label\": \"FreeSid\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CheckTokenMembership\",\n      \"label\": \"CheckTokenMembership\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_token_privileges\",\n      \"label\": \"get token privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x460F58\",\n      \"label\": \"Function 0x460F58\",\n      \"type\": \"function\",\n      \"address\": \"0x460F58\"\n    },\n    {\n      \"id\": \"api_GetTokenInformation\",\n      \"label\": \"GetTokenInformation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_thread__5_matches_\",\n      \"label\": \"create thread (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x46E114\",\n      \"label\": \"Block 0x46E114\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46E114\"\n    },\n    {\n      \"id\": \"bb_0x461747\",\n      \"label\": \"Block 0x461747\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x461747\"\n    },\n    {\n      \"id\": \"bb_0x47D13B\",\n      \"label\": \"Block 0x47D13B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x47D13B\"\n    },\n    {\n      \"id\": \"bb_0x470870\",\n      \"label\": \"Block 0x470870\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x470870\"\n    },\n    {\n      \"id\": \"api_CreateThread\",\n      \"label\": \"CreateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api__beginthreadex\",\n      \"label\": \"_beginthreadex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api__beginthread\",\n      \"label\": \"_beginthread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_thread\",\n      \"label\": \"terminate thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Thread [C0039]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4708A6\",\n      \"label\": \"Block 0x4708A6\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4708A6\"\n    },\n    {\n      \"id\": \"api_TerminateThread\",\n      \"label\": \"TerminateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_impersonate_user\",\n      \"label\": \"impersonate user\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation::Token\",\n        \"Impersonation/Theft [T1134.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x461145\",\n      \"label\": \"Function 0x461145\",\n      \"type\": \"function\",\n      \"address\": \"0x461145\"\n    },\n    {\n      \"id\": \"api_LoadUserProfile\",\n      \"label\": \"LoadUserProfile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LogonUser\",\n      \"label\": \"LogonUser\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__99_elad_levi_gmail_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, 99.elad.levi@gmail.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation::Token\",\n        \"Impersonation/Theft [T1134.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal__autoit_file_limitation\",\n      \"label\": \"(internal) autoit file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__13_matches_\",\n      \"label\": \"link function at runtime on Windows (13 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header\",\n      \"label\": \"parse PE header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40B7E0\",\n      \"label\": \"Function 0x40B7E0\",\n      \"type\": \"function\",\n      \"address\": \"0x40B7E0\"\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"label\": \"resolve function by parsing PE exports (15 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x408BAA\",\n      \"label\": \"Function 0x408BAA\",\n      \"type\": \"function\",\n      \"address\": \"0x408BAA\"\n    },\n    {\n      \"id\": \"func_0x490F26\",\n      \"label\": \"Function 0x490F26\",\n      \"type\": \"function\",\n      \"address\": \"0x490F26\"\n    },\n    {\n      \"id\": \"func_0x410540\",\n      \"label\": \"Function 0x410540\",\n      \"type\": \"function\",\n      \"address\": \"0x410540\"\n    },\n    {\n      \"id\": \"func_0x40D840\",\n      \"label\": \"Function 0x40D840\",\n      \"type\": \"function\",\n      \"address\": \"0x40D840\"\n    },\n    {\n      \"id\": \"func_0x466502\",\n      \"label\": \"Function 0x466502\",\n      \"type\": \"function\",\n      \"address\": \"0x466502\"\n    },\n    {\n      \"id\": \"func_0x4681EE\",\n      \"label\": \"Function 0x4681EE\",\n      \"type\": \"function\",\n      \"address\": \"0x4681EE\"\n    },\n    {\n      \"id\": \"func_0x401641\",\n      \"label\": \"Function 0x401641\",\n      \"type\": \"function\",\n      \"address\": \"0x401641\"\n    },\n    {\n      \"id\": \"func_0x476E0F\",\n      \"label\": \"Function 0x476E0F\",\n      \"type\": \"function\",\n      \"address\": \"0x476E0F\"\n    },\n    {\n      \"id\": \"func_0x4763AC\",\n      \"label\": \"Function 0x4763AC\",\n      \"type\": \"function\",\n      \"address\": \"0x4763AC\"\n    },\n    {\n      \"id\": \"func_0x40A180\",\n      \"label\": \"Function 0x40A180\",\n      \"type\": \"function\",\n      \"address\": \"0x40A180\"\n    },\n    {\n      \"id\": \"func_0x47902A\",\n      \"label\": \"Function 0x47902A\",\n      \"type\": \"function\",\n      \"address\": \"0x47902A\"\n    },\n    {\n      \"id\": \"func_0x4095C0\",\n      \"label\": \"Function 0x4095C0\",\n      \"type\": \"function\",\n      \"address\": \"0x4095C0\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_execute_shellcode_via_indirect_call\",\n      \"label\": \"execute shellcode via indirect call\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4895BB\",\n      \"label\": \"Function 0x4895BB\",\n      \"type\": \"function\",\n      \"address\": \"0x4895BB\"\n    },\n    {\n      \"id\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"label\": \"author     ronnie.salomonsen@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_shortcut_via_ishelllink__2_matches_\",\n      \"label\": \"create shortcut via IShellLink (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47573C\",\n      \"label\": \"Function 0x47573C\",\n      \"type\": \"function\",\n      \"address\": \"0x47573C\"\n    },\n    {\n      \"id\": \"api_CoCreateInstance\",\n      \"label\": \"CoCreateInstance\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_memory__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_memory__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x46B26C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__489_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__489_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401202\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__13_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x40533E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__37_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__37_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x40F4AF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_process__7_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_process__7_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x46B26C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"target\": \"func_0x469B67\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"target\": \"func_0x46AFC6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"target\": \"func_0x46E899\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"target\": \"func_0x469B7E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x469B67\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46AFC6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E899\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x469B7E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_unmoving_mouse_cursor__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_unmoving_mouse_cursor__2_matches_\",\n      \"target\": \"func_0x498EBB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_unmoving_mouse_cursor__2_matches_\",\n      \"target\": \"func_0x499468\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______bitsofbinary\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______bitsofbinary\",\n      \"target\": \"func_0x498EBB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______bitsofbinary\",\n      \"target\": \"func_0x499468\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x46B1FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x463985\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x46A90B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x4624E6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x4034CE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x46B198\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x46B04D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x462CEB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x41EFAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46B1FD\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463985\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4624E6\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4034CE\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B04D\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x462CEB\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EFAD\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B1FD\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463985\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4624E6\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4034CE\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B04D\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x462CEB\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EFAD\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46B1FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x463985\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46A90B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4624E6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4034CE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46B198\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46B04D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x462CEB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x41EFAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46B1FD\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463985\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4624E6\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4034CE\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B04D\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x462CEB\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EFAD\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B1FD\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463985\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4624E6\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4034CE\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B04D\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x462CEB\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EFAD\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46ABF8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46A90B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x41EA9A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46AABA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x4028C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x499468\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46ADD8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46B198\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x469B97\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46A975\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x469EAF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46ABF8\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EA9A\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46AABA\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4028C0\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499468\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ADD8\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469B97\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A975\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469EAF\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ABF8\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EA9A\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46AABA\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4028C0\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499468\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ADD8\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469B97\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A975\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469EAF\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ABF8\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EA9A\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46AABA\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4028C0\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499468\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ADD8\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469B97\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A975\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469EAF\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ABF8\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EA9A\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46AABA\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4028C0\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499468\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ADD8\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469B97\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A975\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469EAF\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46ABF8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46A90B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x41EA9A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46AABA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4028C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x499468\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46ADD8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46B198\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x469B97\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46A975\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x469EAF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46ABF8\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EA9A\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46AABA\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4028C0\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499468\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ADD8\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469B97\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A975\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469EAF\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ABF8\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EA9A\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46AABA\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4028C0\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499468\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ADD8\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469B97\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A975\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469EAF\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ABF8\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EA9A\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46AABA\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4028C0\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499468\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ADD8\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469B97\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A975\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469EAF\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ABF8\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A90B\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41EA9A\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46AABA\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4028C0\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499468\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ADD8\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B198\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469B97\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A975\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x469EAF\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_capture_screenshot\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_capture_screenshot\",\n      \"target\": \"func_0x482483\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x482483\",\n      \"target\": \"api_GetDC\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482483\",\n      \"target\": \"api_CreateCompatibleDC\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482483\",\n      \"target\": \"api_GetDIBits\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482483\",\n      \"target\": \"api_CreateCompatibleBitmap\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x482483\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x482483\",\n      \"target\": \"api_GetDC\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482483\",\n      \"target\": \"api_CreateCompatibleDC\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482483\",\n      \"target\": \"api_GetDIBits\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482483\",\n      \"target\": \"api_CreateCompatibleBitmap\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_remote_server_for_available_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_remote_server_for_available_data\",\n      \"target\": \"bb_0x47CE38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x47CE38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data__4_matches_\",\n      \"target\": \"func_0x47CE38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__4_matches_\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__4_matches_\",\n      \"target\": \"func_0x48135A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__4_matches_\",\n      \"target\": \"func_0x481B87\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CE38\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CE38\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CE38\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x47CE38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x48135A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x481B87\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CE38\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CE38\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CE38\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data__3_matches_\",\n      \"target\": \"func_0x47C394\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__3_matches_\",\n      \"target\": \"func_0x481F24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__3_matches_\",\n      \"target\": \"func_0x4814F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x47C394\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x481F24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x4814F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_download_and_write_a_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_download_and_write_a_file\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_maec_malware_category__downloader\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_maec_malware_category__downloader\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_and_write_data_from_server_to_client\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_and_write_data_from_server_to_client\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_dns__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_dns__3_matches_\",\n      \"target\": \"func_0x481288\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_dns__3_matches_\",\n      \"target\": \"func_0x480482\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_dns__3_matches_\",\n      \"target\": \"func_0x46DD45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481288\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DD45\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x481288\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x480482\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46DD45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481288\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DD45\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_network_resource\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_network_resource\",\n      \"target\": \"func_0x4605C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4605C7\",\n      \"target\": \"api_WNetAddConnection2\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4605C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4605C7\",\n      \"target\": \"api_WNetAddConnection2\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_url\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_url\",\n      \"target\": \"bb_0x47D012\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x47D012\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_to_http_server__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_to_http_server__2_matches_\",\n      \"target\": \"func_0x47C061\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_to_http_server__2_matches_\",\n      \"target\": \"func_0x47C394\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47C061\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47C061\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47C394\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47C061\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_to_url\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_http_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_http_request\",\n      \"target\": \"func_0x47CC3C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CC3C\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47CC3C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CC3C\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_data_from_internet__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__2_matches_\",\n      \"target\": \"func_0x47CE38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__2_matches_\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CE38\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47CE38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CE38\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_http_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_http_request\",\n      \"target\": \"func_0x47C394\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47C394\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C394\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_icmp_echo_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_icmp_echo_request\",\n      \"target\": \"func_0x480482\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_IcmpSendEcho\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_IcmpCreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_IcmpCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x480482\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_IcmpSendEcho\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_IcmpCreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_IcmpCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_pipe__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_pipe__2_matches_\",\n      \"target\": \"func_0x4704C5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_pipe__2_matches_\",\n      \"target\": \"func_0x4703F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4704C5\",\n      \"target\": \"api_CreatePipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4703F0\",\n      \"target\": \"api_CreatePipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4704C5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4703F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4704C5\",\n      \"target\": \"api_CreatePipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4703F0\",\n      \"target\": \"api_CreatePipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_socket\",\n      \"target\": \"bb_0x4810AF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mrhafizfarhad_gmail_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x4810AF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_socket_status\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_socket_status\",\n      \"target\": \"func_0x483070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x483070\",\n      \"target\": \"api_select\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x483070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x483070\",\n      \"target\": \"api_select\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_initialize_winsock_library__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_initialize_winsock_library__3_matches_\",\n      \"target\": \"func_0x4815DA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_initialize_winsock_library__3_matches_\",\n      \"target\": \"func_0x480482\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_initialize_winsock_library__3_matches_\",\n      \"target\": \"func_0x46DD45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4815DA\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DD45\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4815DA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x480482\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46DD45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4815DA\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DD45\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_socket_configuration__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__3_matches_\",\n      \"target\": \"func_0x480482\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__3_matches_\",\n      \"target\": \"func_0x482F75\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__3_matches_\",\n      \"target\": \"func_0x4819FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482F75\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4819FD\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482F75\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4819FD\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x480482\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x482F75\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4819FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482F75\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4819FD\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480482\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482F75\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4819FD\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data_on_socket__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__2_matches_\",\n      \"target\": \"func_0x48135A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__2_matches_\",\n      \"target\": \"func_0x481B87\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x48135A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x481B87\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48135A\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481B87\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data_on_socket__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__2_matches_\",\n      \"target\": \"func_0x481F24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__2_matches_\",\n      \"target\": \"func_0x4814F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x481F24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4814F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F24\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4814F1\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_tcp_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_tcp_socket\",\n      \"target\": \"func_0x480FDF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480FDF\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480FDF\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x480FDF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480FDF\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480FDF\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_tcp_socket__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__2_matches_\",\n      \"target\": \"bb_0x481197\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__2_matches_\",\n      \"target\": \"bb_0x481033\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x481197\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x481033\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_udp_socket__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__2_matches_\",\n      \"target\": \"bb_0x48177E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__2_matches_\",\n      \"target\": \"bb_0x4819FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x48177E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4819FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_act_as_tcp_client\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_act_as_tcp_client\",\n      \"target\": \"func_0x480FDF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480FDF\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480FDF\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x480FDF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480FDF\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480FDF\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_with_autoit\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_crc32\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_with_crc32\",\n      \"target\": \"func_0x4823E8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4823E8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encode_data_using_base64\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64\",\n      \"target\": \"func_0x41BEAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x41BEAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_djb2\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_djb2\",\n      \"target\": \"func_0x408273\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______awillia2_cisco_com__still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______awillia2_cisco_com__still_teamt5_org\",\n      \"target\": \"func_0x408273\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_authenticate_hmac\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac\",\n      \"target\": \"func_0x41BEAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x41BEAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"target\": \"func_0x471F64\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"target\": \"func_0x471E7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"target\": \"func_0x471EC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"target\": \"func_0x471F24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x471F64\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x471E7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x471EC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x471F24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x406122\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406122\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406122\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406122\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406122\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x406122\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406122\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406122\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406122\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406122\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_list_drag_and_drop_files\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_list_drag_and_drop_files\",\n      \"target\": \"func_0x47EA26\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_DragQueryFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_GetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47EA26\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_DragQueryFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_GetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_clipboard__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_clipboard__2_matches_\",\n      \"target\": \"func_0x47EC91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_open_clipboard__2_matches_\",\n      \"target\": \"func_0x47EA26\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47EC91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47EA26\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_clipboard_data\",\n      \"target\": \"func_0x47EA26\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_GlobalLock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_GetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_GlobalUnlock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47EA26\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_GlobalLock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_GetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EA26\",\n      \"target\": \"api_GlobalUnlock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_clipboard_data\",\n      \"target\": \"func_0x47EC91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47EC91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EC91\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_interact_with_driver_via_ioctl__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_comspec_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_comspec_environment_variable\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__3_matches_\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__3_matches_\",\n      \"target\": \"func_0x47EE14\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__3_matches_\",\n      \"target\": \"func_0x487559\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EE14\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x487559\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x47EE14\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x487559\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47EE14\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x487559\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_environment_variable__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_environment_variable__2_matches_\",\n      \"target\": \"func_0x47EE84\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_environment_variable__2_matches_\",\n      \"target\": \"func_0x43D170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EE84\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43D170\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47EE84\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x43D170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47EE84\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43D170\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x477D0E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x4780B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x46DE45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x41F962\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x48AF20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x472F35\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x40445D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x4779B4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x477D0E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4780B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46DE45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41F962\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48AF20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472F35\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40445D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4779B4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE45\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F962\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AF20\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F35\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4779B4\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_current_directory__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x477D0E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x4780B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x4796BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x479560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x4753D4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x40445D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x40AD7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4753D4\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AD7C\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x477D0E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4780B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4796BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x479560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4753D4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40445D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40AD7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x477D0E\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4780B3\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4753D4\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40445D\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AD7C\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_copy_file__3_matches_\",\n      \"target\": \"func_0x46CE1E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_copy_file__3_matches_\",\n      \"target\": \"func_0x46D1BA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_copy_file__3_matches_\",\n      \"target\": \"func_0x472865\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1BA\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1BA\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1BA\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46CE1E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D1BA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x472865\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1BA\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1BA\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1BA\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory__2_matches_\",\n      \"target\": \"func_0x473C3C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__2_matches_\",\n      \"target\": \"func_0x46D1DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x473C3C\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1DF\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x473C3C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D1DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x473C3C\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1DF\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_directory__2_matches_\",\n      \"target\": \"func_0x473C3C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_directory__2_matches_\",\n      \"target\": \"func_0x46E77B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x473C3C\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E77B\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x473C3C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E77B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x473C3C\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E77B\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x4755F7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x4778BA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x46D2C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x46CF94\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x46E77B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x472865\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4755F7\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4778BA\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E77B\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4755F7\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4778BA\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E77B\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4755F7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4778BA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D2C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46CF94\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E77B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x472865\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4755F7\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4778BA\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E77B\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4755F7\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4778BA\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E77B\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x46E0B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x46D1DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x46DADC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46E0B7\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1DF\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DADC\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E0B7\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1DF\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DADC\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E0B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D1DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46DADC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46E0B7\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1DF\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DADC\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E0B7\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D1DF\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DADC\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x4796BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x479560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x479A49\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x475BB5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x46CF94\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x46D2C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475BB5\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475BB5\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475BB5\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4796BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x479560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x479A49\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x475BB5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46CF94\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46D2C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475BB5\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475BB5\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475BB5\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D2C7\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_recursively__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively__3_matches_\",\n      \"target\": \"func_0x4796BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively__3_matches_\",\n      \"target\": \"func_0x479560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively__3_matches_\",\n      \"target\": \"func_0x479A49\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4796BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x479560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x479A49\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796BB\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479560\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479A49\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x4795B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x46D1DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x46DAFA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x46E0B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x477F04\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4795B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x46D1DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x46DAFA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x46E0B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x477F04\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x482A05\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x498461\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x482A05\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x498461\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_version_info\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_version_info\",\n      \"target\": \"func_0x46DB2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46DB2C\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB2C\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB2C\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46DB2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46DB2C\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB2C\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB2C\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__2_matches_\",\n      \"target\": \"bb_0x4795B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__2_matches_\",\n      \"target\": \"bb_0x477F04\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4795B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x477F04\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_move_file__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_move_file__3_matches_\",\n      \"target\": \"func_0x46CE1E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__3_matches_\",\n      \"target\": \"func_0x46E319\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__3_matches_\",\n      \"target\": \"func_0x46CF94\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E319\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E319\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46CE1E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E319\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46CF94\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E319\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CE1E\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E319\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CF94\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read__ini_file__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__4_matches_\",\n      \"target\": \"func_0x4783FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__4_matches_\",\n      \"target\": \"func_0x4787FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__4_matches_\",\n      \"target\": \"func_0x478A19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__4_matches_\",\n      \"target\": \"func_0x4784BF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4783FD\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4787FC\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478A19\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4784BF\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783FD\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4787FC\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478A19\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4784BF\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783FD\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4787FC\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478A19\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4784BF\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4783FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4787FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x478A19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4784BF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4783FD\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4787FC\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478A19\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4784BF\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783FD\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4787FC\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478A19\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4784BF\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783FD\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4787FC\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478A19\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4784BF\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x406A95\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x472475\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x4725B1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x47070D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x40B230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x482A05\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x43921B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x40B3B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x498461\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406A95\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472475\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725B1\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47070D\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B230\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43921B\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B3B0\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406A95\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472475\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725B1\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47070D\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B230\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43921B\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B3B0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406A95\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472475\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725B1\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47070D\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B230\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43921B\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B3B0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406A95\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472475\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725B1\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47070D\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B230\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43921B\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B3B0\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406A95\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472475\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4725B1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47070D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x482A05\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x43921B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B3B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x498461\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406A95\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472475\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725B1\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47070D\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B230\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43921B\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B3B0\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406A95\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472475\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725B1\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47070D\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B230\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43921B\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B3B0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406A95\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472475\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725B1\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47070D\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B230\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43921B\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B3B0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406A95\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472475\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725B1\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47070D\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B230\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482A05\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43921B\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B3B0\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498461\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_clear_file_content\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_clear_file_content\",\n      \"target\": \"func_0x477FD5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x477FD5\",\n      \"target\": \"api_SetFilePointer\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477FD5\",\n      \"target\": \"api_SetEndOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____jakeperalta7\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____jakeperalta7\",\n      \"target\": \"func_0x477FD5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x477FD5\",\n      \"target\": \"api_SetFilePointer\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477FD5\",\n      \"target\": \"api_SetEndOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x472642\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x4725F5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x41F5B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x46CC1D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x470633\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x472865\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x472642\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725F5\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F5B3\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CC1D\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470633\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472642\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725F5\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F5B3\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CC1D\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470633\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472642\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725F5\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F5B3\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CC1D\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470633\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472642\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4725F5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41F5B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46CC1D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x470633\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472865\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x472642\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725F5\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F5B3\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CC1D\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470633\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472642\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725F5\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F5B3\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CC1D\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470633\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472642\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4725F5\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CD62\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41F5B3\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46CC1D\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470633\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472865\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_gui_resources\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_gui_resources\",\n      \"target\": \"func_0x464144\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x464144\",\n      \"target\": \"api_EnumWindows\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x464144\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x464144\",\n      \"target\": \"api_EnumWindows\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_taskbar__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_find_taskbar__3_matches_\",\n      \"target\": \"bb_0x492255\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_find_taskbar__3_matches_\",\n      \"target\": \"bb_0x492289\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_find_taskbar__3_matches_\",\n      \"target\": \"bb_0x41EFCE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x492255\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x492289\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x41EFCE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_graphical_window__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_graphical_window_text__11_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x4947A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x463B0C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x47E8F7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x496FA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x46489C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x464BD3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x461A70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x46359E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x4972B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x465B9A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x491E0D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4947A8\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463B0C\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47E8F7\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x496FA4\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46489C\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x464BD3\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461A70\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46359E\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4972B7\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465B9A\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x491E0D\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4947A8\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463B0C\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47E8F7\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x496FA4\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46489C\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x464BD3\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461A70\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46359E\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4972B7\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465B9A\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x491E0D\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4947A8\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463B0C\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47E8F7\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x496FA4\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46489C\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x464BD3\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461A70\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46359E\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4972B7\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465B9A\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x491E0D\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4947A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x463B0C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x47E8F7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x496FA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46489C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x464BD3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x461A70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46359E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4972B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x465B9A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x491E0D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4947A8\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463B0C\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47E8F7\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x496FA4\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46489C\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x464BD3\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461A70\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46359E\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4972B7\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465B9A\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x491E0D\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4947A8\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463B0C\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47E8F7\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x496FA4\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46489C\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x464BD3\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461A70\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46359E\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4972B7\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465B9A\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x491E0D\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4947A8\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463B0C\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47E8F7\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x496FA4\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46489C\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x464BD3\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461A70\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46359E\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4972B7\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465B9A\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x491E0D\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hide_graphical_window__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x45F0F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x49813A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x496B61\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x4827C2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x49A198\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x49015D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x4950F2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x4981BF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x45F0F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x49813A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x496B61\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4827C2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x49A198\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x49015D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4950F2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4981BF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_keyboard_layout\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_keyboard_layout\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetKeyboardLayoutName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetKeyboardLayoutName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_memory_capacity\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_memory_capacity\",\n      \"target\": \"func_0x41F370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41F370\",\n      \"target\": \"api_GlobalMemoryStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x41F370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41F370\",\n      \"target\": \"api_GlobalMemoryStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x474912\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x4743DE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x473D97\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x4749FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x474776\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x474844\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x474912\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4743DE\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473D97\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4749FD\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474776\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474844\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474912\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4743DE\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473D97\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4749FD\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474776\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474844\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x474912\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4743DE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x473D97\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4749FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x474776\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x474844\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x474912\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4743DE\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473D97\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4749FD\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474776\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474844\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474912\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4743DE\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473D97\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4749FD\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474776\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474844\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_size__3_matches_\",\n      \"target\": \"func_0x4750EB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_size__3_matches_\",\n      \"target\": \"func_0x4751CE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_size__3_matches_\",\n      \"target\": \"func_0x4752B1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4750EB\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4751CE\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4752B1\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4750EB\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4751CE\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4752B1\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4750EB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4751CE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4752B1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4750EB\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4751CE\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4752B1\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4750EB\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4751CE\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4752B1\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_storage_device_properties__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_storage_device_properties__2_matches_\",\n      \"target\": \"func_0x46D588\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_storage_device_properties__2_matches_\",\n      \"target\": \"func_0x46D509\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46D588\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D509\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D588\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D509\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46D588\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D509\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_print_debug_messages\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_print_debug_messages\",\n      \"target\": \"func_0x41F5B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41F5B3\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x41F5B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41F5B3\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_shutdown_system\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_shutdown_system\",\n      \"target\": \"func_0x46E814\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46E814\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E814\",\n      \"target\": \"api_InitiateSystemShutdownEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E814\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46E814\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E814\",\n      \"target\": \"api_InitiateSystemShutdownEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_hostname__2_matches_\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_hostname__2_matches_\",\n      \"target\": \"func_0x46DD45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DD45\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_gethostname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DD45\",\n      \"target\": \"api_gethostname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46DD45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DD45\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_gethostname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DD45\",\n      \"target\": \"api_gethostname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_system_information_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_system_information_on_windows\",\n      \"target\": \"func_0x40615E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40615E\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x40615E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40615E\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x461472\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x4437E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x48B2C1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x48AD7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x46134A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x498064\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x461472\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4437E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x48B2C1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x48AD7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x46134A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x498064\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_or_change_rwx_memory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory\",\n      \"target\": \"bb_0x489881\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x489881\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_processes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_processes__2_matches_\",\n      \"target\": \"func_0x46D3FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_processes__2_matches_\",\n      \"target\": \"func_0x48A5A3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46D3FA\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A5A3\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D3FA\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A5A3\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D3FA\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A5A3\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D3FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x48A5A3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46D3FA\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A5A3\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D3FA\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A5A3\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D3FA\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A5A3\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_acquire_debug_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_acquire_debug_privileges\",\n      \"target\": \"bb_0x48A0B6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"bb_0x48A0B6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_modify_access_privileges__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process__3_matches_\",\n      \"target\": \"func_0x48A009\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__3_matches_\",\n      \"target\": \"func_0x487E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__3_matches_\",\n      \"target\": \"func_0x46EA3E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48A009\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x487E80\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EA3E\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A009\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x487E80\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EA3E\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48A009\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x487E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46EA3E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48A009\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x487E80\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EA3E\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48A009\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x487E80\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EA3E\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_empty_the_recycle_bin\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_empty_the_recycle_bin\",\n      \"target\": \"func_0x477953\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x477953\",\n      \"target\": \"api_SHEmptyRecycleBin\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x477953\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x477953\",\n      \"target\": \"api_SHEmptyRecycleBin\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"target\": \"func_0x48CB5B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"target\": \"func_0x48B8F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48CB5B\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B8F0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48CB5B\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B8F0\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x48CB5B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x48B8F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48CB5B\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B8F0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48CB5B\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B8F0\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x48BB02\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x40533E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x4605C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x4059A7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x48BD6B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48BB02\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40533E\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4605C7\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A7\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BD6B\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BB02\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40533E\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4605C7\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A7\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BD6B\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BB02\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40533E\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4605C7\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A7\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BD6B\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48BB02\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40533E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4605C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4059A7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48BD6B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48BB02\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40533E\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4605C7\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A7\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BD6B\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BB02\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40533E\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4605C7\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A7\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BD6B\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BB02\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40533E\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4605C7\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A7\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BD6B\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value\",\n      \"target\": \"func_0x48C2DE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48C2DE\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C2DE\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x48C2DE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48C2DE\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C2DE\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key__2_matches_\",\n      \"target\": \"func_0x48CB5B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key__2_matches_\",\n      \"target\": \"func_0x48B535\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48CB5B\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B535\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48CB5B\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B535\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x48CB5B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x48B535\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48CB5B\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B535\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48CB5B\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B535\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value\",\n      \"target\": \"func_0x48B535\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48B535\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B535\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48B535\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48B535\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B535\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_user_name\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_session_user_name\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetUserName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41D70E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41D70E\",\n      \"target\": \"api_GetUserName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_token_membership\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_token_membership\",\n      \"target\": \"func_0x4615A7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4615A7\",\n      \"target\": \"api_AllocateAndInitializeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4615A7\",\n      \"target\": \"api_FreeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4615A7\",\n      \"target\": \"api_CheckTokenMembership\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4615A7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4615A7\",\n      \"target\": \"api_AllocateAndInitializeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4615A7\",\n      \"target\": \"api_FreeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4615A7\",\n      \"target\": \"api_CheckTokenMembership\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_token_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_token_privileges\",\n      \"target\": \"func_0x460F58\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x460F58\",\n      \"target\": \"api_GetTokenInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x460F58\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x460F58\",\n      \"target\": \"api_GetTokenInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread__5_matches_\",\n      \"target\": \"bb_0x46E114\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__5_matches_\",\n      \"target\": \"bb_0x461747\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__5_matches_\",\n      \"target\": \"bb_0x47D13B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__5_matches_\",\n      \"target\": \"bb_0x470870\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x46E114\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x461747\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x47D13B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x470870\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_thread\",\n      \"target\": \"bb_0x4708A6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4708A6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_impersonate_user\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_impersonate_user\",\n      \"target\": \"func_0x461145\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x461145\",\n      \"target\": \"api_LoadUserProfile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461145\",\n      \"target\": \"api_LogonUser\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__99_elad_levi_gmail_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__99_elad_levi_gmail_com\",\n      \"target\": \"func_0x461145\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x461145\",\n      \"target\": \"api_LoadUserProfile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461145\",\n      \"target\": \"api_LogonUser\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal__autoit_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__13_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header\",\n      \"target\": \"func_0x40B7E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x40B7E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x408BAA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x490F26\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x410540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x40D840\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x41BEAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x466502\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x4681EE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x401641\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x476E0F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x4763AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x40A180\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x47902A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x487E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x4095C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x40AD7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x408BAA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x490F26\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x410540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x40D840\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x41BEAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x466502\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x4681EE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x401641\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x476E0F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x4763AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x40A180\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x47902A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x487E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x4095C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x40AD7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_execute_shellcode_via_indirect_call\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_execute_shellcode_via_indirect_call\",\n      \"target\": \"func_0x4895BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4895BB\",\n      \"target\": \"api_VirtualAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"target\": \"func_0x4895BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4895BB\",\n      \"target\": \"api_VirtualAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_shortcut_via_ishelllink__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_shortcut_via_ishelllink__2_matches_\",\n      \"target\": \"func_0x4763AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_shortcut_via_ishelllink__2_matches_\",\n      \"target\": \"func_0x47573C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4763AC\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47573C\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______matthew_williams_mandiant_com\",\n      \"target\": \"func_0x4763AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______matthew_williams_mandiant_com\",\n      \"target\": \"func_0x47573C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4763AC\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47573C\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-20 02:13:43.625297\",\n    \"total_functions\": \"2043\",\n    \"total_features\": \"119213\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-20 02:13:47"}
{"_id":{"$oid":"69f1fd5959a6632dae07de7d"},"sha256":"778c2e260d8d3982c7b93c1ecc8201fb16bd62f085004c2886d3c69ef45cec27","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"699461a646277a0a293277ff03365895","sha1":"1d98d127deb12475e785c4a2f6ce10fdb2c488f5","sha256":"778c2e260d8d3982c7b93c1ecc8201fb16bd62f085004c2886d3c69ef45cec27"}},"timestamp":"2026-04-29 18:15:13"}
{"_id":{"$oid":"69f251d159a6632dae07de83"},"sha256":"4792cd702b952d39c1cd215f842223b96e2c17ce9981629cce63014bf095329e","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"Analysis timeout (>10 minutes)"},"verbose":{"success":false,"error":"Analysis timeout (>10 minutes)"},"very_verbose":{"success":false,"error":"Analysis timeout (>10 minutes)"}},"outputs":{"normal":"ERROR:\nAnalysis timeout (>10 minutes)\n\nSTDOUT:\n\n\nSTDERR:\nAnalysis timeout (>10 minutes)","verbose":"ERROR:\nAnalysis timeout (>10 minutes)\n\nSTDOUT:\n\n\nSTDERR:\nAnalysis timeout (>10 minutes)","very_verbose":"ERROR:\nAnalysis timeout (>10 minutes)\n\nSTDOUT:\n\n\nSTDERR:\nAnalysis timeout (>10 minutes)"},"hashes":{"md5":"98962365bde2372a233172635a3de014","sha1":"efdc566207112ca269771024f1ce1bdfec660f9e","sha256":"4792cd702b952d39c1cd215f842223b96e2c17ce9981629cce63014bf095329e"}},"timestamp":"2026-04-30 00:15:37"}
{"_id":{"$oid":"6a04982e204ca8b07f91707c"},"sha256":"0d6e72e20edd52cf3f8cb41446a5eff46c59fb2b79700fb791a85661a5a8f5b4","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"e92f74f5a79b217fb87006d6a729a3eb","sha1":"77173ae144c4791ed62deef3e476493d0d29cb6c","sha256":"0d6e72e20edd52cf3f8cb41446a5eff46c59fb2b79700fb791a85661a5a8f5b4"}},"timestamp":"2026-05-13 20:56:38"}
{"_id":{"$oid":"6a071088204ca8b07f91707e"},"sha256":"f450cef035a0355bdc9c5da156a92a83ea1ca3787cf8ccc6ace3559c3c1100f9","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_djt9jsz3/MBSetup-3.3-019e2b88-d6a1-74d0-8824-310d46fb50a0.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_djt9jsz3/MBSetup-3.3-019e2b88-d6a1-74d0-8824-310d46fb50a0.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_djt9jsz3/MBSetup-3.3-019e2b88-d6a1-74d0-8824-310d46fb50a0.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 306d298f4ffd7cd8a40031876906ee4e                                  │\n│ sha1     │ 446bc7b8d09e39215ed60f87c10e785c6083e836                          │\n│ sha256   │ f450cef035a0355bdc9c5da156a92a83ea1ca3787cf8ccc6ace3559c3c1100f9  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/MBSetup-3.3-019e… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Data from Information Repositories [T1213]            │\n│ DEFENSE EVASION      │ Hide Artifacts::Hidden Window [T1564.003]             │\n│                      │ Impair Defenses::Safe Mode Boot [T1562.009]           │\n│                      │ Modify Registry [T1112]                               │\n│                      │ Obfuscated Files or Information::Indicator Removal    │\n│                      │ from Tools [T1027.005]                                │\n│                      │ Virtualization/Sandbox Evasion::System Checks         │\n│                      │ [T1497.001]                                           │\n│ DISCOVERY            │ Account Discovery [T1087]                             │\n│                      │ Application Window Discovery [T1010]                  │\n│                      │ File and Directory Discovery [T1083]                  │\n│                      │ Process Discovery [T1057]                             │\n│                      │ Query Registry [T1012]                                │\n│                      │ Software Discovery [T1518]                            │\n│                      │ System Information Discovery [T1082]                  │\n│                      │ System Location Discovery [T1614]                     │\n│                      │ System Network Configuration Discovery [T1016]        │\n│                      │ System Owner/User Discovery [T1033]                   │\n│                      │ System Service Discovery [T1007]                      │\n│ EXECUTION            │ Command and Scripting Interpreter [T1059]             │\n│                      │ Shared Modules [T1129]                                │\n│                      │ System Services::Service Execution [T1569.002]        │\n│                      │ Windows Management Instrumentation [T1047]            │\n│ IMPACT               │ Service Stop [T1489]                                  │\n│                      │ System Shutdown/Reboot [T1529]                        │\n│ PERSISTENCE          │ Create or Modify System Process::Windows Service      │\n│                      │ [T1543.003]                                           │\n│ PRIVILEGE ESCALATION │ Access Token Manipulation [T1134]                     │\n│                      │ Access Token Manipulation::Token Impersonation/Theft  │\n│                      │ [T1134.001]                                           │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Virtual Machine Detection [B0009]                 │\n│ ANTI-STATIC ANALYSIS     │ Executable Code Obfuscation::Argument Obfuscation │\n│                          │ [B0032.020]                                       │\n│                          │ Executable Code Obfuscation::Stack Strings        │\n│                          │ [B0032.017]                                       │\n│ COMMUNICATION            │ HTTP Communication::Create Request [C0002.012]    │\n│                          │ HTTP Communication::Get Response [C0002.017]      │\n│                          │ HTTP Communication::Read Header [C0002.014]       │\n│                          │ HTTP Communication::Set Header [C0002.013]        │\n│                          │ HTTP Communication::WinHTTP [C0002.008]           │\n│                          │ Interprocess Communication::Connect Pipe          │\n│                          │ [C0003.002]                                       │\n│                          │ Interprocess Communication::Read Pipe [C0003.003] │\n│                          │ Interprocess Communication::Write Pipe            │\n│                          │ [C0003.004]                                       │\n│ CRYPTOGRAPHY             │ Cryptographic Hash [C0029]                        │\n│                          │ Cryptographic Hash::SHA1 [C0029.002]              │\n│ DISCOVERY                │ Analysis Tool Discovery::Process detection        │\n│                          │ [B0013.001]                                       │\n│                          │ Application Window Discovery [E1010]              │\n│                          │ File and Directory Discovery [E1083]              │\n│                          │ System Information Discovery [E1082]              │\n│ EXECUTION                │ Command and Scripting Interpreter [E1059]         │\n│ FILE SYSTEM              │ Create Directory [C0046]                          │\n│                          │ Delete File [C0047]                               │\n│                          │ Get File Attributes [C0049]                       │\n│                          │ Read File [C0051]                                 │\n│                          │ Writes File [C0052]                               │\n│ OPERATING SYSTEM         │ Environment Variable::Set Variable [C0034.001]    │\n│                          │ Registry::Delete Registry Key [C0036.002]         │\n│                          │ Registry::Delete Registry Value [C0036.007]       │\n│                          │ Registry::Query Registry Key [C0036.005]          │\n│                          │ Registry::Query Registry Value [C0036.006]        │\n│                          │ Registry::Set Registry Key [C0036.001]            │\n│ PROCESS                  │ Allocate Thread Local Storage [C0040]             │\n│                          │ Create Mutex [C0042]                              │\n│                          │ Create Process [C0017]                            │\n│                          │ Create Process::Create Suspended Process          │\n│                          │ [C0017.003]                                       │\n│                          │ Create Thread [C0038]                             │\n│                          │ Set Thread Local Storage Value [C0041]            │\n│                          │ Terminate Process [C0018]                         │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                           ┃ Namespace                             ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ reference analysis tools strings     │ anti-analysis                         │\n│ reference anti-VM strings            │ anti-analysis/anti-vm/vm-detection    │\n│ reference anti-VM strings targeting  │ anti-analysis/anti-vm/vm-detection    │\n│ Parallels                            │                                       │\n│ reference anti-VM strings targeting  │ anti-analysis/anti-vm/vm-detection    │\n│ VMWare                               │                                       │\n│ reference anti-VM strings targeting  │ anti-analysis/anti-vm/vm-detection    │\n│ VirtualBox                           │                                       │\n│ reference anti-VM strings targeting  │ anti-analysis/anti-vm/vm-detection    │\n│ Xen                                  │                                       │\n│ contain obfuscated stackstrings      │ anti-analysis/obfuscation/string/sta… │\n│ get geographical location (3         │ collection                            │\n│ matches)                             │                                       │\n│ reference SQL statements (2 matches) │ collection/database/sql               │\n│ initialize WinHTTP library           │ communication/http                    │\n│ read HTTP header (3 matches)         │ communication/http                    │\n│ set HTTP header                      │ communication/http                    │\n│ check HTTP status code (5 matches)   │ communication/http/client             │\n│ prepare HTTP request (3 matches)     │ communication/http/client             │\n│ receive HTTP response (3 matches)    │ communication/http/client             │\n│ connect pipe                         │ communication/named-pipe/connect      │\n│ read pipe                            │ communication/named-pipe/read         │\n│ write pipe                           │ communication/named-pipe/write        │\n│ hash data via WinCrypt               │ data-manipulation/hashing             │\n│ hash data using SHA1                 │ data-manipulation/hashing/sha1        │\n│ hash data using SHA1 via WinCrypt    │ data-manipulation/hashing/sha1        │\n│ contains PDB path                    │ executable/pe/pdb                     │\n│ extract resource via kernel32        │ executable/resource                   │\n│ functions (5 matches)                │                                       │\n│ manipulate safe mode programs        │ host-interaction/bootloader           │\n│ accept command line arguments        │ host-interaction/cli                  │\n│ query environment variable           │ host-interaction/environment-variable │\n│ set environment variable             │ host-interaction/environment-variable │\n│ get common file path (16 matches)    │ host-interaction/file-system          │\n│ set current directory                │ host-interaction/file-system          │\n│ create directory (2 matches)         │ host-interaction/file-system/create   │\n│ delete file (3 matches)              │ host-interaction/file-system/delete   │\n│ check if file exists (3 matches)     │ host-interaction/file-system/exists   │\n│ enumerate files on Windows (2        │ host-interaction/file-system/files/l… │\n│ matches)                             │                                       │\n│ get file attributes (2 matches)      │ host-interaction/file-system/meta     │\n│ get file version info                │ host-interaction/file-system/meta     │\n│ read file on Windows (5 matches)     │ host-interaction/file-system/read     │\n│ clear file content                   │ host-interaction/file-system/write    │\n│ write file on Windows (2 matches)    │ host-interaction/file-system/write    │\n│ find graphical window                │ host-interaction/gui/window/find      │\n│ get graphical window text            │ host-interaction/gui/window/get-text  │\n│ hide graphical window (15 matches)   │ host-interaction/gui/window/hide      │\n│ get disk information                 │ host-interaction/hardware/storage     │\n│ get disk information via IOCTL (2    │ host-interaction/hardware/storage     │\n│ matches)                             │                                       │\n│ get disk size                        │ host-interaction/hardware/storage     │\n│ get storage device properties        │ host-interaction/hardware/storage     │\n│ create or open mutex on Windows      │ host-interaction/mutex                │\n│ get proxy (2 matches)                │ host-interaction/network/proxy        │\n│ shutdown system                      │ host-interaction/os                   │\n│ get system information on Windows    │ host-interaction/os/info              │\n│ get thread local storage value       │ host-interaction/process              │\n│ create process on Windows (12        │ host-interaction/process/create       │\n│ matches)                             │                                       │\n│ create process suspended             │ host-interaction/process/create       │\n│ enumerate processes                  │ host-interaction/process/list         │\n│ modify access privileges (2 matches) │ host-interaction/process/modify       │\n│ terminate process                    │ host-interaction/process/terminate    │\n│ query or enumerate registry key (4   │ host-interaction/registry             │\n│ matches)                             │                                       │\n│ query or enumerate registry value    │ host-interaction/registry             │\n│ (15 matches)                         │                                       │\n│ delete registry key (4 matches)      │ host-interaction/registry/delete      │\n│ delete registry value                │ host-interaction/registry/delete      │\n│ query service status (4 matches)     │ host-interaction/service              │\n│ create service                       │ host-interaction/service/create       │\n│ delete service (2 matches)           │ host-interaction/service/delete       │\n│ start service (2 matches)            │ host-interaction/service/start        │\n│ stop service                         │ host-interaction/service/stop         │\n│ get session information              │ host-interaction/session              │\n│ get session user name                │ host-interaction/session              │\n│ get token membership                 │ host-interaction/session              │\n│ get installed programs (3 matches)   │ host-interaction/software             │\n│ create thread (2 matches)            │ host-interaction/thread/create        │\n│ allocate thread local storage        │ host-interaction/thread/tls           │\n│ set thread local storage value       │ host-interaction/thread/tls           │\n│ impersonate user                     │ host-interaction/user                 │\n│ connect to WMI namespace via         │ host-interaction/wmi                  │\n│ WbemLocator (6 matches)              │                                       │\n│ get kernel32 base address (2         │ linking/runtime-linking               │\n│ matches)                             │                                       │\n│ get ntdll base address               │ linking/runtime-linking               │\n│ link function at runtime on Windows  │ linking/runtime-linking               │\n│ (16 matches)                         │                                       │\n│ parse PE header (2 matches)          │ load-code/pe                          │\n│ resolve function by parsing PE       │ load-code/pe                          │\n│ exports                              │                                       │\n│ persist via Windows service (2       │ persistence/service                   │\n│ matches)                             │                                       │\n└──────────────────────────────────────┴───────────────────────────────────────┘\n\n","verbose":"md5                     306d298f4ffd7cd8a40031876906ee4e                        \nsha1                    446bc7b8d09e39215ed60f87c10e785c6083e836                \nsha256                  f450cef035a0355bdc9c5da156a92a83ea1ca3787cf8ccc6ace3559…\npath                    /home/apogean/projects/malware/windows/all_runs/MBSetup…\ntimestamp               2026-05-15 17:53:03.829538                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIduyp4j/rules                                   \nfunction count          4017                                                    \nlibrary function count  878                                                     \ntotal feature count     224537                                                  \n\nreference analysis tools strings\nnamespace  anti-analysis\nscope      file         \n\nreference anti-VM strings\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nreference anti-VM strings targeting Parallels\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nreference anti-VM strings targeting VMWare\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nreference anti-VM strings targeting VirtualBox\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nreference anti-VM strings targeting Xen\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\ncontain obfuscated stackstrings\nnamespace  anti-analysis/obfuscation/string/stackstring\nscope      basic block                                 \nmatches    0x4647F0                                    \n\nget geographical location (3 matches)\nnamespace  collection\nscope      function  \nmatches    0x49216E  \n           0x4B8CB0  \n           0x4B8D86  \n\nreference SQL statements (2 matches)\nnamespace  collection/database/sql\nscope      function               \nmatches    0x40CBA0               \n           0x40D560               \n\ninitialize WinHTTP library\nnamespace  communication/http\nscope      function          \nmatches    0x469560          \n\nread HTTP header (3 matches)\nnamespace  communication/http\nscope      function          \nmatches    0x46B430          \n           0x46D980          \n           0x478DD0          \n\nset HTTP header\nnamespace  communication/http\nscope      function          \nmatches    0x478DD0          \n\ncheck HTTP status code (5 matches)\nnamespace  communication/http/client\nscope      function                 \nmatches    0x405050                 \n           0x452990                 \n           0x46B430                 \n           0x46D980                 \n           0x478DD0                 \n\nprepare HTTP request (3 matches)\nnamespace  communication/http/client\nscope      function                 \nmatches    0x46B430                 \n           0x46D980                 \n           0x478DD0                 \n\nreceive HTTP response (3 matches)\nnamespace  communication/http/client\nscope      function                 \nmatches    0x46B430                 \n           0x46D980                 \n           0x478DD0                 \n\nconnect pipe\nnamespace  communication/named-pipe/connect\nscope      function                        \nmatches    0x420990                        \n\nread pipe\nnamespace    communication/named-pipe/read                                      \ndescription  PeekNamedPipe isn't required to read from a pipe; however, pipes   \n             are often utilized to capture the output of a cmd.exe process. In a\n             multi-thread instance, a new thread is created that calls          \n             PeekNamedPipe and ReadFile to obtain the command output.           \nscope        function                                                           \nmatches      0x420990                                                           \n\nwrite pipe\nnamespace  communication/named-pipe/write\nscope      function                      \nmatches    0x420990                      \n\nhash data via WinCrypt\nnamespace  data-manipulation/hashing\nscope      function                 \nmatches    0x40A610                 \n\ninitialize hashing via WinCrypt\nnamespace  data-manipulation/hashing\nscope      function                 \nmatches    0x40A610                 \n\nhash data using SHA1\nnamespace  data-manipulation/hashing/sha1\nscope      function                      \nmatches    0x40A610                      \n\nhash data using SHA1 via WinCrypt\nnamespace  data-manipulation/hashing/sha1\nscope      function                      \nmatches    0x40A610                      \n\ncontains PDB path\nnamespace  executable/pe/pdb\nscope      file             \n\nextract resource via kernel32 functions (5 matches)\nnamespace  executable/resource\nscope      function           \nmatches    0x409790           \n           0x413370           \n           0x447330           \n           0x452880           \n           0x490180           \n\nmanipulate safe mode programs\nnamespace  host-interaction/bootloader\nscope      function                   \nmatches    0x4354B0                   \n\naccept command line arguments\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x4268E0            \n\ninteract with driver via IOCTL (4 matches)\nnamespace  host-interaction/driver\nscope      instruction            \nmatches    0x40CCA8               \n           0x40D661               \n           0x40DCDC               \n           0x40DD29               \n\nquery environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x4B63EF                             \n\nset environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x4B67F8                             \n\nget common file path (16 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x40CBA0                    \n           0x40D560                    \n           0x40DBA0                    \n           0x4268E0                    \n           0x429DB0                    \n           0x42BC20                    \n           0x42CAF0                    \n           0x434AA0                    \n           0x436F10                    \n           0x448B30                    \n           0x449490                    \n           0x4499B0                    \n           0x449B90                    \n           0x44BBB0                    \n           0x455440                    \n           0x492328                    \n\nset current directory\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x4268E0                    \n\ncreate directory (2 matches)\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x449490                           \n           0x44D830                           \n\ndelete file (3 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x415480                           \n           0x43BFF0                           \n           0x44DB40                           \n\ncheck if file exists (3 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x42BC20                           \n           0x449490                           \n           0x46EAC0                           \n\nenumerate files on Windows (2 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x436F10                               \n           0x4B598B                               \n\nget file attributes (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x46EFC7                         \n           0x492987                         \n\nget file version info\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x454FC0                         \n\nread file on Windows (5 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x43EC60                         \n           0x4B1575                         \n           0x4B2933                         \n           0x4B2A80                         \n           0x4B2F28                         \n\nclear file content\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x4BD065                          \n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x4B03D0                          \n           0x4B0CBA                          \n\nfind graphical window\nnamespace  host-interaction/gui/window/find\nscope      instruction                     \nmatches    0x427628                        \n\nget graphical window text\nnamespace  host-interaction/gui/window/get-text\nscope      function                            \nmatches    0x404AC0                            \n\nhide graphical window (15 matches)\nnamespace  host-interaction/gui/window/hide\nscope      basic block                     \nmatches    0x40F39F                        \n           0x40F39F                        \n           0x40F39F                        \n           0x40F39F                        \n           0x40F39F                        \n           0x40F39F                        \n           0x410105                        \n           0x41EF4A                        \n           0x41F805                        \n           0x4255D9                        \n           0x42568A                        \n           0x42761E                        \n           0x464151                        \n           0x4644D8                        \n           0x4683FC                        \n\nget disk information\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x449490                         \n\nget disk information via IOCTL (2 matches)\nnamespace  host-interaction/hardware/storage\nscope      basic block                      \nmatches    0x40CC8C                         \n           0x40D5F0                         \n\nget disk size\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x42A3C0                         \n\nget storage device properties\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x40DBA0                         \n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex\nscope      instruction           \nmatches    0x427500              \n\nget proxy (2 matches)\nnamespace  host-interaction/network/proxy\nscope      function                      \nmatches    0x4178D0                      \n           0x4183B0                      \n\nshutdown system\nnamespace  host-interaction/os\nscope      function           \nmatches    0x434E20           \n\nget system information on Windows\nnamespace  host-interaction/os/info\nscope      function                \nmatches    0x4268E0                \n\nget thread local storage value\nnamespace  host-interaction/process\nscope      function                \nmatches    0x4B24AB                \n\ncreate process on Windows (12 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x4242F9                       \n           0x42E03A                       \n           0x42FE3E                       \n           0x439E34                       \n           0x43A802                       \n           0x43B4FB                       \n           0x446756                       \n           0x44678A                       \n           0x44D0E2                       \n           0x4543E8                       \n           0x45B05B                       \n           0x46873C                       \n\ncreate process suspended\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x4543E8                       \n\nenumerate processes\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    0x455350                     \n\nmodify access privileges (2 matches)\nnamespace  host-interaction/process/modify\nscope      instruction                    \nmatches    0x434F4F                       \n           0x454341                       \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x49F080                          \n\nquery or enumerate registry key (4 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x4089A0                 \n           0x4368C0                 \n           0x438810                 \n           0x46EAC0                 \n\nquery or enumerate registry value (15 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x40A800                 \n           0x40E630                 \n           0x4178D0                 \n           0x41B350                 \n           0x41B6A0                 \n           0x41B9F0                 \n           0x4268E0                 \n           0x42B480                 \n           0x42BC20                 \n           0x4368C0                 \n           0x438810                 \n           0x4486E0                 \n           0x45A370                 \n           0x45B790                 \n           0x46EAC0                 \n\nset registry value (10 matches)\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x408250                        \n           0x4083F6                        \n           0x408613                        \n           0x4183B0                        \n           0x4354B0                        \n           0x448F90                        \n           0x450470                        \n           0x4506E0                        \n           0x45B120                        \n           0x45B790                        \n\ndelete registry key (4 matches)\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x408B30                        \n           0x408E10                        \n           0x42A9F0                        \n           0x435840                        \n\ndelete registry value\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x408E10                        \n\nquery service status (4 matches)\nnamespace  host-interaction/service\nscope      function                \nmatches    0x416C40                \n           0x41AEF0                \n           0x4202E0                \n           0x42B480                \n\ncreate service\nnamespace  host-interaction/service/create\nscope      function                       \nmatches    0x417480                       \n\ndelete service (2 matches)\nnamespace  host-interaction/service/delete\nscope      function                       \nmatches    0x416C40                       \n           0x41BD80                       \n\nstart service (2 matches)\nnamespace  host-interaction/service/start\nscope      function                      \nmatches    0x41AB30                      \n           0x4202E0                      \n\nstop service\nnamespace  host-interaction/service/stop\nscope      function                     \nmatches    0x416C40                     \n\nget session information\nnamespace  host-interaction/session\nscope      function                \nmatches    0x45C2D0                \n\nget session user name\nnamespace  host-interaction/session\nscope      function                \nmatches    0x4183B0                \n\nget token membership\nnamespace  host-interaction/session\nscope      function                \nmatches    0x45C540                \n\nget installed programs (3 matches)\nnamespace  host-interaction/software\nscope      function                 \nmatches    0x4368C0                 \n           0x438810                 \n           0x46EAC0                 \n\ncreate thread (2 matches)\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x44C393                      \n           0x44E7DE                      \n\nallocate thread local storage\nnamespace  host-interaction/thread/tls\nscope      function                   \nmatches    0x4B242D                   \n\nset thread local storage value\nnamespace  host-interaction/thread/tls\nscope      function                   \nmatches    0x4B24EA                   \n\nimpersonate user\nnamespace  host-interaction/user\nscope      function             \nmatches    0x454270             \n\nconnect to WMI namespace via WbemLocator (6 matches)\nnamespace  host-interaction/wmi\nscope      function            \nmatches    0x40C030            \n           0x40C400            \n           0x40C7D0            \n           0x40CBA0            \n           0x40D100            \n           0x40D560            \n\naccess PEB ldr_data (5 matches)\nnamespace  linking/runtime-linking\nscope      basic block            \nmatches    0x440910               \n           0x440CD0               \n           0x4412A0               \n           0x4516F0               \n           0x47DDE0               \n\nget kernel32 base address (2 matches)\nnamespace  linking/runtime-linking\nscope      basic block            \nmatches    0x440CD0               \n           0x4412A0               \n\nget ntdll base address\nnamespace  linking/runtime-linking\nscope      basic block            \nmatches    0x47DDE0               \n\nlink function at runtime on Windows (16 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x40817B               \n           0x40891B               \n           0x408B79               \n           0x408BE9               \n           0x409502               \n           0x435BFA               \n           0x448D22               \n           0x451187               \n           0x45BEB8               \n           0x491106               \n           0x49111B               \n           0x49233D               \n           0x49933F               \n           0x49F111               \n           0x4B22A6               \n           0x453947               \n\nparse PE header (2 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x495147    \n           0x4BE290    \n\nresolve function by parsing PE exports\nnamespace  load-code/pe\nscope      function    \nmatches    0x424690    \n\npersist via Windows service (2 matches)\nnamespace  persistence/service\nscope      function           \nmatches    0x417480           \n           0x4183B0           \n\n\n\n","very_verbose":"md5                     306d298f4ffd7cd8a40031876906ee4e                        \nsha1                    446bc7b8d09e39215ed60f87c10e785c6083e836                \nsha256                  f450cef035a0355bdc9c5da156a92a83ea1ca3787cf8ccc6ace3559…\npath                    /home/apogean/projects/malware/windows/all_runs/MBSetup…\ntimestamp               2026-05-15 17:54:36.222753                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEINiJZZz/rules                                   \nfunction count          4017                                                    \nlibrary function count  878                                                     \ntotal feature count     224537                                                  \n\nPEB access (27 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Debugger Detection::Process Environment   \n            Block [B0001.019]                                                   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nbasic block @ 0x411DE0 in function 0x411DE0\n  or:\n    and:\n      arch: i386\n      characteristic: fs access @ 0x411DEA, 0x411E01\n      or:\n        offset: 0x30 @ 0x411E0F, 0x411E37\n\ncontain loop (543 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x402730\n  or:\n    characteristic: tight loop @ 0x402A80\n\ncreate or open file (8 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x40CC7F\n  or:\n    api: CreateFile @ 0x40CC7F\n\ncreate or open registry key (35 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x4081B1 in function 0x408110\n  or:\n    api: RegCreateKeyEx @ 0x4081C4\n\ndelay execution (18 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x41706E in function 0x416C40\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x417073\n\nget OS version (4 matches, only showing first match of library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x40E180\n  or:\n    api: VerifyVersionInfo @ 0x40E217\n    api: VerSetConditionMask @ 0x40E1E9, 0x40E1ED, 0x40E1F1\n\nget service handle (8 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x416C40\n  or:\n    api: OpenService @ 0x416D64\n\nopen process (2 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org           \nscope   basic block                  \nmbc     Process::Open Process [C0065]\nbasic block @ 0x453BE3 in function 0x453B90\n  or:\n    api: OpenProcess @ 0x453BE7\n\nreference analysis tools strings\nnamespace   anti-analysis                                                       \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \nmbc         Discovery::Analysis Tool Discovery::Process detection [B0013.001]   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /(?<!\\w)ida?(\\.exe)?$/i\n    - \"!\\\\IDAT\" @ file+0x1ED3AC\n  regex: /decompile(\\.exe)?/i\n    - \"\\t<p class='text-content'>Except as specifically permitted under Section 2(g) \nbelow, You must have a license to the Software for every Device on which you \noperate the Software. You may run the Software on a network, provided that you \nhave a license to the Software for each: (1) Device that the Software is \nExecuted on; and (2) Device or user instance that can access the Software over \nthat network that is not included in (1). You may not use on behalf of, or make \nthe functionality of the Software available to, third parties for any purpose, \nsuch as for providing any computer repair, help desk or troubleshooting service.\nExcept as expressly specified or permitted in this Agreement, you may not: (i) \ncopy (except in the course of loading or installing) or modify the Software, \nincluding but not limited to adding new features or otherwise making adaptations\nthat alter the functioning of the Software; (ii) transfer, sublicense, lease, \nlend, rent or otherwise distribute the Software to any third party; (iii) make \nthe functionality of the Software available to any third party through any \nmeans, including but not limited to by uploading the Software to a network or \nfile-sharing service or through any hosting, application services provider, \nservice bureau, SaaS or any other type of services; or (iv) use the Software for\nany illegal purpose or conduct. You acknowledge and agree that portions of the \nSoftware, including but not limited to the source code and the specific design \nand structure of individual modules or programs, constitute or contain trade \nsecrets of Malwarebytes and its licensors. Accordingly, you agree not to \ndisassemble, decompile or reverse engineer the Software or Database (defined \nbelow), in whole or in part, or permit or authorize a third party to do so, \nexcept to the extent such activities are expressly permitted by law \nnotwithstanding this prohibition. You will comply with any additional \nrestrictions contained in your Purchase Receipt or other purchasing \ndocumentation.</p>\" @ file+0x246A9E\n\nreference anti-VM strings\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      moritz.raabe@mandiant.com                                           \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/ctxis/CAPE/blob/master/modules/signatures/antivm…\n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /KVMKVMKVM/i\n    - \"KVMKVMKVM\" @ file+0xEE310\n\nreference anti-VM strings targeting Parallels\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /Parallels/i\n    - \"Parallels Hv\" @ file+0xEE31C\n\nreference anti-VM strings targeting VMWare\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com, @johnk3r                              \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /VMWare/i\n    - \"VMware\" @ file+0xEE350\n    - \"VMwareVMware\" @ file+0xEE2E0\n  regex: /VMwareVMware/i\n    - \"VMwareVMware\" @ file+0xEE2E0\n\nreference anti-VM strings targeting VirtualBox\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /VBOX/i\n    - \"VBoxVBoxVBox\" @ file+0xEE2F0\n  regex: /VBoxVBoxVBox/i\n    - \"VBoxVBoxVBox\" @ file+0xEE2F0\n\nreference anti-VM strings targeting Xen\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /^Xen/i\n    - \"XenVMMXenVMM\" @ file+0xEE300\n  regex: /XenVMMXenVMM/i\n    - \"XenVMMXenVMM\" @ file+0xEE300\n\ncontain obfuscated stackstrings\nnamespace  anti-analysis/obfuscation/string/stackstring                         \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information::Indicator Removal  \n           from Tools [T1027.005]                                               \nmbc        Anti-Static Analysis::Executable Code Obfuscation::Argument          \n           Obfuscation [B0032.020], Anti-Static Analysis::Executable Code       \n           Obfuscation::Stack Strings [B0032.017]                               \nbasic block @ 0x4647F0 in function 0x4647F0\n  characteristic: stack string @ 0x4647F0\n\nget geographical location (3 matches)\nnamespace  collection                                  \nauthor     moritz.raabe, michael.hunhoff@mandiant.com  \nscope      function                                    \natt&ck     Discovery::System Location Discovery [T1614]\nfunction @ 0x49216E\n  or:\n    api: GetLocaleInfoEx @ 0x492182\nfunction @ 0x4B8CB0\n  or:\n    api: GetLocaleInfo @ 0x4B8CDC\nfunction @ 0x4B8D86\n  or:\n    api: GetLocaleInfo @ 0x4B8F27, 0x4B8F42\n\nreference SQL statements (2 matches)\nnamespace  collection/database/sql                               \nauthor     william.ballenthin@mandiant.com                       \nscope      function                                              \natt&ck     Collection::Data from Information Repositories [T1213]\nfunction @ 0x40CBA0\n  and:\n    regex: /SELECT.*FROM.*WHERE/\n      - \"SELECT Signature FROM Win32_DiskDrive WHERE Index=%u\" @ 0x40CCE5\nfunction @ 0x40D560\n  and:\n    regex: /SELECT.*FROM.*WHERE/\n      - \"SELECT SerialNumber FROM Win32_DiskDrive WHERE Index=%u\" @ 0x40D67B\n\ninitialize WinHTTP library\nnamespace  communication/http                                    \nauthor     michael.hunhoff@mandiant.com                          \nscope      function                                              \nmbc        Communication::HTTP Communication::WinHTTP [C0002.008]\nfunction @ 0x469560\n  and:\n    api: WinHttpOpen @ 0x46959B\n\nread HTTP header (3 matches)\nnamespace  communication/http                                           \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Read Header [C0002.014]   \nfunction @ 0x46B430\n  or:\n    api: WinHttpQueryHeaders @ 0x46C0D3, 0x46C214, 0x46C519, 0x46C774, and 1 more...\nfunction @ 0x46D980\n  or:\n    api: WinHttpQueryHeaders @ 0x46E3ED\nfunction @ 0x478DD0\n  or:\n    api: WinHttpQueryHeaders @ 0x4797C8\n\nset HTTP header\nnamespace  communication/http                                           \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Set Header [C0002.013]    \nfunction @ 0x478DD0\n  or:\n    api: WinHttpAddRequestHeaders @ 0x4793D3\n\ncheck HTTP status code (5 matches)\nnamespace  communication/http/client                                 \nauthor     @mr-tz                                                    \nscope      function                                                  \nmbc        Communication::HTTP Communication::Read Header [C0002.014]\nfunction @ 0x405050\n  and:\n    os: windows\n    instruction:\n      and:\n        or:\n          mnemonic: cmp @ 0x4054D2\n        or:\n          number: 0xC8 = OK @ 0x4054D2\n      and:\n        or:\n          mnemonic: cmp @ 0x405673\n        or:\n          number: 0xC8 = OK @ 0x405673\n      and:\n        or:\n          mnemonic: cmp @ 0x4055E7\n        or:\n          number: 0xC8 = OK @ 0x4055E7\n      and:\n        or:\n          mnemonic: cmp @ 0x40545E\n        or:\n          number: 0xC8 = OK @ 0x40545E\n      and:\n        or:\n          mnemonic: cmp @ 0x40555E\n        or:\n          number: 0xC8 = OK @ 0x40555E\n    or:\n      number: 0x13 = HTTP_QUERY_STATUS_CODE @ 0x4051A8, 0x4051BC\nfunction @ 0x452990\n  and:\n    os: windows\n    instruction:\n      and:\n        or:\n          mnemonic: cmp @ 0x4534F9\n        or:\n          number: 0xC8 = OK @ 0x4534F9\n      and:\n        or:\n          mnemonic: cmp @ 0x4534D2\n        or:\n          number: 0xC8 = OK @ 0x4534D2\n      and:\n        or:\n          mnemonic: cmp @ 0x45348D\n        or:\n          number: 0xC8 = OK @ 0x45348D\n      and:\n        or:\n          mnemonic: cmp @ 0x453466\n        or:\n          number: 0xC8 = OK @ 0x453466\n    or:\n      number: 0x13 = HTTP_QUERY_STATUS_CODE @ 0x452ABF\nfunction @ 0x46B430\n  and:\n    os: windows\n    instruction:\n      and:\n        or:\n          mnemonic: cmp @ 0x46C73C\n        or:\n          number: 0xC8 = OK @ 0x46C73C\n    or:\n      number: 0x20000013 = HTTP_QUERY_FLAG_NUMBER | HTTP_QUERY_STATUS_CODE @ 0x46C0C3, 0x46C513\n      number: 0x13 = HTTP_QUERY_STATUS_CODE @ 0x46C427\nfunction @ 0x46D980\n  and:\n    os: windows\n    instruction:\n      and:\n        or:\n          mnemonic: cmp @ 0x46E577\n        or:\n          number: 0xC8 = OK @ 0x46E577\n    or:\n      number: 0x20000013 = HTTP_QUERY_FLAG_NUMBER | HTTP_QUERY_STATUS_CODE @ 0x46E3E7\nfunction @ 0x478DD0\n  and:\n    os: windows\n    instruction:\n      and:\n        or:\n          mnemonic: cmp @ 0x479A70\n        or:\n          number: 0xC8 = OK @ 0x479A70\n    or:\n      number: 0x20000013 = HTTP_QUERY_FLAG_NUMBER | HTTP_QUERY_STATUS_CODE @ 0x4797C2\n\nprepare HTTP request (3 matches)\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com                                 \nscope      function                                                     \nmbc        Communication::HTTP Communication::Create Request [C0002.012]\nfunction @ 0x46B430\n  or:\n    api: WinHttpOpenRequest @ 0x46B85E\nfunction @ 0x46D980\n  or:\n    api: WinHttpOpenRequest @ 0x46DE06\nfunction @ 0x478DD0\n  or:\n    api: WinHttpOpenRequest @ 0x4791F5\n\nreceive HTTP response (3 matches)\nnamespace  communication/http/client                                  \nauthor     michael.hunhoff@mandiant.com                               \nscope      function                                                   \nmbc        Communication::HTTP Communication::Get Response [C0002.017]\nfunction @ 0x46B430\n  or:\n    api: WinHttpReceiveResponse @ 0x46C033, 0x46C486\n    and:\n      api: WinHttpReadData @ 0x46CBE1, 0x46CF86, 0x46D18C\n      optional:\n        api: WinHttpQueryDataAvailable @ 0x46CBB2\nfunction @ 0x46D980\n  or:\n    api: WinHttpReceiveResponse @ 0x46E2F5\nfunction @ 0x478DD0\n  or:\n    api: WinHttpReceiveResponse @ 0x479691\n    and:\n      api: WinHttpReadData @ 0x4799E2\n      optional:\n        api: WinHttpQueryDataAvailable @ 0x4799AC\n\nconnect pipe\nnamespace  communication/named-pipe/connect                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com            \nscope      function                                                           \nmbc        Communication::Interprocess Communication::Connect Pipe [C0003.002]\nfunction @ 0x420990\n  or:\n    api: CallNamedPipe = connect, read, write from pipe in single operation @ 0x420BF4\n\nread pipe\nnamespace    communication/named-pipe/read                                      \nauthor       moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com            \nscope        function                                                           \nmbc          Communication::Interprocess Communication::Read Pipe [C0003.003]   \ndescription  PeekNamedPipe isn't required to read from a pipe; however, pipes   \n             are often utilized to capture the output of a cmd.exe process. In a\n             multi-thread instance, a new thread is created that calls          \n             PeekNamedPipe and ReadFile to obtain the command output.           \nfunction @ 0x420990\n  or:\n    api: CallNamedPipe = connects, writes, and reads pipe in single operation @ 0x420BF4\n\nwrite pipe\nnamespace  communication/named-pipe/write                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com          \nscope      function                                                         \nmbc        Communication::Interprocess Communication::Write Pipe [C0003.004]\nfunction @ 0x420990\n  or:\n    api: CallNamedPipe = connects, writes, and reads pipe in single operation @ 0x420BF4\n\nhash data via WinCrypt\nnamespace  data-manipulation/hashing               \nauthor     michael.hunhoff@mandiant.com            \nscope      function                                \nmbc        Cryptography::Cryptographic Hash [C0029]\nfunction @ 0x40A610\n  and:\n    api: CryptHashData @ 0x40A6C3\n    optional:\n      basic block:\n        and:\n          api: CryptGetHashParam @ 0x40A6ED\n          or:\n            number: 0x2 = HP_HASHVAL @ 0x40A6E8\n\ninitialize hashing via WinCrypt\nnamespace  data-manipulation/hashing   \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x40A610\n  and:\n    api: CryptCreateHash @ 0x40A694\n    optional:\n      api: CryptDestroyHash @ 0x40A74E, 0x40A792\n\nhash data using SHA1\nnamespace  data-manipulation/hashing/sha1                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           william.ballenthin@mandiant.com                                      \nscope      function                                                             \nmbc        Cryptography::Cryptographic Hash::SHA1 [C0029.002]                   \nfunction @ 0x40A610\n  or:\n    basic block:\n      and:\n        number: 0x8004 = CALG_SHA1 @ 0x40A68C\n        api: CryptCreateHash @ 0x40A694\n\nhash data using SHA1 via WinCrypt\nnamespace  data-manipulation/hashing/sha1\nauthor     michael.hunhoff@mandiant.com  \nscope      function                      \nfunction @ 0x40A610\n  or:\n    and:\n      match: initialize hashing via WinCrypt @ 0x40A610\n        and:\n          api: CryptCreateHash @ 0x40A694\n          optional:\n            api: CryptDestroyHash @ 0x40A74E, 0x40A792\n      number: 0x8004 = CALG_SHA1 @ 0x40A68C\n      api: CryptHashData @ 0x40A6C3\n\ncontains PDB path\nnamespace  executable/pe/pdb        \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nregex: /:\\\\.*\\.pdb/\n  - \"C:\\\\Jenkins\\\\workspace\\\\MBAM-Windows\\\\A_MB5_MBSetup\\\\bin\\\\Win32\\\\Release\\\\MBSet\nup.pdb\" @ file+0x102908\n\nextract resource via kernel32 functions (5 matches)\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x409790\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x40986E\n      optional:\n        or:\n          api: FindResource @ 0x409856\n        api: SizeofResource @ 0x40988C\nfunction @ 0x413370\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x41337C\n        api: LockResource @ 0x413387\n      optional:\n        api: SizeofResource @ 0x413395\nfunction @ 0x447330\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x44737F\n        api: LockResource @ 0x44738A\n      optional:\n        or:\n          api: FindResource @ 0x447356\n        api: SizeofResource @ 0x447369\nfunction @ 0x452880\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x4528C8\n        api: LockResource @ 0x4528D7\n      optional:\n        or:\n          api: FindResource @ 0x4528A2\n        api: SizeofResource @ 0x4528B5\nfunction @ 0x490180\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x490301\n        api: LockResource @ 0x4903C1\n      optional:\n        or:\n          api: FindResourceEx @ 0x4901D4\n        api: SizeofResource @ 0x4901E7\n\nmanipulate safe mode programs\nnamespace  host-interaction/bootloader                                 \nauthor     william.ballenthin@mandiant.com                             \nscope      function                                                    \natt&ck     Defense Evasion::Impair Defenses::Safe Mode Boot [T1562.009]\nfunction @ 0x4354B0\n  and:\n    os: windows\n    or:\n      substring: Control\\SafeBoot\\Minimal\\\n        - \"SYSTEM\\\\CurrentControlSet\\\\Control\\\\SafeBoot\\\\Minimal\\\\MBAMInstallerService\" @ 0x4354F3\n      substring: Control\\SafeBoot\\Network\\\n        - \"SYSTEM\\\\CurrentControlSet\\\\Control\\\\SafeBoot\\\\Network\\\\MBAMInstallerService\" @ 0x4356C3\n\naccept command line arguments\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x4268E0\n  or:\n    api: GetCommandLine @ 0x426E6A\n    api: CommandLineToArgv @ 0x426E71\n\ninteract with driver via IOCTL (4 matches)\nnamespace  host-interaction/driver  \nauthor     moritz.raabe@mandiant.com\nscope      instruction              \ninstruction @ 0x40CCA8\n  or:\n    api: DeviceIoControl @ 0x40CCA8\ninstruction @ 0x40D661\n  or:\n    api: DeviceIoControl @ 0x40D661\ninstruction @ 0x40DCDC\n  or:\n    api: DeviceIoControl @ 0x40DCDC\ninstruction @ 0x40DD29\n  or:\n    api: DeviceIoControl @ 0x40DD29\n\nquery environment variable\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x4B63EF\n  or:\n    api: GetEnvironmentStrings @ 0x4B63F2\n\nset environment variable\nnamespace  host-interaction/environment-variable                           \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \nmbc        Operating System::Environment Variable::Set Variable [C0034.001]\nfunction @ 0x4B67F8\n  or:\n    api: SetEnvironmentVariable @ 0x4B6669\n\nget common file path (16 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x40CBA0\n  or:\n    api: GetSystemDirectory @ 0x40CBF9\nfunction @ 0x40D560\n  or:\n    api: GetSystemDirectory @ 0x40D5B9\nfunction @ 0x40DBA0\n  or:\n    api: GetSystemDirectory @ 0x40DBFF\nfunction @ 0x4268E0\n  or:\n    api: GetWindowsDirectory @ 0x426BC2\nfunction @ 0x429DB0\n  or:\n    api: SHGetKnownFolderPath @ 0x429F06, 0x42A25B\nfunction @ 0x42BC20\n  or:\n    api: GetWindowsDirectory @ 0x42C195\nfunction @ 0x42CAF0\n  or:\n    api: GetSystemDirectory @ 0x42CD1D\nfunction @ 0x434AA0\n  or:\n    api: GetSystemDirectory @ 0x434B44\nfunction @ 0x436F10\n  or:\n    api: SHGetKnownFolderPath @ 0x436FA5, 0x437FBB\nfunction @ 0x448B30\n  or:\n    api: GetSystemDirectory @ 0x448C83\nfunction @ 0x449490\n  or:\n    api: GetTempPath @ 0x449794\n    api: SHGetKnownFolderPath @ 0x44961C\nfunction @ 0x4499B0\n  or:\n    api: GetWindowsDirectory @ 0x449A0C\nfunction @ 0x449B90\n  or:\n    api: SHGetKnownFolderPath @ 0x449C00\nfunction @ 0x44BBB0\n  or:\n    api: SHGetKnownFolderPath @ 0x44BC19\nfunction @ 0x455440\n  or:\n    api: GetCurrentDirectory @ 0x455619\nfunction @ 0x492328\n  or:\n    api: GetTempPath @ 0x49235D\n\nset current directory\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x4268E0\n  or:\n    api: SetCurrentDirectory @ 0x426BEF\n\ncreate directory (2 matches)\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x449490\n  or:\n    api: CreateDirectory @ 0x4498D1\nfunction @ 0x44D830\n  or:\n    api: CreateDirectory @ 0x44DA4A\n\ndelete file (3 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x415480\n  or:\n    api: DeleteFile @ 0x41634F\nfunction @ 0x43BFF0\n  or:\n    api: DeleteFile @ 0x43C266\nfunction @ 0x44DB40\n  or:\n    api: DeleteFile @ 0x44E452\n\ncheck if file exists (3 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x42BC20\n  or:\n    basic block:\n      and:\n        api: GetLastError @ 0x42C423\n        instruction:\n          and:\n            mnemonic: cmp @ 0x42C42B\n            number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x42C42B\nfunction @ 0x449490\n  or:\n    api: PathFileExists @ 0x449885\nfunction @ 0x46EAC0\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x46EFDC\n        instruction:\n          and:\n            mnemonic: cmp @ 0x46EFE2\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x46EFE2\n\nenumerate files on Windows (2 matches)\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ 0x436F10\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x4380E1\n      or:\n        api: FindNextFile @ 0x438407\n      optional:\n        api: FindClose @ 0x43845D\n        match: contain loop @ 0x436F10\n          or:\n            characteristic: loop @ 0x436F10\n            characteristic: tight loop @ 0x436FE0, 0x437FF3\nfunction @ 0x4B598B\n  or:\n    and:\n      or:\n        api: FindFirstFileEx @ 0x4B5A26\n      or:\n        api: FindNextFile @ 0x4B5AA1\n      optional:\n        api: FindClose @ 0x4B5AC3, 0x4B5AE6\n        match: contain loop @ 0x4B598B\n          or:\n            characteristic: loop @ 0x4B598B\n\nget file attributes (2 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x46EFC7 in function 0x46EAC0\n  or:\n    api: GetFileAttributes @ 0x46EFDC\nbasic block @ 0x492987 in function 0x492960\n  or:\n    api: GetFileAttributes @ 0x49298B\n\nget file version info\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x454FC0\n  and:\n    or:\n      api: GetFileVersionInfo @ 0x45512E\n    optional: = retrieve specified version information from the version-information resource\n      api: VerQueryValue @ 0x455204\n      or:\n        api: GetFileVersionInfoSize @ 0x455018\n\nread file on Windows (5 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x43EC60\n  or:\n    and:\n      os: windows\n      or:\n        api: fread @ 0x43EDCD, 0x43EDEF\nfunction @ 0x4B1575\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x4B164B\nfunction @ 0x4B2933\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x4B29E7\nfunction @ 0x4B2A80\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x4B2B5F\nfunction @ 0x4B2F28\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x4B31F6\n\nclear file content\nnamespace  host-interaction/file-system/write\nauthor     jakeperalta7                      \nscope      function                          \nmbc        File System::Writes File [C0052]  \nfunction @ 0x4BD065\n  and:\n    api: SetEndOfFile @ 0x4BD1B1\n    not:\n      api: SetFilePointer\n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x4B03D0\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4B0616\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4B05EB\n      or:\n        api: WriteFile @ 0x4B0685, 0x4B06CB\nfunction @ 0x4B0CBA\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4B0D31\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4B0D55\n      or:\n        api: WriteFile @ 0x4B0E3F\n\nfind graphical window\nnamespace  host-interaction/gui/window/find               \nauthor     moritz.raabe@mandiant.com                      \nscope      instruction                                    \natt&ck     Discovery::Application Window Discovery [T1010]\ninstruction @ 0x427628\n  or:\n    api: FindWindow @ 0x427628\n\nget graphical window text\nnamespace  host-interaction/gui/window/get-text           \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \nmbc        Discovery::Application Window Discovery [E1010]\nfunction @ 0x404AC0\n  or:\n    and:\n      api: GetWindowText @ 0x404AFA\n\nhide graphical window (15 matches)\nnamespace  host-interaction/gui/window/hide                          \nauthor     michael.hunhoff@mandiant.com                              \nscope      basic block                                               \natt&ck     Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\nbasic block @ 0x40F39F in function 0x40F4B2\n  and:\n    number: 0x0 = SW_HIDE @ 0x40F39F, 0x40F3BA\n    api: ShowWindow @ 0x40F3A9, 0x40F3AF\nbasic block @ 0x40F39F in function 0x40F4B2\n  and:\n    number: 0x0 = SW_HIDE @ 0x40F39F, 0x40F3BA\n    api: ShowWindow @ 0x40F3A9, 0x40F3AF\nbasic block @ 0x40F39F in function 0x40F4B2\n  and:\n    number: 0x0 = SW_HIDE @ 0x40F39F, 0x40F3BA\n    api: ShowWindow @ 0x40F3A9, 0x40F3AF\nbasic block @ 0x40F39F in function 0x40F4B2\n  and:\n    number: 0x0 = SW_HIDE @ 0x40F39F, 0x40F3BA\n    api: ShowWindow @ 0x40F3A9, 0x40F3AF\nbasic block @ 0x40F39F in function 0x40F4B2\n  and:\n    number: 0x0 = SW_HIDE @ 0x40F39F, 0x40F3BA\n    api: ShowWindow @ 0x40F3A9, 0x40F3AF\nbasic block @ 0x40F39F in function 0x40F4B2\n  and:\n    number: 0x0 = SW_HIDE @ 0x40F39F, 0x40F3BA\n    api: ShowWindow @ 0x40F3A9, 0x40F3AF\nbasic block @ 0x410105 in function 0x4100B0\n  and:\n    number: 0x0 = SW_HIDE @ 0x410105, 0x410120\n    api: ShowWindow @ 0x41010F, 0x410115\nbasic block @ 0x41EF4A in function 0x41E490\n  and:\n    number: 0x0 = SW_HIDE @ 0x41EF4A, 0x41EF60, 0x41EF7B, 0x41EF85, and 4 more...\n    api: ShowWindow @ 0x41EF83, 0x41EF9B\nbasic block @ 0x41F805 in function 0x41F270\n  and:\n    number: 0x0 = SW_HIDE @ 0x41F80E, 0x41F810, 0x41F825\n    api: ShowWindow @ 0x41F82D, 0x41F837, 0x41F847\nbasic block @ 0x4255D9 in function 0x424970\n  and:\n    number: 0x0 = SW_HIDE @ 0x4255E5, 0x425609, 0x42562B\n    api: ShowWindow @ 0x4255E9\nbasic block @ 0x42568A in function 0x424970\n  and:\n    number: 0x0 = SW_HIDE @ 0x425696, 0x4256A6, 0x4256B6, 0x4256DA\n    api: ShowWindow @ 0x42569A, 0x4256BA\nbasic block @ 0x42761E in function 0x4268E0\n  and:\n    number: 0x0 = SW_HIDE @ 0x427641, 0x427643, 0x427645, 0x427647, and 4 more...\n    api: ShowWindow @ 0x427639\nbasic block @ 0x464151 in function 0x463840\n  and:\n    number: 0x0 = SW_HIDE @ 0x464151, 0x464167, 0x464182, 0x464189, and 2 more...\n    api: ShowWindow @ 0x464187, 0x46419F\nbasic block @ 0x4644D8 in function 0x4641F0\n  and:\n    number: 0x0 = SW_HIDE @ 0x4644E3, 0x46450C, 0x46450E, 0x464523\n    api: ShowWindow @ 0x464528, 0x46452F, 0x464547\nbasic block @ 0x4683FC in function 0x467950\n  and:\n    number: 0x0 = SW_HIDE @ 0x4683FC\n    api: ShowWindow @ 0x468400\n\nget disk information\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ 0x449490\n  or:\n    api: GetLogicalDrives @ 0x44950B\n\nget disk information via IOCTL (2 matches)\nnamespace   host-interaction/hardware/storage                                   \nauthor      william.ballenthin@mandiant.com                                     \nscope       basic block                                                         \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-…\n            http://www.ioctls.net/                                              \nbasic block @ 0x40CC8C in function 0x40CBA0\n  and:\n    or:\n      match: interact with driver via IOCTL @ 0x40CCA8\n        or:\n          api: DeviceIoControl @ 0x40CCA8\n    or:\n      number: 0x2D1080 = IOCTL_STORAGE_GET_DEVICE_NUMBER @ 0x40CCA2\nbasic block @ 0x40D5F0 in function 0x40D560\n  and:\n    or:\n      match: interact with driver via IOCTL @ 0x40D661\n        or:\n          api: DeviceIoControl @ 0x40D661\n    or:\n      number: 0x2D1080 = IOCTL_STORAGE_GET_DEVICE_NUMBER @ 0x40D65B\n\nget disk size\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ 0x42A3C0\n  or:\n    api: GetDiskFreeSpaceEx @ 0x42A422\n\nget storage device properties\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com                                        \nscope       function                                                            \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/winioctl/ni-wini…\nfunction @ 0x40DBA0\n  and:\n    number: 0x2D1400 = IOCTL_STORAGE_QUERY_PROPERTY @ 0x40DCC0, 0x40DD23\n    or:\n      match: interact with driver via IOCTL @ 0x40DCDC, 0x40DD29\n        or:\n          api: DeviceIoControl @ 0x40DD29\n        or:\n          api: DeviceIoControl @ 0x40DCDC\n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex                                               \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           mehunhoff@google.com                                                 \nscope      instruction                                                          \nmbc        Process::Create Mutex [C0042]                                        \ninstruction @ 0x427500\n  or:\n    api: CreateMutex @ 0x427500\n\nget proxy (2 matches)\nnamespace  host-interaction/network/proxy                           \nauthor     moritz.raabe@mandiant.com                                \nscope      function                                                 \natt&ck     Discovery::System Network Configuration Discovery [T1016]\nfunction @ 0x4178D0\n  and:\n    match: create or open registry key @ 0x417920\n      or:\n        api: RegOpenKeyEx @ 0x417942\n    string: \"ProxyServer\" @ 0x4179D3\nfunction @ 0x4183B0\n  and:\n    match: create or open registry key @ 0x418499, 0x41858B\n      or:\n        api: RegOpenKeyEx @ 0x4184C1\n      or:\n        api: RegCreateKeyEx @ 0x4185AC\n    string: \"ProxyServer\" @ 0x4186C7\n\nshutdown system\nnamespace  host-interaction/os                   \nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \natt&ck     Impact::System Shutdown/Reboot [T1529]\nfunction @ 0x434E20\n  or:\n    api: InitiateSystemShutdownEx @ 0x43502C\n\nget system information on Windows\nnamespace  host-interaction/os/info                       \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com  \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x4268E0\n  and:\n    os: windows\n    or:\n      api: GetNativeSystemInfo @ 0x42777D\n\nget thread local storage value\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x4B24AB\n  and:\n    api: TlsGetValue @ 0x4B24E4\n\ncreate process on Windows (12 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x4242F9 in function 0x4240D0\n  or:\n    api: ShellExecute @ 0x424307\nbasic block @ 0x42E03A in function 0x42D700\n  or:\n    api: ShellExecute @ 0x42E04D\nbasic block @ 0x42FE3E in function 0x42F9D0\n  or:\n    api: ShellExecute @ 0x42FE7C\nbasic block @ 0x439E34 in function 0x439510\n  or:\n    api: CreateProcess @ 0x439E51\nbasic block @ 0x43A802 in function 0x43A650\n  or:\n    api: CreateProcess @ 0x43A827\nbasic block @ 0x43B4FB in function 0x43B170\n  or:\n    api: ShellExecute @ 0x43B54A\nbasic block @ 0x446756 in function 0x4465C0\n  or:\n    api: ShellExecute @ 0x446765\nbasic block @ 0x44678A in function 0x4465C0\n  or:\n    api: ShellExecute @ 0x44679B\nbasic block @ 0x44D0E2 in function 0x44C600\n  or:\n    api: ShellExecute @ 0x44D105\nbasic block @ 0x4543E8 in function 0x454270\n  or:\n    api: CreateProcessWithToken @ 0x454455\nbasic block @ 0x45B05B in function 0x45AE90\n  or:\n    api: ShellExecute @ 0x45B0A0\nbasic block @ 0x46873C in function 0x468420\n  or:\n    api: ShellExecute @ 0x46874A\n\ncreate process suspended\nnamespace   host-interaction/process/create                                     \nauthor      william.ballenthin@mandiant.com, mehunhoff@google.com               \nscope       basic block                                                         \nmbc         Process::Create Process::Create Suspended Process [C0017.003]       \nreferences  https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/an-…\n            https://learn.microsoft.com/en-us/windows/win32/procthread/process-…\nbasic block @ 0x4543E8 in function 0x454270\n  or:\n    and:\n      or:\n        number: 0x4 = CREATE_SUSPENDED @ 0x454435\n      or:\n        api: CreateProcessWithToken @ 0x454455\n\nenumerate processes\nnamespace  host-interaction/process/list                                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      function                                                             \natt&ck     Discovery::Process Discovery [T1057], Discovery::Software Discovery  \n           [T1518]                                                              \nfunction @ 0x455350\n  or:\n    and:\n      api: Process32First @ 0x4553A5\n      api: Process32Next @ 0x4553C5\n      optional:\n        basic block:\n          and:\n            api: CreateToolhelp32Snapshot @ 0x45536D\n            or:\n              number: 0x2 = TH32CS_SNAPPROCESS @ 0x45536B\n\nmodify access privileges (2 matches)\nnamespace  host-interaction/process/modify                        \nauthor     moritz.raabe@mandiant.com                              \nscope      instruction                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\ninstruction @ 0x434F4F\n  and:\n    api: AdjustTokenPrivileges @ 0x434F4F\ninstruction @ 0x454341\n  and:\n    api: AdjustTokenPrivileges @ 0x454341\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x49F080\n  or:\n    and:\n      or:\n        api: TerminateProcess @ 0x49F098\n        api: ExitProcess @ 0x49F0AA\n\nquery or enumerate registry key (4 matches)\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ 0x4089A0\n  and:\n    or:\n      api: RegEnumKeyEx @ 0x408A4A, 0x408A83\nfunction @ 0x4368C0\n  and:\n    optional:\n      match: create or open registry key @ 0x436B3E, 0x436C32\n        or:\n          api: RegOpenKeyEx @ 0x436C76\n        or:\n          api: RegOpenKeyEx @ 0x436B52\n    or:\n      api: RegEnumKeyEx @ 0x436BD7\nfunction @ 0x438810\n  and:\n    optional:\n      match: create or open registry key @ 0x438A60, 0x438D8B\n        or:\n          api: RegOpenKeyEx @ 0x438A99\n        or:\n          api: RegOpenKeyEx @ 0x438DB0\n    or:\n      api: RegEnumKeyEx @ 0x438B1F\nfunction @ 0x46EAC0\n  and:\n    optional:\n      match: create or open registry key @ 0x46EAC0, 0x46EBA5\n        or:\n          api: RegOpenKeyEx @ 0x46EB3A\n        or:\n          api: RegOpenKeyEx @ 0x46EBC6\n    or:\n      api: RegEnumKeyEx @ 0x46EB97\n\nquery or enumerate registry value (15 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x40A800\n  and:\n    optional:\n      match: create or open registry key @ 0x40A82C\n        or:\n          api: RegOpenKeyEx @ 0x40A84C\n    or:\n      api: RegQueryValueEx @ 0x40A86A, 0x40A89A\nfunction @ 0x40E630\n  and:\n    or:\n      api: RegQueryValueEx @ 0x40E666\nfunction @ 0x4178D0\n  and:\n    optional:\n      match: create or open registry key @ 0x417920\n        or:\n          api: RegOpenKeyEx @ 0x417942\n    or:\n      api: RegQueryValueEx @ 0x41798C, 0x4179DE, 0x417E09\nfunction @ 0x41B350\n  and:\n    optional:\n      match: create or open registry key @ 0x41B44A\n        or:\n          api: RegOpenKeyEx @ 0x41B466\n    or:\n      api: RegQueryValueEx @ 0x41B55C\nfunction @ 0x41B6A0\n  and:\n    optional:\n      match: create or open registry key @ 0x41B79A\n        or:\n          api: RegOpenKeyEx @ 0x41B7B6\n    or:\n      api: RegQueryValueEx @ 0x41B8AB\nfunction @ 0x41B9F0\n  and:\n    or:\n      api: RegEnumValue @ 0x41BB9A\nfunction @ 0x4268E0\n  and:\n    optional:\n      match: create or open registry key @ 0x42836D\n        or:\n          api: RegOpenKeyEx @ 0x42838F\n    or:\n      api: RegQueryValueEx @ 0x4283C6\nfunction @ 0x42B480\n  and:\n    optional:\n      match: create or open registry key @ 0x42B850\n        or:\n          api: RegOpenKeyEx @ 0x42B8A4\n    or:\n      api: RegQueryValueEx @ 0x42B8D5\nfunction @ 0x42BC20\n  and:\n    optional:\n      match: create or open registry key @ 0x42BD86, 0x42C045\n        or:\n          api: RegOpenKeyEx @ 0x42C05D\n        or:\n          api: RegOpenKeyEx @ 0x42BD9A\n    or:\n      api: RegQueryValueEx @ 0x42C0A3\nfunction @ 0x4368C0\n  and:\n    optional:\n      match: create or open registry key @ 0x436B3E, 0x436C32\n        or:\n          api: RegOpenKeyEx @ 0x436C76\n        or:\n          api: RegOpenKeyEx @ 0x436B52\n    or:\n      api: RegQueryValueEx @ 0x436CC0\nfunction @ 0x438810\n  and:\n    optional:\n      match: create or open registry key @ 0x438A60, 0x438D8B\n        or:\n          api: RegOpenKeyEx @ 0x438A99\n        or:\n          api: RegOpenKeyEx @ 0x438DB0\n    or:\n      api: RegQueryValueEx @ 0x438DFA\nfunction @ 0x4486E0\n  and:\n    or:\n      api: RegQueryValueEx @ 0x448827, 0x44885C\nfunction @ 0x45A370\n  and:\n    optional:\n      match: create or open registry key @ 0x45A3CE\n        or:\n          api: RegOpenKeyEx @ 0x45A402\n    or:\n      api: RegQueryValueEx @ 0x45A499\nfunction @ 0x45B790\n  and:\n    optional:\n      match: create or open registry key @ 0x45B7E9\n        or:\n          api: RegOpenKeyEx @ 0x45B819\n    or:\n      api: RegQueryValueEx @ 0x45B847, 0x45B899\nfunction @ 0x46EAC0\n  and:\n    optional:\n      match: create or open registry key @ 0x46EAC0, 0x46EBA5\n        or:\n          api: RegOpenKeyEx @ 0x46EB3A\n        or:\n          api: RegOpenKeyEx @ 0x46EBC6\n    or:\n      api: RegGetValue @ 0x46EC1E, 0x46EE59, 0x46EEB1, 0x46EEF6, and 2 more...\n\nset registry value (10 matches)\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x408250\n  or:\n    and:\n      or:\n        api: RegSetValueEx @ 0x4084D0, 0x408528, 0x408571, 0x4086BF\nfunction @ 0x4083F6\n  or:\n    and:\n      or:\n        api: RegSetValueEx @ 0x4084D0\nfunction @ 0x408613\n  or:\n    and:\n      or:\n        api: RegSetValueEx @ 0x4086BF\nfunction @ 0x4183B0\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x418499, 0x41858B\n          or:\n            api: RegOpenKeyEx @ 0x4184C1\n          or:\n            api: RegCreateKeyEx @ 0x4185AC\n      or:\n        api: RegSetValueEx @ 0x4187B8, 0x418ED7\n        api: RegSetKeyValue @ 0x4186D4, 0x4188B0, 0x4189A4, 0x418BDD, and 36 more...\nfunction @ 0x4354B0\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x4354B0, 0x4356A5\n          or:\n            api: RegCreateKeyEx @ 0x4354FD\n          or:\n            api: RegCreateKeyEx @ 0x4356CD\n      or:\n        api: RegSetValueEx @ 0x4355D6, 0x435754\nfunction @ 0x448F90\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x448F90\n          or:\n            api: RegCreateKeyEx @ 0x448FE0\n      or:\n        api: RegSetValueEx @ 0x44900D\nfunction @ 0x450470\n  or:\n    and:\n      or:\n        api: RegSetValueEx @ 0x45050D\nfunction @ 0x4506E0\n  or:\n    and:\n      or:\n        api: RegSetValueEx @ 0x45077D\nfunction @ 0x45B120\n  or:\n    and:\n      or:\n        api: RegSetValueEx @ 0x45B259\nfunction @ 0x45B790\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x45B7E9\n          or:\n            api: RegOpenKeyEx @ 0x45B819\n      or:\n        api: RegSetValueEx @ 0x45B90F\n\ndelete registry key (4 matches)\nnamespace  host-interaction/registry/delete                                \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\nscope      function                                                        \natt&ck     Defense Evasion::Modify Registry [T1112]                        \nmbc        Operating System::Registry::Delete Registry Key [C0036.002]     \nfunction @ 0x408B30\n  and:\n    or:\n      api: RegDeleteKey @ 0x408BAE, 0x408C38\nfunction @ 0x408E10\n  and:\n    or:\n      api: RegDeleteKey @ 0x40954F\nfunction @ 0x42A9F0\n  and:\n    optional:\n      match: create or open registry key @ 0x42A9F0, 0x42AA46\n        or:\n          api: RegOpenKeyEx @ 0x42AA36\n        or:\n          api: RegCreateKeyEx @ 0x42AA6F\n    or:\n      api: RegDeleteKey @ 0x42AA54, 0x42AA8E\nfunction @ 0x435840\n  and:\n    optional:\n      match: create or open registry key @ 0x435840, 0x435A2A\n        or:\n          api: RegCreateKeyEx @ 0x43588D\n        or:\n          api: RegCreateKeyEx @ 0x435A52\n    or:\n      api: RegDeleteKey @ 0x43595B, 0x435ACE\n\ndelete registry value\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ 0x408E10\n  and:\n    or:\n      api: RegDeleteValue @ 0x40915C\n\nquery service status (4 matches)\nnamespace  host-interaction/service                   \nauthor     michael.hunhoff@mandiant.com               \nscope      function                                   \natt&ck     Discovery::System Service Discovery [T1007]\nfunction @ 0x416C40\n  or:\n    api: QueryServiceStatusEx @ 0x416E86, 0x417086\nfunction @ 0x41AEF0\n  or:\n    api: QueryServiceStatusEx @ 0x41B185\nfunction @ 0x4202E0\n  or:\n    api: QueryServiceStatusEx @ 0x420573, 0x420818\nfunction @ 0x42B480\n  or:\n    api: QueryServiceStatusEx @ 0x42B802\n\ncreate service\nnamespace  host-interaction/service/create                                      \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003], Execution::System Services::Service Execution           \n           [T1569.002]                                                          \nfunction @ 0x417480\n  and:\n    api: CreateService @ 0x417694\n    optional:\n      api: OpenSCManager @ 0x417564\n\ndelete service (2 matches)\nnamespace  host-interaction/service/delete                                      \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003]                                                          \nfunction @ 0x416C40\n  and:\n    api: DeleteService @ 0x41716F\n    optional:\n      match: get service handle @ 0x416C40\n        or:\n          api: OpenService @ 0x416D64\nfunction @ 0x41BD80\n  and:\n    api: DeleteService @ 0x41BFBC\n    optional:\n      match: get service handle @ 0x41BD80\n        or:\n          api: OpenService @ 0x41BEBD\n\nstart service (2 matches)\nnamespace  host-interaction/service/start                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003]                                                          \nfunction @ 0x41AB30\n  and:\n    api: StartService @ 0x41AD48\n    optional:\n      match: get service handle @ 0x41AB30\n        or:\n          api: OpenService @ 0x41AC46\nfunction @ 0x4202E0\n  and:\n    api: StartService @ 0x4206B2\n    optional:\n      match: get service handle @ 0x4202E0\n        or:\n          api: OpenService @ 0x42047A\n\nstop service\nnamespace  host-interaction/service/stop                                        \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003], Impact::Service Stop [T1489]                            \nfunction @ 0x416C40\n  and:\n    optional:\n      match: get service handle @ 0x416C40\n        or:\n          api: OpenService @ 0x416D64\n    or:\n      basic block:\n        and:\n          number: 0x1 = SERVICE_CONTROL_STOP @ 0x416F52\n          or:\n            api: ControlServiceEx @ 0x416F64\n\nget session information\nnamespace  host-interaction/session                      \nauthor     michael.hunhoff@mandiant.com                  \nscope      function                                      \natt&ck     Discovery::System Owner/User Discovery [T1033]\nfunction @ 0x45C2D0\n  and:\n    api: WTSQuerySessionInformation @ 0x45C35C\n    optional:\n      api: WTSFreeMemory @ 0x45C446\n\nget session user name\nnamespace  host-interaction/session                                             \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope      function                                                             \natt&ck     Discovery::System Owner/User Discovery [T1033], Discovery::Account   \n           Discovery [T1087]                                                    \nfunction @ 0x4183B0\n  or:\n    api: GetUserName @ 0x418FC4\n\nget token membership\nnamespace  host-interaction/session                      \nauthor     michael.hunhoff@mandiant.com                  \nscope      function                                      \natt&ck     Discovery::System Owner/User Discovery [T1033]\nfunction @ 0x45C540\n  and:\n    api: CheckTokenMembership @ 0x45C598\n    optional:\n      api: AllocateAndInitializeSid @ 0x45C585\n      api: FreeSid @ 0x45C5A8\n\nget installed programs (3 matches)\nnamespace  host-interaction/software            \nauthor     moritz.raabe@mandiant.com, @_re_fox  \nscope      function                             \natt&ck     Discovery::Software Discovery [T1518]\nfunction @ 0x4368C0\n  and:\n    match: create or open registry key @ 0x436B3E, 0x436C32\n      or:\n        api: RegOpenKeyEx @ 0x436C76\n      or:\n        api: RegOpenKeyEx @ 0x436B52\n    characteristic: loop @ 0x4368C0\n    regex: /SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Uninstall/i\n      - \"SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Uninstall\" @ 0x43695F\n    optional:\n      string: \"DisplayName\" @ 0x436CB5\nfunction @ 0x438810\n  and:\n    match: create or open registry key @ 0x438A60, 0x438D8B\n      or:\n        api: RegOpenKeyEx @ 0x438A99\n      or:\n        api: RegOpenKeyEx @ 0x438DB0\n    characteristic: loop @ 0x438810\n    regex: /SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Uninstall/i\n      - \"SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Uninstall\" @ 0x438868\nfunction @ 0x46EAC0\n  and:\n    match: create or open registry key @ 0x46EAC0, 0x46EBA5\n      or:\n        api: RegOpenKeyEx @ 0x46EB3A\n      or:\n        api: RegOpenKeyEx @ 0x46EBC6\n    characteristic: loop @ 0x46EAC0\n    regex: /SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Uninstall/i\n      - \"SOFTWARE\\\\MICROSOFT\\\\WINDOWS\\\\CURRENTVERSION\\\\UNINSTALL\" @ 0x46EB30\n    optional:\n      string: \"DisplayName\" @ 0x46EC12\n\ncreate thread (2 matches)\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x44C393 in function 0x44BBB0\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthreadex @ 0x44C486\nbasic block @ 0x44E7DE in function 0x44DB40\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthreadex @ 0x44E8A4\n\nallocate thread local storage\nnamespace  host-interaction/thread/tls                   \nauthor     michael.hunhoff@mandiant.com                  \nscope      function                                      \nmbc        Process::Allocate Thread Local Storage [C0040]\nfunction @ 0x4B242D\n  or:\n    api: TlsAlloc @ 0x4B2461\n\nset thread local storage value\nnamespace  host-interaction/thread/tls                    \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \nmbc        Process::Set Thread Local Storage Value [C0041]\nfunction @ 0x4B24EA\n  and:\n    api: TlsSetValue @ 0x4B2526\n\nimpersonate user\nnamespace  host-interaction/user                                                \nauthor     michael.hunhoff@mandiant.com, 99.elad.levi@gmail.com                 \nscope      function                                                             \natt&ck     Privilege Escalation::Access Token Manipulation::Token               \n           Impersonation/Theft [T1134.001]                                      \nfunction @ 0x454270\n  or:\n    and:\n      api: OpenProcessToken @ 0x4542E3\n      or:\n        api: DuplicateTokenEx @ 0x4543B9\n      api: CreateProcessWithToken @ 0x454455\n\nconnect to WMI namespace via WbemLocator (6 matches)\nnamespace  host-interaction/wmi                                 \nauthor     michael.hunhoff@mandiant.com                         \nscope      function                                             \natt&ck     Execution::Windows Management Instrumentation [T1047]\nfunction @ 0x40C030\n  or:\n    and: = static detection rule\n      basic block:\n        and:\n          api: CoCreateInstance @ 0x40C0AB\n          or:\n            bytes: 11f890453a1dd011891f00aa004b2e24 = CLSID_WbemLocator as bytes @ 0x40C0A6\n          or:\n            bytes: 87a612dc7f73cf11884d00aa004b2e24 = IID_IWbemLocator as bytes @ 0x40C09D\n      basic block:\n        or:\n          and:\n            arch: i386\n            offset: 0xC = ppv->ConnectServer @ 0x40C0D0\nfunction @ 0x40C400\n  or:\n    and: = static detection rule\n      basic block:\n        and:\n          api: CoCreateInstance @ 0x40C47B\n          or:\n            bytes: 11f890453a1dd011891f00aa004b2e24 = CLSID_WbemLocator as bytes @ 0x40C476\n          or:\n            bytes: 87a612dc7f73cf11884d00aa004b2e24 = IID_IWbemLocator as bytes @ 0x40C46D\n      basic block:\n        or:\n          and:\n            arch: i386\n            offset: 0xC = ppv->ConnectServer @ 0x40C4A0\nfunction @ 0x40C7D0\n  or:\n    and: = static detection rule\n      basic block:\n        and:\n          api: CoCreateInstance @ 0x40C84B\n          or:\n            bytes: 11f890453a1dd011891f00aa004b2e24 = CLSID_WbemLocator as bytes @ 0x40C846\n          or:\n            bytes: 87a612dc7f73cf11884d00aa004b2e24 = IID_IWbemLocator as bytes @ 0x40C83D\n      basic block:\n        or:\n          and:\n            arch: i386\n            offset: 0xC = ppv->ConnectServer @ 0x40C870\nfunction @ 0x40CBA0\n  or:\n    and: = static detection rule\n      basic block:\n        and:\n          api: CoCreateInstance @ 0x40CD48\n          or:\n            bytes: 11f890453a1dd011891f00aa004b2e24 = CLSID_WbemLocator as bytes @ 0x40CD43\n          or:\n            bytes: 87a612dc7f73cf11884d00aa004b2e24 = IID_IWbemLocator as bytes @ 0x40CD3A\n      basic block:\n        or:\n          and:\n            arch: i386\n            offset: 0xC = ppv->ConnectServer @ 0x40CD76\nfunction @ 0x40D100\n  or:\n    and: = static detection rule\n      basic block:\n        and:\n          api: CoCreateInstance @ 0x40D18E\n          or:\n            bytes: 11f890453a1dd011891f00aa004b2e24 = CLSID_WbemLocator as bytes @ 0x40D189\n          or:\n            bytes: 87a612dc7f73cf11884d00aa004b2e24 = IID_IWbemLocator as bytes @ 0x40D180\n      basic block:\n        or:\n          and:\n            arch: i386\n            offset: 0xC = ppv->ConnectServer @ 0x40D1B3\nfunction @ 0x40D560\n  or:\n    and: = static detection rule\n      basic block:\n        and:\n          api: CoCreateInstance @ 0x40D6DB\n          or:\n            bytes: 11f890453a1dd011891f00aa004b2e24 = CLSID_WbemLocator as bytes @ 0x40D6D6\n          or:\n            bytes: 87a612dc7f73cf11884d00aa004b2e24 = IID_IWbemLocator as bytes @ 0x40D6CD\n      basic block:\n        or:\n          and:\n            arch: i386\n            offset: 0xC = ppv->ConnectServer @ 0x40D709\n\naccess PEB ldr_data (5 matches)\nnamespace   linking/runtime-linking                                             \nauthor      moritz.raabe@mandiant.com                                           \nscope       basic block                                                         \natt&ck      Execution::Shared Modules [T1129]                                   \nreferences  https://www.geoffchappell.com/studies/windows/km/ntoskrnl/inc/api/n…\n            https://github.com/d35ha/CallObfuscator/blob/5834aff9ff4511f1408ae4…\nbasic block @ 0x440910 in function 0x440910\n  or:\n    and: = x32\n      arch: i386\n      match: PEB access @ 0x440910\n        or:\n          and:\n            arch: i386\n            characteristic: fs access @ 0x44091A, 0x440932\n            or:\n              offset: 0x30 @ 0x440977, 0x4409A3\n      offset: 0xC = PEB.LDR_DATA @ 0x44095E\n      or: = resolve a module list\n        offset: 0xC = PEB.LDR_DATA.InLoadOrderModuleList @ 0x44095E\nbasic block @ 0x440CD0 in function 0x440CD0\n  or:\n    and: = x32\n      arch: i386\n      match: PEB access @ 0x440CD0\n        or:\n          and:\n            arch: i386\n            characteristic: fs access @ 0x440CDA, 0x440CEE, 0x440D83\n            or:\n              offset: 0x30 @ 0x440D4B\n      offset: 0xC = PEB.LDR_DATA @ 0x440D0C\n      or: = resolve a module list\n        offset: 0xC = PEB.LDR_DATA.InLoadOrderModuleList @ 0x440D0C\n        offset: 0x14 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x440D1A\n        offset: 0x1C = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x440D28\nbasic block @ 0x4412A0 in function 0x4412A0\n  or:\n    and: = x32\n      arch: i386\n      match: PEB access @ 0x4412A0\n        or:\n          and:\n            arch: i386\n            characteristic: fs access @ 0x4412AA, 0x4412BE, 0x441353\n            or:\n              offset: 0x30 @ 0x44131B\n      offset: 0xC = PEB.LDR_DATA @ 0x4412DC\n      or: = resolve a module list\n        offset: 0xC = PEB.LDR_DATA.InLoadOrderModuleList @ 0x4412DC\n        offset: 0x14 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x4412EA\n        offset: 0x1C = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x4412F8\nbasic block @ 0x4516F0 in function 0x4516F0\n  or:\n    and: = x32\n      arch: i386\n      match: PEB access @ 0x4516F0\n        or:\n          and:\n            arch: i386\n            characteristic: fs access @ 0x4516FA, 0x451711, 0x4517B9\n            or:\n              offset: 0x30 @ 0x451786\n      offset: 0xC = PEB.LDR_DATA @ 0x451730\n      or: = resolve a module list\n        offset: 0xC = PEB.LDR_DATA.InLoadOrderModuleList @ 0x451730\n        offset: 0x14 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x45176D\n        offset: 0x1C = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x451777\nbasic block @ 0x47DDE0 in function 0x47DDE0\n  or:\n    and: = x32\n      arch: i386\n      match: PEB access @ 0x47DDE0\n        or:\n          and:\n            arch: i386\n            characteristic: fs access @ 0x47DDEA, 0x47DE02\n            or:\n              offset: 0x30 @ 0x47DE6C\n      offset: 0xC = PEB.LDR_DATA @ 0x47DE2A\n      or: = resolve a module list\n        offset: 0xC = PEB.LDR_DATA.InLoadOrderModuleList @ 0x47DE2A\n        offset: 0x14 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x47DE38\n        offset: 0x1C = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x47DE46\n\nget kernel32 base address (2 matches)\nnamespace   linking/runtime-linking                                             \nauthor      moritz.raabe@mandiant.com                                           \nscope       basic block                                                         \natt&ck      Execution::Shared Modules [T1129]                                   \nreferences  https://idafchev.github.io/exploit/2017/09/26/writing_windows_shell…\n            https://www.geoffchappell.com/studies/windows/win32/ntdll/structs/l…\nbasic block @ 0x440CD0 in function 0x440CD0\n  and:\n    match: access PEB ldr_data @ 0x440CD0\n      or:\n        and: = x32\n          arch: i386\n          match: PEB access @ 0x440CD0\n            or:\n              and:\n                arch: i386\n                characteristic: fs access @ 0x440CDA, 0x440CEE, 0x440D83\n                or:\n                  offset: 0x30 @ 0x440D4B\n          offset: 0xC = PEB.LDR_DATA @ 0x440D0C\n          or: = resolve a module list\n            offset: 0xC = PEB.LDR_DATA.InLoadOrderModuleList @ 0x440D0C\n            offset: 0x14 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x440D1A\n            offset: 0x1C = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x440D28\n    count(offset): 2 @ 0x440CF8, 0x440D5C\n    or:\n      and:\n        arch: i386\n        offset: 0x18 = LDR_DATA_TABLE_ENTRY.DllBase @ 0x440D21\nbasic block @ 0x4412A0 in function 0x4412A0\n  and:\n    match: access PEB ldr_data @ 0x4412A0\n      or:\n        and: = x32\n          arch: i386\n          match: PEB access @ 0x4412A0\n            or:\n              and:\n                arch: i386\n                characteristic: fs access @ 0x4412AA, 0x4412BE, 0x441353\n                or:\n                  offset: 0x30 @ 0x44131B\n          offset: 0xC = PEB.LDR_DATA @ 0x4412DC\n          or: = resolve a module list\n            offset: 0xC = PEB.LDR_DATA.InLoadOrderModuleList @ 0x4412DC\n            offset: 0x14 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x4412EA\n            offset: 0x1C = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x4412F8\n    count(offset): 2 @ 0x4412C8, 0x44132C\n    or:\n      and:\n        arch: i386\n        offset: 0x18 = LDR_DATA_TABLE_ENTRY.DllBase @ 0x4412F1\n\nget ntdll base address\nnamespace   linking/runtime-linking                                             \nauthor      moritz.raabe@mandiant.com                                           \nscope       basic block                                                         \natt&ck      Execution::Shared Modules [T1129]                                   \nreferences  https://idafchev.github.io/exploit/2017/09/26/writing_windows_shell…\n            https://www.geoffchappell.com/studies/windows/win32/ntdll/structs/l…\nbasic block @ 0x47DDE0 in function 0x47DDE0\n  and:\n    match: access PEB ldr_data @ 0x47DDE0\n      or:\n        and: = x32\n          arch: i386\n          match: PEB access @ 0x47DDE0\n            or:\n              and:\n                arch: i386\n                characteristic: fs access @ 0x47DDEA, 0x47DE02\n                or:\n                  offset: 0x30 @ 0x47DE6C\n          offset: 0xC = PEB.LDR_DATA @ 0x47DE2A\n          or: = resolve a module list\n            offset: 0xC = PEB.LDR_DATA.InLoadOrderModuleList @ 0x47DE2A\n            offset: 0x14 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x47DE38\n            offset: 0x1C = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x47DE46\n    count(offset): 1 @ 0x47DE1A\n    or:\n      and:\n        arch: i386\n        offset: 0x18 = LDR_DATA_TABLE_ENTRY.DllBase @ 0x47DE3F\n\nlink function at runtime on Windows (16 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x40817B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40817B\ninstruction @ 0x40891B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40891B\ninstruction @ 0x408B79\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x408B79\ninstruction @ 0x408BE9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x408BE9\ninstruction @ 0x409502\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x409502\ninstruction @ 0x435BFA\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x435BFA\ninstruction @ 0x448D22\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x448D22\ninstruction @ 0x451187\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x451187\ninstruction @ 0x453947\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x453947\ninstruction @ 0x45BEB8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x45BEB8\ninstruction @ 0x491106\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x491106\ninstruction @ 0x49111B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x49111B\ninstruction @ 0x49233D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x49233D\ninstruction @ 0x49933F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x49933F\ninstruction @ 0x49F111\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x49F111\ninstruction @ 0x4B22A6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4B22A6\n\nparse PE header (2 matches)\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x495147\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x495158, 0x495162, 0x49516F, 0x495175, and 1 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x495162\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x495153\nfunction @ 0x4BE290\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x4BE29B, 0x4BE2A5, 0x4BE2B4\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x4BE2A5\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x4BE296\n\nresolve function by parsing PE exports\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x424690\n  and:\n    os: windows\n    or:\n      mnemonic: movzx @ 0x4248E0\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x4246FE\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x424751\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x4246C2\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x4246E9\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x424708\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x4246C9\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x4246D0\n\npersist via Windows service (2 matches)\nnamespace  persistence/service                                                  \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003], Execution::System Services::Service Execution           \n           [T1569.002]                                                          \nfunction @ 0x417480\n  or:\n    and:\n      or:\n        basic block:\n          and:\n            number: 0x2 = SERVICE_AUTO_START @ 0x417680\n            api: CreateService @ 0x417694\nfunction @ 0x4183B0\n  or:\n    and:\n      match: set registry value @ 0x4183B0\n        or:\n          and:\n            optional:\n              match: create or open registry key @ 0x418499, 0x41858B\n                or:\n                  api: RegOpenKeyEx @ 0x4184C1\n                or:\n                  api: RegCreateKeyEx @ 0x4185AC\n            or:\n              api: RegSetValueEx @ 0x4187B8, 0x418ED7\n              api: RegSetKeyValue @ 0x4186D4, 0x4188B0, 0x4189A4, 0x418BDD, and 36 more...\n      regex: /System\\\\(ControlSet\\d{3}|CurrentControlSet)\\\\Services/i\n        - \"System\\\\CurrentControlSet\\\\Services\\\\\" @ 0x4183EF\n\n\n\n"},"hashes":{"md5":"306d298f4ffd7cd8a40031876906ee4e","sha1":"446bc7b8d09e39215ed60f87c10e785c6083e836","sha256":"f450cef035a0355bdc9c5da156a92a83ea1ca3787cf8ccc6ace3559c3c1100f9"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 4017</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 224537</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"MBSetup\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"306d298f4ffd7cd8a40031876906ee4e\",\n        \"sha256\": \"f450cef035a0355bdc9c5da156a92a83ea1ca3787cf8ccc6ace3559\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_peb_access__27_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"PEB access (27 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Process Environment\",\n        \"Block [B0001.019]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x411DE0\",\n      \"label\": \"Block 0x411DE0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x411DE0\"\n    },\n    {\n      \"id\": \"cap_contain_loop__543_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (543 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x402730\",\n      \"label\": \"Function 0x402730\",\n      \"type\": \"function\",\n      \"address\": \"0x402730\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__8_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (8 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4081B1\",\n      \"label\": \"Block 0x4081B1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4081B1\"\n    },\n    {\n      \"id\": \"api_RegCreateKeyEx\",\n      \"label\": \"RegCreateKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__18_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (18 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x41706E\",\n      \"label\": \"Block 0x41706E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x41706E\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_os_version__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"get OS version (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x40E180\",\n      \"label\": \"Function 0x40E180\",\n      \"type\": \"function\",\n      \"address\": \"0x40E180\"\n    },\n    {\n      \"id\": \"api_VerifyVersionInfo\",\n      \"label\": \"VerifyVersionInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_VerSetConditionMask\",\n      \"label\": \"VerSetConditionMask\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_service_handle__8_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"get service handle (8 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x416C40\",\n      \"label\": \"Function 0x416C40\",\n      \"type\": \"function\",\n      \"address\": \"0x416C40\"\n    },\n    {\n      \"id\": \"api_OpenService\",\n      \"label\": \"OpenService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_open_process__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"open process (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Open Process [C0065]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x453BE3\",\n      \"label\": \"Block 0x453BE3\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x453BE3\"\n    },\n    {\n      \"id\": \"api_OpenProcess\",\n      \"label\": \"OpenProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_reference_analysis_tools_strings\",\n      \"label\": \"reference analysis tools strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings\",\n      \"label\": \"reference anti-VM strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_parallels\",\n      \"label\": \"reference anti-VM strings targeting Parallels\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_vmware\",\n      \"label\": \"reference anti-VM strings targeting VMWare\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com___johnk3r\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, @johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_virtualbox\",\n      \"label\": \"reference anti-VM strings targeting VirtualBox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"label\": \"reference anti-VM strings targeting Xen\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_obfuscated_stackstrings\",\n      \"label\": \"contain obfuscated stackstrings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4647F0\",\n      \"label\": \"Block 0x4647F0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4647F0\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_geographical_location__3_matches_\",\n      \"label\": \"get geographical location (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4B8D86\",\n      \"label\": \"Function 0x4B8D86\",\n      \"type\": \"function\",\n      \"address\": \"0x4B8D86\"\n    },\n    {\n      \"id\": \"func_0x4B8CB0\",\n      \"label\": \"Function 0x4B8CB0\",\n      \"type\": \"function\",\n      \"address\": \"0x4B8CB0\"\n    },\n    {\n      \"id\": \"func_0x49216E\",\n      \"label\": \"Function 0x49216E\",\n      \"type\": \"function\",\n      \"address\": \"0x49216E\"\n    },\n    {\n      \"id\": \"api_GetLocaleInfo\",\n      \"label\": \"GetLocaleInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetLocaleInfoEx\",\n      \"label\": \"GetLocaleInfoEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_sql_statements__2_matches_\",\n      \"label\": \"reference SQL statements (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40CBA0\",\n      \"label\": \"Function 0x40CBA0\",\n      \"type\": \"function\",\n      \"address\": \"0x40CBA0\"\n    },\n    {\n      \"id\": \"func_0x40D560\",\n      \"label\": \"Function 0x40D560\",\n      \"type\": \"function\",\n      \"address\": \"0x40D560\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_initialize_winhttp_library\",\n      \"label\": \"initialize WinHTTP library\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::WinHTTP [C0002.008]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x469560\",\n      \"label\": \"Function 0x469560\",\n      \"type\": \"function\",\n      \"address\": \"0x469560\"\n    },\n    {\n      \"id\": \"api_WinHttpOpen\",\n      \"label\": \"WinHttpOpen\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::WinHTTP [C0002.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_http_header__3_matches_\",\n      \"label\": \"read HTTP header (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Read Header [C0002.014]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46B430\",\n      \"label\": \"Function 0x46B430\",\n      \"type\": \"function\",\n      \"address\": \"0x46B430\"\n    },\n    {\n      \"id\": \"func_0x478DD0\",\n      \"label\": \"Function 0x478DD0\",\n      \"type\": \"function\",\n      \"address\": \"0x478DD0\"\n    },\n    {\n      \"id\": \"func_0x46D980\",\n      \"label\": \"Function 0x46D980\",\n      \"type\": \"function\",\n      \"address\": \"0x46D980\"\n    },\n    {\n      \"id\": \"api_WinHttpQueryHeaders\",\n      \"label\": \"WinHttpQueryHeaders\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Read Header [C0002.014]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_http_header\",\n      \"label\": \"set HTTP header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Set Header [C0002.013]\"\n      ]\n    },\n    {\n      \"id\": \"api_WinHttpAddRequestHeaders\",\n      \"label\": \"WinHttpAddRequestHeaders\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_check_http_status_code__5_matches_\",\n      \"label\": \"check HTTP status code (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Read Header [C0002.014]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x452990\",\n      \"label\": \"Function 0x452990\",\n      \"type\": \"function\",\n      \"address\": \"0x452990\"\n    },\n    {\n      \"id\": \"func_0x405050\",\n      \"label\": \"Function 0x405050\",\n      \"type\": \"function\",\n      \"address\": \"0x405050\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz\",\n      \"label\": \"author     @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Read Header [C0002.014]\"\n      ]\n    },\n    {\n      \"id\": \"cap_prepare_http_request__3_matches_\",\n      \"label\": \"prepare HTTP request (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"api_WinHttpOpenRequest\",\n      \"label\": \"WinHttpOpenRequest\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_receive_http_response__3_matches_\",\n      \"label\": \"receive HTTP response (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"api_WinHttpReceiveResponse\",\n      \"label\": \"WinHttpReceiveResponse\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_WinHttpQueryDataAvailable\",\n      \"label\": \"WinHttpQueryDataAvailable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_WinHttpReadData\",\n      \"label\": \"WinHttpReadData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_connect_pipe\",\n      \"label\": \"connect pipe\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Interprocess Communication::Connect Pipe [C0003.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x420990\",\n      \"label\": \"Function 0x420990\",\n      \"type\": \"function\",\n      \"address\": \"0x420990\"\n    },\n    {\n      \"id\": \"api_CallNamedPipe\",\n      \"label\": \"CallNamedPipe\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Interprocess Communication::Connect Pipe [C0003.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_pipe\",\n      \"label\": \"read pipe\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Interprocess Communication::Read Pipe [C0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author       moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Interprocess Communication::Read Pipe [C0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_pipe\",\n      \"label\": \"write pipe\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Interprocess Communication::Write Pipe [C0003.004]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_via_wincrypt\",\n      \"label\": \"hash data via WinCrypt\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash [C0029]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40A610\",\n      \"label\": \"Function 0x40A610\",\n      \"type\": \"function\",\n      \"address\": \"0x40A610\"\n    },\n    {\n      \"id\": \"api_CryptHashData\",\n      \"label\": \"CryptHashData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CryptGetHashParam\",\n      \"label\": \"CryptGetHashParam\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_initialize_hashing_via_wincrypt\",\n      \"label\": \"initialize hashing via WinCrypt\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_CryptCreateHash\",\n      \"label\": \"CryptCreateHash\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CryptDestroyHash\",\n      \"label\": \"CryptDestroyHash\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_hash_data_using_sha1\",\n      \"label\": \"hash data using SHA1\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash::SHA1 [C0029.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_william_ballenthin_mandiant_com\",\n      \"label\": \"william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash::SHA1 [C0029.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_using_sha1_via_wincrypt\",\n      \"label\": \"hash data using SHA1 via WinCrypt\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_contains_pdb_path\",\n      \"label\": \"contains PDB path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions__5_matches_\",\n      \"label\": \"extract resource via kernel32 functions (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x447330\",\n      \"label\": \"Function 0x447330\",\n      \"type\": \"function\",\n      \"address\": \"0x447330\"\n    },\n    {\n      \"id\": \"func_0x409790\",\n      \"label\": \"Function 0x409790\",\n      \"type\": \"function\",\n      \"address\": \"0x409790\"\n    },\n    {\n      \"id\": \"func_0x490180\",\n      \"label\": \"Function 0x490180\",\n      \"type\": \"function\",\n      \"address\": \"0x490180\"\n    },\n    {\n      \"id\": \"func_0x413370\",\n      \"label\": \"Function 0x413370\",\n      \"type\": \"function\",\n      \"address\": \"0x413370\"\n    },\n    {\n      \"id\": \"func_0x452880\",\n      \"label\": \"Function 0x452880\",\n      \"type\": \"function\",\n      \"address\": \"0x452880\"\n    },\n    {\n      \"id\": \"api_FindResourceEx\",\n      \"label\": \"FindResourceEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_manipulate_safe_mode_programs\",\n      \"label\": \"manipulate safe mode programs\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Impair Defenses::Safe Mode Boot [T1562.009]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4354B0\",\n      \"label\": \"Function 0x4354B0\",\n      \"type\": \"function\",\n      \"address\": \"0x4354B0\"\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments\",\n      \"label\": \"accept command line arguments\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4268E0\",\n      \"label\": \"Function 0x4268E0\",\n      \"type\": \"function\",\n      \"address\": \"0x4268E0\"\n    },\n    {\n      \"id\": \"api_CommandLineToArgv\",\n      \"label\": \"CommandLineToArgv\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_interact_with_driver_via_ioctl__4_matches_\",\n      \"label\": \"interact with driver via IOCTL (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_DeviceIoControl\",\n      \"label\": \"DeviceIoControl\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_environment_variable\",\n      \"label\": \"query environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4B63EF\",\n      \"label\": \"Function 0x4B63EF\",\n      \"type\": \"function\",\n      \"address\": \"0x4B63EF\"\n    },\n    {\n      \"id\": \"api_GetEnvironmentStrings\",\n      \"label\": \"GetEnvironmentStrings\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_environment_variable\",\n      \"label\": \"set environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable::Set Variable [C0034.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4B67F8\",\n      \"label\": \"Function 0x4B67F8\",\n      \"type\": \"function\",\n      \"address\": \"0x4B67F8\"\n    },\n    {\n      \"id\": \"api_SetEnvironmentVariable\",\n      \"label\": \"SetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__16_matches_\",\n      \"label\": \"get common file path (16 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x44BBB0\",\n      \"label\": \"Function 0x44BBB0\",\n      \"type\": \"function\",\n      \"address\": \"0x44BBB0\"\n    },\n    {\n      \"id\": \"func_0x455440\",\n      \"label\": \"Function 0x455440\",\n      \"type\": \"function\",\n      \"address\": \"0x455440\"\n    },\n    {\n      \"id\": \"func_0x434AA0\",\n      \"label\": \"Function 0x434AA0\",\n      \"type\": \"function\",\n      \"address\": \"0x434AA0\"\n    },\n    {\n      \"id\": \"func_0x448B30\",\n      \"label\": \"Function 0x448B30\",\n      \"type\": \"function\",\n      \"address\": \"0x448B30\"\n    },\n    {\n      \"id\": \"func_0x42CAF0\",\n      \"label\": \"Function 0x42CAF0\",\n      \"type\": \"function\",\n      \"address\": \"0x42CAF0\"\n    },\n    {\n      \"id\": \"func_0x436F10\",\n      \"label\": \"Function 0x436F10\",\n      \"type\": \"function\",\n      \"address\": \"0x436F10\"\n    },\n    {\n      \"id\": \"func_0x40DBA0\",\n      \"label\": \"Function 0x40DBA0\",\n      \"type\": \"function\",\n      \"address\": \"0x40DBA0\"\n    },\n    {\n      \"id\": \"func_0x429DB0\",\n      \"label\": \"Function 0x429DB0\",\n      \"type\": \"function\",\n      \"address\": \"0x429DB0\"\n    },\n    {\n      \"id\": \"func_0x492328\",\n      \"label\": \"Function 0x492328\",\n      \"type\": \"function\",\n      \"address\": \"0x492328\"\n    },\n    {\n      \"id\": \"func_0x4499B0\",\n      \"label\": \"Function 0x4499B0\",\n      \"type\": \"function\",\n      \"address\": \"0x4499B0\"\n    },\n    {\n      \"id\": \"func_0x449B90\",\n      \"label\": \"Function 0x449B90\",\n      \"type\": \"function\",\n      \"address\": \"0x449B90\"\n    },\n    {\n      \"id\": \"func_0x449490\",\n      \"label\": \"Function 0x449490\",\n      \"type\": \"function\",\n      \"address\": \"0x449490\"\n    },\n    {\n      \"id\": \"func_0x42BC20\",\n      \"label\": \"Function 0x42BC20\",\n      \"type\": \"function\",\n      \"address\": \"0x42BC20\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHGetKnownFolderPath\",\n      \"label\": \"SHGetKnownFolderPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetCurrentDirectory\",\n      \"label\": \"GetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_current_directory\",\n      \"label\": \"set current directory\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_SetCurrentDirectory\",\n      \"label\": \"SetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_directory__2_matches_\",\n      \"label\": \"create directory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x44D830\",\n      \"label\": \"Function 0x44D830\",\n      \"type\": \"function\",\n      \"address\": \"0x44D830\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_delete_file__3_matches_\",\n      \"label\": \"delete file (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x415480\",\n      \"label\": \"Function 0x415480\",\n      \"type\": \"function\",\n      \"address\": \"0x415480\"\n    },\n    {\n      \"id\": \"func_0x43BFF0\",\n      \"label\": \"Function 0x43BFF0\",\n      \"type\": \"function\",\n      \"address\": \"0x43BFF0\"\n    },\n    {\n      \"id\": \"func_0x44DB40\",\n      \"label\": \"Function 0x44DB40\",\n      \"type\": \"function\",\n      \"address\": \"0x44DB40\"\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__3_matches_\",\n      \"label\": \"check if file exists (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46EAC0\",\n      \"label\": \"Function 0x46EAC0\",\n      \"type\": \"function\",\n      \"address\": \"0x46EAC0\"\n    },\n    {\n      \"id\": \"api_GetLastError\",\n      \"label\": \"GetLastError\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_PathFileExists\",\n      \"label\": \"PathFileExists\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"label\": \"enumerate files on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4B598B\",\n      \"label\": \"Function 0x4B598B\",\n      \"type\": \"function\",\n      \"address\": \"0x4B598B\"\n    },\n    {\n      \"id\": \"api_FindFirstFileEx\",\n      \"label\": \"FindFirstFileEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindNextFile\",\n      \"label\": \"FindNextFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindFirstFile\",\n      \"label\": \"FindFirstFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindClose\",\n      \"label\": \"FindClose\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes__2_matches_\",\n      \"label\": \"get file attributes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x46EFC7\",\n      \"label\": \"Block 0x46EFC7\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46EFC7\"\n    },\n    {\n      \"id\": \"bb_0x492987\",\n      \"label\": \"Block 0x492987\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x492987\"\n    },\n    {\n      \"id\": \"cap_get_file_version_info\",\n      \"label\": \"get file version info\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x454FC0\",\n      \"label\": \"Function 0x454FC0\",\n      \"type\": \"function\",\n      \"address\": \"0x454FC0\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfoSize\",\n      \"label\": \"GetFileVersionInfoSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfo\",\n      \"label\": \"GetFileVersionInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_VerQueryValue\",\n      \"label\": \"VerQueryValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__5_matches_\",\n      \"label\": \"read file on Windows (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4B2F28\",\n      \"label\": \"Function 0x4B2F28\",\n      \"type\": \"function\",\n      \"address\": \"0x4B2F28\"\n    },\n    {\n      \"id\": \"func_0x4B2933\",\n      \"label\": \"Function 0x4B2933\",\n      \"type\": \"function\",\n      \"address\": \"0x4B2933\"\n    },\n    {\n      \"id\": \"func_0x43EC60\",\n      \"label\": \"Function 0x43EC60\",\n      \"type\": \"function\",\n      \"address\": \"0x43EC60\"\n    },\n    {\n      \"id\": \"func_0x4B2A80\",\n      \"label\": \"Function 0x4B2A80\",\n      \"type\": \"function\",\n      \"address\": \"0x4B2A80\"\n    },\n    {\n      \"id\": \"func_0x4B1575\",\n      \"label\": \"Function 0x4B1575\",\n      \"type\": \"function\",\n      \"address\": \"0x4B1575\"\n    },\n    {\n      \"id\": \"api_fread\",\n      \"label\": \"fread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_clear_file_content\",\n      \"label\": \"clear file content\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4BD065\",\n      \"label\": \"Function 0x4BD065\",\n      \"type\": \"function\",\n      \"address\": \"0x4BD065\"\n    },\n    {\n      \"id\": \"api_SetFilePointer\",\n      \"label\": \"SetFilePointer\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SetEndOfFile\",\n      \"label\": \"SetEndOfFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____jakeperalta7\",\n      \"label\": \"author     jakeperalta7\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__2_matches_\",\n      \"label\": \"write file on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4B03D0\",\n      \"label\": \"Function 0x4B03D0\",\n      \"type\": \"function\",\n      \"address\": \"0x4B03D0\"\n    },\n    {\n      \"id\": \"func_0x4B0CBA\",\n      \"label\": \"Function 0x4B0CBA\",\n      \"type\": \"function\",\n      \"address\": \"0x4B0CBA\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_graphical_window\",\n      \"label\": \"find graphical window\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindWindow\",\n      \"label\": \"FindWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_graphical_window_text\",\n      \"label\": \"get graphical window text\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404AC0\",\n      \"label\": \"Function 0x404AC0\",\n      \"type\": \"function\",\n      \"address\": \"0x404AC0\"\n    },\n    {\n      \"id\": \"api_GetWindowText\",\n      \"label\": \"GetWindowText\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_hide_graphical_window__15_matches_\",\n      \"label\": \"hide graphical window (15 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x410105\",\n      \"label\": \"Block 0x410105\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x410105\"\n    },\n    {\n      \"id\": \"bb_0x4683FC\",\n      \"label\": \"Block 0x4683FC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4683FC\"\n    },\n    {\n      \"id\": \"bb_0x40F39F\",\n      \"label\": \"Block 0x40F39F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40F39F\"\n    },\n    {\n      \"id\": \"bb_0x4255D9\",\n      \"label\": \"Block 0x4255D9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4255D9\"\n    },\n    {\n      \"id\": \"bb_0x41EF4A\",\n      \"label\": \"Block 0x41EF4A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x41EF4A\"\n    },\n    {\n      \"id\": \"bb_0x464151\",\n      \"label\": \"Block 0x464151\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x464151\"\n    },\n    {\n      \"id\": \"bb_0x4644D8\",\n      \"label\": \"Block 0x4644D8\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4644D8\"\n    },\n    {\n      \"id\": \"bb_0x42761E\",\n      \"label\": \"Block 0x42761E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x42761E\"\n    },\n    {\n      \"id\": \"bb_0x41F805\",\n      \"label\": \"Block 0x41F805\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x41F805\"\n    },\n    {\n      \"id\": \"bb_0x42568A\",\n      \"label\": \"Block 0x42568A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x42568A\"\n    },\n    {\n      \"id\": \"api_ShowWindow\",\n      \"label\": \"ShowWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_information\",\n      \"label\": \"get disk information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetLogicalDrives\",\n      \"label\": \"GetLogicalDrives\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_information_via_ioctl__2_matches_\",\n      \"label\": \"get disk information via IOCTL (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40CC8C\",\n      \"label\": \"Block 0x40CC8C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40CC8C\"\n    },\n    {\n      \"id\": \"bb_0x40D5F0\",\n      \"label\": \"Block 0x40D5F0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40D5F0\"\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_disk_size\",\n      \"label\": \"get disk size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x42A3C0\",\n      \"label\": \"Function 0x42A3C0\",\n      \"type\": \"function\",\n      \"address\": \"0x42A3C0\"\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpaceEx\",\n      \"label\": \"GetDiskFreeSpaceEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_storage_device_properties\",\n      \"label\": \"get storage device properties\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_or_open_mutex_on_windows\",\n      \"label\": \"create or open mutex on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateMutex\",\n      \"label\": \"CreateMutex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_mehunhoff_google_com\",\n      \"label\": \"mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_proxy__2_matches_\",\n      \"label\": \"get proxy (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Network Configuration Discovery [T1016]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4178D0\",\n      \"label\": \"Function 0x4178D0\",\n      \"type\": \"function\",\n      \"address\": \"0x4178D0\"\n    },\n    {\n      \"id\": \"func_0x4183B0\",\n      \"label\": \"Function 0x4183B0\",\n      \"type\": \"function\",\n      \"address\": \"0x4183B0\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_shutdown_system\",\n      \"label\": \"shutdown system\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::System Shutdown/Reboot [T1529]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x434E20\",\n      \"label\": \"Function 0x434E20\",\n      \"type\": \"function\",\n      \"address\": \"0x434E20\"\n    },\n    {\n      \"id\": \"api_InitiateSystemShutdownEx\",\n      \"label\": \"InitiateSystemShutdownEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_system_information_on_windows\",\n      \"label\": \"get system information on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetNativeSystemInfo\",\n      \"label\": \"GetNativeSystemInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_thread_local_storage_value\",\n      \"label\": \"get thread local storage value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x4B24AB\",\n      \"label\": \"Function 0x4B24AB\",\n      \"type\": \"function\",\n      \"address\": \"0x4B24AB\"\n    },\n    {\n      \"id\": \"api_TlsGetValue\",\n      \"label\": \"TlsGetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__12_matches_\",\n      \"label\": \"create process on Windows (12 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4242F9\",\n      \"label\": \"Block 0x4242F9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4242F9\"\n    },\n    {\n      \"id\": \"bb_0x42FE3E\",\n      \"label\": \"Block 0x42FE3E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x42FE3E\"\n    },\n    {\n      \"id\": \"bb_0x4543E8\",\n      \"label\": \"Block 0x4543E8\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4543E8\"\n    },\n    {\n      \"id\": \"bb_0x44678A\",\n      \"label\": \"Block 0x44678A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x44678A\"\n    },\n    {\n      \"id\": \"bb_0x439E34\",\n      \"label\": \"Block 0x439E34\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x439E34\"\n    },\n    {\n      \"id\": \"bb_0x45B05B\",\n      \"label\": \"Block 0x45B05B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x45B05B\"\n    },\n    {\n      \"id\": \"bb_0x43A802\",\n      \"label\": \"Block 0x43A802\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x43A802\"\n    },\n    {\n      \"id\": \"bb_0x42E03A\",\n      \"label\": \"Block 0x42E03A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x42E03A\"\n    },\n    {\n      \"id\": \"bb_0x46873C\",\n      \"label\": \"Block 0x46873C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46873C\"\n    },\n    {\n      \"id\": \"bb_0x43B4FB\",\n      \"label\": \"Block 0x43B4FB\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x43B4FB\"\n    },\n    {\n      \"id\": \"bb_0x44D0E2\",\n      \"label\": \"Block 0x44D0E2\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x44D0E2\"\n    },\n    {\n      \"id\": \"bb_0x446756\",\n      \"label\": \"Block 0x446756\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x446756\"\n    },\n    {\n      \"id\": \"api_ShellExecute\",\n      \"label\": \"ShellExecute\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_CreateProcessWithToken\",\n      \"label\": \"CreateProcessWithToken\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_create_process_suspended\",\n      \"label\": \"create process suspended\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process::Create Suspended Process [C0017.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process::Create Suspended Process [C0017.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_processes\",\n      \"label\": \"enumerate processes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\",\n        \"Discovery::Software Discovery\",\n        \"[T1518]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x455350\",\n      \"label\": \"Function 0x455350\",\n      \"type\": \"function\",\n      \"address\": \"0x455350\"\n    },\n    {\n      \"id\": \"api_CreateToolhelp32Snapshot\",\n      \"label\": \"CreateToolhelp32Snapshot\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_Process32First\",\n      \"label\": \"Process32First\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_Process32Next\",\n      \"label\": \"Process32Next\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_modify_access_privileges__2_matches_\",\n      \"label\": \"modify access privileges (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"api_AdjustTokenPrivileges\",\n      \"label\": \"AdjustTokenPrivileges\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x49F080\",\n      \"label\": \"Function 0x49F080\",\n      \"type\": \"function\",\n      \"address\": \"0x49F080\"\n    },\n    {\n      \"id\": \"api_TerminateProcess\",\n      \"label\": \"TerminateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_ExitProcess\",\n      \"label\": \"ExitProcess\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key__4_matches_\",\n      \"label\": \"query or enumerate registry key (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4089A0\",\n      \"label\": \"Function 0x4089A0\",\n      \"type\": \"function\",\n      \"address\": \"0x4089A0\"\n    },\n    {\n      \"id\": \"func_0x438810\",\n      \"label\": \"Function 0x438810\",\n      \"type\": \"function\",\n      \"address\": \"0x438810\"\n    },\n    {\n      \"id\": \"func_0x4368C0\",\n      \"label\": \"Function 0x4368C0\",\n      \"type\": \"function\",\n      \"address\": \"0x4368C0\"\n    },\n    {\n      \"id\": \"api_RegEnumKeyEx\",\n      \"label\": \"RegEnumKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"label\": \"query or enumerate registry value (15 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x42B480\",\n      \"label\": \"Function 0x42B480\",\n      \"type\": \"function\",\n      \"address\": \"0x42B480\"\n    },\n    {\n      \"id\": \"func_0x40A800\",\n      \"label\": \"Function 0x40A800\",\n      \"type\": \"function\",\n      \"address\": \"0x40A800\"\n    },\n    {\n      \"id\": \"func_0x45B790\",\n      \"label\": \"Function 0x45B790\",\n      \"type\": \"function\",\n      \"address\": \"0x45B790\"\n    },\n    {\n      \"id\": \"func_0x4486E0\",\n      \"label\": \"Function 0x4486E0\",\n      \"type\": \"function\",\n      \"address\": \"0x4486E0\"\n    },\n    {\n      \"id\": \"func_0x41B350\",\n      \"label\": \"Function 0x41B350\",\n      \"type\": \"function\",\n      \"address\": \"0x41B350\"\n    },\n    {\n      \"id\": \"func_0x45A370\",\n      \"label\": \"Function 0x45A370\",\n      \"type\": \"function\",\n      \"address\": \"0x45A370\"\n    },\n    {\n      \"id\": \"func_0x41B6A0\",\n      \"label\": \"Function 0x41B6A0\",\n      \"type\": \"function\",\n      \"address\": \"0x41B6A0\"\n    },\n    {\n      \"id\": \"func_0x41B9F0\",\n      \"label\": \"Function 0x41B9F0\",\n      \"type\": \"function\",\n      \"address\": \"0x41B9F0\"\n    },\n    {\n      \"id\": \"func_0x40E630\",\n      \"label\": \"Function 0x40E630\",\n      \"type\": \"function\",\n      \"address\": \"0x40E630\"\n    },\n    {\n      \"id\": \"api_RegEnumValue\",\n      \"label\": \"RegEnumValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegGetValue\",\n      \"label\": \"RegGetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value__10_matches_\",\n      \"label\": \"set registry value (10 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408250\",\n      \"label\": \"Function 0x408250\",\n      \"type\": \"function\",\n      \"address\": \"0x408250\"\n    },\n    {\n      \"id\": \"func_0x450470\",\n      \"label\": \"Function 0x450470\",\n      \"type\": \"function\",\n      \"address\": \"0x450470\"\n    },\n    {\n      \"id\": \"func_0x408613\",\n      \"label\": \"Function 0x408613\",\n      \"type\": \"function\",\n      \"address\": \"0x408613\"\n    },\n    {\n      \"id\": \"func_0x45B120\",\n      \"label\": \"Function 0x45B120\",\n      \"type\": \"function\",\n      \"address\": \"0x45B120\"\n    },\n    {\n      \"id\": \"func_0x4506E0\",\n      \"label\": \"Function 0x4506E0\",\n      \"type\": \"function\",\n      \"address\": \"0x4506E0\"\n    },\n    {\n      \"id\": \"func_0x4083F6\",\n      \"label\": \"Function 0x4083F6\",\n      \"type\": \"function\",\n      \"address\": \"0x4083F6\"\n    },\n    {\n      \"id\": \"func_0x448F90\",\n      \"label\": \"Function 0x448F90\",\n      \"type\": \"function\",\n      \"address\": \"0x448F90\"\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"api_RegSetKeyValue\",\n      \"label\": \"RegSetKeyValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_registry_key__4_matches_\",\n      \"label\": \"delete registry key (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408E10\",\n      \"label\": \"Function 0x408E10\",\n      \"type\": \"function\",\n      \"address\": \"0x408E10\"\n    },\n    {\n      \"id\": \"func_0x435840\",\n      \"label\": \"Function 0x435840\",\n      \"type\": \"function\",\n      \"address\": \"0x435840\"\n    },\n    {\n      \"id\": \"func_0x42A9F0\",\n      \"label\": \"Function 0x42A9F0\",\n      \"type\": \"function\",\n      \"address\": \"0x42A9F0\"\n    },\n    {\n      \"id\": \"func_0x408B30\",\n      \"label\": \"Function 0x408B30\",\n      \"type\": \"function\",\n      \"address\": \"0x408B30\"\n    },\n    {\n      \"id\": \"api_RegDeleteKey\",\n      \"label\": \"RegDeleteKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_value\",\n      \"label\": \"delete registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegDeleteValue\",\n      \"label\": \"RegDeleteValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_service_status__4_matches_\",\n      \"label\": \"query service status (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Service Discovery [T1007]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x41AEF0\",\n      \"label\": \"Function 0x41AEF0\",\n      \"type\": \"function\",\n      \"address\": \"0x41AEF0\"\n    },\n    {\n      \"id\": \"func_0x4202E0\",\n      \"label\": \"Function 0x4202E0\",\n      \"type\": \"function\",\n      \"address\": \"0x4202E0\"\n    },\n    {\n      \"id\": \"api_QueryServiceStatusEx\",\n      \"label\": \"QueryServiceStatusEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_service\",\n      \"label\": \"create service\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\",\n        \"Execution::System Services::Service Execution\",\n        \"[T1569.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x417480\",\n      \"label\": \"Function 0x417480\",\n      \"type\": \"function\",\n      \"address\": \"0x417480\"\n    },\n    {\n      \"id\": \"api_OpenSCManager\",\n      \"label\": \"OpenSCManager\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateService\",\n      \"label\": \"CreateService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_service__2_matches_\",\n      \"label\": \"delete service (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x41BD80\",\n      \"label\": \"Function 0x41BD80\",\n      \"type\": \"function\",\n      \"address\": \"0x41BD80\"\n    },\n    {\n      \"id\": \"api_DeleteService\",\n      \"label\": \"DeleteService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_start_service__2_matches_\",\n      \"label\": \"start service (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x41AB30\",\n      \"label\": \"Function 0x41AB30\",\n      \"type\": \"function\",\n      \"address\": \"0x41AB30\"\n    },\n    {\n      \"id\": \"api_StartService\",\n      \"label\": \"StartService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_stop_service\",\n      \"label\": \"stop service\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\",\n        \"Impact::Service Stop [T1489]\"\n      ]\n    },\n    {\n      \"id\": \"api_ControlServiceEx\",\n      \"label\": \"ControlServiceEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_session_information\",\n      \"label\": \"get session information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x45C2D0\",\n      \"label\": \"Function 0x45C2D0\",\n      \"type\": \"function\",\n      \"address\": \"0x45C2D0\"\n    },\n    {\n      \"id\": \"api_WTSQuerySessionInformation\",\n      \"label\": \"WTSQuerySessionInformation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_WTSFreeMemory\",\n      \"label\": \"WTSFreeMemory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_session_user_name\",\n      \"label\": \"get session user name\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\",\n        \"Discovery::Account\",\n        \"Discovery [T1087]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetUserName\",\n      \"label\": \"GetUserName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_token_membership\",\n      \"label\": \"get token membership\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x45C540\",\n      \"label\": \"Function 0x45C540\",\n      \"type\": \"function\",\n      \"address\": \"0x45C540\"\n    },\n    {\n      \"id\": \"api_AllocateAndInitializeSid\",\n      \"label\": \"AllocateAndInitializeSid\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CheckTokenMembership\",\n      \"label\": \"CheckTokenMembership\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FreeSid\",\n      \"label\": \"FreeSid\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_installed_programs__3_matches_\",\n      \"label\": \"get installed programs (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Software Discovery [T1518]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com____re_fox\",\n      \"label\": \"author     moritz.raabe@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Software Discovery [T1518]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_thread__2_matches_\",\n      \"label\": \"create thread (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x44E7DE\",\n      \"label\": \"Block 0x44E7DE\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x44E7DE\"\n    },\n    {\n      \"id\": \"bb_0x44C393\",\n      \"label\": \"Block 0x44C393\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x44C393\"\n    },\n    {\n      \"id\": \"api__beginthreadex\",\n      \"label\": \"_beginthreadex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_allocate_thread_local_storage\",\n      \"label\": \"allocate thread local storage\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Allocate Thread Local Storage [C0040]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4B242D\",\n      \"label\": \"Function 0x4B242D\",\n      \"type\": \"function\",\n      \"address\": \"0x4B242D\"\n    },\n    {\n      \"id\": \"api_TlsAlloc\",\n      \"label\": \"TlsAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_thread_local_storage_value\",\n      \"label\": \"set thread local storage value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Set Thread Local Storage Value [C0041]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4B24EA\",\n      \"label\": \"Function 0x4B24EA\",\n      \"type\": \"function\",\n      \"address\": \"0x4B24EA\"\n    },\n    {\n      \"id\": \"api_TlsSetValue\",\n      \"label\": \"TlsSetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_impersonate_user\",\n      \"label\": \"impersonate user\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation::Token\",\n        \"Impersonation/Theft [T1134.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x454270\",\n      \"label\": \"Function 0x454270\",\n      \"type\": \"function\",\n      \"address\": \"0x454270\"\n    },\n    {\n      \"id\": \"api_DuplicateTokenEx\",\n      \"label\": \"DuplicateTokenEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_OpenProcessToken\",\n      \"label\": \"OpenProcessToken\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__99_elad_levi_gmail_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, 99.elad.levi@gmail.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation::Token\",\n        \"Impersonation/Theft [T1134.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_to_wmi_namespace_via_wbemlocator__6_matches_\",\n      \"label\": \"connect to WMI namespace via WbemLocator (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Windows Management Instrumentation [T1047]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40C400\",\n      \"label\": \"Function 0x40C400\",\n      \"type\": \"function\",\n      \"address\": \"0x40C400\"\n    },\n    {\n      \"id\": \"func_0x40D100\",\n      \"label\": \"Function 0x40D100\",\n      \"type\": \"function\",\n      \"address\": \"0x40D100\"\n    },\n    {\n      \"id\": \"func_0x40C7D0\",\n      \"label\": \"Function 0x40C7D0\",\n      \"type\": \"function\",\n      \"address\": \"0x40C7D0\"\n    },\n    {\n      \"id\": \"func_0x40C030\",\n      \"label\": \"Function 0x40C030\",\n      \"type\": \"function\",\n      \"address\": \"0x40C030\"\n    },\n    {\n      \"id\": \"api_CoCreateInstance\",\n      \"label\": \"CoCreateInstance\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_access_peb_ldr_data__5_matches_\",\n      \"label\": \"access PEB ldr_data (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4516F0\",\n      \"label\": \"Block 0x4516F0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4516F0\"\n    },\n    {\n      \"id\": \"bb_0x47DDE0\",\n      \"label\": \"Block 0x47DDE0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x47DDE0\"\n    },\n    {\n      \"id\": \"bb_0x440910\",\n      \"label\": \"Block 0x440910\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x440910\"\n    },\n    {\n      \"id\": \"bb_0x440CD0\",\n      \"label\": \"Block 0x440CD0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x440CD0\"\n    },\n    {\n      \"id\": \"bb_0x4412A0\",\n      \"label\": \"Block 0x4412A0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4412A0\"\n    },\n    {\n      \"id\": \"cap_get_kernel32_base_address__2_matches_\",\n      \"label\": \"get kernel32 base address (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_ntdll_base_address\",\n      \"label\": \"get ntdll base address\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__16_matches_\",\n      \"label\": \"link function at runtime on Windows (16 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header__2_matches_\",\n      \"label\": \"parse PE header (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x495147\",\n      \"label\": \"Function 0x495147\",\n      \"type\": \"function\",\n      \"address\": \"0x495147\"\n    },\n    {\n      \"id\": \"func_0x4BE290\",\n      \"label\": \"Function 0x4BE290\",\n      \"type\": \"function\",\n      \"address\": \"0x4BE290\"\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"label\": \"resolve function by parsing PE exports\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x424690\",\n      \"label\": \"Function 0x424690\",\n      \"type\": \"function\",\n      \"address\": \"0x424690\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_persist_via_windows_service__2_matches_\",\n      \"label\": \"persist via Windows service (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\",\n        \"Execution::System Services::Service Execution\",\n        \"[T1569.002]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_peb_access__27_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_peb_access__27_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x411DE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__543_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__543_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x402730\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__8_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x4081B1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__18_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__18_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x41706E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_os_version__4_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x40E180\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E180\",\n      \"target\": \"api_VerifyVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E180\",\n      \"target\": \"api_VerSetConditionMask\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_service_handle__8_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_service_handle__8_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x416C40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x416C40\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_process__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_process__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x453BE3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_analysis_tools_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_parallels\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_vmware\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com___johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_virtualbox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_obfuscated_stackstrings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings\",\n      \"target\": \"bb_0x4647F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4647F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_geographical_location__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__3_matches_\",\n      \"target\": \"func_0x4B8D86\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__3_matches_\",\n      \"target\": \"func_0x4B8CB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__3_matches_\",\n      \"target\": \"func_0x49216E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4B8D86\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B8CB0\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x49216E\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B8D86\",\n      \"target\": \"api_GetLocaleInfoEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B8CB0\",\n      \"target\": \"api_GetLocaleInfoEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x49216E\",\n      \"target\": \"api_GetLocaleInfoEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4B8D86\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4B8CB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x49216E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4B8D86\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B8CB0\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x49216E\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B8D86\",\n      \"target\": \"api_GetLocaleInfoEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B8CB0\",\n      \"target\": \"api_GetLocaleInfoEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x49216E\",\n      \"target\": \"api_GetLocaleInfoEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_sql_statements__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_reference_sql_statements__2_matches_\",\n      \"target\": \"func_0x40CBA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_reference_sql_statements__2_matches_\",\n      \"target\": \"func_0x40D560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40CBA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40D560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_initialize_winhttp_library\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_initialize_winhttp_library\",\n      \"target\": \"func_0x469560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x469560\",\n      \"target\": \"api_WinHttpOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x469560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x469560\",\n      \"target\": \"api_WinHttpOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_http_header__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_http_header__3_matches_\",\n      \"target\": \"func_0x46B430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_http_header__3_matches_\",\n      \"target\": \"func_0x478DD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_http_header__3_matches_\",\n      \"target\": \"func_0x46D980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46B430\",\n      \"target\": \"api_WinHttpQueryHeaders\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478DD0\",\n      \"target\": \"api_WinHttpQueryHeaders\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D980\",\n      \"target\": \"api_WinHttpQueryHeaders\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46B430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x478DD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46D980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46B430\",\n      \"target\": \"api_WinHttpQueryHeaders\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478DD0\",\n      \"target\": \"api_WinHttpQueryHeaders\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D980\",\n      \"target\": \"api_WinHttpQueryHeaders\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_http_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_http_header\",\n      \"target\": \"func_0x478DD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x478DD0\",\n      \"target\": \"api_WinHttpAddRequestHeaders\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x478DD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x478DD0\",\n      \"target\": \"api_WinHttpAddRequestHeaders\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_http_status_code__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_http_status_code__5_matches_\",\n      \"target\": \"func_0x452990\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_http_status_code__5_matches_\",\n      \"target\": \"func_0x46B430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_http_status_code__5_matches_\",\n      \"target\": \"func_0x405050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_http_status_code__5_matches_\",\n      \"target\": \"func_0x478DD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_http_status_code__5_matches_\",\n      \"target\": \"func_0x46D980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz\",\n      \"target\": \"func_0x452990\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz\",\n      \"target\": \"func_0x46B430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz\",\n      \"target\": \"func_0x405050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz\",\n      \"target\": \"func_0x478DD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz\",\n      \"target\": \"func_0x46D980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_prepare_http_request__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_prepare_http_request__3_matches_\",\n      \"target\": \"func_0x46B430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_prepare_http_request__3_matches_\",\n      \"target\": \"func_0x478DD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_prepare_http_request__3_matches_\",\n      \"target\": \"func_0x46D980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46B430\",\n      \"target\": \"api_WinHttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478DD0\",\n      \"target\": \"api_WinHttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D980\",\n      \"target\": \"api_WinHttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46B430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x478DD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46B430\",\n      \"target\": \"api_WinHttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478DD0\",\n      \"target\": \"api_WinHttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D980\",\n      \"target\": \"api_WinHttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_http_response__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_http_response__3_matches_\",\n      \"target\": \"func_0x46B430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_http_response__3_matches_\",\n      \"target\": \"func_0x478DD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_http_response__3_matches_\",\n      \"target\": \"func_0x46D980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46B430\",\n      \"target\": \"api_WinHttpReceiveResponse\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478DD0\",\n      \"target\": \"api_WinHttpReceiveResponse\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D980\",\n      \"target\": \"api_WinHttpReceiveResponse\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B430\",\n      \"target\": \"api_WinHttpQueryDataAvailable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478DD0\",\n      \"target\": \"api_WinHttpQueryDataAvailable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D980\",\n      \"target\": \"api_WinHttpQueryDataAvailable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B430\",\n      \"target\": \"api_WinHttpReadData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478DD0\",\n      \"target\": \"api_WinHttpReadData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D980\",\n      \"target\": \"api_WinHttpReadData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46B430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x478DD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46B430\",\n      \"target\": \"api_WinHttpReceiveResponse\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478DD0\",\n      \"target\": \"api_WinHttpReceiveResponse\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D980\",\n      \"target\": \"api_WinHttpReceiveResponse\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B430\",\n      \"target\": \"api_WinHttpQueryDataAvailable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478DD0\",\n      \"target\": \"api_WinHttpQueryDataAvailable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D980\",\n      \"target\": \"api_WinHttpQueryDataAvailable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B430\",\n      \"target\": \"api_WinHttpReadData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478DD0\",\n      \"target\": \"api_WinHttpReadData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D980\",\n      \"target\": \"api_WinHttpReadData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_pipe\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_pipe\",\n      \"target\": \"func_0x420990\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x420990\",\n      \"target\": \"api_CallNamedPipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x420990\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x420990\",\n      \"target\": \"api_CallNamedPipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_pipe\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_pipe\",\n      \"target\": \"func_0x420990\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x420990\",\n      \"target\": \"api_CallNamedPipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x420990\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x420990\",\n      \"target\": \"api_CallNamedPipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_pipe\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_pipe\",\n      \"target\": \"func_0x420990\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x420990\",\n      \"target\": \"api_CallNamedPipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x420990\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x420990\",\n      \"target\": \"api_CallNamedPipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_via_wincrypt\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt\",\n      \"target\": \"func_0x40A610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A610\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A610\",\n      \"target\": \"api_CryptGetHashParam\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40A610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A610\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A610\",\n      \"target\": \"api_CryptGetHashParam\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_initialize_hashing_via_wincrypt\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_initialize_hashing_via_wincrypt\",\n      \"target\": \"func_0x40A610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A610\",\n      \"target\": \"api_CryptCreateHash\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A610\",\n      \"target\": \"api_CryptDestroyHash\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40A610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A610\",\n      \"target\": \"api_CryptCreateHash\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A610\",\n      \"target\": \"api_CryptDestroyHash\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_sha1\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_sha1\",\n      \"target\": \"func_0x40A610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A610\",\n      \"target\": \"api_CryptCreateHash\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40A610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A610\",\n      \"target\": \"api_CryptCreateHash\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_sha1_via_wincrypt\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_sha1_via_wincrypt\",\n      \"target\": \"func_0x40A610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A610\",\n      \"target\": \"api_CryptCreateHash\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A610\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A610\",\n      \"target\": \"api_CryptDestroyHash\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40A610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A610\",\n      \"target\": \"api_CryptCreateHash\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A610\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A610\",\n      \"target\": \"api_CryptDestroyHash\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contains_pdb_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__5_matches_\",\n      \"target\": \"func_0x447330\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__5_matches_\",\n      \"target\": \"func_0x409790\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__5_matches_\",\n      \"target\": \"func_0x490180\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__5_matches_\",\n      \"target\": \"func_0x413370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__5_matches_\",\n      \"target\": \"func_0x452880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x447330\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409790\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x490180\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x413370\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x452880\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x447330\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409790\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x490180\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x413370\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x452880\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x447330\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409790\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x490180\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x413370\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x452880\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x447330\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409790\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x490180\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x413370\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x452880\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x447330\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409790\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x490180\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x413370\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x452880\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x447330\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x409790\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x490180\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x413370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x452880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x447330\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409790\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x490180\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x413370\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x452880\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x447330\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409790\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x490180\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x413370\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x452880\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x447330\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409790\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x490180\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x413370\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x452880\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x447330\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409790\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x490180\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x413370\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x452880\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x447330\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409790\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x490180\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x413370\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x452880\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_manipulate_safe_mode_programs\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_manipulate_safe_mode_programs\",\n      \"target\": \"func_0x4354B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x4354B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments\",\n      \"target\": \"func_0x4268E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_CommandLineToArgv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4268E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_CommandLineToArgv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_interact_with_driver_via_ioctl__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable\",\n      \"target\": \"func_0x4B63EF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4B63EF\",\n      \"target\": \"api_GetEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x4B63EF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4B63EF\",\n      \"target\": \"api_GetEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_environment_variable\",\n      \"target\": \"func_0x4B67F8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4B67F8\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4B67F8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4B67F8\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__16_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__16_matches_\",\n      \"target\": \"func_0x44BBB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__16_matches_\",\n      \"target\": \"func_0x455440\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__16_matches_\",\n      \"target\": \"func_0x434AA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__16_matches_\",\n      \"target\": \"func_0x448B30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__16_matches_\",\n      \"target\": \"func_0x42CAF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__16_matches_\",\n      \"target\": \"func_0x436F10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__16_matches_\",\n      \"target\": \"func_0x4268E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__16_matches_\",\n      \"target\": \"func_0x40D560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__16_matches_\",\n      \"target\": \"func_0x40DBA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__16_matches_\",\n      \"target\": \"func_0x429DB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__16_matches_\",\n      \"target\": \"func_0x492328\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__16_matches_\",\n      \"target\": \"func_0x4499B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__16_matches_\",\n      \"target\": \"func_0x40CBA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__16_matches_\",\n      \"target\": \"func_0x449B90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__16_matches_\",\n      \"target\": \"func_0x449490\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__16_matches_\",\n      \"target\": \"func_0x42BC20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x44BBB0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x455440\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x434AA0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448B30\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42CAF0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D560\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DBA0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x429DB0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x492328\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4499B0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40CBA0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449B90\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x44BBB0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x455440\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x434AA0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448B30\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42CAF0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D560\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DBA0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x429DB0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x492328\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4499B0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40CBA0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449B90\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x44BBB0\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x455440\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x434AA0\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448B30\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42CAF0\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D560\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DBA0\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x429DB0\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x492328\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4499B0\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40CBA0\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449B90\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x44BBB0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x455440\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x434AA0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448B30\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42CAF0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D560\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DBA0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x429DB0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x492328\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4499B0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40CBA0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449B90\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x44BBB0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x455440\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x434AA0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448B30\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42CAF0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D560\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DBA0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x429DB0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x492328\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4499B0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40CBA0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449B90\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x44BBB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x455440\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x434AA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x448B30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x42CAF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x436F10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4268E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40D560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40DBA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x429DB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x492328\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4499B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40CBA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x449B90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x449490\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x42BC20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x44BBB0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x455440\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x434AA0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448B30\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42CAF0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D560\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DBA0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x429DB0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x492328\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4499B0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40CBA0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449B90\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x44BBB0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x455440\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x434AA0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448B30\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42CAF0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D560\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DBA0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x429DB0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x492328\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4499B0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40CBA0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449B90\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x44BBB0\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x455440\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x434AA0\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448B30\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42CAF0\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D560\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DBA0\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x429DB0\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x492328\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4499B0\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40CBA0\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449B90\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_SHGetKnownFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x44BBB0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x455440\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x434AA0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448B30\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42CAF0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D560\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DBA0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x429DB0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x492328\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4499B0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40CBA0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449B90\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x44BBB0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x455440\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x434AA0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448B30\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42CAF0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D560\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DBA0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x429DB0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x492328\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4499B0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40CBA0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449B90\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_current_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_current_directory\",\n      \"target\": \"func_0x4268E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4268E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory__2_matches_\",\n      \"target\": \"func_0x44D830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__2_matches_\",\n      \"target\": \"func_0x449490\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x44D830\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x44D830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x449490\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x44D830\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x415480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x43BFF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x44DB40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x415480\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43BFF0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x44DB40\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x415480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x43BFF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x44DB40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x415480\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43BFF0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x44DB40\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x42BC20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x449490\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x46EAC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x42BC20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x449490\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46EAC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"target\": \"func_0x436F10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"target\": \"func_0x4B598B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_FindFirstFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B598B\",\n      \"target\": \"api_FindFirstFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B598B\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B598B\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B598B\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x436F10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4B598B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_FindFirstFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B598B\",\n      \"target\": \"api_FindFirstFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B598B\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B598B\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x436F10\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B598B\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__2_matches_\",\n      \"target\": \"bb_0x46EFC7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__2_matches_\",\n      \"target\": \"bb_0x492987\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x46EFC7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x492987\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_version_info\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_version_info\",\n      \"target\": \"func_0x454FC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x454FC0\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454FC0\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454FC0\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x454FC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x454FC0\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454FC0\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454FC0\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__5_matches_\",\n      \"target\": \"func_0x4B2F28\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__5_matches_\",\n      \"target\": \"func_0x4B2933\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__5_matches_\",\n      \"target\": \"func_0x43EC60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__5_matches_\",\n      \"target\": \"func_0x4B2A80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__5_matches_\",\n      \"target\": \"func_0x4B1575\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4B2F28\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B2933\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43EC60\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B2A80\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B1575\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B2F28\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B2933\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43EC60\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B2A80\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B1575\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4B2F28\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4B2933\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x43EC60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4B2A80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4B1575\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4B2F28\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B2933\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43EC60\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B2A80\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B1575\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B2F28\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B2933\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43EC60\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B2A80\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B1575\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_clear_file_content\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_clear_file_content\",\n      \"target\": \"func_0x4BD065\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4BD065\",\n      \"target\": \"api_SetFilePointer\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4BD065\",\n      \"target\": \"api_SetEndOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____jakeperalta7\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____jakeperalta7\",\n      \"target\": \"func_0x4BD065\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4BD065\",\n      \"target\": \"api_SetFilePointer\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4BD065\",\n      \"target\": \"api_SetEndOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x4B03D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x4B0CBA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4B03D0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B0CBA\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4B03D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4B0CBA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4B03D0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4B0CBA\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_graphical_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_graphical_window_text\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text\",\n      \"target\": \"func_0x404AC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404AC0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x404AC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404AC0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hide_graphical_window__15_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__15_matches_\",\n      \"target\": \"bb_0x410105\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__15_matches_\",\n      \"target\": \"bb_0x4683FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__15_matches_\",\n      \"target\": \"bb_0x40F39F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__15_matches_\",\n      \"target\": \"bb_0x4255D9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__15_matches_\",\n      \"target\": \"bb_0x41EF4A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__15_matches_\",\n      \"target\": \"bb_0x464151\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__15_matches_\",\n      \"target\": \"bb_0x4644D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__15_matches_\",\n      \"target\": \"bb_0x42761E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__15_matches_\",\n      \"target\": \"bb_0x41F805\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__15_matches_\",\n      \"target\": \"bb_0x42568A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x410105\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4683FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x40F39F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4255D9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x41EF4A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x464151\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4644D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x42761E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x41F805\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x42568A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information\",\n      \"target\": \"func_0x449490\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_GetLogicalDrives\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x449490\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x449490\",\n      \"target\": \"api_GetLogicalDrives\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information_via_ioctl__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information_via_ioctl__2_matches_\",\n      \"target\": \"bb_0x40CC8C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information_via_ioctl__2_matches_\",\n      \"target\": \"bb_0x40D5F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"bb_0x40CC8C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"bb_0x40D5F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_size\",\n      \"target\": \"func_0x42A3C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x42A3C0\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x42A3C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x42A3C0\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_storage_device_properties\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_storage_device_properties\",\n      \"target\": \"func_0x40DBA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40DBA0\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40DBA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40DBA0\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_mutex_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_proxy__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_proxy__2_matches_\",\n      \"target\": \"func_0x4178D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_proxy__2_matches_\",\n      \"target\": \"func_0x4183B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4178D0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4178D0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4178D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4183B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4178D0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4178D0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_shutdown_system\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_shutdown_system\",\n      \"target\": \"func_0x434E20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x434E20\",\n      \"target\": \"api_InitiateSystemShutdownEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x434E20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x434E20\",\n      \"target\": \"api_InitiateSystemShutdownEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_system_information_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_system_information_on_windows\",\n      \"target\": \"func_0x4268E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_GetNativeSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x4268E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_GetNativeSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_thread_local_storage_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value\",\n      \"target\": \"func_0x4B24AB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4B24AB\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4B24AB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4B24AB\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__12_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__12_matches_\",\n      \"target\": \"bb_0x4242F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__12_matches_\",\n      \"target\": \"bb_0x42FE3E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__12_matches_\",\n      \"target\": \"bb_0x4543E8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__12_matches_\",\n      \"target\": \"bb_0x44678A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__12_matches_\",\n      \"target\": \"bb_0x439E34\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__12_matches_\",\n      \"target\": \"bb_0x45B05B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__12_matches_\",\n      \"target\": \"bb_0x43A802\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__12_matches_\",\n      \"target\": \"bb_0x42E03A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__12_matches_\",\n      \"target\": \"bb_0x46873C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__12_matches_\",\n      \"target\": \"bb_0x43B4FB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__12_matches_\",\n      \"target\": \"bb_0x44D0E2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__12_matches_\",\n      \"target\": \"bb_0x446756\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4242F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x42FE3E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4543E8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x44678A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x439E34\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x45B05B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x43A802\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x42E03A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x46873C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x43B4FB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x44D0E2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x446756\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_suspended\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_suspended\",\n      \"target\": \"bb_0x4543E8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"bb_0x4543E8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_processes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_processes\",\n      \"target\": \"func_0x455350\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x455350\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x455350\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x455350\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x455350\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x455350\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x455350\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x455350\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_modify_access_privileges__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x49F080\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x49F080\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x49F080\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x49F080\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x49F080\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x49F080\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__4_matches_\",\n      \"target\": \"func_0x4089A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__4_matches_\",\n      \"target\": \"func_0x438810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__4_matches_\",\n      \"target\": \"func_0x4368C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__4_matches_\",\n      \"target\": \"func_0x46EAC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4089A0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438810\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4368C0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4089A0\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438810\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4368C0\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4089A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x438810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4368C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46EAC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4089A0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438810\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4368C0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4089A0\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438810\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4368C0\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"target\": \"func_0x42B480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"target\": \"func_0x46EAC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"target\": \"func_0x4368C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"target\": \"func_0x40A800\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"target\": \"func_0x4178D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"target\": \"func_0x45B790\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"target\": \"func_0x4486E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"target\": \"func_0x4268E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"target\": \"func_0x41B350\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"target\": \"func_0x45A370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"target\": \"func_0x438810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"target\": \"func_0x41B6A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"target\": \"func_0x41B9F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"target\": \"func_0x40E630\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__15_matches_\",\n      \"target\": \"func_0x42BC20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x42B480\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4368C0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A800\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4178D0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B790\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4486E0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B350\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45A370\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438810\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B6A0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B9F0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E630\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42B480\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4368C0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A800\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4178D0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B790\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4486E0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B350\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45A370\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438810\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B6A0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B9F0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E630\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42B480\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4368C0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A800\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4178D0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B790\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4486E0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B350\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45A370\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438810\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B6A0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B9F0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E630\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42B480\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4368C0\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A800\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4178D0\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B790\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4486E0\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B350\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45A370\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438810\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B6A0\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B9F0\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E630\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x42B480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46EAC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4368C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40A800\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4178D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x45B790\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4486E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4268E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41B350\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x45A370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x438810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41B6A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41B9F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40E630\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x42BC20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x42B480\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4368C0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A800\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4178D0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B790\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4486E0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B350\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45A370\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438810\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B6A0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B9F0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E630\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42B480\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4368C0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A800\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4178D0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B790\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4486E0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B350\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45A370\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438810\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B6A0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B9F0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E630\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42B480\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4368C0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A800\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4178D0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B790\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4486E0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B350\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45A370\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438810\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B6A0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B9F0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E630\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42B480\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4368C0\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A800\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4178D0\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B790\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4486E0\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4268E0\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B350\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45A370\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438810\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B6A0\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41B9F0\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E630\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42BC20\",\n      \"target\": \"api_RegGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value__10_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__10_matches_\",\n      \"target\": \"func_0x4354B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__10_matches_\",\n      \"target\": \"func_0x408250\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__10_matches_\",\n      \"target\": \"func_0x45B790\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__10_matches_\",\n      \"target\": \"func_0x450470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__10_matches_\",\n      \"target\": \"func_0x4183B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__10_matches_\",\n      \"target\": \"func_0x408613\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__10_matches_\",\n      \"target\": \"func_0x45B120\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__10_matches_\",\n      \"target\": \"func_0x4506E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__10_matches_\",\n      \"target\": \"func_0x4083F6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__10_matches_\",\n      \"target\": \"func_0x448F90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4354B0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408250\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B790\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x450470\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408613\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B120\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4506E0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4083F6\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448F90\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4354B0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408250\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B790\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x450470\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408613\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B120\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4506E0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4083F6\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448F90\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4354B0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408250\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B790\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x450470\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408613\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B120\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4506E0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4083F6\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448F90\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4354B0\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408250\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B790\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x450470\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408613\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B120\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4506E0\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4083F6\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448F90\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4354B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408250\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x45B790\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x450470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4183B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408613\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x45B120\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4506E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4083F6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x448F90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4354B0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408250\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B790\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x450470\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408613\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B120\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4506E0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4083F6\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448F90\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4354B0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408250\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B790\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x450470\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408613\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B120\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4506E0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4083F6\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448F90\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4354B0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408250\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B790\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x450470\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408613\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B120\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4506E0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4083F6\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448F90\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4354B0\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408250\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B790\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x450470\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408613\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45B120\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4506E0\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4083F6\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448F90\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_key__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key__4_matches_\",\n      \"target\": \"func_0x408E10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key__4_matches_\",\n      \"target\": \"func_0x435840\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key__4_matches_\",\n      \"target\": \"func_0x42A9F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key__4_matches_\",\n      \"target\": \"func_0x408B30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408E10\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x435840\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42A9F0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408B30\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408E10\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x435840\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42A9F0\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408B30\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408E10\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x435840\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42A9F0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408B30\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x408E10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x435840\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x42A9F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x408B30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408E10\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x435840\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42A9F0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408B30\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408E10\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x435840\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42A9F0\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408B30\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408E10\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x435840\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42A9F0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408B30\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value\",\n      \"target\": \"func_0x408E10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408E10\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x408E10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408E10\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_service_status__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_service_status__4_matches_\",\n      \"target\": \"func_0x416C40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_service_status__4_matches_\",\n      \"target\": \"func_0x41AEF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_service_status__4_matches_\",\n      \"target\": \"func_0x42B480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_service_status__4_matches_\",\n      \"target\": \"func_0x4202E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x416C40\",\n      \"target\": \"api_QueryServiceStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41AEF0\",\n      \"target\": \"api_QueryServiceStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42B480\",\n      \"target\": \"api_QueryServiceStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4202E0\",\n      \"target\": \"api_QueryServiceStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x416C40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x41AEF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x42B480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4202E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x416C40\",\n      \"target\": \"api_QueryServiceStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41AEF0\",\n      \"target\": \"api_QueryServiceStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x42B480\",\n      \"target\": \"api_QueryServiceStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4202E0\",\n      \"target\": \"api_QueryServiceStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_service\",\n      \"target\": \"func_0x417480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x417480\",\n      \"target\": \"api_OpenSCManager\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x417480\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x417480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x417480\",\n      \"target\": \"api_OpenSCManager\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x417480\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_service__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_service__2_matches_\",\n      \"target\": \"func_0x416C40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_service__2_matches_\",\n      \"target\": \"func_0x41BD80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x416C40\",\n      \"target\": \"api_DeleteService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41BD80\",\n      \"target\": \"api_DeleteService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x416C40\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41BD80\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x416C40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x41BD80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x416C40\",\n      \"target\": \"api_DeleteService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41BD80\",\n      \"target\": \"api_DeleteService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x416C40\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41BD80\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_start_service__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_start_service__2_matches_\",\n      \"target\": \"func_0x4202E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_start_service__2_matches_\",\n      \"target\": \"func_0x41AB30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4202E0\",\n      \"target\": \"api_StartService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41AB30\",\n      \"target\": \"api_StartService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4202E0\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41AB30\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4202E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x41AB30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4202E0\",\n      \"target\": \"api_StartService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41AB30\",\n      \"target\": \"api_StartService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4202E0\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41AB30\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_stop_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_stop_service\",\n      \"target\": \"func_0x416C40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x416C40\",\n      \"target\": \"api_ControlServiceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x416C40\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x416C40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x416C40\",\n      \"target\": \"api_ControlServiceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x416C40\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_session_information\",\n      \"target\": \"func_0x45C2D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x45C2D0\",\n      \"target\": \"api_WTSQuerySessionInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45C2D0\",\n      \"target\": \"api_WTSFreeMemory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x45C2D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x45C2D0\",\n      \"target\": \"api_WTSQuerySessionInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45C2D0\",\n      \"target\": \"api_WTSFreeMemory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_user_name\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_session_user_name\",\n      \"target\": \"func_0x4183B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_GetUserName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4183B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_GetUserName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_token_membership\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_token_membership\",\n      \"target\": \"func_0x45C540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x45C540\",\n      \"target\": \"api_AllocateAndInitializeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45C540\",\n      \"target\": \"api_CheckTokenMembership\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45C540\",\n      \"target\": \"api_FreeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x45C540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x45C540\",\n      \"target\": \"api_AllocateAndInitializeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45C540\",\n      \"target\": \"api_CheckTokenMembership\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x45C540\",\n      \"target\": \"api_FreeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_installed_programs__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_installed_programs__3_matches_\",\n      \"target\": \"func_0x4368C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_installed_programs__3_matches_\",\n      \"target\": \"func_0x438810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_installed_programs__3_matches_\",\n      \"target\": \"func_0x46EAC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4368C0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438810\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com____re_fox\",\n      \"target\": \"func_0x4368C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com____re_fox\",\n      \"target\": \"func_0x438810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com____re_fox\",\n      \"target\": \"func_0x46EAC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4368C0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438810\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EAC0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread__2_matches_\",\n      \"target\": \"bb_0x44E7DE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__2_matches_\",\n      \"target\": \"bb_0x44C393\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x44E7DE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x44C393\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_thread_local_storage\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_thread_local_storage\",\n      \"target\": \"func_0x4B242D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4B242D\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4B242D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4B242D\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_thread_local_storage_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value\",\n      \"target\": \"func_0x4B24EA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4B24EA\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4B24EA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4B24EA\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_impersonate_user\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_impersonate_user\",\n      \"target\": \"func_0x454270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x454270\",\n      \"target\": \"api_CreateProcessWithToken\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454270\",\n      \"target\": \"api_DuplicateTokenEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454270\",\n      \"target\": \"api_OpenProcessToken\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__99_elad_levi_gmail_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__99_elad_levi_gmail_com\",\n      \"target\": \"func_0x454270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x454270\",\n      \"target\": \"api_CreateProcessWithToken\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454270\",\n      \"target\": \"api_DuplicateTokenEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454270\",\n      \"target\": \"api_OpenProcessToken\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_to_wmi_namespace_via_wbemlocator__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_to_wmi_namespace_via_wbemlocator__6_matches_\",\n      \"target\": \"func_0x40C400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_to_wmi_namespace_via_wbemlocator__6_matches_\",\n      \"target\": \"func_0x40D100\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_to_wmi_namespace_via_wbemlocator__6_matches_\",\n      \"target\": \"func_0x40D560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_to_wmi_namespace_via_wbemlocator__6_matches_\",\n      \"target\": \"func_0x40CBA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_to_wmi_namespace_via_wbemlocator__6_matches_\",\n      \"target\": \"func_0x40C7D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_to_wmi_namespace_via_wbemlocator__6_matches_\",\n      \"target\": \"func_0x40C030\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40C400\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D100\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D560\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40CBA0\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C7D0\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C030\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40C400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40D100\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40D560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40CBA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40C7D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40C030\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40C400\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D100\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D560\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40CBA0\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C7D0\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C030\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_peb_ldr_data__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__5_matches_\",\n      \"target\": \"bb_0x4516F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__5_matches_\",\n      \"target\": \"bb_0x47DDE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__5_matches_\",\n      \"target\": \"bb_0x440910\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__5_matches_\",\n      \"target\": \"bb_0x440CD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__5_matches_\",\n      \"target\": \"bb_0x4412A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4516F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x47DDE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x440910\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x440CD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4412A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_kernel32_base_address__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_kernel32_base_address__2_matches_\",\n      \"target\": \"bb_0x4412A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_kernel32_base_address__2_matches_\",\n      \"target\": \"bb_0x440CD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4412A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x440CD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_ntdll_base_address\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_ntdll_base_address\",\n      \"target\": \"bb_0x47DDE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x47DDE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__16_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__2_matches_\",\n      \"target\": \"func_0x495147\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__2_matches_\",\n      \"target\": \"func_0x4BE290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x495147\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4BE290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"target\": \"func_0x424690\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x424690\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_persist_via_windows_service__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_persist_via_windows_service__2_matches_\",\n      \"target\": \"func_0x417480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_persist_via_windows_service__2_matches_\",\n      \"target\": \"func_0x4183B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x417480\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x417480\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x417480\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x417480\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x417480\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x417480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4183B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x417480\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x417480\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegSetKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x417480\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x417480\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x417480\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4183B0\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-05-15 17:54:36.222753\",\n    \"total_functions\": \"4017\",\n    \"total_features\": \"224537\",\n    \"pdb_path\": \"C:\\\\\\\\Jenkins\\\\\\\\workspace\\\\\\\\MBAM-Windows\\\\\\\\A_MB5_MBSetup\\\\\\\\bin\\\\\\\\Win32\\\\\\\\Release\\\\\\\\MBSet\\nup.pdb\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-05-15 17:54:40"}
{"_id":{"$oid":"6a11b98832de6bb6782baab0"},"sha256":"dccfa4b16aa79e273cc7ffc35493c495a7fd09f92a4b790f2dc41c65f64d5378","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":true,"path":"/tmp/sdm_capa_rumhvgh4/HxDSetup-019f4697afc57a618c20213defc8d8b0.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_rumhvgh4/HxDSetup-019f4697afc57a618c20213defc8d8b0.exe_very_verbose.txt"}},"outputs":{"normal":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"md5                     4f9e75a41d02666cd5cc86bd33a578fe                        \nsha1                    ac08b28e953d7d200bbb3c2e644890a689d0d8b1                \nsha256                  dccfa4b16aa79e273cc7ffc35493c495a7fd09f92a4b790f2dc41c6…\npath                    /home/apogean/projects/malware/windows/all_runs/HxDSetu…\ntimestamp               2026-07-09 16:55:46.461962                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEI4Uyd9d/rules                                   \nfunction count          555                                                     \nlibrary function count  2                                                       \ntotal feature count     59937                                                   \n\nreference analysis tools strings\nnamespace  anti-analysis\nscope      file         \n\nget geographical location (5 matches)\nnamespace  collection\nscope      function  \nmatches    0x405DD4  \n           0x405DE8  \n           0x408EB4  \n           0x408F00  \n           0x40E658  \n\ncompiled with Borland Delphi\nnamespace  compiler/delphi\nscope      file           \n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32\nscope      function                        \nmatches    0x40C6B0                        \n\nencode data using XOR (3 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x40AA4B                      \n           0x40AA4B                      \n           0x40C70D                      \n\ngenerate random numbers using the Delphi LCG\nnamespace  data-manipulation/prng/lcg\nscope      basic block               \nmatches    0x4030E4                  \n\npackaged as an Inno Setup installer\nnamespace  executable/installer/inno-setup\nscope      file                           \n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls\nscope      file                     \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x40EE2C           \n\naccept command line arguments (3 matches)\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x40B84C            \n           0x40B89C            \n           0x40B8FC            \n\nquery environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x40B710                             \n\nget common file path (3 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x40699C                    \n           0x40B9A4                    \n           0x40B9D0                    \n\ncreate directory\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x40E42C                           \n\ndelete directory\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x411CBF                           \n\ndelete file\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x40E180                           \n\ncheck if file exists\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x40E5F4                           \n\nget file attributes\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x40B698                         \n\nclear file content\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x40C410                          \n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x4044F0                          \n           0x4096AC                          \n\nget disk size\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x408068                         \n\nshutdown system\nnamespace  host-interaction/os\nscope      function           \nmatches    0x40E550           \n\nget system information on Windows\nnamespace  host-interaction/os/info\nscope      function                \nmatches    0x40ED58                \n\nget thread local storage value\nnamespace  host-interaction/process\nscope      function                \nmatches    0x406588                \n\ncreate process on Windows\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x40EB68                       \n\ncreate process suspended\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x40EB68                       \n\nallocate or change RWX memory\nnamespace  host-interaction/process/inject\nscope      basic block                    \nmatches    0x40EDB4                       \n\nmodify access privileges\nnamespace  host-interaction/process/modify\nscope      instruction                    \nmatches    0x40E5A6                       \n\nquery or enumerate registry value (4 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x403714                 \n           0x405DD4                 \n           0x405DE8                 \n           0x40BB34                 \n\nset thread local storage value\nnamespace  host-interaction/thread/tls\nscope      function                   \nmatches    0x406544                   \n\nlink function at runtime on Windows (7 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x405C20               \n           0x40674C               \n           0x40676E               \n           0x411112               \n           0x411138               \n           0x4112FA               \n           0x411310               \n\nidentify system language via API\nnamespace  targeting/language\nscope      function          \nmatches    0x40E684          \n\n\n\n","very_verbose":"md5                     4f9e75a41d02666cd5cc86bd33a578fe                        \nsha1                    ac08b28e953d7d200bbb3c2e644890a689d0d8b1                \nsha256                  dccfa4b16aa79e273cc7ffc35493c495a7fd09f92a4b790f2dc41c6…\npath                    /home/apogean/projects/malware/windows/all_runs/HxDSetu…\ntimestamp               2026-07-09 16:56:06.216098                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEICEZ6Yq/rules                                   \nfunction count          555                                                     \nlibrary function count  2                                                       \ntotal feature count     59937                                                   \n\nallocate memory (5 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x4015E4 in function 0x4015E4\n  or:\n    api: VirtualAlloc @ 0x4015FA\n\nallocate or change RW memory (5 matches, only showing first match of library \nrule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x4015E4 in function 0x4015E4\n  and:\n    or:\n      match: allocate memory @ 0x4015E4\n        or:\n          api: VirtualAlloc @ 0x4015FA\n    or:\n      number: 0x4 = PAGE_READWRITE @ 0x4015EC\n\ncalculate modulo 256 via x86 assembly (3 matches, only showing first match of \nlibrary rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x40C70F\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x40C70F\n    or:\n      number: 0xFF @ 0x40C70F\n\nchange memory protection (2 matches, only showing first match of library rule)\nauthor  @mr-tz                                  \nscope   basic block                             \nmbc     Memory::Change Memory Protection [C0008]\nbasic block @ 0x40EDB4 in function 0x40ED58\n  or:\n    api: VirtualProtect @ 0x40EDC2\n\ncontain loop (130 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x40148C\n  or:\n    characteristic: tight loop @ 0x401497\n\ncreate or open file (library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x40C31D\n  or:\n    api: CreateFile @ 0x40C31D\n\ncreate or open registry key (10 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x403714 in function 0x403714\n  or:\n    api: RegOpenKeyEx @ 0x403736\n\ndelay execution (21 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x401670 in function 0x40165C\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x401672\n\nget OS version (2 matches, only showing first match of library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x40A358\n  or:\n    api: GetVersionEx @ 0x40A366\n\nreference analysis tools strings\nnamespace   anti-analysis                                                       \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \nmbc         Discovery::Analysis Tool Discovery::Process detection [B0013.001]   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /(?<!\\w)ida?(\\.exe)?$/i\n    - \")IDA\" @ file+0xEFD6A\n\nget geographical location (5 matches)\nnamespace  collection                                  \nauthor     moritz.raabe, michael.hunhoff@mandiant.com  \nscope      function                                    \natt&ck     Discovery::System Location Discovery [T1614]\nfunction @ 0x405DD4\n  or:\n    api: GetLocaleInfo @ 0x405F46\nfunction @ 0x405DE8\n  or:\n    api: GetLocaleInfo @ 0x405F46\nfunction @ 0x408EB4\n  or:\n    api: GetLocaleInfo @ 0x408ED2\nfunction @ 0x408F00\n  or:\n    api: GetLocaleInfo @ 0x408F13\nfunction @ 0x40E658\n  or:\n    api: GetLocaleInfo @ 0x40E66E\n\ncompiled with Borland Delphi\nnamespace  compiler/delphi                        \nauthor     william.ballenthin@mandiant.com, @mr-tz\nscope      file                                   \nor:\n  substring: SOFTWARE\\Borland\\Delphi\\RTL\n    - \"SOFTWARE\\\\Borland\\\\Delphi\\\\RTL\" @ file+0x2BAC\n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32 \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \nmbc        Data::Checksum::CRC32 [C0032.001]\nfunction @ 0x40C6B0\n  or:\n    and:\n      number: 0x1 = bits in a byte @ 0x40C6BF, 0x40C6C3, 0x40C6CC\n      instruction:\n        and:\n          operand[1].number: 0x1 @ 0x40C6BF\n          or:\n            mnemonic: test @ 0x40C6BF\n      instruction:\n        and:\n          mnemonic: shr @ 0x40C6C3\n          number: 0x1 @ 0x40C6C3\n        and:\n          mnemonic: shr @ 0x40C6CC\n          number: 0x1 @ 0x40C6CC\n      characteristic: nzxor @ 0x40C6C5\n      operand[1].number: 0xEDB88320 @ 0x40C6C5\n\nencode data using XOR (3 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x40AA4B in function 0x40AA03\n  and:\n    characteristic: tight loop @ 0x40AA4B\n    characteristic: nzxor @ 0x40AA5B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x40AA4B in function 0x40AA03\n  and:\n    characteristic: tight loop @ 0x40AA4B\n    characteristic: nzxor @ 0x40AA5B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x40C70D in function 0x40C6E4\n  and:\n    characteristic: tight loop @ 0x40C70D\n    characteristic: nzxor @ 0x40C718, 0x40C728\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\ngenerate random numbers using the Delphi LCG\nnamespace   data-manipulation/prng/lcg                                          \nauthor      william.ballenthin@mandiant.com                                     \nscope       basic block                                                         \nmbc         Cryptography::Generate Pseudo-random Sequence [C0021]               \nreferences  https://en.wikipedia.org/wiki/Linear_congruential_generator,        \n            https://community.osr.com/discussion/130410/generating-random-numbe…\nbasic block @ 0x4030E4 in function 0x4030E4\n  and:\n    instruction:\n      and:\n        mnemonic: imul @ 0x4030E7\n        number: 0x8088405 = multiplier a @ 0x4030E7\n    mnemonic: inc = increment c @ 0x4030F1\n\npackaged as an Inno Setup installer\nnamespace   executable/installer/inno-setup  \nauthor      awillia2@cisco.com               \nscope       file                             \nreferences  https://jrsoftware.org/isinfo.php\nand:\n  regex: /^Inno Setup Setup Data \\(/\n    - \"Inno Setup Setup Data (5.5.7) (u)\" @ file+0x1120C, file+0x2D5F54\n  regex: /^Inno Setup Messages \\(/\n    - \"Inno Setup Messages (5.5.3) (u)\" @ file+0x1124C\n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls   \nauthor     michael.hunhoff@mandiant.com\nscope      file                        \nsection: .tls @ 0x41A000\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x40EE2C\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x40EE5B\n        api: LockResource @ 0x40EE6C\n      optional:\n        or:\n          api: FindResource @ 0x40EE36\n        api: SizeofResource @ 0x40EE49\n\naccept command line arguments (3 matches)\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x40B84C\n  or:\n    api: GetCommandLine @ 0x40B862\nfunction @ 0x40B89C\n  or:\n    api: GetCommandLine @ 0x40B8B1\nfunction @ 0x40B8FC\n  or:\n    api: GetCommandLine @ 0x40B947\n\nquery environment variable\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x40B710\n  or:\n    api: GetEnvironmentVariable @ 0x40B746\n\nget common file path (3 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x40699C\n  or:\n    api: GetSystemDirectory @ 0x4069AF\nfunction @ 0x40B9A4\n  or:\n    api: GetWindowsDirectory @ 0x40B9B7\nfunction @ 0x40B9D0\n  or:\n    api: GetSystemDirectory @ 0x40B9E3\n\ncreate directory\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x40E42C\n  or:\n    api: CreateDirectory @ 0x40E474\n\ndelete directory\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ 0x411CBF\n  or:\n    api: RemoveDirectory @ 0x411E1C\n\ndelete file\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x40E180\n  or:\n    api: DeleteFile @ 0x40E1B7\n\ncheck if file exists\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x40E5F4\n  or:\n    basic block:\n      and:\n        api: GetLastError @ 0x40E636\n        instruction:\n          and:\n            mnemonic: cmp @ 0x40E63B\n            number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x40E63B\n\nget file attributes\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x40B698 in function 0x40B698\n  or:\n    api: GetFileAttributes @ 0x40B6C1\n\nclear file content\nnamespace  host-interaction/file-system/write\nauthor     jakeperalta7                      \nscope      function                          \nmbc        File System::Writes File [C0052]  \nfunction @ 0x40C410\n  and:\n    api: SetEndOfFile @ 0x40C417\n    not:\n      api: SetFilePointer\n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x4044F0\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x40453B\n      or:\n        api: WriteFile @ 0x40452F, 0x40454A\nfunction @ 0x4096AC\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x409763\n      or:\n        api: WriteFile @ 0x409758, 0x409772\n\nget disk size\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ 0x408068\n  or:\n    api: GetDiskFreeSpace @ 0x408089\n\nshutdown system\nnamespace  host-interaction/os                   \nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \natt&ck     Impact::System Shutdown/Reboot [T1529]\nfunction @ 0x40E550\n  or:\n    api: ExitWindowsEx @ 0x40E5BC\n\nget system information on Windows\nnamespace  host-interaction/os/info                       \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com  \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x40ED58\n  and:\n    os: windows\n    or:\n      api: GetSystemInfo @ 0x40ED6B\n\nget thread local storage value\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x406588\n  and:\n    api: TlsGetValue @ 0x4065AD, 0x4065BE\n\ncreate process on Windows\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x40EB68 in function 0x40EB68\n  or:\n    api: CreateProcess @ 0x40EBD8\n\ncreate process suspended\nnamespace   host-interaction/process/create                                     \nauthor      william.ballenthin@mandiant.com, mehunhoff@google.com               \nscope       basic block                                                         \nmbc         Process::Create Process::Create Suspended Process [C0017.003]       \nreferences  https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/an-…\n            https://learn.microsoft.com/en-us/windows/win32/procthread/process-…\nbasic block @ 0x40EB68 in function 0x40EB68\n  or:\n    and:\n      or:\n        number: 0x4 = CREATE_SUSPENDED @ 0x40EB99\n      or:\n        api: CreateProcess @ 0x40EBD8\n\nallocate or change RWX memory\nnamespace  host-interaction/process/inject\nauthor     @mr-tz, mehunhoff@google.com   \nscope      basic block                    \nmbc        Memory::Allocate Memory [C0007]\nbasic block @ 0x40EDB4 in function 0x40ED58\n  or:\n    basic block:\n      and:\n        or:\n          match: change memory protection @ 0x40EDB4\n            or:\n              api: VirtualProtect @ 0x40EDC2\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x40EDB9\n\nmodify access privileges\nnamespace  host-interaction/process/modify                        \nauthor     moritz.raabe@mandiant.com                              \nscope      instruction                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\ninstruction @ 0x40E5A6\n  and:\n    api: AdjustTokenPrivileges @ 0x40E5A6\n\nquery or enumerate registry value (4 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x403714\n  and:\n    optional:\n      match: create or open registry key @ 0x403714\n        or:\n          api: RegOpenKeyEx @ 0x403736\n    or:\n      api: RegQueryValueEx @ 0x403769\nfunction @ 0x405DD4\n  and:\n    optional:\n      match: create or open registry key @ 0x405E24, 0x405E2D, 0x405E4B, 0x405E69\n        or:\n          api: RegOpenKeyEx @ 0x405E7E\n        or:\n          api: RegOpenKeyEx @ 0x405E60\n        or:\n          api: RegOpenKeyEx @ 0x405E24\n        or:\n          api: RegOpenKeyEx @ 0x405E42\n    or:\n      api: RegQueryValueEx @ 0x405EC7, 0x405EE5\nfunction @ 0x405DE8\n  and:\n    optional:\n      match: create or open registry key @ 0x405DE8, 0x405E2D, 0x405E4B, 0x405E69\n        or:\n          api: RegOpenKeyEx @ 0x405E24\n        or:\n          api: RegOpenKeyEx @ 0x405E7E\n        or:\n          api: RegOpenKeyEx @ 0x405E60\n        or:\n          api: RegOpenKeyEx @ 0x405E42\n    or:\n      api: RegQueryValueEx @ 0x405EC7, 0x405EE5\nfunction @ 0x40BB34\n  and:\n    or:\n      api: RegQueryValueEx @ 0x40BB70, 0x40BBE0\n\nset thread local storage value\nnamespace  host-interaction/thread/tls                    \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \nmbc        Process::Set Thread Local Storage Value [C0041]\nfunction @ 0x406544\n  and:\n    api: TlsSetValue @ 0x406581\n\n(internal) installer file limitation\nnamespace    internal/limitation/static                                         \nauthor       william.ballenthin@mandiant.com                                    \nscope        file                                                               \ndescription  This sample appears to be an installer.                            \n                                                                                \n             capa cannot handle installers well. This means the results may be  \n             misleading or incomplete.                                          \n             You should try to understand the install mechanism and analyze     \n             created files with capa.                                           \n                                                                                \nor:\n  match: executable/installer @ global\n    and:\n      regex: /^Inno Setup Setup Data \\(/\n        - \"Inno Setup Setup Data (5.5.7) (u)\" @ file+0x1120C, file+0x2D5F54\n      regex: /^Inno Setup Messages \\(/\n        - \"Inno Setup Messages (5.5.3) (u)\" @ file+0x1124C\n\nlink function at runtime on Windows (7 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x405C20\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x405C20\ninstruction @ 0x40674C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40674C\ninstruction @ 0x40676E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40676E\ninstruction @ 0x411112\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x411112\ninstruction @ 0x411138\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x411138\ninstruction @ 0x4112FA\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4112FA\ninstruction @ 0x411310\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x411310\n\nidentify system language via API\nnamespace  targeting/language                                                   \nauthor     william.ballenthin@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Location Discovery::System Language Discovery      \n           [T1614.001]                                                          \nfunction @ 0x40E684\n  and:\n    os: windows\n    or:\n      api: GetUserDefaultLangID @ 0x40E6E6\n\n\n\n"},"hashes":{"md5":"4f9e75a41d02666cd5cc86bd33a578fe","sha1":"ac08b28e953d7d200bbb3c2e644890a689d0d8b1","sha256":"dccfa4b16aa79e273cc7ffc35493c495a7fd09f92a4b790f2dc41c65f64d5378"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 555</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 59937</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"HxDSetu\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"4f9e75a41d02666cd5cc86bd33a578fe\",\n        \"sha256\": \"dccfa4b16aa79e273cc7ffc35493c495a7fd09f92a4b790f2dc41c6\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_allocate_memory__5_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"allocate memory (5 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4015E4\",\n      \"label\": \"Block 0x4015E4\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4015E4\"\n    },\n    {\n      \"id\": \"api_VirtualAlloc\",\n      \"label\": \"VirtualAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_library_rule_\",\n      \"label\": \"library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Modulo [C0058]\"\n      ]\n    },\n    {\n      \"id\": \"cap_change_memory_protection__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"change memory protection (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Change Memory Protection [C0008]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40EDB4\",\n      \"label\": \"Block 0x40EDB4\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40EDB4\"\n    },\n    {\n      \"id\": \"api_VirtualProtect\",\n      \"label\": \"VirtualProtect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_contain_loop__130_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (130 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x40148C\",\n      \"label\": \"Function 0x40148C\",\n      \"type\": \"function\",\n      \"address\": \"0x40148C\"\n    },\n    {\n      \"id\": \"bb_0x403714\",\n      \"label\": \"Block 0x403714\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x403714\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__21_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (21 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401670\",\n      \"label\": \"Block 0x401670\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401670\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_os_version__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"get OS version (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x40A358\",\n      \"label\": \"Function 0x40A358\",\n      \"type\": \"function\",\n      \"address\": \"0x40A358\"\n    },\n    {\n      \"id\": \"api_GetVersionEx\",\n      \"label\": \"GetVersionEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_reference_analysis_tools_strings\",\n      \"label\": \"reference analysis tools strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_geographical_location__5_matches_\",\n      \"label\": \"get geographical location (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40E658\",\n      \"label\": \"Function 0x40E658\",\n      \"type\": \"function\",\n      \"address\": \"0x40E658\"\n    },\n    {\n      \"id\": \"func_0x408F00\",\n      \"label\": \"Function 0x408F00\",\n      \"type\": \"function\",\n      \"address\": \"0x408F00\"\n    },\n    {\n      \"id\": \"func_0x405DE8\",\n      \"label\": \"Function 0x405DE8\",\n      \"type\": \"function\",\n      \"address\": \"0x405DE8\"\n    },\n    {\n      \"id\": \"func_0x408EB4\",\n      \"label\": \"Function 0x408EB4\",\n      \"type\": \"function\",\n      \"address\": \"0x408EB4\"\n    },\n    {\n      \"id\": \"func_0x405DD4\",\n      \"label\": \"Function 0x405DD4\",\n      \"type\": \"function\",\n      \"address\": \"0x405DD4\"\n    },\n    {\n      \"id\": \"api_GetLocaleInfo\",\n      \"label\": \"GetLocaleInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"cap_compiled_with_borland_delphi\",\n      \"label\": \"compiled with Borland Delphi\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com___mr_tz\",\n      \"label\": \"author     william.ballenthin@mandiant.com, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_hash_data_with_crc32\",\n      \"label\": \"hash data with CRC32\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40C6B0\",\n      \"label\": \"Function 0x40C6B0\",\n      \"type\": \"function\",\n      \"address\": \"0x40C6B0\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_using_the_delphi_lcg\",\n      \"label\": \"generate random numbers using the Delphi LCG\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence [C0021]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4030E4\",\n      \"label\": \"Block 0x4030E4\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4030E4\"\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence [C0021]\"\n      ]\n    },\n    {\n      \"id\": \"cap_packaged_as_an_inno_setup_installer\",\n      \"label\": \"packaged as an Inno Setup installer\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author______awillia2_cisco_com\",\n      \"label\": \"author      awillia2@cisco.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"label\": \"contain a thread local storage (.tls) section\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x40EE2C\",\n      \"label\": \"Function 0x40EE2C\",\n      \"type\": \"function\",\n      \"address\": \"0x40EE2C\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments__3_matches_\",\n      \"label\": \"accept command line arguments (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40B84C\",\n      \"label\": \"Function 0x40B84C\",\n      \"type\": \"function\",\n      \"address\": \"0x40B84C\"\n    },\n    {\n      \"id\": \"func_0x40B8FC\",\n      \"label\": \"Function 0x40B8FC\",\n      \"type\": \"function\",\n      \"address\": \"0x40B8FC\"\n    },\n    {\n      \"id\": \"func_0x40B89C\",\n      \"label\": \"Function 0x40B89C\",\n      \"type\": \"function\",\n      \"address\": \"0x40B89C\"\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable\",\n      \"label\": \"query environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40B710\",\n      \"label\": \"Function 0x40B710\",\n      \"type\": \"function\",\n      \"address\": \"0x40B710\"\n    },\n    {\n      \"id\": \"api_GetEnvironmentVariable\",\n      \"label\": \"GetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path__3_matches_\",\n      \"label\": \"get common file path (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40B9D0\",\n      \"label\": \"Function 0x40B9D0\",\n      \"type\": \"function\",\n      \"address\": \"0x40B9D0\"\n    },\n    {\n      \"id\": \"func_0x40699C\",\n      \"label\": \"Function 0x40699C\",\n      \"type\": \"function\",\n      \"address\": \"0x40699C\"\n    },\n    {\n      \"id\": \"func_0x40B9A4\",\n      \"label\": \"Function 0x40B9A4\",\n      \"type\": \"function\",\n      \"address\": \"0x40B9A4\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory\",\n      \"label\": \"create directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40E42C\",\n      \"label\": \"Function 0x40E42C\",\n      \"type\": \"function\",\n      \"address\": \"0x40E42C\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_directory\",\n      \"label\": \"delete directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x411CBF\",\n      \"label\": \"Function 0x411CBF\",\n      \"type\": \"function\",\n      \"address\": \"0x411CBF\"\n    },\n    {\n      \"id\": \"api_RemoveDirectory\",\n      \"label\": \"RemoveDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_file\",\n      \"label\": \"delete file\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40E180\",\n      \"label\": \"Function 0x40E180\",\n      \"type\": \"function\",\n      \"address\": \"0x40E180\"\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists\",\n      \"label\": \"check if file exists\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40E5F4\",\n      \"label\": \"Function 0x40E5F4\",\n      \"type\": \"function\",\n      \"address\": \"0x40E5F4\"\n    },\n    {\n      \"id\": \"api_GetLastError\",\n      \"label\": \"GetLastError\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_file_attributes\",\n      \"label\": \"get file attributes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40B698\",\n      \"label\": \"Block 0x40B698\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40B698\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_clear_file_content\",\n      \"label\": \"clear file content\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40C410\",\n      \"label\": \"Function 0x40C410\",\n      \"type\": \"function\",\n      \"address\": \"0x40C410\"\n    },\n    {\n      \"id\": \"api_SetEndOfFile\",\n      \"label\": \"SetEndOfFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SetFilePointer\",\n      \"label\": \"SetFilePointer\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____jakeperalta7\",\n      \"label\": \"author     jakeperalta7\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__2_matches_\",\n      \"label\": \"write file on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4096AC\",\n      \"label\": \"Function 0x4096AC\",\n      \"type\": \"function\",\n      \"address\": \"0x4096AC\"\n    },\n    {\n      \"id\": \"func_0x4044F0\",\n      \"label\": \"Function 0x4044F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4044F0\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_disk_size\",\n      \"label\": \"get disk size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408068\",\n      \"label\": \"Function 0x408068\",\n      \"type\": \"function\",\n      \"address\": \"0x408068\"\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpace\",\n      \"label\": \"GetDiskFreeSpace\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_shutdown_system\",\n      \"label\": \"shutdown system\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::System Shutdown/Reboot [T1529]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40E550\",\n      \"label\": \"Function 0x40E550\",\n      \"type\": \"function\",\n      \"address\": \"0x40E550\"\n    },\n    {\n      \"id\": \"api_ExitWindowsEx\",\n      \"label\": \"ExitWindowsEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_system_information_on_windows\",\n      \"label\": \"get system information on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40ED58\",\n      \"label\": \"Function 0x40ED58\",\n      \"type\": \"function\",\n      \"address\": \"0x40ED58\"\n    },\n    {\n      \"id\": \"api_GetSystemInfo\",\n      \"label\": \"GetSystemInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_thread_local_storage_value\",\n      \"label\": \"get thread local storage value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x406588\",\n      \"label\": \"Function 0x406588\",\n      \"type\": \"function\",\n      \"address\": \"0x406588\"\n    },\n    {\n      \"id\": \"api_TlsGetValue\",\n      \"label\": \"TlsGetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_process_on_windows\",\n      \"label\": \"create process on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40EB68\",\n      \"label\": \"Block 0x40EB68\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40EB68\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_create_process_suspended\",\n      \"label\": \"create process suspended\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process::Create Suspended Process [C0017.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process::Create Suspended Process [C0017.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_allocate_or_change_rwx_memory\",\n      \"label\": \"allocate or change RWX memory\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"label\": \"author     @mr-tz, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_modify_access_privileges\",\n      \"label\": \"modify access privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"api_AdjustTokenPrivileges\",\n      \"label\": \"AdjustTokenPrivileges\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"label\": \"query or enumerate registry value (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x403714\",\n      \"label\": \"Function 0x403714\",\n      \"type\": \"function\",\n      \"address\": \"0x403714\"\n    },\n    {\n      \"id\": \"func_0x40BB34\",\n      \"label\": \"Function 0x40BB34\",\n      \"type\": \"function\",\n      \"address\": \"0x40BB34\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_thread_local_storage_value\",\n      \"label\": \"set thread local storage value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Set Thread Local Storage Value [C0041]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x406544\",\n      \"label\": \"Function 0x406544\",\n      \"type\": \"function\",\n      \"address\": \"0x406544\"\n    },\n    {\n      \"id\": \"api_TlsSetValue\",\n      \"label\": \"TlsSetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap__internal__installer_file_limitation\",\n      \"label\": \"(internal) installer file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__7_matches_\",\n      \"label\": \"link function at runtime on Windows (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_identify_system_language_via_api\",\n      \"label\": \"identify system language via API\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery::System Language Discovery\",\n        \"[T1614.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40E684\",\n      \"label\": \"Function 0x40E684\",\n      \"type\": \"function\",\n      \"address\": \"0x40E684\"\n    },\n    {\n      \"id\": \"api_GetUserDefaultLangID\",\n      \"label\": \"GetUserDefaultLangID\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_memory__5_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_memory__5_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x4015E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x4015E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_change_memory_protection__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_change_memory_protection__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x40EDB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__130_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__130_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x40148C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x403714\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__21_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__21_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x401670\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_os_version__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x40A358\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A358\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_analysis_tools_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_geographical_location__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__5_matches_\",\n      \"target\": \"func_0x40E658\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__5_matches_\",\n      \"target\": \"func_0x408F00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__5_matches_\",\n      \"target\": \"func_0x405DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__5_matches_\",\n      \"target\": \"func_0x408EB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__5_matches_\",\n      \"target\": \"func_0x405DD4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E658\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408F00\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DE8\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408EB4\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DD4\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40E658\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408F00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408EB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405DD4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E658\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408F00\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DE8\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408EB4\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DD4\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_with_borland_delphi\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_crc32\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_with_crc32\",\n      \"target\": \"func_0x40C6B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x40C6B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_using_the_delphi_lcg\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_the_delphi_lcg\",\n      \"target\": \"bb_0x4030E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"bb_0x4030E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_packaged_as_an_inno_setup_installer\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______awillia2_cisco_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x40EE2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40EE2C\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EE2C\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EE2C\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EE2C\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40EE2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40EE2C\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EE2C\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EE2C\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EE2C\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__3_matches_\",\n      \"target\": \"func_0x40B84C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__3_matches_\",\n      \"target\": \"func_0x40B8FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__3_matches_\",\n      \"target\": \"func_0x40B89C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40B84C\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B8FC\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B89C\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B84C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B8FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B89C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40B84C\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B8FC\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B89C\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable\",\n      \"target\": \"func_0x40B710\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40B710\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x40B710\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40B710\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x40B9D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x40699C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x40B9A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40B9D0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40699C\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B9A4\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B9D0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40699C\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B9A4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B9D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40699C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B9A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40B9D0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40699C\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B9A4\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B9D0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40699C\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B9A4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory\",\n      \"target\": \"func_0x40E42C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E42C\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40E42C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E42C\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_directory\",\n      \"target\": \"func_0x411CBF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x411CBF\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x411CBF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x411CBF\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file\",\n      \"target\": \"func_0x40E180\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E180\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40E180\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E180\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists\",\n      \"target\": \"func_0x40E5F4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E5F4\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40E5F4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E5F4\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes\",\n      \"target\": \"bb_0x40B698\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40B698\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_clear_file_content\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_clear_file_content\",\n      \"target\": \"func_0x40C410\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40C410\",\n      \"target\": \"api_SetEndOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C410\",\n      \"target\": \"api_SetFilePointer\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____jakeperalta7\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____jakeperalta7\",\n      \"target\": \"func_0x40C410\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40C410\",\n      \"target\": \"api_SetEndOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C410\",\n      \"target\": \"api_SetFilePointer\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x4096AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x4044F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4096AC\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4044F0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4096AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4044F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4096AC\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4044F0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_size\",\n      \"target\": \"func_0x408068\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408068\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x408068\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408068\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_shutdown_system\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_shutdown_system\",\n      \"target\": \"func_0x40E550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E550\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40E550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E550\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_system_information_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_system_information_on_windows\",\n      \"target\": \"func_0x40ED58\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40ED58\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x40ED58\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40ED58\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_thread_local_storage_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value\",\n      \"target\": \"func_0x406588\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406588\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x406588\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406588\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows\",\n      \"target\": \"bb_0x40EB68\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x40EB68\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_suspended\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_suspended\",\n      \"target\": \"bb_0x40EB68\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"bb_0x40EB68\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_or_change_rwx_memory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory\",\n      \"target\": \"bb_0x40EDB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x40EDB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_modify_access_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"target\": \"func_0x403714\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"target\": \"func_0x40BB34\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"target\": \"func_0x405DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"target\": \"func_0x405DD4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403714\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BB34\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DE8\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DD4\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403714\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BB34\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DE8\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DD4\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403714\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40BB34\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405DD4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403714\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BB34\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DE8\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DD4\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403714\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BB34\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DE8\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DD4\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_thread_local_storage_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value\",\n      \"target\": \"func_0x406544\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406544\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x406544\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406544\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal__installer_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_identify_system_language_via_api\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_identify_system_language_via_api\",\n      \"target\": \"func_0x40E684\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E684\",\n      \"target\": \"api_GetUserDefaultLangID\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40E684\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E684\",\n      \"target\": \"api_GetUserDefaultLangID\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 16:56:06.216098\",\n    \"total_functions\": \"555\",\n    \"total_features\": \"59937\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 16:56:07"}
{"_id":{"$oid":"6a131bac32de6bb6782baac3"},"sha256":"a14055e8b09fd980e82a3eb551fe7ca60018b5486d46e462fda29ee88f252ca0","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_dswg4lxd/BrowsingHistoryView-019e5a9f39047902b64b76f6e25fc509.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_dswg4lxd/BrowsingHistoryView-019e5a9f39047902b64b76f6e25fc509.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_dswg4lxd/BrowsingHistoryView-019e5a9f39047902b64b76f6e25fc509.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 0f5aba101aa4d94be74690aa60bf7840                                  │\n│ sha1     │ 40557e751e76b1f9608c2d0c12ce0cccd2588e11                          │\n│ sha256   │ a14055e8b09fd980e82a3eb551fe7ca60018b5486d46e462fda29ee88f252ca0  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/BrowsingHistoryV… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Clipboard Data [T1115]                                │\n│                      │ Data from Information Repositories [T1213]            │\n│                      │ Input Capture::Keylogging [T1056.001]                 │\n│ DEFENSE EVASION      │ Hide Artifacts::Hidden Window [T1564.003]             │\n│                      │ Obfuscated Files or Information [T1027]               │\n│ DISCOVERY            │ Application Window Discovery [T1010]                  │\n│                      │ File and Directory Discovery [T1083]                  │\n│                      │ Process Discovery [T1057]                             │\n│                      │ Query Registry [T1012]                                │\n│                      │ Software Discovery [T1518]                            │\n│                      │ System Information Discovery [T1082]                  │\n│ EXECUTION            │ Shared Modules [T1129]                                │\n│ PERSISTENCE          │ Boot or Logon Autostart Execution::Registry Run Keys  │\n│                      │ / Startup Folder [T1547.001]                          │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Debugger Detection::Timing/Delay Check            │\n│                          │ GetTickCount [B0001.032]                          │\n│ COLLECTION               │ Keylogging::Polling [F0002.002]                   │\n│ DATA                     │ Check String [C0019]                              │\n│                          │ Encode Data::XOR [C0026.002]                      │\n│ DEFENSE EVASION          │ Obfuscated Files or                               │\n│                          │ Information::Encoding-Standard Algorithm          │\n│                          │ [E1027.m02]                                       │\n│                          │ Obfuscated Files or                               │\n│                          │ Information::Encryption-Standard Algorithm        │\n│                          │ [E1027.m05]                                       │\n│ DISCOVERY                │ Application Window Discovery [E1010]              │\n│                          │ Code Discovery::Enumerate PE Sections [B0046.001] │\n│                          │ File and Directory Discovery [E1083]              │\n│                          │ System Information Discovery [E1082]              │\n│ FILE SYSTEM              │ Copy File [C0045]                                 │\n│                          │ Delete File [C0047]                               │\n│                          │ Get File Attributes [C0049]                       │\n│                          │ Read File [C0051]                                 │\n│                          │ Writes File [C0052]                               │\n│ IMPACT                   │ Clipboard Modification [E1510]                    │\n│ OPERATING SYSTEM         │ Registry::Query Registry Value [C0036.006]        │\n│                          │ Registry::Set Registry Key [C0036.001]            │\n│ PERSISTENCE              │ Registry Run Keys / Startup Folder [F0012]        │\n│ PROCESS                  │ Create Process [C0017]                            │\n│                          │ Create Thread [C0038]                             │\n│                          │ Terminate Process [C0018]                         │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ check for time delay via GetTickCount │ anti-analysis/anti-debugging/debugg… │\n│ parse credit card information         │ collection/credit-card               │\n│ reference SQL statements (2 matches)  │ collection/database/sql              │\n│ log keystrokes via polling (2         │ collection/keylog                    │\n│ matches)                              │                                      │\n│ encode data using XOR (6 matches)     │ data-manipulation/encoding/xor       │\n│ encrypt data using speck              │ data-manipulation/encryption/speck   │\n│ extract resource via kernel32         │ executable/resource                  │\n│ functions                             │                                      │\n│ write clipboard data (3 matches)      │ host-interaction/clipboard           │\n│ query environment variable (2         │ host-interaction/environment-variab… │\n│ matches)                              │                                      │\n│ get common file path (9 matches)      │ host-interaction/file-system         │\n│ get file system object information    │ host-interaction/file-system         │\n│ copy file (2 matches)                 │ host-interaction/file-system/copy    │\n│ delete file (5 matches)               │ host-interaction/file-system/delete  │\n│ check if file exists (7 matches)      │ host-interaction/file-system/exists  │\n│ enumerate files on Windows            │ host-interaction/file-system/files/… │\n│ get file attributes (23 matches)      │ host-interaction/file-system/meta    │\n│ get file version info                 │ host-interaction/file-system/meta    │\n│ read .ini file (5 matches)            │ host-interaction/file-system/read    │\n│ read file on Windows (13 matches)     │ host-interaction/file-system/read    │\n│ read file via mapping                 │ host-interaction/file-system/read    │\n│ write file on Windows (17 matches)    │ host-interaction/file-system/write   │\n│ enumerate gui resources               │ host-interaction/gui                 │\n│ get graphical window text (2 matches) │ host-interaction/gui/window/get-text │\n│ hide graphical window (4 matches)     │ host-interaction/gui/window/hide     │\n│ get disk information                  │ host-interaction/hardware/storage    │\n│ enumerate internet cache              │ host-interaction/internet/cache      │\n│ check OS version                      │ host-interaction/os/version          │\n│ create process on Windows (5 matches) │ host-interaction/process/create      │\n│ enumerate processes                   │ host-interaction/process/list        │\n│ terminate process                     │ host-interaction/process/terminate   │\n│ query or enumerate registry value (4  │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ set registry value                    │ host-interaction/registry/create     │\n│ create thread                         │ host-interaction/thread/create       │\n│ link function at runtime on Windows   │ linking/runtime-linking              │\n│ (36 matches)                          │                                      │\n│ link many functions at runtime (4     │ linking/runtime-linking              │\n│ matches)                              │                                      │\n│ linked against sqlite3                │ linking/static/sqlite3               │\n│ enumerate PE sections (3 matches)     │ load-code/pe                         │\n│ parse PE header                       │ load-code/pe                         │\n│ resolve function by parsing PE        │ load-code/pe                         │\n│ exports (28 matches)                  │                                      │\n│ persist via Run registry key (3       │ persistence/registry/run             │\n│ matches)                              │                                      │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     0f5aba101aa4d94be74690aa60bf7840                        \nsha1                    40557e751e76b1f9608c2d0c12ce0cccd2588e11                \nsha256                  a14055e8b09fd980e82a3eb551fe7ca60018b5486d46e462fda29ee…\npath                    /home/apogean/projects/malware/windows/all_runs/Browsin…\ntimestamp               2026-05-24 21:08:35.534989                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIGiuBUG/rules                                   \nfunction count          1623                                                    \nlibrary function count  11                                                      \ntotal feature count     118065                                                  \n\ncheck for time delay via GetTickCount\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    0x4750E0                                       \n\nparse credit card information\nnamespace  collection/credit-card\nscope      function              \nmatches    0x439DD0              \n\nreference SQL statements (2 matches)\nnamespace  collection/database/sql\nscope      function               \nmatches    0x45E8B0               \n           0x45EE50               \n\nlog keystrokes via polling (2 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    0x46F590         \n           0x4741C0         \n\nencode data using XOR (6 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x4659F1                      \n           0x467600                      \n           0x467B22                      \n           0x467BD7                      \n           0x468920                      \n           0x487D70                      \n\nencrypt data using speck\nnamespace  data-manipulation/encryption/speck\nscope      function                          \nmatches    0x45EE50                          \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x465A20           \n\nopen clipboard (3 matches)\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x46E560                  \n           0x46ECC0                  \n           0x476940                  \n\nwrite clipboard data (3 matches)\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x476940                  \n           0x47A390                  \n           0x47B5A0                  \n\nquery environment variable (2 matches)\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x46E0B0                             \n           0x482B00                             \n\nget common file path (9 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x46B6F0                    \n           0x46E0B0                    \n           0x46ECC0                    \n           0x46ED80                    \n           0x471C90                    \n           0x479D70                    \n           0x479DC0                    \n           0x47A0E0                    \n           0x481F50                    \n\nget file system object information\nnamespace  host-interaction/file-system\nscope      basic block                 \nmatches    0x471CBE                    \n\ncopy file (2 matches)\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    0x46B6F0                         \n           0x481F50                         \n\ndelete file (5 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x46B6F0                           \n           0x46EA60                           \n           0x46ECC0                           \n           0x477A20                           \n           0x481F50                           \n\ncheck if file exists (7 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x46BA40                           \n           0x475A80                           \n           0x479FC0                           \n           0x47E0B0                           \n           0x4841A0                           \n           0x484310                           \n           0x4890E0                           \n\nenumerate files on Windows\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x478A40                               \n\nget file attributes (23 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x46BA40                         \n           0x46F114                         \n           0x475A80                         \n           0x479FC0                         \n           0x47E16A                         \n           0x48422E                         \n           0x484407                         \n           0x48445C                         \n           0x4844C8                         \n           0x484534                         \n           0x4845A4                         \n           0x484618                         \n           0x484678                         \n           0x4846E4                         \n           0x484750                         \n           0x4848A0                         \n           0x484CD3                         \n           0x484D68                         \n           0x485092                         \n           0x485433                         \n           0x4855FA                         \n           0x4896E2                         \n           0x489776                         \n\nget file size (5 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x465EB0                         \n           0x477380                         \n           0x477E40                         \n           0x47B5A0                         \n           0x486890                         \n\nget file version info\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x488410                         \n\nread .ini file (5 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x466940                         \n           0x466A20                         \n           0x475630                         \n           0x4756B0                         \n           0x475A80                         \n\nread file on Windows (13 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x465EB0                         \n           0x477590                         \n           0x477850                         \n           0x477CA0                         \n           0x477E40                         \n           0x47B5A0                         \n           0x47C090                         \n           0x47C1A0                         \n           0x47C640                         \n           0x47CA10                         \n           0x47CB10                         \n           0x47CC50                         \n           0x486890                         \n\nread file via mapping\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x477380                         \n\nwrite file on Windows (17 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x470860                          \n           0x4708E0                          \n           0x470F80                          \n           0x472220                          \n           0x472570                          \n           0x472640                          \n           0x4727D0                          \n           0x472C00                          \n           0x472E90                          \n           0x472FB0                          \n           0x4737C0                          \n           0x473A20                          \n           0x474520                          \n           0x474770                          \n           0x474960                          \n           0x477380                          \n           0x48113A                          \n\nenumerate gui resources\nnamespace  host-interaction/gui\nscope      function            \nmatches    0x46F2B0            \n\nget graphical window text (2 matches)\nnamespace  host-interaction/gui/window/get-text\nscope      function                            \nmatches    0x4761B0                            \n           0x4764B0                            \n\nhide graphical window (4 matches)\nnamespace  host-interaction/gui/window/hide\nscope      basic block                     \nmatches    0x46CA70                        \n           0x46E543                        \n           0x46F135                        \n           0x487EB7                        \n\nget disk information\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x477380                         \n\nenumerate internet cache\nnamespace  host-interaction/internet/cache\nscope      function                       \nmatches    0x476ED0                       \n\ncheck OS version\nnamespace  host-interaction/os/version\nscope      function                   \nmatches    0x485840                   \n\ncreate process on Windows (5 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x46E32C                       \n           0x46F5BD                       \n           0x470344                       \n           0x470395                       \n           0x479A00                       \n\nenumerate processes\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    0x46A230                     \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x40193E                          \n\nquery or enumerate registry value (4 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x4667E0                 \n           0x4781D0                 \n           0x485840                 \n           0x4890E0                 \n\nset registry value\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x4667E0                        \n\ncreate thread\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x41154B                      \n\nlink function at runtime on Windows (36 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x469E68               \n           0x469E79               \n           0x469E8A               \n           0x469E9B               \n           0x469EAC               \n           0x46A359               \n           0x46A367               \n           0x46A375               \n           0x46A383               \n           0x46A391               \n           0x46A3F1               \n           0x46A44C               \n           0x46A87C               \n           0x46A88D               \n           0x46A89E               \n           0x46A8AF               \n           0x46A8C0               \n           0x46AABA               \n           0x46AACC               \n           0x46AADF               \n           0x46AAF2               \n           0x46AB04               \n           0x46AB17               \n           0x46AB2A               \n           0x46AB3C               \n           0x46F2F6               \n           0x47821C               \n           0x47A90F               \n           0x47A96F               \n           0x47FBA1               \n           0x485920               \n           0x485AF0               \n           0x48914A               \n           0x48926F               \n           0x489390               \n           0x4894A6               \n\nlink many functions at runtime (4 matches)\nnamespace  linking/runtime-linking\nscope      function               \nmatches    0x469E40               \n           0x46A230               \n           0x46A850               \n           0x46AA90               \n\nlinked against sqlite3\nnamespace  linking/static/sqlite3\nscope      file                  \n\nenumerate PE sections (3 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x42DF60    \n           0x4484F0    \n           0x449830    \n\nparse PE header\nnamespace  load-code/pe\nscope      function    \nmatches    0x40193E    \n\nresolve function by parsing PE exports (28 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x4274A0    \n           0x42D080    \n           0x43A8C0    \n           0x43B060    \n           0x43C8A0    \n           0x43D170    \n           0x43E5D0    \n           0x445080    \n           0x4471E0    \n           0x448790    \n           0x449830    \n           0x44FAD0    \n           0x451A00    \n           0x451C10    \n           0x452260    \n           0x453200    \n           0x453BB0    \n           0x456FA0    \n           0x458770    \n           0x45A790    \n           0x45B320    \n           0x45EE50    \n           0x4693D0    \n           0x46B010    \n           0x46DA50    \n           0x481F50    \n           0x482C10    \n           0x484310    \n\npersist via Run registry key (3 matches)\nnamespace  persistence/registry/run\nscope      function                \nmatches    0x4781D0                \n           0x485840                \n           0x4890E0                \n\n\n\n","very_verbose":"md5                     0f5aba101aa4d94be74690aa60bf7840                        \nsha1                    40557e751e76b1f9608c2d0c12ce0cccd2588e11                \nsha256                  a14055e8b09fd980e82a3eb551fe7ca60018b5486d46e462fda29ee…\npath                    /home/apogean/projects/malware/windows/all_runs/Browsin…\ntimestamp               2026-05-24 21:09:20.973471                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEI8A7jGf/rules                                   \nfunction count          1623                                                    \nlibrary function count  11                                                      \ntotal feature count     118065                                                  \n\ncalculate modulo 256 via x86 assembly (24 matches, only showing first match of \nlibrary rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x4053A2\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x4053A2\n    or:\n      number: 0xFF @ 0x4053A2\n\ncontain loop (747 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x4014A0\n  or:\n    characteristic: loop @ 0x4014A0\n\ncreate or open file (12 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x465ED9\n  or:\n    api: CreateFile @ 0x465ED9\n\ncreate or open registry key (6 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x478260 in function 0x4781D0\n  or:\n    api: RegOpenKeyEx @ 0x478293\n\nget OS version (5 matches, only showing first match of library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x46A5E0\n  or:\n    api: GetVersionEx @ 0x46A60C\n\nopen process (4 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org           \nscope   basic block                  \nmbc     Process::Open Process [C0065]\nbasic block @ 0x46A2B0 in function 0x46A230\n  or:\n    api: OpenProcess @ 0x46A30D\n\ncheck for time delay via GetTickCount\nnamespace  anti-analysis/anti-debugging/debugger-detection                      \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check     \n           GetTickCount [B0001.032]                                             \nfunction @ 0x4750E0\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x47514B\n        mnemonic: cmp @ 0x47514F\n    count(api(GetTickCount)): 2 or more @ 0x4750E6, 0x475145\n\nparse credit card information\nnamespace  collection/credit-card    \nauthor     @_re_fox                  \nscope      function                  \nmbc        Data::Check String [C0019]\nfunction @ 0x439DD0\n  and:\n    not: = if a function also compares these non-hex characters it's most likely NOT \nparsing CC data\n      and:\n        match: parse credit card information/efff727f6e2f4f8da22050885c920578\n        match: parse credit card information/9d69217cd41f45bda65f68dc58eba594\n        match: parse credit card information/7e601cb3a1fe4ac693b83e4540bae902\n        match: parse credit card information/af277ea9d2704e6a9db43fc05a4d9459\n    3 or more:\n      instruction:\n        and:\n          mnemonic: cmp @ 0x43A0F9\n          number: 0x3D = '=' (Track 2 separator) @ 0x43A0F9\n        and:\n          mnemonic: cmp @ 0x43A0BD\n          number: 0x3D = '=' (Track 2 separator) @ 0x43A0BD\n      instruction:\n        and:\n          mnemonic: cmp @ 0x43A038\n          number: 0x25 = '%' (Track 1 start sentinel) @ 0x43A038\n      instruction:\n        and:\n          mnemonic: cmp @ 0x43A0B4\n          number: 0x3F = '?' (Track 1 & 2 end sentinel) @ 0x43A0B4\n        and:\n          mnemonic: cmp @ 0x43A145\n          number: 0x3F = '?' (Track 1 & 2 end sentinel) @ 0x43A145\n\nreference SQL statements (2 matches)\nnamespace  collection/database/sql                               \nauthor     william.ballenthin@mandiant.com                       \nscope      function                                              \natt&ck     Collection::Data from Information Repositories [T1213]\nfunction @ 0x45E8B0\n  and:\n    regex: /SELECT.*FROM.*WHERE/\n      - \"INSERT INTO vacuum_db.sqlite_master SELECT*FROM \\\"%w\\\".sqlite_master WHERE type\nIN('view','trigger') OR(type='table'AND rootpage=0)\" @ 0x45ED0C\n      - \"SELECT sql FROM \\\"%w\\\".sqlite_master WHERE type='index' AND length(sql)>10\" @ 0x45ECBF\n      - \"SELECT sql FROM \\\"%w\\\".sqlite_master WHERE type='table'AND \nname<>'sqlite_sequence' AND coalesce(rootpage,1)>0\" @ 0x45EC9F\n      - \"SELECT'INSERT INTO vacuum_db.'||quote(name)||' \nSELECT*FROM\\\"%w\\\".'||quote(name)FROM vacuum_db.sqlite_master WHERE \ntype='table'AND coalesce(rootpage,1)>0\" @ 0x45ECE5\nfunction @ 0x45EE50\n  and:\n    regex: /SELECT.*FROM.*WHERE/\n      - \"SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid\" @ 0x462664\n\nlog keystrokes via polling (2 matches)\nnamespace  collection/keylog                                \nauthor     michael.hunhoff@mandiant.com                     \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nmbc        Collection::Keylogging::Polling [F0002.002]      \nfunction @ 0x46F590\n  or:\n    api: GetKeyState @ 0x46F788\nfunction @ 0x4741C0\n  or:\n    api: GetKeyState @ 0x4741E5\n\nencode data using XOR (6 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x4659F1 in function 0x4659E0\n  and:\n    characteristic: tight loop @ 0x4659F1\n    characteristic: nzxor @ 0x465A09\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x467600 in function 0x4675E0\n  and:\n    characteristic: tight loop @ 0x467600\n    characteristic: nzxor @ 0x46760D\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x467B22 in function 0x467AB0\n  and:\n    characteristic: tight loop @ 0x467B22\n    characteristic: nzxor @ 0x467B39, 0x467B3D\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x467BD7 in function 0x467B80\n  and:\n    characteristic: tight loop @ 0x467BD7\n    characteristic: nzxor @ 0x467BEE, 0x467BF2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x468920 in function 0x468670\n  and:\n    characteristic: tight loop @ 0x468920\n    characteristic: nzxor @ 0x46892D\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x487D70 in function 0x487D60\n  and:\n    characteristic: tight loop @ 0x487D70\n    characteristic: nzxor @ 0x487D70, 0x487D7D\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nencrypt data using speck\nnamespace   data-manipulation/encryption/speck                                  \nauthor      still@teamt5.org                                                    \nscope       function                                                            \natt&ck      Defense Evasion::Obfuscated Files or Information [T1027]            \nmbc         Defense Evasion::Obfuscated Files or                                \n            Information::Encryption-Standard Algorithm [E1027.m05]              \nreferences  https://github.com/maxmouchet/gfc/blob/8d818b0fe2023c92cbf8d7eb8967…\n            https://github.com/TheWover/donut/blob/47758d787209dd1744f58c140102…\nfunction @ 0x45EE50\n  and:\n    match: contain loop @ 0x45EE50\n      or:\n        characteristic: loop @ 0x45EE50\n        characteristic: tight loop @ 0x45F1F0, 0x45F875, 0x460660, 0x4606E1, and 5 more...\n    instruction:\n      and:\n        mnemonic: cmp @ 0x463C49\n        or:\n          number: 0x1A = encryption loop @ 0x463C49\n      and:\n        mnemonic: cmp @ 0x4615A1\n        or:\n          number: 0x1A = encryption loop @ 0x4615A1\n      and:\n        mnemonic: cmp @ 0x4634AB\n        or:\n          number: 0x1A = encryption loop @ 0x4634AB\n    instruction:\n      and:\n        mnemonic: cmp @ 0x45F5C0\n        or:\n          number: 0x3 = master key copy loop @ 0x45F5C0\n      and:\n        mnemonic: cmp @ 0x463620\n        or:\n          number: 0x4 = master key copy loop @ 0x463620\n      and:\n        mnemonic: cmp @ 0x45F604\n        or:\n          number: 0x3 = master key copy loop @ 0x45F604\n      and:\n        mnemonic: cmp @ 0x462ECC\n        or:\n          number: 0x3 = master key copy loop @ 0x462ECC\n      and:\n        mnemonic: cmp @ 0x462F8D\n        or:\n          number: 0x4 = master key copy loop @ 0x462F8D\n      and:\n        mnemonic: cmp @ 0x4601AE\n        or:\n          number: 0x3 = master key copy loop @ 0x4601AE\n      and:\n        mnemonic: cmp @ 0x45F096\n        or:\n          number: 0x4 = master key copy loop @ 0x45F096\n      and:\n        mnemonic: cmp @ 0x45FD5E\n        or:\n          number: 0x4 = master key copy loop @ 0x45FD5E\n    count(characteristic(nzxor)): 2 or more @ 0x45FD02, 0x45FD0D, 0x45FD33, 0x45FD3E, and 2 more...\n    2 or more:\n      mnemonic: shl @ 0x460C88, 0x460D66, 0x460DC0, 0x460E02, and 11 more...\n      mnemonic: imul @ 0x45EF12, 0x45EFE9, 0x45F039, 0x45F81E, and 7 more...\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x465A20\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x465A4E\n        api: LockResource @ 0x465A59\n      optional:\n        or:\n          api: FindResource @ 0x465A31\n        api: SizeofResource @ 0x465A40\n\nopen clipboard (3 matches)\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ 0x46E560\n  and:\n    api: OpenClipboard @ 0x46E5C9\nfunction @ 0x46ECC0\n  and:\n    api: OpenClipboard @ 0x46ED34\nfunction @ 0x476940\n  and:\n    api: OpenClipboard @ 0x47695A\n    optional:\n      api: CloseClipboard @ 0x4769DF\n\nwrite clipboard data (3 matches)\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \nmbc         Impact::Clipboard Modification [E1510]                              \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ 0x476940\n  and:\n    optional:\n      match: open clipboard @ 0x476940\n        and:\n          api: OpenClipboard @ 0x47695A\n          optional:\n            api: CloseClipboard @ 0x4769DF\n      api: EmptyClipboard @ 0x476968\n    or:\n      api: SetClipboardData @ 0x4769D9\nfunction @ 0x47A390\n  and:\n    optional:\n      api: EmptyClipboard @ 0x47A398\n    or:\n      api: SetClipboardData @ 0x47A3EA\nfunction @ 0x47B5A0\n  and:\n    optional:\n      api: EmptyClipboard @ 0x47B5AC\n    or:\n      api: SetClipboardData @ 0x47B62A\n\nquery environment variable (2 matches)\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x46E0B0\n  or:\n    api: ExpandEnvironmentStrings @ 0x46E18E\nfunction @ 0x482B00\n  or:\n    api: ExpandEnvironmentStrings @ 0x482BC2\n\nget common file path (9 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x46B6F0\n  or:\n    api: GetTempPath @ 0x46B807\n    api: GetTempFileName @ 0x46B845\n    api: GetWindowsDirectory @ 0x46B81E\nfunction @ 0x46E0B0\n  or:\n    api: GetCurrentDirectory @ 0x46E1F4\nfunction @ 0x46ECC0\n  or:\n    api: GetTempPath @ 0x46ECD3\n    api: GetTempFileName @ 0x46ED0A\n    api: GetWindowsDirectory @ 0x46ECEA\nfunction @ 0x46ED80\n  or:\n    api: GetTempPath @ 0x46F12F\nfunction @ 0x471C90\n  or:\n    api: GetWindowsDirectory @ 0x471CFA\nfunction @ 0x479D70\n  or:\n    api: GetSystemDirectory @ 0x479D84\nfunction @ 0x479DC0\n  or:\n    api: GetWindowsDirectory @ 0x479DD4\nfunction @ 0x47A0E0\n  or:\n    api: GetTempPath @ 0x47A0EF\n    api: GetTempFileName @ 0x47A11E\n    api: GetWindowsDirectory @ 0x47A103\nfunction @ 0x481F50\n  or:\n    api: GetTempPath @ 0x482080\n    api: GetTempFileName @ 0x4820BE\n    api: GetWindowsDirectory @ 0x482097\n\nget file system object information\nnamespace  host-interaction/file-system                   \nauthor     michael.hunhoff@mandiant.com                   \nscope      basic block                                    \natt&ck     Discovery::File and Directory Discovery [T1083]\nbasic block @ 0x471CBE in function 0x471C90\n  or:\n    api: SHGetFileInfo @ 0x471D18\n\ncopy file (2 matches)\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ 0x46B6F0\n  or:\n    api: CopyFile @ 0x46B856\nfunction @ 0x481F50\n  or:\n    api: CopyFile @ 0x4820CF\n\ndelete file (5 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x46B6F0\n  or:\n    api: DeleteFile @ 0x46B874\nfunction @ 0x46EA60\n  or:\n    api: DeleteFile @ 0x46EA9E\nfunction @ 0x46ECC0\n  or:\n    api: DeleteFile @ 0x46ED6B\nfunction @ 0x477A20\n  or:\n    api: DeleteFile @ 0x477B94\nfunction @ 0x481F50\n  or:\n    api: DeleteFile @ 0x48297D\n\ncheck if file exists (7 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x46BA40\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x46BA8C\n        instruction:\n          and:\n            mnemonic: cmp @ 0x46BA92\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x46BA92\nfunction @ 0x475A80\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x475A84\n        instruction:\n          and:\n            mnemonic: cmp @ 0x475A8A\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x475A8A\nfunction @ 0x479FC0\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x479FC1\n        instruction:\n          and:\n            mnemonic: cmp @ 0x479FC9\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x479FC9\nfunction @ 0x47E0B0\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x47E185\n        instruction:\n          and:\n            mnemonic: cmp @ 0x47E18B\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x47E18B\nfunction @ 0x4841A0\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x484268\n        instruction:\n          and:\n            mnemonic: cmp @ 0x48426E\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x48426E\nfunction @ 0x484310\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x4848E6\n        instruction:\n          and:\n            mnemonic: cmp @ 0x4848E8\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x4848E8\n      and:\n        api: GetFileAttributes @ 0x4845F7\n        instruction:\n          and:\n            mnemonic: cmp @ 0x4845F9\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x4845F9\n      and:\n        api: GetFileAttributes @ 0x484733\n        instruction:\n          and:\n            mnemonic: cmp @ 0x484735\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x484735\n      and:\n        api: GetFileAttributes @ 0x484436\n        instruction:\n          and:\n            mnemonic: cmp @ 0x484438\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x484438\n      and:\n        api: GetFileAttributes @ 0x484517\n        instruction:\n          and:\n            mnemonic: cmp @ 0x484519\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x484519\n      and:\n        api: GetFileAttributes @ 0x484D89\n        instruction:\n          and:\n            mnemonic: cmp @ 0x484D8F\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x484D8F\n      and:\n        api: GetFileAttributes @ 0x4846C7\n        instruction:\n          and:\n            mnemonic: cmp @ 0x4846C9\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x4846C9\n      and:\n        api: GetFileAttributes @ 0x48479F\n        instruction:\n          and:\n            mnemonic: cmp @ 0x4847A1\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x4847A1\n      and:\n        api: GetFileAttributes @ 0x4850B3\n        instruction:\n          and:\n            mnemonic: cmp @ 0x4850B9\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x4850B9\n      and:\n        api: GetFileAttributes @ 0x484CF6\n        instruction:\n          and:\n            mnemonic: cmp @ 0x484CFC\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x484CFC\n      and:\n        api: GetFileAttributes @ 0x484583\n        instruction:\n          and:\n            mnemonic: cmp @ 0x484585\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x484585\n      and:\n        api: GetFileAttributes @ 0x485454\n        instruction:\n          and:\n            mnemonic: cmp @ 0x48545A\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x48545A\n      and:\n        api: GetFileAttributes @ 0x48465B\n        instruction:\n          and:\n            mnemonic: cmp @ 0x48465D\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x48465D\n      and:\n        api: GetFileAttributes @ 0x48561B\n        instruction:\n          and:\n            mnemonic: cmp @ 0x485621\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x485621\n      and:\n        api: GetFileAttributes @ 0x484464\n        instruction:\n          and:\n            mnemonic: cmp @ 0x484466\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x484466\nfunction @ 0x4890E0\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x489777\n        instruction:\n          and:\n            mnemonic: cmp @ 0x489779\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x489779\n\nenumerate files on Windows\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ 0x478A40\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x478A53\n      or:\n        api: FindNextFile @ 0x478A6F\n      optional:\n        api: FindClose @ 0x478A83\n\nget file attributes (23 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x46BA40 in function 0x46BA40\n  or:\n    api: GetFileAttributes @ 0x46BA8C\nbasic block @ 0x46F114 in function 0x46ED80\n  or:\n    api: GetFileAttributes @ 0x46F11F\nbasic block @ 0x475A80 in function 0x475A80\n  or:\n    api: GetFileAttributes @ 0x475A84\nbasic block @ 0x479FC0 in function 0x479FC0\n  or:\n    api: GetFileAttributes @ 0x479FC1\nbasic block @ 0x47E16A in function 0x47E0B0\n  or:\n    api: GetFileAttributes @ 0x47E185\nbasic block @ 0x48422E in function 0x4841A0\n  or:\n    api: GetFileAttributes @ 0x484268\nbasic block @ 0x484407 in function 0x484310\n  or:\n    api: GetFileAttributes @ 0x484436\nbasic block @ 0x48445C in function 0x484310\n  or:\n    api: GetFileAttributes @ 0x484464\nbasic block @ 0x4844C8 in function 0x484310\n  or:\n    api: GetFileAttributes @ 0x484517\nbasic block @ 0x484534 in function 0x484310\n  or:\n    api: GetFileAttributes @ 0x484583\nbasic block @ 0x4845A4 in function 0x484310\n  or:\n    api: GetFileAttributes @ 0x4845F7\nbasic block @ 0x484618 in function 0x484310\n  or:\n    api: GetFileAttributes @ 0x48465B\nbasic block @ 0x484678 in function 0x484310\n  or:\n    api: GetFileAttributes @ 0x4846C7\nbasic block @ 0x4846E4 in function 0x484310\n  or:\n    api: GetFileAttributes @ 0x484733\nbasic block @ 0x484750 in function 0x484310\n  or:\n    api: GetFileAttributes @ 0x48479F\nbasic block @ 0x4848A0 in function 0x484310\n  or:\n    api: GetFileAttributes @ 0x4848E6\nbasic block @ 0x484CD3 in function 0x484310\n  or:\n    api: GetFileAttributes @ 0x484CF6\nbasic block @ 0x484D68 in function 0x484310\n  or:\n    api: GetFileAttributes @ 0x484D89\nbasic block @ 0x485092 in function 0x484310\n  or:\n    api: GetFileAttributes @ 0x4850B3\nbasic block @ 0x485433 in function 0x484310\n  or:\n    api: GetFileAttributes @ 0x485454\nbasic block @ 0x4855FA in function 0x484310\n  or:\n    api: GetFileAttributes @ 0x48561B\nbasic block @ 0x4896E2 in function 0x4890E0\n  or:\n    api: GetFileAttributes @ 0x489729\nbasic block @ 0x489776 in function 0x4890E0\n  or:\n    api: GetFileAttributes @ 0x489777\n\nget file size (5 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x465EB0\n  or:\n    api: GetFileSize @ 0x465EE9\nfunction @ 0x477380\n  or:\n    api: GetFileSize @ 0x4774B2\nfunction @ 0x477E40\n  or:\n    api: GetFileSize @ 0x477EC5\nfunction @ 0x47B5A0\n  or:\n    api: GetFileSize @ 0x47B5DD\nfunction @ 0x486890\n  or:\n    api: GetFileSize @ 0x4868BC\n\nget file version info\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x488410\n  and:\n    or:\n      api: GetFileVersionInfo @ 0x4884BD\n    optional: = retrieve specified version information from the version-information resource\n      api: VerQueryValue @ 0x4884D2, 0x488512\n      or:\n        api: GetFileVersionInfoSize @ 0x48842D\n\nread .ini file (5 matches)\nnamespace  host-interaction/file-system/read     \nauthor     @_re_fox, michael.hunhoff@mandiant.com\nscope      function                              \nmbc        File System::Read File [C0051]        \nfunction @ 0x466940\n  and:\n    or:\n      api: GetPrivateProfileString @ 0x4669CA\nfunction @ 0x466A20\n  and:\n    or:\n      api: GetPrivateProfileInt @ 0x466A58\nfunction @ 0x475630\n  and:\n    or:\n      api: GetPrivateProfileString @ 0x47566F\nfunction @ 0x4756B0\n  and:\n    or:\n      api: GetPrivateProfileString @ 0x4756F6\nfunction @ 0x475A80\n  and:\n    or:\n      api: GetPrivateProfileInt @ 0x475AD8\n      api: GetPrivateProfileString @ 0x475B17, 0x475B3D, 0x475B66\n\nread file on Windows (13 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x465EB0\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x465ED3\n          match: create or open file @ 0x465ED9\n            or:\n              api: CreateFile @ 0x465ED9\n      or:\n        api: ReadFile @ 0x465F0E\nfunction @ 0x477590\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x4777EB\nfunction @ 0x477850\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x4779CD\nfunction @ 0x477CA0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x477CE0, 0x477D13, 0x477D9B\nfunction @ 0x477E40\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x477E5F\n          match: create or open file @ 0x477E65\n            or:\n              api: CreateFile @ 0x477E65\n      or:\n        api: ReadFile @ 0x477E9A\nfunction @ 0x47B5A0\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x47B5C0\n          match: create or open file @ 0x47B5C6\n            or:\n              api: CreateFile @ 0x47B5C6\n      or:\n        api: ReadFile @ 0x47B60D\nfunction @ 0x47C090\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x47C0D1\nfunction @ 0x47C1A0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x47C239\nfunction @ 0x47C640\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x47C6FB, 0x47C75A\nfunction @ 0x47CA10\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x47CA66\nfunction @ 0x47CB10\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x47CC2A\nfunction @ 0x47CC50\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x47CC7A\n          match: create or open file @ 0x47CC86\n            or:\n              api: CreateFile @ 0x47CC86\n      or:\n        api: ReadFile @ 0x47CCAC\nfunction @ 0x486890\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x4868A1\n          match: create or open file @ 0x4868AD\n            or:\n              api: CreateFile @ 0x4868AD\n      or:\n        api: ReadFile @ 0x48690D\n\nread file via mapping\nnamespace  host-interaction/file-system/read\nauthor     michael.hunhoff@mandiant.com     \nscope      function                         \nmbc        File System::Read File [C0051]   \nfunction @ 0x477380\n  or:\n    and:\n      basic block:\n        and:\n          api: MapViewOfFile @ 0x4774F5\n          or:\n            number: 0x4 = FILE_MAP_READ @ 0x4774F2\n      optional:\n        api: UnmapViewOfFile @ 0x47751A\n        and:\n          match: get file size @ 0x477380\n            or:\n              api: GetFileSize @ 0x4774B2\n        basic block:\n          and:\n            api: CreateFileMapping @ 0x4774E1\n            or:\n              number: 0x2 = PAGE_READONLY @ 0x4774D6\n\nwrite file on Windows (17 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x470860\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x4708D0\nfunction @ 0x4708E0\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x470950\nfunction @ 0x470F80\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x470FA3\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x470F9C\n      or:\n        api: WriteFile @ 0x470FBB\nfunction @ 0x472220\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x47234F\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4723A8\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4724B9\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4723B3\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4724C3\n      or:\n        api: WriteFile @ 0x4723D9, 0x4724E2\nfunction @ 0x472570\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4725E7\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4725F3\n      or:\n        api: WriteFile @ 0x472616\nfunction @ 0x472640\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x47272A\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x472733\n      or:\n        api: WriteFile @ 0x472676, 0x47274B, 0x47279E\nfunction @ 0x4727D0\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x47294C\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x472A56, 0x472A59\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x472B13\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x472A79\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x472B0D\n      or:\n        api: WriteFile @ 0x4728E2, 0x472B31, 0x472B8A, 0x472BD2\nfunction @ 0x472C00\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x472DD3\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x472D49\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x472DC8\n      or:\n        api: WriteFile @ 0x472C68, 0x472DF2, 0x472E5A\nfunction @ 0x472E90\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x472F14\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x472F0E\n      or:\n        api: WriteFile @ 0x472F30, 0x472F8C\nfunction @ 0x472FB0\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x472FF4\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4730D3\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x473133\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4730C8\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x472FFA\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x47312C\n      or:\n        api: WriteFile @ 0x47301B, 0x473058, 0x4730EB, 0x47314F, and 2 more...\nfunction @ 0x4737C0\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x473933\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x473843\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x473998\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x473849\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x47392A\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4738E7\n      or:\n        api: WriteFile @ 0x473862, 0x47394B, 0x4739A0, 0x4739F8\nfunction @ 0x473A20\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x473B93\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x473AA3\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x473BF8\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x473AA9\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x473B8A\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x473B47\n      or:\n        api: WriteFile @ 0x473AC2, 0x473BAB, 0x473C00, 0x473C58\nfunction @ 0x474520\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x474587\n            number: 0x2 = FILE_WRITE_DATA @ 0x474582\n            match: create or open file @ 0x47458D\n              or:\n                api: CreateFile @ 0x47458D\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x474620\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x47454B\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4745CC\n      or:\n        api: WriteFile @ 0x4745D4\nfunction @ 0x474770\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x47488D\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x474822\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x47479D\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x4747D5\n            number: 0x2 = FILE_WRITE_DATA @ 0x4747D0\n            match: create or open file @ 0x4747DB\n              or:\n                api: CreateFile @ 0x4747DB\n      or:\n        api: WriteFile @ 0x47482A\nfunction @ 0x474960\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x4749B7\n            number: 0x2 = FILE_WRITE_DATA @ 0x4749B2\n            match: create or open file @ 0x4749BD\n              or:\n                api: CreateFile @ 0x4749BD\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x474A60\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x474AA8\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x474B17\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x474A0C\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x474B89\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x47497E\n      or:\n        api: WriteFile @ 0x474A14\nfunction @ 0x477380\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4774D6\n      or:\n        api: WriteFile @ 0x477513\nfunction @ 0x48113A\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x48121F\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x481294\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x48128E\n      or:\n        api: WriteFile @ 0x48116D, 0x4812B0\n\nenumerate gui resources\nnamespace  host-interaction/gui                           \nauthor     johnk3r, anushka.virgaonkar@mandiant.com       \nscope      function                                       \natt&ck     Discovery::Application Window Discovery [T1010]\nfunction @ 0x46F2B0\n  or:\n    api: EnumResourceTypes @ 0x46F328\n\nget graphical window text (2 matches)\nnamespace  host-interaction/gui/window/get-text           \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \nmbc        Discovery::Application Window Discovery [E1010]\nfunction @ 0x4761B0\n  or:\n    and:\n      api: GetWindowText @ 0x4761FB\nfunction @ 0x4764B0\n  or:\n    and:\n      api: GetWindowText @ 0x4765C6\n\nhide graphical window (4 matches)\nnamespace  host-interaction/gui/window/hide                          \nauthor     michael.hunhoff@mandiant.com                              \nscope      basic block                                               \natt&ck     Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\nbasic block @ 0x46CA70 in function 0x46CA70\n  and:\n    number: 0x0 = SW_HIDE @ 0x46CA9F\n    api: ShowWindow @ 0x46CA8E\nbasic block @ 0x46E543 in function 0x46E500\n  and:\n    number: 0x0 = SW_HIDE @ 0x46E549\n    api: ShowWindow @ 0x46E54C\nbasic block @ 0x46F135 in function 0x46ED80\n  and:\n    number: 0x0 = SW_HIDE @ 0x46F164, 0x46F166, 0x46F174, 0x46F185, and 5 more...\n    api: ShowWindow @ 0x46F258\nbasic block @ 0x487EB7 in function 0x487E80\n  and:\n    number: 0x0 = SW_HIDE @ 0x487EC0, 0x487ED6\n    api: ShowWindow @ 0x487ED1, 0x487EE1\n\nget disk information\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ 0x477380\n  or:\n    api: GetDriveType @ 0x477405\n\nenumerate internet cache\nnamespace  host-interaction/internet/cache\nauthor     michael.hunhoff@mandiant.com   \nscope      function                       \nfunction @ 0x476ED0\n  and:\n    api: FindFirstUrlCacheEntry @ 0x476EF6\n    optional:\n      api: FindNextUrlCacheEntry @ 0x476F95, 0x476FCC\n      api: FindCloseUrlCache @ 0x476FE5\n      match: contain loop @ 0x476ED0\n        or:\n          characteristic: loop @ 0x476ED0\n\ncheck OS version\nnamespace  host-interaction/os/version                    \nauthor     michael.hunhoff@mandiant.com, johnk3r          \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x485840\n  and:\n    match: get OS version @ 0x485840\n      or:\n        api: GetVersionEx @ 0x485B1A\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x485A82\n            number: 0x5 = Windows 2000 @ 0x485A82\n        optional:\n          instruction:\n            and:\n              mnemonic: cmp @ 0x485995\n              or:\n                number: 0x1 = Windows XP @ 0x485995\n            and:\n              mnemonic: cmp @ 0x485BA7\n              or:\n                number: 0x2 = Windows XP 64-bit / Windows Server 2003 / Windows Server 2003 R2 @ 0x485BA7\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x4858D2\n            number: 0x6 = Windows Vista / Windows Server 2008 @ 0x4858D2\n        optional:\n          instruction:\n            and:\n              mnemonic: cmp @ 0x485BA7\n              or:\n                number: 0x2 = Windows Server 2012 / Windows 8 @ 0x485BA7\n            and:\n              mnemonic: cmp @ 0x48598C\n              or:\n                number: 0x3 = Windows Server 2012 R2 / Windows 8.1 @ 0x48598C\n            and:\n              mnemonic: cmp @ 0x485995\n              or:\n                number: 0x1 = Windows Server 2008 R2 / Windows 7 @ 0x485995\n            and:\n              mnemonic: cmp @ 0x48593F\n              or:\n                number: 0x3 = Windows Server 2012 R2 / Windows 8.1 @ 0x48593F\n\ncreate process on Windows (5 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x46E32C in function 0x46E2E0\n  or:\n    api: ShellExecute @ 0x46E33C\nbasic block @ 0x46F5BD in function 0x46F590\n  or:\n    api: ShellExecute @ 0x46F605\nbasic block @ 0x470344 in function 0x46FEB0\n  or:\n    api: ShellExecute @ 0x47035D\nbasic block @ 0x470395 in function 0x46FEB0\n  or:\n    api: ShellExecute @ 0x4703AE\nbasic block @ 0x479A00 in function 0x479A00\n  or:\n    api: ShellExecute @ 0x479A13\n\nenumerate processes\nnamespace  host-interaction/process/list                                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      function                                                             \natt&ck     Discovery::Process Discovery [T1057], Discovery::Software Discovery  \n           [T1518]                                                              \nfunction @ 0x46A230\n  or:\n    and:\n      api: Process32First @ 0x46A293\n      api: Process32Next @ 0x46A2A1, 0x46A51C\n      optional:\n        basic block:\n          and:\n            api: CreateToolhelp32Snapshot @ 0x46A25E\n            or:\n              number: 0x2 = TH32CS_SNAPPROCESS @ 0x46A253\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x40193E\n  or:\n    api: exit @ 0x401AE1\n\nquery or enumerate registry value (4 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x4667E0\n  and:\n    or:\n      api: RegQueryValueEx @ 0x466832\nfunction @ 0x4781D0\n  and:\n    optional:\n      match: create or open registry key @ 0x478260\n        or:\n          api: RegOpenKeyEx @ 0x478293\n    or:\n      api: RegQueryValueEx @ 0x4782C2\nfunction @ 0x485840\n  and:\n    optional:\n      match: create or open registry key @ 0x485B34\n        or:\n          api: RegOpenKeyEx @ 0x485B67\n    or:\n      api: RegQueryValueEx @ 0x485B99\nfunction @ 0x4890E0\n  and:\n    optional:\n      match: create or open registry key @ 0x489191, 0x4892AF, 0x4893DC, 0x4894F9\n        or:\n          api: RegOpenKeyEx @ 0x4891BE\n        or:\n          api: RegOpenKeyEx @ 0x489409\n        or:\n          api: RegOpenKeyEx @ 0x489526\n        or:\n          api: RegOpenKeyEx @ 0x4892DC\n    or:\n      api: RegQueryValueEx @ 0x4891EA, 0x489326, 0x489435, 0x489552\n\nset registry value\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x4667E0\n  or:\n    and:\n      or:\n        api: RegSetValueEx @ 0x46680E\n\ncreate thread\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x41154B in function 0x4114D0\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthreadex @ 0x411561\n\nlink function at runtime on Windows (36 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x469E68\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x469E68\ninstruction @ 0x469E79\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x469E79\ninstruction @ 0x469E8A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x469E8A\ninstruction @ 0x469E9B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x469E9B\ninstruction @ 0x469EAC\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x469EAC\ninstruction @ 0x46A359\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46A359\ninstruction @ 0x46A367\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46A367\ninstruction @ 0x46A375\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46A375\ninstruction @ 0x46A383\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46A383\ninstruction @ 0x46A391\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46A391\ninstruction @ 0x46A3F1\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46A3F1\ninstruction @ 0x46A44C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46A44C\ninstruction @ 0x46A87C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46A87C\ninstruction @ 0x46A88D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46A88D\ninstruction @ 0x46A89E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46A89E\ninstruction @ 0x46A8AF\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46A8AF\ninstruction @ 0x46A8C0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46A8C0\ninstruction @ 0x46AABA\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46AABA\ninstruction @ 0x46AACC\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46AACC\ninstruction @ 0x46AADF\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46AADF\ninstruction @ 0x46AAF2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46AAF2\ninstruction @ 0x46AB04\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46AB04\ninstruction @ 0x46AB17\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46AB17\ninstruction @ 0x46AB2A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46AB2A\ninstruction @ 0x46AB3C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46AB3C\ninstruction @ 0x46F2F6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46F2F6\ninstruction @ 0x47821C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x47821C\ninstruction @ 0x47A90F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x47A90F\ninstruction @ 0x47A96F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x47A96F\ninstruction @ 0x47FBA1\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x47FBA1\ninstruction @ 0x485920\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x485920\ninstruction @ 0x485AF0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x485AF0\ninstruction @ 0x48914A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x48914A\ninstruction @ 0x48926F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x48926F\ninstruction @ 0x489390\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x489390\ninstruction @ 0x4894A6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4894A6\n\nlink many functions at runtime (4 matches)\nnamespace  linking/runtime-linking                      \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com\nscope      function                                     \natt&ck     Execution::Shared Modules [T1129]            \nfunction @ 0x469E40\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x469E68, 0x469E79, 0x469E8A, 0x469E9B, and 1 more...\nfunction @ 0x46A230\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x46A359, 0x46A367, 0x46A375, 0x46A383, and 3 more...\nfunction @ 0x46A850\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x46A87C, 0x46A88D, 0x46A89E, 0x46A8AF, and 1 more...\nfunction @ 0x46AA90\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x46AABA, 0x46AACC, 0x46AADF, 0x46AAF2, and 4 more...\n\nlinked against sqlite3\nnamespace  linking/static/sqlite3\nauthor     still@teamt5.org      \nscope      file                  \nor:\n  3 or more:\n    string: \"database corruption\" @ file+0x92F44\n    string: \"SQLite format 3\" @ file+0x8C508\n    substring: qualified table names are not allowed on\n      - \"qualified table names are not allowed on INSERT, UPDATE, and DELETE statements \nwithin triggers\" @ file+0x92C10\n\nenumerate PE sections (3 matches)\nnamespace   load-code/pe                                                        \nauthor      @Ana06, @mr-tz                                                      \nscope       function                                                            \nmbc         Discovery::Code Discovery::Enumerate PE Sections [B0046.001]        \nreferences  https://0x00sec.org/t/reflective-dll-injection/3080,                \n            https://www.ired.team/offensive-security/code-injection-process-inj…\nfunction @ 0x42DF60\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x42E185\n        or:\n          mnemonic: movzx @ 0x42E185\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x42E0BA\n              or:\n                mnemonic: mov @ 0x42E0BA\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x42E0AA\n    count(basic block): 3 or more @ 0x42DF60, 0x42DFA7, 0x42DFB8, 0x42DFC4, and 51 more...\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x42DFD3, 0x42DFDA, 0x42E02A, 0x42E054, and 3 more...\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x42DFAE, 0x42E0BA, 0x42E0F2, 0x42E104, and 6 more...\n      operand[1].offset: 0x10 = IMAGE_SECTION_HEADER.SizeOfRawData @ 0x42DFAA, 0x42DFC7, 0x42E050, 0x42E072, and 6 more...\nfunction @ 0x4484F0\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x448507\n        or:\n          mnemonic: movzx @ 0x448507\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x448520\n              or:\n                mnemonic: mov @ 0x448520\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x448523\n    count(basic block): 3 or more @ 0x4484F0, 0x44851D, 0x44853B, 0x448548, and 33 more...\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x448561, 0x4485E6\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x448520, 0x44869D, 0x448727\n      operand[1].offset: 0x10 = IMAGE_SECTION_HEADER.SizeOfRawData @ 0x448526, 0x448603, 0x44861C, 0x44867A, and 2 more...\nfunction @ 0x449830\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x449C03\n        or:\n          mnemonic: mov @ 0x449C03\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x449B3C\n        or:\n          mnemonic: mov @ 0x449B3C\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x44AE04\n              or:\n                mnemonic: mov @ 0x44AE04\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x44AE00\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x44ADC0\n              or:\n                mnemonic: mov @ 0x44ADC0\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x44ADCB\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x44ACC8\n              or:\n                mnemonic: mov @ 0x44ACC8\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x44ACCF\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x44AB4D\n              or:\n                mnemonic: add @ 0x44AB4D\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x44AB42\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x44AC36\n              or:\n                mnemonic: mov @ 0x44AC36\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x44AC44\n    count(basic block): 3 or more @ 0x449830, 0x44985C, 0x449866, 0x449870, and 375 more...\n    optional:\n      offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x449B38, 0x449BFC, 0x44A382, 0x44A3A9, and 9 more...\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x449C15, 0x44A06D, 0x44A2A9, 0x44A36D, and 41 more...\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x449A2F, 0x44A21A, 0x44A862, 0x44A8B5, and 19 more...\n      operand[1].offset: 0x10 = IMAGE_SECTION_HEADER.SizeOfRawData @ 0x449949, 0x44995B, 0x449B40, 0x449C00, and 13 more...\n\nparse PE header\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x40193E\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x401953, 0x40195F, 0x40196B, 0x401972, and 14 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x40195F\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x401953\n\nresolve function by parsing PE exports (28 matches)\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x4274A0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x4274A0\n      mnemonic: movzx @ 0x42762D, 0x427630, 0x427639, 0x42763C, and 28 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x4274C9, 0x427C07, 0x427C15, 0x427C35\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x427860, 0x427895, 0x4278C2\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x4274F5, 0x427576, 0x4276A8, 0x4277A0, and 8 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x4274D5, 0x427529, 0x42760B, 0x42772E, and 3 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x4274C1, 0x4275D2, 0x4275DE, 0x427684, and 10 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x4274CD, 0x4275DA, 0x4275E5, 0x427699, and 8 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x4274DD, 0x4274E9, 0x42756C, 0x4275C1, and 12 more...\nfunction @ 0x42D080\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x42D080\n      mnemonic: movzx @ 0x42D091\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x42D2BE, 0x42D380\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x42D0AC\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x42D146, 0x42D195, 0x42D1BB, 0x42D217, and 5 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x42D0E0, 0x42D19D, 0x42D1F9, 0x42D234, and 3 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x42D0A3, 0x42D13E, 0x42D1B3, 0x42D230, and 4 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x42D166, 0x42D1E6, 0x42D2E9, 0x42D2F6, and 3 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x42D0D6, 0x42D0EB, 0x42D1B7, 0x42D21A, and 6 more...\nfunction @ 0x43A8C0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x43A8C0\n      mnemonic: movzx @ 0x43A8D6, 0x43A908, 0x43A98E, 0x43A9F3, and 10 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x43A960, 0x43A996, 0x43AE28, 0x43AFB5\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x43A8F5, 0x43AFE1\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x43AD03\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x43A9E6, 0x43AA12, 0x43AB45, 0x43AB55, and 9 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x43AA82, 0x43AADD, 0x43AB87, 0x43AC65, and 2 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x43A8ED, 0x43A980, 0x43A9C9, 0x43AA34, and 12 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x43A8F1, 0x43A970, 0x43AA3C, 0x43AA69, and 9 more...\nfunction @ 0x43B060\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x43B060\n      mnemonic: movzx @ 0x43B07D, 0x43B152, 0x43B180, 0x43B320, and 10 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x43B3ED\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x43B101, 0x43B13C\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x43B1DD, 0x43B1EB, 0x43B27D, 0x43B2B3, and 10 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x43B0A8, 0x43B140, 0x43B201, 0x43B281, and 8 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x43B0AC, 0x43B1FE, 0x43B20E, 0x43B242, and 6 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x43B0BA, 0x43B14E, 0x43B1A3, 0x43B233, and 6 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x43B0B0, 0x43B144, 0x43B187, 0x43B24B, and 4 more...\nfunction @ 0x43C8A0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x43C8A0\n      mnemonic: movzx @ 0x43C8AB, 0x43CA7B, 0x43CA85, 0x43CA88, and 38 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x43C8EF, 0x43CD33, 0x43CD9B\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x43CA00, 0x43CF2F, 0x43CF33, 0x43CF68, and 2 more...\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x43C955, 0x43CA7E, 0x43CAAB, 0x43CAC1, and 14 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x43C8D0, 0x43CA60, 0x43CE92, 0x43CF29, and 4 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x43C941, 0x43C97A, 0x43CCF5, 0x43CD22, and 10 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x43C958, 0x43C972, 0x43C9F7, 0x43CA13, and 13 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x43C95B, 0x43C9E2, 0x43CCFB, 0x43CD25, and 5 more...\nfunction @ 0x43D170\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x43D170\n      mnemonic: movzx @ 0x43D1B7, 0x43D374, 0x43D3AF, 0x43D3C8, and 23 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x43D23E\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x43D383, 0x43D51F\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x43D186, 0x43D226, 0x43D259, 0x43D41D, and 2 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x43D3EC, 0x43D54A, 0x43D562, 0x43D59B\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x43D3F0, 0x43D55D, 0x43D5B0\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x43D1D8, 0x43D587, 0x43D5AA, 0x43D603, and 1 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x43D1A2, 0x43D1FA, 0x43D402, 0x43D540, and 1 more...\nfunction @ 0x43E5D0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x43E5D0\n      mnemonic: movzx @ 0x43DC1D, 0x43DC29\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x43DAB3, 0x43DC3F, 0x43DCB2, 0x43DCCA, and 6 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x43DD41\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x43DA11, 0x43DA5E, 0x43DA70, 0x43DC16, and 5 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x43D9ED, 0x43DB7A, 0x43DC89, 0x43DC90\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x43D91B, 0x43D94D, 0x43DA5A, 0x43DB8A, and 1 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x43D8F1, 0x43D905, 0x43D99D, 0x43D9F2, and 8 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x43D923, 0x43DB20, 0x43DB30, 0x43DBD8, and 1 more...\nfunction @ 0x445080\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x445080\n      mnemonic: movzx @ 0x4450B0, 0x4452C2, 0x445492, 0x4456F3, and 32 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x445458, 0x44564B, 0x4457EF, 0x445802, and 13 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x4450A2, 0x445917, 0x4459E6, 0x445A15, and 4 more...\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x445FF8, 0x44613C, 0x446179, 0x4462B8, and 1 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x44513D, 0x44519D, 0x4451FD, 0x445231, and 33 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x4450D8, 0x445199, 0x445204, 0x44532D, and 13 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x445175, 0x4451DB, 0x445228, 0x445259, and 24 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x4450DC, 0x445262, 0x445357, 0x445381, and 23 more...\nfunction @ 0x4471E0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x4471E0\n      mnemonic: movzx @ 0x447235, 0x447239, 0x447288, 0x4472A4, and 56 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x4473D1, 0x447505, 0x447D04\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x44831D\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x4472A7, 0x44737B, 0x447400, 0x44742E, and 30 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x447202, 0x44744E, 0x447654, 0x447679, and 26 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x4472C2, 0x447395, 0x4473B3, 0x4473BE, and 27 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x44754F, 0x4475A5, 0x447618, 0x4477DC, and 24 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x4471FA, 0x447391, 0x4473A5, 0x44746B, and 19 more...\nfunction @ 0x448790\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x448790\n      mnemonic: movzx @ 0x448858, 0x44888C, 0x44888F, 0x4488FE, and 10 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x4487BF, 0x4487DE, 0x4488A3, 0x4488D0\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x448854\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x4487BA, 0x448809, 0x448813, 0x448865, and 4 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x4488C3, 0x4488D6\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x44884A, 0x44899F, 0x4489D1, 0x448A42, and 1 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x44885F, 0x4488E7, 0x448931, 0x448937, and 2 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x44886A, 0x448AA4\nfunction @ 0x449830\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x449830\n      mnemonic: movzx @ 0x449F14, 0x449F42, 0x44A63E, 0x44A78F, and 16 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x449B38, 0x449BFC, 0x44A382, 0x44A3A9, and 9 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x449F23, 0x44B525\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x449A2F, 0x44A21A, 0x44A234, 0x44A450, and 22 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x449866, 0x4498F1, 0x449A84, 0x449C8A, and 3 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x449A90, 0x449B58, 0x449B88, 0x449C83, and 18 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x449A3E, 0x449AF9, 0x449BA6, 0x449FF4, and 25 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x4498EB, 0x44993F, 0x449999, 0x449A4F, and 28 more...\nfunction @ 0x44FAD0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x44FAD0\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x44FB21, 0x44FB82\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x44FB97\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x44FB9A, 0x44FBD2, 0x44FC68\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x44FBF8\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x44FAF5, 0x44FBAD, 0x44FC77\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x44FAE3, 0x44FB4A, 0x44FC81\nfunction @ 0x451A00\n  and:\n    os: windows\n    or:\n      mnemonic: movzx @ 0x451A07\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x451A16\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x451A12\n      3 or more:\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x451A07\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x451A1A\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x451A42\nfunction @ 0x451C10\n  and:\n    os: windows\n    or:\n      mnemonic: movzx @ 0x451C2D, 0x451C57, 0x451C5B, 0x451C74, and 8 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x451C51, 0x451EBD\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x451C28, 0x451D5F, 0x451E56\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x451C57, 0x451D17, 0x451D89, 0x451DC7, and 2 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x451C49, 0x451C78, 0x451C94, 0x451D43, and 3 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x451C32, 0x451CB9, 0x451D36, 0x451D63, and 1 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x451CB3, 0x451CF8, 0x451D25, 0x451D2D, and 3 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x451C3F, 0x451D32, 0x451E85\nfunction @ 0x452260\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x452260\n      mnemonic: movzx @ 0x452299, 0x4522AE, 0x452321, 0x45264B, and 4 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x45231E, 0x4525E0, 0x4525E6, 0x452BBF, and 3 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x452C93, 0x452E05\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x452285, 0x4524E4, 0x452503, 0x45254F, and 20 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x452279, 0x4523A4, 0x4523C7, 0x4524EC, and 4 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x452311, 0x452329, 0x45243D, 0x45245D, and 9 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x45227D, 0x452526, 0x45254B, 0x452579, and 16 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x4522C6, 0x452303, 0x4524D2, 0x4525AC, and 22 more...\nfunction @ 0x453200\n  and:\n    os: windows\n    or:\n      mnemonic: movzx @ 0x453232, 0x45327D, 0x4532A6, 0x4532C5\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x45322F, 0x4532EA\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x45322B\n      3 or more:\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x453232, 0x453246, 0x45326F\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x453216, 0x453222, 0x45324A, 0x453306\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x453219, 0x453251, 0x45325B, 0x453273\nfunction @ 0x453BB0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x453BB0\n      mnemonic: movzx @ 0x453DA6, 0x453DB6, 0x453EB2, 0x453F54, and 2 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x45499B, 0x4549B8, 0x4549D4, 0x454A04, and 1 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x453CC1\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x453C88, 0x453CAA, 0x453DC4, 0x453E30, and 41 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x453D2D, 0x453EF6, 0x454331, 0x45461B, and 11 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x453DDA, 0x453FE0, 0x454111, 0x4543A0, and 8 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x453C1D, 0x453C96, 0x453DCA, 0x453E29, and 23 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x453C02, 0x453E9D, 0x453EC5, 0x454030, and 13 more...\nfunction @ 0x456FA0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x456FA0\n      mnemonic: movzx @ 0x457258, 0x45725B, 0x457262, 0x457265, and 14 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x457226, 0x4572A6, 0x457382, 0x4573D9, and 10 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x457132, 0x457140, 0x45747F, 0x4576DE, and 8 more...\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x4570E1, 0x457222, 0x45729C, 0x4572AA, and 24 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x456FB4, 0x45741F, 0x45749F, 0x4574AC, and 10 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x45709F, 0x4570B0, 0x4570CC, 0x4572BA, and 21 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x457360, 0x4573D0, 0x457627, 0x457643, and 8 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x4571CB, 0x4572F6, 0x45735C, 0x45736A, and 15 more...\nfunction @ 0x458770\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x458770\n      mnemonic: movzx @ 0x458CD7, 0x459452\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x4587A2, 0x458817, 0x458B44, 0x458BBB, and 7 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x4587C0, 0x458E1A, 0x459499, 0x45964B, and 1 more...\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x4588F4, 0x458906, 0x458FD0, 0x459626, and 1 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x45878B, 0x4589A5, 0x4589B6, 0x458A7A, and 12 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x4587C8, 0x45884A, 0x4589EE, 0x458AD7, and 9 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x458968, 0x458990, 0x4589D6, 0x458A0B, and 24 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x45903B, 0x459044\nfunction @ 0x45A790\n  and:\n    os: windows\n    or:\n      mnemonic: movzx @ 0x45A9EF, 0x45AA35, 0x45AAB6, 0x45AB73\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x45A7D1, 0x45AC32, 0x45AC75, 0x45ACDA, and 4 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x45A947, 0x45AC0A, 0x45AF64\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x45A7F5, 0x45A8D6, 0x45A9D8, 0x45AAAC, and 9 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x45A7A6, 0x45A8BF, 0x45AA7E, 0x45AC1A, and 4 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x45AAE4, 0x45AB04, 0x45AB86, 0x45AC52, and 7 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x45A7D5, 0x45A829, 0x45A89B, 0x45A999, and 10 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x45AA57, 0x45AB36, 0x45AB5D, 0x45AC6D, and 3 more...\nfunction @ 0x45B320\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x45B320\n      mnemonic: movzx @ 0x45B3D2, 0x45BD67, 0x45C4BB, 0x45C617, and 11 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x45B4B2, 0x45B5FD, 0x45B761, 0x45BC89, and 13 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x45BC1F, 0x45C7DE\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x45B34A, 0x45B3C6, 0x45B475, 0x45B53D, and 50 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x45B4B6, 0x45B66C, 0x45B6D3, 0x45D205\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x45B59A, 0x45B5A7, 0x45BBCF, 0x45C4C2, and 5 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x45B465, 0x45B533, 0x45B541, 0x45B555, and 31 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x45B4CA, 0x45B4E6, 0x45B6E4, 0x45BC85, and 8 more...\nfunction @ 0x45EE50\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x45EE50\n      mnemonic: movzx @ 0x45EEE1, 0x45F172, 0x45F1D0, 0x45F3FF, and 49 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x45EEB4, 0x462368, 0x462971, 0x462A40, and 1 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x4602C1, 0x460306, 0x4603D5, 0x4603D9\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x45EE69, 0x45EE8D, 0x45EF59, 0x45EF8E, and 254 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x45EE7E, 0x45EECE, 0x45F08B, 0x45F2C8, and 74 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x45EE6D, 0x45F088, 0x45F1D3, 0x45F1FA, and 82 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x45EEFD, 0x45EF32, 0x45EF67, 0x45EF99, and 95 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x45F858, 0x45F86D, 0x45F8C7, 0x45F8EC, and 83 more...\nfunction @ 0x4693D0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x4693D0\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x4693EE, 0x4695A4, 0x4696A9, 0x4696BB, and 1 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x46947A\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x469685, 0x469722, 0x469728, 0x469733, and 5 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x469425, 0x4696D6, 0x469792, 0x469A68\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x469549, 0x469689, 0x46972C, 0x469741, and 3 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x46962E, 0x4697E7, 0x469830, 0x46990F, and 3 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x46965E, 0x469704, 0x4697D1, 0x4698B0, and 1 more...\nfunction @ 0x46B010\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x46B010\n      mnemonic: movzx @ 0x46B19D, 0x46B277, 0x46B34A, 0x46B42B, and 1 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x46B095, 0x46B09E, 0x46B13E\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x46B184, 0x46B5D7\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x46B35B, 0x46B36E, 0x46B3A2, 0x46B3AC, and 1 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x46B1B0, 0x46B1C3, 0x46B1F7, 0x46B201\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x46B1AC, 0x46B1BF, 0x46B1F3, 0x46B1FD, and 1 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x46B519, 0x46B52C, 0x46B560, 0x46B56A, and 2 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x46B51D, 0x46B530, 0x46B564, 0x46B56E\nfunction @ 0x46DA50\n  and:\n    os: windows\n    or:\n      mnemonic: movzx @ 0x46DB56\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x46DB12, 0x46DB4C\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x46DB01, 0x46DB50\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x46DA74\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x46DAF9, 0x46DB06\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x46DAFD\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x46DA88\nfunction @ 0x481F50\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x481F50\n      mnemonic: movzx @ 0x481F90, 0x481FDD, 0x481FEF, 0x48225C, and 7 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x482446, 0x482457\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x4821F6\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x482269, 0x482278, 0x4822A8, 0x4822B0, and 20 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x482290, 0x4822A1\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x482285\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x482148, 0x482170, 0x482194, 0x482341, and 4 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x482345, 0x482358, 0x48238C, 0x482396, and 1 more...\nfunction @ 0x482C10\n  and:\n    os: windows\n    or:\n      mnemonic: movzx @ 0x482C79, 0x482C7E, 0x482C83, 0x482C93, and 2 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x482CBB\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x482D26, 0x482D32\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x482D7C, 0x482D8F, 0x482DAE\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x482D01, 0x482D16, 0x482D2B, 0x482DB3, and 3 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x482C1C\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x482D6B, 0x482D77, 0x482DBF, 0x482DE8, and 3 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x482DF8, 0x482E13\nfunction @ 0x484310\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x484310\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x484ECF, 0x484EDB, 0x484F2A, 0x484FDA, and 6 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x484BB7, 0x484BD2\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x485050, 0x48513D, 0x485146, 0x4853F1, and 2 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x484D56, 0x484F1E, 0x484F6B, 0x4852BF, and 3 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x4843CF, 0x484633, 0x484F1A, 0x4852BB, and 1 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x4843BE, 0x484A73, 0x484F05, 0x4852A6\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x4845E3, 0x484B2B, 0x484B72, 0x484D09, and 2 more...\n\npersist via Run registry key (3 matches)\nnamespace  persistence/registry/run                                             \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com                      \nscope      function                                                             \natt&ck     Persistence::Boot or Logon Autostart Execution::Registry Run Keys /  \n           Startup Folder [T1547.001]                                           \nmbc        Persistence::Registry Run Keys / Startup Folder [F0012]              \nfunction @ 0x4781D0\n  and:\n    or:\n      number: 0x80000001 = HKEY_CURRENT_USER @ 0x47828E\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Explorer\\\\Shell Folders/i\n        - \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Explorer\\\\Shell Folders\" @ 0x478289\nfunction @ 0x485840\n  and:\n    or:\n      number: 0x80000001 = HKEY_CURRENT_USER @ 0x485B62\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Explorer\\\\Shell Folders/i\n        - \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Explorer\\\\Shell Folders\" @ 0x485B5D\nfunction @ 0x4890E0\n  and:\n    or:\n      number: 0x80000001 = HKEY_CURRENT_USER @ 0x4891B9, 0x4892D7, 0x489404, 0x489521\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Explorer\\\\Shell Folders/i\n        - \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Explorer\\\\Shell Folders\" @ 0x4891B4, 0x4892D2, 0x4893FF, 0x48951C\n\n\n\n"},"hashes":{"md5":"0f5aba101aa4d94be74690aa60bf7840","sha1":"40557e751e76b1f9608c2d0c12ce0cccd2588e11","sha256":"a14055e8b09fd980e82a3eb551fe7ca60018b5486d46e462fda29ee88f252ca0"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 1623</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 118065</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Browsin\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"0f5aba101aa4d94be74690aa60bf7840\",\n        \"sha256\": \"a14055e8b09fd980e82a3eb551fe7ca60018b5486d46e462fda29ee\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_library_rule_\",\n      \"label\": \"library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Modulo [C0058]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_loop__747_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (747 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x4014A0\",\n      \"label\": \"Function 0x4014A0\",\n      \"type\": \"function\",\n      \"address\": \"0x4014A0\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__12_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (12 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x478260\",\n      \"label\": \"Block 0x478260\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x478260\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_get_os_version__5_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"get OS version (5 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x46A5E0\",\n      \"label\": \"Function 0x46A5E0\",\n      \"type\": \"function\",\n      \"address\": \"0x46A5E0\"\n    },\n    {\n      \"id\": \"api_GetVersionEx\",\n      \"label\": \"GetVersionEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_open_process__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"open process (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Open Process [C0065]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x46A2B0\",\n      \"label\": \"Block 0x46A2B0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46A2B0\"\n    },\n    {\n      \"id\": \"api_OpenProcess\",\n      \"label\": \"OpenProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_check_for_time_delay_via_gettickcount\",\n      \"label\": \"check for time delay via GetTickCount\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"GetTickCount [B0001.032]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4750E0\",\n      \"label\": \"Function 0x4750E0\",\n      \"type\": \"function\",\n      \"address\": \"0x4750E0\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"GetTickCount [B0001.032]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_credit_card_information\",\n      \"label\": \"parse credit card information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Check String [C0019]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x439DD0\",\n      \"label\": \"Function 0x439DD0\",\n      \"type\": \"function\",\n      \"address\": \"0x439DD0\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox\",\n      \"label\": \"author     @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Check String [C0019]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_sql_statements__2_matches_\",\n      \"label\": \"reference SQL statements (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x45E8B0\",\n      \"label\": \"Function 0x45E8B0\",\n      \"type\": \"function\",\n      \"address\": \"0x45E8B0\"\n    },\n    {\n      \"id\": \"func_0x45EE50\",\n      \"label\": \"Function 0x45EE50\",\n      \"type\": \"function\",\n      \"address\": \"0x45EE50\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"label\": \"log keystrokes via polling (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46F590\",\n      \"label\": \"Function 0x46F590\",\n      \"type\": \"function\",\n      \"address\": \"0x46F590\"\n    },\n    {\n      \"id\": \"func_0x4741C0\",\n      \"label\": \"Function 0x4741C0\",\n      \"type\": \"function\",\n      \"address\": \"0x4741C0\"\n    },\n    {\n      \"id\": \"api_GetKeyState\",\n      \"label\": \"GetKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_speck\",\n      \"label\": \"encrypt data using speck\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or\",\n        \"Information::Encryption-Standard Algorithm [E1027.m05]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______still_teamt5_org\",\n      \"label\": \"author      still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or\",\n        \"Information::Encryption-Standard Algorithm [E1027.m05]\"\n      ]\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x465A20\",\n      \"label\": \"Function 0x465A20\",\n      \"type\": \"function\",\n      \"address\": \"0x465A20\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_open_clipboard__3_matches_\",\n      \"label\": \"open clipboard (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x476940\",\n      \"label\": \"Function 0x476940\",\n      \"type\": \"function\",\n      \"address\": \"0x476940\"\n    },\n    {\n      \"id\": \"func_0x46ECC0\",\n      \"label\": \"Function 0x46ECC0\",\n      \"type\": \"function\",\n      \"address\": \"0x46ECC0\"\n    },\n    {\n      \"id\": \"func_0x46E560\",\n      \"label\": \"Function 0x46E560\",\n      \"type\": \"function\",\n      \"address\": \"0x46E560\"\n    },\n    {\n      \"id\": \"api_CloseClipboard\",\n      \"label\": \"CloseClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_OpenClipboard\",\n      \"label\": \"OpenClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_write_clipboard_data__3_matches_\",\n      \"label\": \"write clipboard data (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47B5A0\",\n      \"label\": \"Function 0x47B5A0\",\n      \"type\": \"function\",\n      \"address\": \"0x47B5A0\"\n    },\n    {\n      \"id\": \"func_0x47A390\",\n      \"label\": \"Function 0x47A390\",\n      \"type\": \"function\",\n      \"address\": \"0x47A390\"\n    },\n    {\n      \"id\": \"api_EmptyClipboard\",\n      \"label\": \"EmptyClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SetClipboardData\",\n      \"label\": \"SetClipboardData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable__2_matches_\",\n      \"label\": \"query environment variable (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46E0B0\",\n      \"label\": \"Function 0x46E0B0\",\n      \"type\": \"function\",\n      \"address\": \"0x46E0B0\"\n    },\n    {\n      \"id\": \"func_0x482B00\",\n      \"label\": \"Function 0x482B00\",\n      \"type\": \"function\",\n      \"address\": \"0x482B00\"\n    },\n    {\n      \"id\": \"api_ExpandEnvironmentStrings\",\n      \"label\": \"ExpandEnvironmentStrings\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path__9_matches_\",\n      \"label\": \"get common file path (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x471C90\",\n      \"label\": \"Function 0x471C90\",\n      \"type\": \"function\",\n      \"address\": \"0x471C90\"\n    },\n    {\n      \"id\": \"func_0x46B6F0\",\n      \"label\": \"Function 0x46B6F0\",\n      \"type\": \"function\",\n      \"address\": \"0x46B6F0\"\n    },\n    {\n      \"id\": \"func_0x46ED80\",\n      \"label\": \"Function 0x46ED80\",\n      \"type\": \"function\",\n      \"address\": \"0x46ED80\"\n    },\n    {\n      \"id\": \"func_0x47A0E0\",\n      \"label\": \"Function 0x47A0E0\",\n      \"type\": \"function\",\n      \"address\": \"0x47A0E0\"\n    },\n    {\n      \"id\": \"func_0x481F50\",\n      \"label\": \"Function 0x481F50\",\n      \"type\": \"function\",\n      \"address\": \"0x481F50\"\n    },\n    {\n      \"id\": \"func_0x479DC0\",\n      \"label\": \"Function 0x479DC0\",\n      \"type\": \"function\",\n      \"address\": \"0x479DC0\"\n    },\n    {\n      \"id\": \"func_0x479D70\",\n      \"label\": \"Function 0x479D70\",\n      \"type\": \"function\",\n      \"address\": \"0x479D70\"\n    },\n    {\n      \"id\": \"api_GetCurrentDirectory\",\n      \"label\": \"GetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempFileName\",\n      \"label\": \"GetTempFileName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_system_object_information\",\n      \"label\": \"get file system object information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x471CBE\",\n      \"label\": \"Block 0x471CBE\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x471CBE\"\n    },\n    {\n      \"id\": \"api_SHGetFileInfo\",\n      \"label\": \"SHGetFileInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_copy_file__2_matches_\",\n      \"label\": \"copy file (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"api_CopyFile\",\n      \"label\": \"CopyFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_file__5_matches_\",\n      \"label\": \"delete file (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46EA60\",\n      \"label\": \"Function 0x46EA60\",\n      \"type\": \"function\",\n      \"address\": \"0x46EA60\"\n    },\n    {\n      \"id\": \"func_0x477A20\",\n      \"label\": \"Function 0x477A20\",\n      \"type\": \"function\",\n      \"address\": \"0x477A20\"\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__7_matches_\",\n      \"label\": \"check if file exists (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4841A0\",\n      \"label\": \"Function 0x4841A0\",\n      \"type\": \"function\",\n      \"address\": \"0x4841A0\"\n    },\n    {\n      \"id\": \"func_0x46BA40\",\n      \"label\": \"Function 0x46BA40\",\n      \"type\": \"function\",\n      \"address\": \"0x46BA40\"\n    },\n    {\n      \"id\": \"func_0x4890E0\",\n      \"label\": \"Function 0x4890E0\",\n      \"type\": \"function\",\n      \"address\": \"0x4890E0\"\n    },\n    {\n      \"id\": \"func_0x475A80\",\n      \"label\": \"Function 0x475A80\",\n      \"type\": \"function\",\n      \"address\": \"0x475A80\"\n    },\n    {\n      \"id\": \"func_0x479FC0\",\n      \"label\": \"Function 0x479FC0\",\n      \"type\": \"function\",\n      \"address\": \"0x479FC0\"\n    },\n    {\n      \"id\": \"func_0x47E0B0\",\n      \"label\": \"Function 0x47E0B0\",\n      \"type\": \"function\",\n      \"address\": \"0x47E0B0\"\n    },\n    {\n      \"id\": \"func_0x484310\",\n      \"label\": \"Function 0x484310\",\n      \"type\": \"function\",\n      \"address\": \"0x484310\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_enumerate_files_on_windows\",\n      \"label\": \"enumerate files on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x478A40\",\n      \"label\": \"Function 0x478A40\",\n      \"type\": \"function\",\n      \"address\": \"0x478A40\"\n    },\n    {\n      \"id\": \"api_FindClose\",\n      \"label\": \"FindClose\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindNextFile\",\n      \"label\": \"FindNextFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindFirstFile\",\n      \"label\": \"FindFirstFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes__23_matches_\",\n      \"label\": \"get file attributes (23 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4846E4\",\n      \"label\": \"Block 0x4846E4\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4846E4\"\n    },\n    {\n      \"id\": \"bb_0x4845A4\",\n      \"label\": \"Block 0x4845A4\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4845A4\"\n    },\n    {\n      \"id\": \"bb_0x4844C8\",\n      \"label\": \"Block 0x4844C8\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4844C8\"\n    },\n    {\n      \"id\": \"bb_0x4855FA\",\n      \"label\": \"Block 0x4855FA\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4855FA\"\n    },\n    {\n      \"id\": \"bb_0x489776\",\n      \"label\": \"Block 0x489776\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x489776\"\n    },\n    {\n      \"id\": \"bb_0x485092\",\n      \"label\": \"Block 0x485092\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x485092\"\n    },\n    {\n      \"id\": \"bb_0x484407\",\n      \"label\": \"Block 0x484407\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x484407\"\n    },\n    {\n      \"id\": \"bb_0x4896E2\",\n      \"label\": \"Block 0x4896E2\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4896E2\"\n    },\n    {\n      \"id\": \"bb_0x484618\",\n      \"label\": \"Block 0x484618\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x484618\"\n    },\n    {\n      \"id\": \"bb_0x46F114\",\n      \"label\": \"Block 0x46F114\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46F114\"\n    },\n    {\n      \"id\": \"bb_0x479FC0\",\n      \"label\": \"Block 0x479FC0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x479FC0\"\n    },\n    {\n      \"id\": \"bb_0x48422E\",\n      \"label\": \"Block 0x48422E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x48422E\"\n    },\n    {\n      \"id\": \"bb_0x46BA40\",\n      \"label\": \"Block 0x46BA40\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46BA40\"\n    },\n    {\n      \"id\": \"bb_0x484D68\",\n      \"label\": \"Block 0x484D68\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x484D68\"\n    },\n    {\n      \"id\": \"bb_0x47E16A\",\n      \"label\": \"Block 0x47E16A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x47E16A\"\n    },\n    {\n      \"id\": \"bb_0x484750\",\n      \"label\": \"Block 0x484750\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x484750\"\n    },\n    {\n      \"id\": \"bb_0x4848A0\",\n      \"label\": \"Block 0x4848A0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4848A0\"\n    },\n    {\n      \"id\": \"bb_0x48445C\",\n      \"label\": \"Block 0x48445C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x48445C\"\n    },\n    {\n      \"id\": \"bb_0x484534\",\n      \"label\": \"Block 0x484534\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x484534\"\n    },\n    {\n      \"id\": \"bb_0x475A80\",\n      \"label\": \"Block 0x475A80\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x475A80\"\n    },\n    {\n      \"id\": \"bb_0x485433\",\n      \"label\": \"Block 0x485433\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x485433\"\n    },\n    {\n      \"id\": \"bb_0x484CD3\",\n      \"label\": \"Block 0x484CD3\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x484CD3\"\n    },\n    {\n      \"id\": \"bb_0x484678\",\n      \"label\": \"Block 0x484678\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x484678\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size__5_matches_\",\n      \"label\": \"get file size (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x465EB0\",\n      \"label\": \"Function 0x465EB0\",\n      \"type\": \"function\",\n      \"address\": \"0x465EB0\"\n    },\n    {\n      \"id\": \"func_0x486890\",\n      \"label\": \"Function 0x486890\",\n      \"type\": \"function\",\n      \"address\": \"0x486890\"\n    },\n    {\n      \"id\": \"func_0x477380\",\n      \"label\": \"Function 0x477380\",\n      \"type\": \"function\",\n      \"address\": \"0x477380\"\n    },\n    {\n      \"id\": \"func_0x477E40\",\n      \"label\": \"Function 0x477E40\",\n      \"type\": \"function\",\n      \"address\": \"0x477E40\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_file_version_info\",\n      \"label\": \"get file version info\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x488410\",\n      \"label\": \"Function 0x488410\",\n      \"type\": \"function\",\n      \"address\": \"0x488410\"\n    },\n    {\n      \"id\": \"api_VerQueryValue\",\n      \"label\": \"VerQueryValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfoSize\",\n      \"label\": \"GetFileVersionInfoSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfo\",\n      \"label\": \"GetFileVersionInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read__ini_file__5_matches_\",\n      \"label\": \"read .ini file (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x466940\",\n      \"label\": \"Function 0x466940\",\n      \"type\": \"function\",\n      \"address\": \"0x466940\"\n    },\n    {\n      \"id\": \"func_0x475630\",\n      \"label\": \"Function 0x475630\",\n      \"type\": \"function\",\n      \"address\": \"0x475630\"\n    },\n    {\n      \"id\": \"func_0x4756B0\",\n      \"label\": \"Function 0x4756B0\",\n      \"type\": \"function\",\n      \"address\": \"0x4756B0\"\n    },\n    {\n      \"id\": \"func_0x466A20\",\n      \"label\": \"Function 0x466A20\",\n      \"type\": \"function\",\n      \"address\": \"0x466A20\"\n    },\n    {\n      \"id\": \"api_GetPrivateProfileString\",\n      \"label\": \"GetPrivateProfileString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetPrivateProfileInt\",\n      \"label\": \"GetPrivateProfileInt\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__13_matches_\",\n      \"label\": \"read file on Windows (13 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x477590\",\n      \"label\": \"Function 0x477590\",\n      \"type\": \"function\",\n      \"address\": \"0x477590\"\n    },\n    {\n      \"id\": \"func_0x47CA10\",\n      \"label\": \"Function 0x47CA10\",\n      \"type\": \"function\",\n      \"address\": \"0x47CA10\"\n    },\n    {\n      \"id\": \"func_0x47CC50\",\n      \"label\": \"Function 0x47CC50\",\n      \"type\": \"function\",\n      \"address\": \"0x47CC50\"\n    },\n    {\n      \"id\": \"func_0x47C640\",\n      \"label\": \"Function 0x47C640\",\n      \"type\": \"function\",\n      \"address\": \"0x47C640\"\n    },\n    {\n      \"id\": \"func_0x47CB10\",\n      \"label\": \"Function 0x47CB10\",\n      \"type\": \"function\",\n      \"address\": \"0x47CB10\"\n    },\n    {\n      \"id\": \"func_0x477850\",\n      \"label\": \"Function 0x477850\",\n      \"type\": \"function\",\n      \"address\": \"0x477850\"\n    },\n    {\n      \"id\": \"func_0x47C090\",\n      \"label\": \"Function 0x47C090\",\n      \"type\": \"function\",\n      \"address\": \"0x47C090\"\n    },\n    {\n      \"id\": \"func_0x477CA0\",\n      \"label\": \"Function 0x477CA0\",\n      \"type\": \"function\",\n      \"address\": \"0x477CA0\"\n    },\n    {\n      \"id\": \"func_0x47C1A0\",\n      \"label\": \"Function 0x47C1A0\",\n      \"type\": \"function\",\n      \"address\": \"0x47C1A0\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_via_mapping\",\n      \"label\": \"read file via mapping\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFileMapping\",\n      \"label\": \"CreateFileMapping\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_MapViewOfFile\",\n      \"label\": \"MapViewOfFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_UnmapViewOfFile\",\n      \"label\": \"UnmapViewOfFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__17_matches_\",\n      \"label\": \"write file on Windows (17 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x470860\",\n      \"label\": \"Function 0x470860\",\n      \"type\": \"function\",\n      \"address\": \"0x470860\"\n    },\n    {\n      \"id\": \"func_0x472640\",\n      \"label\": \"Function 0x472640\",\n      \"type\": \"function\",\n      \"address\": \"0x472640\"\n    },\n    {\n      \"id\": \"func_0x472FB0\",\n      \"label\": \"Function 0x472FB0\",\n      \"type\": \"function\",\n      \"address\": \"0x472FB0\"\n    },\n    {\n      \"id\": \"func_0x472570\",\n      \"label\": \"Function 0x472570\",\n      \"type\": \"function\",\n      \"address\": \"0x472570\"\n    },\n    {\n      \"id\": \"func_0x474960\",\n      \"label\": \"Function 0x474960\",\n      \"type\": \"function\",\n      \"address\": \"0x474960\"\n    },\n    {\n      \"id\": \"func_0x472E90\",\n      \"label\": \"Function 0x472E90\",\n      \"type\": \"function\",\n      \"address\": \"0x472E90\"\n    },\n    {\n      \"id\": \"func_0x474770\",\n      \"label\": \"Function 0x474770\",\n      \"type\": \"function\",\n      \"address\": \"0x474770\"\n    },\n    {\n      \"id\": \"func_0x474520\",\n      \"label\": \"Function 0x474520\",\n      \"type\": \"function\",\n      \"address\": \"0x474520\"\n    },\n    {\n      \"id\": \"func_0x4737C0\",\n      \"label\": \"Function 0x4737C0\",\n      \"type\": \"function\",\n      \"address\": \"0x4737C0\"\n    },\n    {\n      \"id\": \"func_0x473A20\",\n      \"label\": \"Function 0x473A20\",\n      \"type\": \"function\",\n      \"address\": \"0x473A20\"\n    },\n    {\n      \"id\": \"func_0x472C00\",\n      \"label\": \"Function 0x472C00\",\n      \"type\": \"function\",\n      \"address\": \"0x472C00\"\n    },\n    {\n      \"id\": \"func_0x470F80\",\n      \"label\": \"Function 0x470F80\",\n      \"type\": \"function\",\n      \"address\": \"0x470F80\"\n    },\n    {\n      \"id\": \"func_0x4708E0\",\n      \"label\": \"Function 0x4708E0\",\n      \"type\": \"function\",\n      \"address\": \"0x4708E0\"\n    },\n    {\n      \"id\": \"func_0x4727D0\",\n      \"label\": \"Function 0x4727D0\",\n      \"type\": \"function\",\n      \"address\": \"0x4727D0\"\n    },\n    {\n      \"id\": \"func_0x48113A\",\n      \"label\": \"Function 0x48113A\",\n      \"type\": \"function\",\n      \"address\": \"0x48113A\"\n    },\n    {\n      \"id\": \"func_0x472220\",\n      \"label\": \"Function 0x472220\",\n      \"type\": \"function\",\n      \"address\": \"0x472220\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_gui_resources\",\n      \"label\": \"enumerate gui resources\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46F2B0\",\n      \"label\": \"Function 0x46F2B0\",\n      \"type\": \"function\",\n      \"address\": \"0x46F2B0\"\n    },\n    {\n      \"id\": \"api_EnumResourceTypes\",\n      \"label\": \"EnumResourceTypes\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     johnk3r, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_graphical_window_text__2_matches_\",\n      \"label\": \"get graphical window text (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4761B0\",\n      \"label\": \"Function 0x4761B0\",\n      \"type\": \"function\",\n      \"address\": \"0x4761B0\"\n    },\n    {\n      \"id\": \"func_0x4764B0\",\n      \"label\": \"Function 0x4764B0\",\n      \"type\": \"function\",\n      \"address\": \"0x4764B0\"\n    },\n    {\n      \"id\": \"api_GetWindowText\",\n      \"label\": \"GetWindowText\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hide_graphical_window__4_matches_\",\n      \"label\": \"hide graphical window (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x487EB7\",\n      \"label\": \"Block 0x487EB7\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x487EB7\"\n    },\n    {\n      \"id\": \"bb_0x46CA70\",\n      \"label\": \"Block 0x46CA70\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46CA70\"\n    },\n    {\n      \"id\": \"bb_0x46E543\",\n      \"label\": \"Block 0x46E543\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46E543\"\n    },\n    {\n      \"id\": \"bb_0x46F135\",\n      \"label\": \"Block 0x46F135\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46F135\"\n    },\n    {\n      \"id\": \"api_ShowWindow\",\n      \"label\": \"ShowWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_information\",\n      \"label\": \"get disk information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetDriveType\",\n      \"label\": \"GetDriveType\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_enumerate_internet_cache\",\n      \"label\": \"enumerate internet cache\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x476ED0\",\n      \"label\": \"Function 0x476ED0\",\n      \"type\": \"function\",\n      \"address\": \"0x476ED0\"\n    },\n    {\n      \"id\": \"api_FindFirstUrlCacheEntry\",\n      \"label\": \"FindFirstUrlCacheEntry\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindCloseUrlCache\",\n      \"label\": \"FindCloseUrlCache\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindNextUrlCacheEntry\",\n      \"label\": \"FindNextUrlCacheEntry\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_check_os_version\",\n      \"label\": \"check OS version\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x485840\",\n      \"label\": \"Function 0x485840\",\n      \"type\": \"function\",\n      \"address\": \"0x485840\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__5_matches_\",\n      \"label\": \"create process on Windows (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x46F5BD\",\n      \"label\": \"Block 0x46F5BD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46F5BD\"\n    },\n    {\n      \"id\": \"bb_0x46E32C\",\n      \"label\": \"Block 0x46E32C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46E32C\"\n    },\n    {\n      \"id\": \"bb_0x470344\",\n      \"label\": \"Block 0x470344\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x470344\"\n    },\n    {\n      \"id\": \"bb_0x470395\",\n      \"label\": \"Block 0x470395\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x470395\"\n    },\n    {\n      \"id\": \"bb_0x479A00\",\n      \"label\": \"Block 0x479A00\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x479A00\"\n    },\n    {\n      \"id\": \"api_ShellExecute\",\n      \"label\": \"ShellExecute\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_enumerate_processes\",\n      \"label\": \"enumerate processes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\",\n        \"Discovery::Software Discovery\",\n        \"[T1518]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46A230\",\n      \"label\": \"Function 0x46A230\",\n      \"type\": \"function\",\n      \"address\": \"0x46A230\"\n    },\n    {\n      \"id\": \"api_Process32Next\",\n      \"label\": \"Process32Next\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateToolhelp32Snapshot\",\n      \"label\": \"CreateToolhelp32Snapshot\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_Process32First\",\n      \"label\": \"Process32First\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40193E\",\n      \"label\": \"Function 0x40193E\",\n      \"type\": \"function\",\n      \"address\": \"0x40193E\"\n    },\n    {\n      \"id\": \"api_exit\",\n      \"label\": \"exit\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"label\": \"query or enumerate registry value (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4667E0\",\n      \"label\": \"Function 0x4667E0\",\n      \"type\": \"function\",\n      \"address\": \"0x4667E0\"\n    },\n    {\n      \"id\": \"func_0x4781D0\",\n      \"label\": \"Function 0x4781D0\",\n      \"type\": \"function\",\n      \"address\": \"0x4781D0\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value\",\n      \"label\": \"set registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_create_thread\",\n      \"label\": \"create thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x41154B\",\n      \"label\": \"Block 0x41154B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x41154B\"\n    },\n    {\n      \"id\": \"api__beginthreadex\",\n      \"label\": \"_beginthreadex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__36_matches_\",\n      \"label\": \"link function at runtime on Windows (36 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_many_functions_at_runtime__4_matches_\",\n      \"label\": \"link many functions at runtime (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x469E40\",\n      \"label\": \"Function 0x469E40\",\n      \"type\": \"function\",\n      \"address\": \"0x469E40\"\n    },\n    {\n      \"id\": \"func_0x46AA90\",\n      \"label\": \"Function 0x46AA90\",\n      \"type\": \"function\",\n      \"address\": \"0x46AA90\"\n    },\n    {\n      \"id\": \"func_0x46A850\",\n      \"label\": \"Function 0x46A850\",\n      \"type\": \"function\",\n      \"address\": \"0x46A850\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_linked_against_sqlite3\",\n      \"label\": \"linked against sqlite3\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____still_teamt5_org\",\n      \"label\": \"author     still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_enumerate_pe_sections__3_matches_\",\n      \"label\": \"enumerate PE sections (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x449830\",\n      \"label\": \"Function 0x449830\",\n      \"type\": \"function\",\n      \"address\": \"0x449830\"\n    },\n    {\n      \"id\": \"func_0x42DF60\",\n      \"label\": \"Function 0x42DF60\",\n      \"type\": \"function\",\n      \"address\": \"0x42DF60\"\n    },\n    {\n      \"id\": \"func_0x4484F0\",\n      \"label\": \"Function 0x4484F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4484F0\"\n    },\n    {\n      \"id\": \"cap_author_______ana06___mr_tz\",\n      \"label\": \"author      @Ana06, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header\",\n      \"label\": \"parse PE header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"label\": \"resolve function by parsing PE exports (28 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x4274A0\",\n      \"label\": \"Function 0x4274A0\",\n      \"type\": \"function\",\n      \"address\": \"0x4274A0\"\n    },\n    {\n      \"id\": \"func_0x43A8C0\",\n      \"label\": \"Function 0x43A8C0\",\n      \"type\": \"function\",\n      \"address\": \"0x43A8C0\"\n    },\n    {\n      \"id\": \"func_0x445080\",\n      \"label\": \"Function 0x445080\",\n      \"type\": \"function\",\n      \"address\": \"0x445080\"\n    },\n    {\n      \"id\": \"func_0x46B010\",\n      \"label\": \"Function 0x46B010\",\n      \"type\": \"function\",\n      \"address\": \"0x46B010\"\n    },\n    {\n      \"id\": \"func_0x458770\",\n      \"label\": \"Function 0x458770\",\n      \"type\": \"function\",\n      \"address\": \"0x458770\"\n    },\n    {\n      \"id\": \"func_0x42D080\",\n      \"label\": \"Function 0x42D080\",\n      \"type\": \"function\",\n      \"address\": \"0x42D080\"\n    },\n    {\n      \"id\": \"func_0x43D170\",\n      \"label\": \"Function 0x43D170\",\n      \"type\": \"function\",\n      \"address\": \"0x43D170\"\n    },\n    {\n      \"id\": \"func_0x43C8A0\",\n      \"label\": \"Function 0x43C8A0\",\n      \"type\": \"function\",\n      \"address\": \"0x43C8A0\"\n    },\n    {\n      \"id\": \"func_0x482C10\",\n      \"label\": \"Function 0x482C10\",\n      \"type\": \"function\",\n      \"address\": \"0x482C10\"\n    },\n    {\n      \"id\": \"func_0x453200\",\n      \"label\": \"Function 0x453200\",\n      \"type\": \"function\",\n      \"address\": \"0x453200\"\n    },\n    {\n      \"id\": \"func_0x448790\",\n      \"label\": \"Function 0x448790\",\n      \"type\": \"function\",\n      \"address\": \"0x448790\"\n    },\n    {\n      \"id\": \"func_0x45A790\",\n      \"label\": \"Function 0x45A790\",\n      \"type\": \"function\",\n      \"address\": \"0x45A790\"\n    },\n    {\n      \"id\": \"func_0x456FA0\",\n      \"label\": \"Function 0x456FA0\",\n      \"type\": \"function\",\n      \"address\": \"0x456FA0\"\n    },\n    {\n      \"id\": \"func_0x451C10\",\n      \"label\": \"Function 0x451C10\",\n      \"type\": \"function\",\n      \"address\": \"0x451C10\"\n    },\n    {\n      \"id\": \"func_0x43E5D0\",\n      \"label\": \"Function 0x43E5D0\",\n      \"type\": \"function\",\n      \"address\": \"0x43E5D0\"\n    },\n    {\n      \"id\": \"func_0x453BB0\",\n      \"label\": \"Function 0x453BB0\",\n      \"type\": \"function\",\n      \"address\": \"0x453BB0\"\n    },\n    {\n      \"id\": \"func_0x43B060\",\n      \"label\": \"Function 0x43B060\",\n      \"type\": \"function\",\n      \"address\": \"0x43B060\"\n    },\n    {\n      \"id\": \"func_0x4693D0\",\n      \"label\": \"Function 0x4693D0\",\n      \"type\": \"function\",\n      \"address\": \"0x4693D0\"\n    },\n    {\n      \"id\": \"func_0x46DA50\",\n      \"label\": \"Function 0x46DA50\",\n      \"type\": \"function\",\n      \"address\": \"0x46DA50\"\n    },\n    {\n      \"id\": \"func_0x44FAD0\",\n      \"label\": \"Function 0x44FAD0\",\n      \"type\": \"function\",\n      \"address\": \"0x44FAD0\"\n    },\n    {\n      \"id\": \"func_0x45B320\",\n      \"label\": \"Function 0x45B320\",\n      \"type\": \"function\",\n      \"address\": \"0x45B320\"\n    },\n    {\n      \"id\": \"func_0x452260\",\n      \"label\": \"Function 0x452260\",\n      \"type\": \"function\",\n      \"address\": \"0x452260\"\n    },\n    {\n      \"id\": \"func_0x4471E0\",\n      \"label\": \"Function 0x4471E0\",\n      \"type\": \"function\",\n      \"address\": \"0x4471E0\"\n    },\n    {\n      \"id\": \"func_0x451A00\",\n      \"label\": \"Function 0x451A00\",\n      \"type\": \"function\",\n      \"address\": \"0x451A00\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_persist_via_run_registry_key__3_matches_\",\n      \"label\": \"persist via Run registry key (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Registry Run Keys / Startup Folder [F0012]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__747_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__747_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x4014A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__12_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x478260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version__5_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_os_version__5_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x46A5E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46A5E0\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_process__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_process__4_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x46A2B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_time_delay_via_gettickcount\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount\",\n      \"target\": \"func_0x4750E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4750E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_credit_card_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_credit_card_information\",\n      \"target\": \"func_0x439DD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox\",\n      \"target\": \"func_0x439DD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_sql_statements__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_reference_sql_statements__2_matches_\",\n      \"target\": \"func_0x45E8B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_reference_sql_statements__2_matches_\",\n      \"target\": \"func_0x45EE50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x45E8B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x45EE50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"target\": \"func_0x46F590\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"target\": \"func_0x4741C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46F590\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4741C0\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46F590\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4741C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46F590\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4741C0\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_speck\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_speck\",\n      \"target\": \"func_0x45EE50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______still_teamt5_org\",\n      \"target\": \"func_0x45EE50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x465A20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x465A20\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465A20\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465A20\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465A20\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x465A20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x465A20\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465A20\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465A20\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465A20\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_clipboard__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_clipboard__3_matches_\",\n      \"target\": \"func_0x476940\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_open_clipboard__3_matches_\",\n      \"target\": \"func_0x46ECC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_open_clipboard__3_matches_\",\n      \"target\": \"func_0x46E560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x476940\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ECC0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E560\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476940\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ECC0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E560\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x476940\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46ECC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x476940\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ECC0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E560\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476940\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ECC0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E560\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_clipboard_data__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_clipboard_data__3_matches_\",\n      \"target\": \"func_0x476940\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_clipboard_data__3_matches_\",\n      \"target\": \"func_0x47B5A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_clipboard_data__3_matches_\",\n      \"target\": \"func_0x47A390\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x476940\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47B5A0\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A390\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476940\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47B5A0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A390\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476940\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47B5A0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A390\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476940\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47B5A0\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A390\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x476940\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47B5A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47A390\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x476940\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47B5A0\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A390\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476940\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47B5A0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A390\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476940\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47B5A0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A390\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476940\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47B5A0\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A390\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__2_matches_\",\n      \"target\": \"func_0x46E0B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__2_matches_\",\n      \"target\": \"func_0x482B00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46E0B0\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482B00\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x46E0B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x482B00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46E0B0\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482B00\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x471C90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x46B6F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x46ED80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x46ECC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x46E0B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x47A0E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x481F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x479DC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x479D70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x471C90\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B6F0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ED80\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ECC0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E0B0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0E0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F50\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479DC0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479D70\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x471C90\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B6F0\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ED80\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ECC0\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E0B0\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0E0\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F50\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479DC0\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479D70\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x471C90\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B6F0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ED80\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ECC0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E0B0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0E0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F50\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479DC0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479D70\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x471C90\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B6F0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ED80\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ECC0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E0B0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0E0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F50\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479DC0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479D70\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x471C90\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B6F0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ED80\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ECC0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E0B0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0E0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F50\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479DC0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479D70\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x471C90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46B6F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46ED80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46ECC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46E0B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47A0E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x481F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x479DC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x479D70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x471C90\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B6F0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ED80\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ECC0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E0B0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0E0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F50\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479DC0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479D70\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x471C90\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B6F0\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ED80\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ECC0\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E0B0\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0E0\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F50\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479DC0\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479D70\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x471C90\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B6F0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ED80\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ECC0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E0B0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0E0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F50\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479DC0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479D70\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x471C90\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B6F0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ED80\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ECC0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E0B0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0E0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F50\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479DC0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479D70\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x471C90\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B6F0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ED80\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ECC0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E0B0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0E0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F50\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479DC0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479D70\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_system_object_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_system_object_information\",\n      \"target\": \"bb_0x471CBE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x471CBE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_copy_file__2_matches_\",\n      \"target\": \"func_0x481F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_copy_file__2_matches_\",\n      \"target\": \"func_0x46B6F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481F50\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B6F0\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x481F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46B6F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481F50\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B6F0\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__5_matches_\",\n      \"target\": \"func_0x46B6F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__5_matches_\",\n      \"target\": \"func_0x46ECC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__5_matches_\",\n      \"target\": \"func_0x46EA60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__5_matches_\",\n      \"target\": \"func_0x481F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__5_matches_\",\n      \"target\": \"func_0x477A20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46B6F0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ECC0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EA60\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F50\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477A20\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46B6F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46ECC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46EA60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x481F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x477A20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46B6F0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46ECC0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EA60\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F50\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477A20\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__7_matches_\",\n      \"target\": \"func_0x4841A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__7_matches_\",\n      \"target\": \"func_0x46BA40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__7_matches_\",\n      \"target\": \"func_0x4890E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__7_matches_\",\n      \"target\": \"func_0x475A80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__7_matches_\",\n      \"target\": \"func_0x479FC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__7_matches_\",\n      \"target\": \"func_0x47E0B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__7_matches_\",\n      \"target\": \"func_0x484310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4841A0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BA40\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4890E0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475A80\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479FC0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47E0B0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x484310\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4841A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46BA40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4890E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x475A80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x479FC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47E0B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x484310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4841A0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BA40\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4890E0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475A80\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479FC0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47E0B0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x484310\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows\",\n      \"target\": \"func_0x478A40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x478A40\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478A40\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478A40\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x478A40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x478A40\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478A40\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478A40\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__23_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x4846E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x4845A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x4844C8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x4855FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x489776\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x485092\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x484407\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x4896E2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x484618\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x46F114\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x479FC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x48422E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x46BA40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x484D68\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x47E16A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x484750\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x4848A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x48445C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x484534\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x475A80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x485433\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x484CD3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__23_matches_\",\n      \"target\": \"bb_0x484678\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4846E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4845A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4844C8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4855FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x489776\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x485092\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x484407\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4896E2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x484618\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x46F114\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x479FC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x48422E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x46BA40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x484D68\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x47E16A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x484750\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4848A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x48445C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x484534\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x475A80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x485433\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x484CD3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x484678\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size__5_matches_\",\n      \"target\": \"func_0x465EB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__5_matches_\",\n      \"target\": \"func_0x486890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__5_matches_\",\n      \"target\": \"func_0x47B5A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__5_matches_\",\n      \"target\": \"func_0x477380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__5_matches_\",\n      \"target\": \"func_0x477E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x465EB0\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x486890\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47B5A0\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477380\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477E40\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x465EB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x486890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47B5A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x477380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x477E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x465EB0\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x486890\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47B5A0\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477380\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477E40\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_version_info\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_version_info\",\n      \"target\": \"func_0x488410\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x488410\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x488410\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x488410\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x488410\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x488410\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x488410\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x488410\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read__ini_file__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__5_matches_\",\n      \"target\": \"func_0x466940\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__5_matches_\",\n      \"target\": \"func_0x475630\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__5_matches_\",\n      \"target\": \"func_0x4756B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__5_matches_\",\n      \"target\": \"func_0x475A80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__5_matches_\",\n      \"target\": \"func_0x466A20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x466940\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475630\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4756B0\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475A80\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x466A20\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x466940\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475630\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4756B0\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475A80\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x466A20\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x466940\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x475630\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4756B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x475A80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x466A20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x466940\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475630\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4756B0\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475A80\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x466A20\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x466940\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475630\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4756B0\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475A80\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x466A20\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__13_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__13_matches_\",\n      \"target\": \"func_0x477590\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__13_matches_\",\n      \"target\": \"func_0x465EB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__13_matches_\",\n      \"target\": \"func_0x47CA10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__13_matches_\",\n      \"target\": \"func_0x486890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__13_matches_\",\n      \"target\": \"func_0x47CC50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__13_matches_\",\n      \"target\": \"func_0x47C640\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__13_matches_\",\n      \"target\": \"func_0x47B5A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__13_matches_\",\n      \"target\": \"func_0x47CB10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__13_matches_\",\n      \"target\": \"func_0x477850\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__13_matches_\",\n      \"target\": \"func_0x47C090\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__13_matches_\",\n      \"target\": \"func_0x477CA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__13_matches_\",\n      \"target\": \"func_0x47C1A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__13_matches_\",\n      \"target\": \"func_0x477E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x477590\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465EB0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CA10\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x486890\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CC50\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C640\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47B5A0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CB10\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477850\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C090\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477CA0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C1A0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477E40\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477590\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465EB0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CA10\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x486890\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CC50\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C640\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47B5A0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CB10\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477850\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C090\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477CA0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C1A0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477E40\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x477590\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x465EB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47CA10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x486890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47CC50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47C640\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47B5A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47CB10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x477850\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47C090\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x477CA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47C1A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x477E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x477590\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465EB0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CA10\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x486890\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CC50\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C640\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47B5A0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CB10\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477850\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C090\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477CA0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C1A0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477E40\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477590\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x465EB0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CA10\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x486890\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CC50\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C640\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47B5A0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CB10\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477850\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C090\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477CA0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47C1A0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477E40\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_via_mapping\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_via_mapping\",\n      \"target\": \"func_0x477380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x477380\",\n      \"target\": \"api_CreateFileMapping\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477380\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477380\",\n      \"target\": \"api_MapViewOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477380\",\n      \"target\": \"api_UnmapViewOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x477380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x477380\",\n      \"target\": \"api_CreateFileMapping\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477380\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477380\",\n      \"target\": \"api_MapViewOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477380\",\n      \"target\": \"api_UnmapViewOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__17_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x470860\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x472640\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x472FB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x472570\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x474960\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x472E90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x474770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x474520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x4737C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x473A20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x472C00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x470F80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x477380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x4708E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x4727D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x48113A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__17_matches_\",\n      \"target\": \"func_0x472220\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x470860\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472640\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472FB0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472570\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474960\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472E90\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474770\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474520\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4737C0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473A20\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472C00\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470F80\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477380\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4708E0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4727D0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48113A\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472220\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470860\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472640\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472FB0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472570\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474960\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472E90\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474770\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474520\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4737C0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473A20\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472C00\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470F80\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477380\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4708E0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4727D0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48113A\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472220\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x470860\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472640\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472FB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472570\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x474960\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472E90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x474770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x474520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4737C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x473A20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472C00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x470F80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x477380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4708E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4727D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48113A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472220\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x470860\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472640\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472FB0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472570\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474960\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472E90\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474770\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474520\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4737C0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473A20\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472C00\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470F80\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477380\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4708E0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4727D0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48113A\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472220\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470860\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472640\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472FB0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472570\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474960\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472E90\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474770\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474520\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4737C0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473A20\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472C00\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470F80\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x477380\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4708E0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4727D0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48113A\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472220\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_gui_resources\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_gui_resources\",\n      \"target\": \"func_0x46F2B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46F2B0\",\n      \"target\": \"api_EnumResourceTypes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46F2B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46F2B0\",\n      \"target\": \"api_EnumResourceTypes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_graphical_window_text__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__2_matches_\",\n      \"target\": \"func_0x4761B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__2_matches_\",\n      \"target\": \"func_0x4764B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4761B0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4764B0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4761B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4764B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4761B0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4764B0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hide_graphical_window__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__4_matches_\",\n      \"target\": \"bb_0x487EB7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__4_matches_\",\n      \"target\": \"bb_0x46CA70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__4_matches_\",\n      \"target\": \"bb_0x46E543\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__4_matches_\",\n      \"target\": \"bb_0x46F135\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x487EB7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x46CA70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x46E543\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x46F135\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information\",\n      \"target\": \"func_0x477380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x477380\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x477380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x477380\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_internet_cache\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_internet_cache\",\n      \"target\": \"func_0x476ED0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x476ED0\",\n      \"target\": \"api_FindFirstUrlCacheEntry\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476ED0\",\n      \"target\": \"api_FindCloseUrlCache\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476ED0\",\n      \"target\": \"api_FindNextUrlCacheEntry\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x476ED0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x476ED0\",\n      \"target\": \"api_FindFirstUrlCacheEntry\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476ED0\",\n      \"target\": \"api_FindCloseUrlCache\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476ED0\",\n      \"target\": \"api_FindNextUrlCacheEntry\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_os_version\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_os_version\",\n      \"target\": \"func_0x485840\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x485840\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x485840\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x485840\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__5_matches_\",\n      \"target\": \"bb_0x46F5BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__5_matches_\",\n      \"target\": \"bb_0x46E32C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__5_matches_\",\n      \"target\": \"bb_0x470344\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__5_matches_\",\n      \"target\": \"bb_0x470395\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__5_matches_\",\n      \"target\": \"bb_0x479A00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x46F5BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x46E32C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x470344\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x470395\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x479A00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_processes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_processes\",\n      \"target\": \"func_0x46A230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46A230\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A230\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A230\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46A230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46A230\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A230\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A230\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x40193E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40193E\",\n      \"target\": \"api_exit\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40193E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40193E\",\n      \"target\": \"api_exit\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"target\": \"func_0x4890E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"target\": \"func_0x4667E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"target\": \"func_0x485840\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"target\": \"func_0x4781D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4890E0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4667E0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x485840\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4781D0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4890E0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4667E0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x485840\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4781D0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4890E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4667E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x485840\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4781D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4890E0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4667E0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x485840\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4781D0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4890E0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4667E0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x485840\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4781D0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value\",\n      \"target\": \"func_0x4667E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4667E0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4667E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4667E0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread\",\n      \"target\": \"bb_0x41154B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x41154B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__36_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_many_functions_at_runtime__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__4_matches_\",\n      \"target\": \"func_0x46A230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__4_matches_\",\n      \"target\": \"func_0x469E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__4_matches_\",\n      \"target\": \"func_0x46AA90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__4_matches_\",\n      \"target\": \"func_0x46A850\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x46A230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x469E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x46AA90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x46A850\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_sqlite3\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_pe_sections__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__3_matches_\",\n      \"target\": \"func_0x449830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__3_matches_\",\n      \"target\": \"func_0x42DF60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__3_matches_\",\n      \"target\": \"func_0x4484F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______ana06___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x449830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x42DF60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x4484F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header\",\n      \"target\": \"func_0x40193E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x40193E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x4274A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x449830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x43A8C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x445080\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x46B010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x458770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x481F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x42D080\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x43D170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x43C8A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x482C10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x45EE50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x453200\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x448790\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x45A790\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x456FA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x451C10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x43E5D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x453BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x43B060\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x4693D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x46DA50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x44FAD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x45B320\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x452260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x484310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x4471E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__28_matches_\",\n      \"target\": \"func_0x451A00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x4274A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x449830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x43A8C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x445080\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x46B010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x458770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x481F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x42D080\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x43D170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x43C8A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x482C10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x45EE50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x453200\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x448790\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x45A790\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x456FA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x451C10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x43E5D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x453BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x43B060\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x4693D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x46DA50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x44FAD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x45B320\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x452260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x484310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x4471E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x451A00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_persist_via_run_registry_key__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_persist_via_run_registry_key__3_matches_\",\n      \"target\": \"func_0x4890E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_persist_via_run_registry_key__3_matches_\",\n      \"target\": \"func_0x4781D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_persist_via_run_registry_key__3_matches_\",\n      \"target\": \"func_0x485840\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x4890E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x4781D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x485840\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-05-24 21:09:20.973471\",\n    \"total_functions\": \"1623\",\n    \"total_features\": \"118065\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-05-24 21:09:24"}
{"_id":{"$oid":"6a13e5ba32de6bb6782baac6"},"sha256":"637175bedfe6852886341e15c4d48241d7a58083a45272df0aac35469c653f6f","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_50chlbjt/001_upx_unpacked.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_50chlbjt/001_upx_unpacked.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_50chlbjt/001_upx_unpacked.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 8f293fe4c3cfcbc2e5981327e228d80a                                  │\n│ sha1     │ d47b85ee7ed12c5a32dd9409fdd805359f3f82e8                          │\n│ sha256   │ ce8b3d8414576a20ee60cfabc560360f602ac6715ffd1e546b508cd5be5394aa  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /tmp/sdm_unpack_5820llhr/WirelessNetView-019e5db7803a7fb0825cc53… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic             ┃ ATT&CK Technique                                 ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION                │ Clipboard Data [T1115]                           │\n│                           │ Input Capture::Keylogging [T1056.001]            │\n│ DEFENSE EVASION           │ Hide Artifacts::Hidden Window [T1564.003]        │\n│                           │ Obfuscated Files or Information [T1027]          │\n│ DISCOVERY                 │ Application Window Discovery [T1010]             │\n│                           │ File and Directory Discovery [T1083]             │\n│                           │ Query Registry [T1012]                           │\n│                           │ System Location Discovery [T1614]                │\n│ EXECUTION                 │ Shared Modules [T1129]                           │\n└───────────────────────────┴──────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Keylogging::Polling [F0002.002]                       │\n│ DATA                 │ Encode Data::XOR [C0026.002]                          │\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Encoding-Standard    │\n│                      │ Algorithm [E1027.m02]                                 │\n│ DISCOVERY            │ Application Window Discovery [E1010]                  │\n│                      │ File and Directory Discovery [E1083]                  │\n│ FILE SYSTEM          │ Delete File [C0047]                                   │\n│                      │ Get File Attributes [C0049]                           │\n│                      │ Read File [C0051]                                     │\n│                      │ Writes File [C0052]                                   │\n│ IMPACT               │ Clipboard Modification [E1510]                        │\n│ OPERATING SYSTEM     │ Registry::Query Registry Value [C0036.006]            │\n│ PROCESS              │ Create Process [C0017]                                │\n│                      │ Create Thread [C0038]                                 │\n│                      │ Terminate Process [C0018]                             │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ get geographical location             │ collection                           │\n│ log keystrokes via polling (3         │ collection/keylog                    │\n│ matches)                              │                                      │\n│ encode data using XOR                 │ data-manipulation/encoding/xor       │\n│ contains PDB path                     │ executable/pe/pdb                    │\n│ extract resource via kernel32         │ executable/resource                  │\n│ functions                             │                                      │\n│ open clipboard                        │ host-interaction/clipboard           │\n│ write clipboard data                  │ host-interaction/clipboard           │\n│ get common file path (2 matches)      │ host-interaction/file-system         │\n│ get file system object information    │ host-interaction/file-system         │\n│ delete file                           │ host-interaction/file-system/delete  │\n│ check if file exists                  │ host-interaction/file-system/exists  │\n│ get file attributes                   │ host-interaction/file-system/meta    │\n│ get file size (3 matches)             │ host-interaction/file-system/meta    │\n│ read .ini file (7 matches)            │ host-interaction/file-system/read    │\n│ read file on Windows (2 matches)      │ host-interaction/file-system/read    │\n│ write file on Windows (3 matches)     │ host-interaction/file-system/write   │\n│ enumerate gui resources               │ host-interaction/gui                 │\n│ find graphical window                 │ host-interaction/gui/window/find     │\n│ get graphical window text (2 matches) │ host-interaction/gui/window/get-text │\n│ hide graphical window (2 matches)     │ host-interaction/gui/window/hide     │\n│ create process on Windows             │ host-interaction/process/create      │\n│ terminate process (2 matches)         │ host-interaction/process/terminate   │\n│ query or enumerate registry value     │ host-interaction/registry            │\n│ create thread (2 matches)             │ host-interaction/thread/create       │\n│ link function at runtime on Windows   │ linking/runtime-linking              │\n│ (35 matches)                          │                                      │\n│ link many functions at runtime (4     │ linking/runtime-linking              │\n│ matches)                              │                                      │\n│ parse PE header                       │ load-code/pe                         │\n│ resolve function by parsing PE        │ load-code/pe                         │\n│ exports (2 matches)                   │                                      │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     8f293fe4c3cfcbc2e5981327e228d80a                        \nsha1                    d47b85ee7ed12c5a32dd9409fdd805359f3f82e8                \nsha256                  ce8b3d8414576a20ee60cfabc560360f602ac6715ffd1e546b508cd…\npath                    /tmp/sdm_unpack_5820llhr/WirelessNetView-019e5db7803a7f…\ntimestamp               2026-05-25 11:31:19.421276                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIdI6Zur/rules                                   \nfunction count          367                                                     \nlibrary function count  2                                                       \ntotal feature count     17372                                                   \n\nget geographical location\nnamespace  collection\nscope      function  \nmatches    0x405023  \n\nlog keystrokes via polling (3 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    0x4044BC         \n           0x4044CF         \n           0x40AF40         \n\nencode data using XOR\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x40C929                      \n\ncontains PDB path\nnamespace  executable/pe/pdb\nscope      file             \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x40C8D5           \n\nopen clipboard\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x409DB4                  \n\nwrite clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x404949                  \n\nget common file path (2 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x404D61                    \n           0x409DB4                    \n\nget file system object information\nnamespace  host-interaction/file-system\nscope      basic block                 \nmatches    0x4083D0                    \n\ndelete file\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x409DB4                           \n\ncheck if file exists\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x404B74                           \n\nget file attributes\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x404B74                         \n\nget file size (3 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x404949                         \n           0x4087D8                         \n           0x408E1D                         \n\nread .ini file (7 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x4060D8                         \n           0x4060FD                         \n           0x406170                         \n           0x40652E                         \n           0x40C62F                         \n           0x40C6D5                         \n           0x40C853                         \n\nread file on Windows (2 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x404949                         \n           0x405317                         \n\nwrite file on Windows (3 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x404783                          \n           0x405336                          \n           0x40756E                          \n\nenumerate gui resources\nnamespace  host-interaction/gui\nscope      function            \nmatches    0x40B84A            \n\nfind graphical window\nnamespace  host-interaction/gui/window/find\nscope      instruction                     \nmatches    0x40B943                        \n\nget graphical window text (2 matches)\nnamespace  host-interaction/gui/window/get-text\nscope      function                            \nmatches    0x40630B                            \n           0x4063CA                            \n\nhide graphical window (2 matches)\nnamespace  host-interaction/gui/window/hide\nscope      basic block                     \nmatches    0x40127C                        \n           0x40B2AA                        \n\ncreate process on Windows\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x4051A5                       \n\nterminate process (2 matches)\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x401801                          \n           0x40D3D0                          \n\nquery or enumerate registry value\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x40C721                 \n\ncreate thread (2 matches)\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x4095D1                      \n           0x40A9DA                      \n\nlink function at runtime on Windows (35 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x403339               \n           0x40BDB4               \n           0x40BDC5               \n           0x40BDD6               \n           0x40BDE7               \n           0x40BDF8               \n           0x40BE3C               \n           0x40BE4D               \n           0x40BE5E               \n           0x40BE6F               \n           0x40BE80               \n           0x40C99E               \n           0x40C9B0               \n           0x40C9C2               \n           0x40C9D4               \n           0x40C9E6               \n           0x40C9F8               \n           0x40CA0A               \n           0x40CA1C               \n           0x40CA2E               \n           0x40CA40               \n           0x40CB8B               \n           0x40D0DF               \n           0x40D0EB               \n           0x40D0F7               \n           0x40D103               \n           0x40D10F               \n           0x40D11B               \n           0x40D127               \n           0x40D133               \n           0x40D13F               \n           0x40D14B               \n           0x40D1F2               \n           0x40D1FE               \n           0x40D20A               \n\nlink many functions at runtime (4 matches)\nnamespace  linking/runtime-linking\nscope      function               \nmatches    0x40BD8C               \n           0x40BE10               \n           0x40C976               \n           0x40D0B8               \n\nparse PE header\nnamespace  load-code/pe\nscope      function    \nmatches    0x40D3D0    \n\nresolve function by parsing PE exports (2 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x4024E9    \n           0x40C1F3    \n\n\n\n","very_verbose":"md5                     8f293fe4c3cfcbc2e5981327e228d80a                        \nsha1                    d47b85ee7ed12c5a32dd9409fdd805359f3f82e8                \nsha256                  ce8b3d8414576a20ee60cfabc560360f602ac6715ffd1e546b508cd…\npath                    /tmp/sdm_unpack_5820llhr/WirelessNetView-019e5db7803a7f…\ntimestamp               2026-05-25 11:31:29.560369                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIAwryS5/rules                                   \nfunction count          367                                                     \nlibrary function count  2                                                       \ntotal feature count     17372                                                   \n\ncontain loop (90 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401000\n  or:\n    characteristic: loop @ 0x401000\n\ncreate or open file (3 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x404763\n  or:\n    api: CreateFile @ 0x404763\n\ncreate or open registry key (library rule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x40C706 in function 0x40C706\n  or:\n    api: RegOpenKeyEx @ 0x40C71A\n\ndelay execution (2 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x4095D1 in function 0x4094FF\n  or:\n    and:\n      os: windows\n      or:\n        api: WaitForSingleObject @ 0x409603\n\nget OS version (library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x404CA1\n  or:\n    api: GetVersionEx @ 0x404CBB\n\nopen process (library rule)\nauthor  0x534a@mailbox.org           \nscope   basic block                  \nmbc     Process::Open Process [C0065]\nbasic block @ 0x40BFC0 in function 0x40BF8E\n  or:\n    api: OpenProcess @ 0x40BFC9\n\nget geographical location\nnamespace  collection                                  \nauthor     moritz.raabe, michael.hunhoff@mandiant.com  \nscope      function                                    \natt&ck     Discovery::System Location Discovery [T1614]\nfunction @ 0x405023\n  or:\n    api: GetLocaleInfo @ 0x40504C, 0x40505E, 0x405076, 0x405089, and 1 more...\n\nlog keystrokes via polling (3 matches)\nnamespace  collection/keylog                                \nauthor     michael.hunhoff@mandiant.com                     \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nmbc        Collection::Keylogging::Polling [F0002.002]      \nfunction @ 0x4044BC\n  or:\n    api: GetKeyState @ 0x4044C0\nfunction @ 0x4044CF\n  or:\n    api: GetKeyState @ 0x4044E8\nfunction @ 0x40AF40\n  or:\n    api: GetKeyState @ 0x40B039\n\nencode data using XOR\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x40C929 in function 0x40C8D5\n  and:\n    characteristic: tight loop @ 0x40C929\n    characteristic: nzxor @ 0x40C939\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\ncontains PDB path\nnamespace  executable/pe/pdb        \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nregex: /:\\\\.*\\.pdb/\n  - \"c:\\\\Projects\\\\VS2005\\\\WirelessNetView\\\\Release\\\\WirelessNetView.pdb\" @ file+0xE7B0\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x40C8D5\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x40C903\n        api: LockResource @ 0x40C90E\n      optional:\n        or:\n          api: FindResource @ 0x40C8E2\n        api: SizeofResource @ 0x40C8F3\n\nopen clipboard\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ 0x409DB4\n  and:\n    api: OpenClipboard @ 0x409E2C\n\nwrite clipboard data\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \nmbc         Impact::Clipboard Modification [E1510]                              \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ 0x404949\n  and:\n    optional:\n      api: EmptyClipboard @ 0x404953\n    or:\n      api: SetClipboardData @ 0x4049BC\n\nget common file path (2 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x404D61\n  or:\n    api: GetWindowsDirectory @ 0x404D77\nfunction @ 0x409DB4\n  or:\n    api: GetTempPath @ 0x409DCE\n    api: GetTempFileName @ 0x409E03\n    api: GetWindowsDirectory @ 0x409DE0\n\nget file system object information\nnamespace  host-interaction/file-system                   \nauthor     michael.hunhoff@mandiant.com                   \nscope      basic block                                    \natt&ck     Discovery::File and Directory Discovery [T1083]\nbasic block @ 0x4083D0 in function 0x4083A2\n  or:\n    api: SHGetFileInfo @ 0x4083FC\n\ndelete file\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x409DB4\n  or:\n    api: DeleteFile @ 0x409E64\n\ncheck if file exists\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x404B74\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x404B78\n        instruction:\n          and:\n            mnemonic: cmp @ 0x404B80\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x404B80\n\nget file attributes\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x404B74 in function 0x404B74\n  or:\n    api: GetFileAttributes @ 0x404B78\n\nget file size (3 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x404949\n  or:\n    api: GetFileSize @ 0x404970\nfunction @ 0x4087D8\n  or:\n    api: GetFileSize @ 0x4087FD\nfunction @ 0x408E1D\n  or:\n    api: GetFileSize @ 0x408E3D\n\nread .ini file (7 matches)\nnamespace  host-interaction/file-system/read     \nauthor     @_re_fox, michael.hunhoff@mandiant.com\nscope      function                              \nmbc        File System::Read File [C0051]        \nfunction @ 0x4060D8\n  and:\n    or:\n      api: GetPrivateProfileString @ 0x4060F4\nfunction @ 0x4060FD\n  and:\n    or:\n      api: GetPrivateProfileString @ 0x406146\nfunction @ 0x406170\n  and:\n    or:\n      api: GetPrivateProfileString @ 0x4061BD\nfunction @ 0x40652E\n  and:\n    or:\n      api: GetPrivateProfileInt @ 0x406569\nfunction @ 0x40C62F\n  and:\n    or:\n      api: GetPrivateProfileString @ 0x40C6B0\nfunction @ 0x40C6D5\n  and:\n    or:\n      api: GetPrivateProfileInt @ 0x40C6FC\nfunction @ 0x40C853\n  and:\n    or:\n      api: GetPrivateProfileString @ 0x40C882\n\nread file on Windows (2 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x404949\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x4049A1\nfunction @ 0x405317\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x40532E\n\nwrite file on Windows (3 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x404783\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x40479F\nfunction @ 0x405336\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x40534D\nfunction @ 0x40756E\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x4075CF\n\nenumerate gui resources\nnamespace  host-interaction/gui                           \nauthor     johnk3r, anushka.virgaonkar@mandiant.com       \nscope      function                                       \natt&ck     Discovery::Application Window Discovery [T1010]\nfunction @ 0x40B84A\n  or:\n    api: EnumResourceTypes @ 0x40B88F\n\nfind graphical window\nnamespace  host-interaction/gui/window/find               \nauthor     moritz.raabe@mandiant.com                      \nscope      instruction                                    \natt&ck     Discovery::Application Window Discovery [T1010]\ninstruction @ 0x40B943\n  or:\n    api: FindWindow @ 0x40B943\n\nget graphical window text (2 matches)\nnamespace  host-interaction/gui/window/get-text           \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \nmbc        Discovery::Application Window Discovery [E1010]\nfunction @ 0x40630B\n  or:\n    and:\n      api: GetWindowText @ 0x406352\nfunction @ 0x4063CA\n  or:\n    and:\n      api: GetWindowText @ 0x40648E\n\nhide graphical window (2 matches)\nnamespace  host-interaction/gui/window/hide                          \nauthor     michael.hunhoff@mandiant.com                              \nscope      basic block                                               \natt&ck     Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\nbasic block @ 0x40127C in function 0x40109F\n  and:\n    number: 0x0 = SW_HIDE @ 0x401282, 0x401297\n    api: ShowWindow @ 0x401295, 0x4012A4\nbasic block @ 0x40B2AA in function 0x40B0C6\n  and:\n    number: 0x0 = SW_HIDE @ 0x40B2AA\n    api: ShowWindow @ 0x40B2B2\n\ncreate process on Windows\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x4051A5 in function 0x4051A5\n  or:\n    api: ShellExecute @ 0x4051BB\n\nterminate process (2 matches)\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x401801\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x40180F\nfunction @ 0x40D3D0\n  or:\n    api: exit @ 0x40D573\n\nquery or enumerate registry value\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x40C721\n  and:\n    or:\n      api: RegQueryValueEx @ 0x40C73C\n\ncreate thread (2 matches)\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x4095D1 in function 0x4094FF\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x4095FA\nbasic block @ 0x40A9DA in function 0x40A9CC\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x40A9EA\n\nlink function at runtime on Windows (35 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x403339\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x403339\ninstruction @ 0x40BDB4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40BDB4\ninstruction @ 0x40BDC5\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40BDC5\ninstruction @ 0x40BDD6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40BDD6\ninstruction @ 0x40BDE7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40BDE7\ninstruction @ 0x40BDF8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40BDF8\ninstruction @ 0x40BE3C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40BE3C\ninstruction @ 0x40BE4D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40BE4D\ninstruction @ 0x40BE5E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40BE5E\ninstruction @ 0x40BE6F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40BE6F\ninstruction @ 0x40BE80\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40BE80\ninstruction @ 0x40C99E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40C99E\ninstruction @ 0x40C9B0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40C9B0\ninstruction @ 0x40C9C2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40C9C2\ninstruction @ 0x40C9D4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40C9D4\ninstruction @ 0x40C9E6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40C9E6\ninstruction @ 0x40C9F8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40C9F8\ninstruction @ 0x40CA0A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40CA0A\ninstruction @ 0x40CA1C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40CA1C\ninstruction @ 0x40CA2E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40CA2E\ninstruction @ 0x40CA40\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40CA40\ninstruction @ 0x40CB8B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40CB8B\ninstruction @ 0x40D0DF\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40D0DF\ninstruction @ 0x40D0EB\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40D0EB\ninstruction @ 0x40D0F7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40D0F7\ninstruction @ 0x40D103\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40D103\ninstruction @ 0x40D10F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40D10F\ninstruction @ 0x40D11B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40D11B\ninstruction @ 0x40D127\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40D127\ninstruction @ 0x40D133\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40D133\ninstruction @ 0x40D13F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40D13F\ninstruction @ 0x40D14B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40D14B\ninstruction @ 0x40D1F2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40D1F2\ninstruction @ 0x40D1FE\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40D1FE\ninstruction @ 0x40D20A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40D20A\n\nlink many functions at runtime (4 matches)\nnamespace  linking/runtime-linking                      \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com\nscope      function                                     \natt&ck     Execution::Shared Modules [T1129]            \nfunction @ 0x40BD8C\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x40BDB4, 0x40BDC5, 0x40BDD6, 0x40BDE7, and 1 more...\nfunction @ 0x40BE10\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x40BE3C, 0x40BE4D, 0x40BE5E, 0x40BE6F, and 1 more...\nfunction @ 0x40C976\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x40C99E, 0x40C9B0, 0x40C9C2, 0x40C9D4, and 6 more...\nfunction @ 0x40D0B8\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x40D0DF, 0x40D0EB, 0x40D0F7, 0x40D103, and 6 more...\n\nparse PE header\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x40D3D0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x40D3E5, 0x40D3F1, 0x40D3FD, 0x40D404, and 14 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x40D3F1\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x40D3E5\n\nresolve function by parsing PE exports (2 matches)\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x4024E9\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x4024E9\n      mnemonic: movzx @ 0x4027F8, 0x402822, 0x40294A, 0x40294E, and 7 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x402802\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x4025C2, 0x4026ED, 0x402A70\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x4028E2, 0x402A78\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x40270C, 0x402743, 0x402783, 0x402854, and 3 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x4028B6, 0x402966, 0x40296A, 0x402AA5, and 3 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x4026B4, 0x402986, 0x402A21, 0x402A2B, and 6 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x40277D, 0x40295A, 0x402A01, 0x402AE3, and 5 more...\nfunction @ 0x40C1F3\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x40C1F3\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x40C4B1, 0x40C4F0, 0x40C52E\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x40C2A5, 0x40C2C0, 0x40C3C0\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x40C23F, 0x40C254, 0x40C275, 0x40C2B0, and 12 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x40C39C, 0x40C3A9\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x40C21C, 0x40C38D, 0x40C398, 0x40C463\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x40C237, 0x40C2FB, 0x40C3A2, 0x40C3EA, and 1 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x40C2DC, 0x40C35F, 0x40C3B9, 0x40C419, and 1 more...\n\n\n\n"},"hashes":{"md5":"8f293fe4c3cfcbc2e5981327e228d80a","sha1":"d47b85ee7ed12c5a32dd9409fdd805359f3f82e8","sha256":"ce8b3d8414576a20ee60cfabc560360f602ac6715ffd1e546b508cd5be5394aa"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 367</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 17372</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"WirelessNetView-019e5db7803a7f\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"8f293fe4c3cfcbc2e5981327e228d80a\",\n        \"sha256\": \"ce8b3d8414576a20ee60cfabc560360f602ac6715ffd1e546b508cd\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__90_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (90 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401000\",\n      \"label\": \"Function 0x401000\",\n      \"type\": \"function\",\n      \"address\": \"0x401000\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__3_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (3 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4095D1\",\n      \"label\": \"Block 0x4095D1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4095D1\"\n    },\n    {\n      \"id\": \"api_WaitForSingleObject\",\n      \"label\": \"WaitForSingleObject\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_geographical_location\",\n      \"label\": \"get geographical location\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405023\",\n      \"label\": \"Function 0x405023\",\n      \"type\": \"function\",\n      \"address\": \"0x405023\"\n    },\n    {\n      \"id\": \"api_GetLocaleInfo\",\n      \"label\": \"GetLocaleInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_polling__3_matches_\",\n      \"label\": \"log keystrokes via polling (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40AF40\",\n      \"label\": \"Function 0x40AF40\",\n      \"type\": \"function\",\n      \"address\": \"0x40AF40\"\n    },\n    {\n      \"id\": \"func_0x4044CF\",\n      \"label\": \"Function 0x4044CF\",\n      \"type\": \"function\",\n      \"address\": \"0x4044CF\"\n    },\n    {\n      \"id\": \"func_0x4044BC\",\n      \"label\": \"Function 0x4044BC\",\n      \"type\": \"function\",\n      \"address\": \"0x4044BC\"\n    },\n    {\n      \"id\": \"api_GetKeyState\",\n      \"label\": \"GetKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contains_pdb_path\",\n      \"label\": \"contains PDB path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x40C8D5\",\n      \"label\": \"Function 0x40C8D5\",\n      \"type\": \"function\",\n      \"address\": \"0x40C8D5\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_open_clipboard\",\n      \"label\": \"open clipboard\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x409DB4\",\n      \"label\": \"Function 0x409DB4\",\n      \"type\": \"function\",\n      \"address\": \"0x409DB4\"\n    },\n    {\n      \"id\": \"api_OpenClipboard\",\n      \"label\": \"OpenClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_write_clipboard_data\",\n      \"label\": \"write clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404949\",\n      \"label\": \"Function 0x404949\",\n      \"type\": \"function\",\n      \"address\": \"0x404949\"\n    },\n    {\n      \"id\": \"api_EmptyClipboard\",\n      \"label\": \"EmptyClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SetClipboardData\",\n      \"label\": \"SetClipboardData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path__2_matches_\",\n      \"label\": \"get common file path (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404D61\",\n      \"label\": \"Function 0x404D61\",\n      \"type\": \"function\",\n      \"address\": \"0x404D61\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempFileName\",\n      \"label\": \"GetTempFileName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_system_object_information\",\n      \"label\": \"get file system object information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4083D0\",\n      \"label\": \"Block 0x4083D0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4083D0\"\n    },\n    {\n      \"id\": \"api_SHGetFileInfo\",\n      \"label\": \"SHGetFileInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_file\",\n      \"label\": \"delete file\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_file_exists\",\n      \"label\": \"check if file exists\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404B74\",\n      \"label\": \"Function 0x404B74\",\n      \"type\": \"function\",\n      \"address\": \"0x404B74\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_get_file_attributes\",\n      \"label\": \"get file attributes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x404B74\",\n      \"label\": \"Block 0x404B74\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x404B74\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size__3_matches_\",\n      \"label\": \"get file size (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408E1D\",\n      \"label\": \"Function 0x408E1D\",\n      \"type\": \"function\",\n      \"address\": \"0x408E1D\"\n    },\n    {\n      \"id\": \"func_0x4087D8\",\n      \"label\": \"Function 0x4087D8\",\n      \"type\": \"function\",\n      \"address\": \"0x4087D8\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read__ini_file__7_matches_\",\n      \"label\": \"read .ini file (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4060D8\",\n      \"label\": \"Function 0x4060D8\",\n      \"type\": \"function\",\n      \"address\": \"0x4060D8\"\n    },\n    {\n      \"id\": \"func_0x40652E\",\n      \"label\": \"Function 0x40652E\",\n      \"type\": \"function\",\n      \"address\": \"0x40652E\"\n    },\n    {\n      \"id\": \"func_0x40C6D5\",\n      \"label\": \"Function 0x40C6D5\",\n      \"type\": \"function\",\n      \"address\": \"0x40C6D5\"\n    },\n    {\n      \"id\": \"func_0x40C62F\",\n      \"label\": \"Function 0x40C62F\",\n      \"type\": \"function\",\n      \"address\": \"0x40C62F\"\n    },\n    {\n      \"id\": \"func_0x4060FD\",\n      \"label\": \"Function 0x4060FD\",\n      \"type\": \"function\",\n      \"address\": \"0x4060FD\"\n    },\n    {\n      \"id\": \"func_0x40C853\",\n      \"label\": \"Function 0x40C853\",\n      \"type\": \"function\",\n      \"address\": \"0x40C853\"\n    },\n    {\n      \"id\": \"func_0x406170\",\n      \"label\": \"Function 0x406170\",\n      \"type\": \"function\",\n      \"address\": \"0x406170\"\n    },\n    {\n      \"id\": \"api_GetPrivateProfileInt\",\n      \"label\": \"GetPrivateProfileInt\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetPrivateProfileString\",\n      \"label\": \"GetPrivateProfileString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__2_matches_\",\n      \"label\": \"read file on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405317\",\n      \"label\": \"Function 0x405317\",\n      \"type\": \"function\",\n      \"address\": \"0x405317\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__3_matches_\",\n      \"label\": \"write file on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404783\",\n      \"label\": \"Function 0x404783\",\n      \"type\": \"function\",\n      \"address\": \"0x404783\"\n    },\n    {\n      \"id\": \"func_0x40756E\",\n      \"label\": \"Function 0x40756E\",\n      \"type\": \"function\",\n      \"address\": \"0x40756E\"\n    },\n    {\n      \"id\": \"func_0x405336\",\n      \"label\": \"Function 0x405336\",\n      \"type\": \"function\",\n      \"address\": \"0x405336\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_gui_resources\",\n      \"label\": \"enumerate gui resources\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40B84A\",\n      \"label\": \"Function 0x40B84A\",\n      \"type\": \"function\",\n      \"address\": \"0x40B84A\"\n    },\n    {\n      \"id\": \"api_EnumResourceTypes\",\n      \"label\": \"EnumResourceTypes\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     johnk3r, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_graphical_window\",\n      \"label\": \"find graphical window\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindWindow\",\n      \"label\": \"FindWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_graphical_window_text__2_matches_\",\n      \"label\": \"get graphical window text (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40630B\",\n      \"label\": \"Function 0x40630B\",\n      \"type\": \"function\",\n      \"address\": \"0x40630B\"\n    },\n    {\n      \"id\": \"func_0x4063CA\",\n      \"label\": \"Function 0x4063CA\",\n      \"type\": \"function\",\n      \"address\": \"0x4063CA\"\n    },\n    {\n      \"id\": \"api_GetWindowText\",\n      \"label\": \"GetWindowText\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_hide_graphical_window__2_matches_\",\n      \"label\": \"hide graphical window (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40127C\",\n      \"label\": \"Block 0x40127C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40127C\"\n    },\n    {\n      \"id\": \"bb_0x40B2AA\",\n      \"label\": \"Block 0x40B2AA\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40B2AA\"\n    },\n    {\n      \"id\": \"api_ShowWindow\",\n      \"label\": \"ShowWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_process_on_windows\",\n      \"label\": \"create process on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4051A5\",\n      \"label\": \"Block 0x4051A5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4051A5\"\n    },\n    {\n      \"id\": \"api_ShellExecute\",\n      \"label\": \"ShellExecute\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_terminate_process__2_matches_\",\n      \"label\": \"terminate process (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40D3D0\",\n      \"label\": \"Function 0x40D3D0\",\n      \"type\": \"function\",\n      \"address\": \"0x40D3D0\"\n    },\n    {\n      \"id\": \"func_0x401801\",\n      \"label\": \"Function 0x401801\",\n      \"type\": \"function\",\n      \"address\": \"0x401801\"\n    },\n    {\n      \"id\": \"api_exit\",\n      \"label\": \"exit\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_ExitProcess\",\n      \"label\": \"ExitProcess\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value\",\n      \"label\": \"query or enumerate registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40C721\",\n      \"label\": \"Function 0x40C721\",\n      \"type\": \"function\",\n      \"address\": \"0x40C721\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_thread__2_matches_\",\n      \"label\": \"create thread (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40A9DA\",\n      \"label\": \"Block 0x40A9DA\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40A9DA\"\n    },\n    {\n      \"id\": \"api_CreateThread\",\n      \"label\": \"CreateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__35_matches_\",\n      \"label\": \"link function at runtime on Windows (35 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_many_functions_at_runtime__4_matches_\",\n      \"label\": \"link many functions at runtime (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40C976\",\n      \"label\": \"Function 0x40C976\",\n      \"type\": \"function\",\n      \"address\": \"0x40C976\"\n    },\n    {\n      \"id\": \"func_0x40D0B8\",\n      \"label\": \"Function 0x40D0B8\",\n      \"type\": \"function\",\n      \"address\": \"0x40D0B8\"\n    },\n    {\n      \"id\": \"func_0x40BE10\",\n      \"label\": \"Function 0x40BE10\",\n      \"type\": \"function\",\n      \"address\": \"0x40BE10\"\n    },\n    {\n      \"id\": \"func_0x40BD8C\",\n      \"label\": \"Function 0x40BD8C\",\n      \"type\": \"function\",\n      \"address\": \"0x40BD8C\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header\",\n      \"label\": \"parse PE header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports__2_matches_\",\n      \"label\": \"resolve function by parsing PE exports (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x40C1F3\",\n      \"label\": \"Function 0x40C1F3\",\n      \"type\": \"function\",\n      \"address\": \"0x40C1F3\"\n    },\n    {\n      \"id\": \"func_0x4024E9\",\n      \"label\": \"Function 0x4024E9\",\n      \"type\": \"function\",\n      \"address\": \"0x4024E9\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__90_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__90_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__3_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x4095D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_geographical_location\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location\",\n      \"target\": \"func_0x405023\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405023\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405023\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405023\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_polling__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__3_matches_\",\n      \"target\": \"func_0x40AF40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__3_matches_\",\n      \"target\": \"func_0x4044CF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__3_matches_\",\n      \"target\": \"func_0x4044BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40AF40\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4044CF\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4044BC\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40AF40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4044CF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4044BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40AF40\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4044CF\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4044BC\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contains_pdb_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x40C8D5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40C8D5\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C8D5\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C8D5\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C8D5\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40C8D5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40C8D5\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C8D5\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C8D5\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C8D5\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_clipboard\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_clipboard\",\n      \"target\": \"func_0x409DB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x409DB4\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x409DB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x409DB4\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_clipboard_data\",\n      \"target\": \"func_0x404949\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404949\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404949\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404949\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404949\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404949\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__2_matches_\",\n      \"target\": \"func_0x409DB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__2_matches_\",\n      \"target\": \"func_0x404D61\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x409DB4\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404D61\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409DB4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404D61\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409DB4\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404D61\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x409DB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404D61\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x409DB4\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404D61\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409DB4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404D61\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409DB4\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404D61\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_system_object_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_system_object_information\",\n      \"target\": \"bb_0x4083D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4083D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file\",\n      \"target\": \"func_0x409DB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x409DB4\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x409DB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x409DB4\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists\",\n      \"target\": \"func_0x404B74\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404B74\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x404B74\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404B74\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes\",\n      \"target\": \"bb_0x404B74\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x404B74\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size__3_matches_\",\n      \"target\": \"func_0x408E1D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__3_matches_\",\n      \"target\": \"func_0x404949\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__3_matches_\",\n      \"target\": \"func_0x4087D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408E1D\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404949\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4087D8\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x408E1D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404949\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4087D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408E1D\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404949\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4087D8\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read__ini_file__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__7_matches_\",\n      \"target\": \"func_0x4060D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__7_matches_\",\n      \"target\": \"func_0x40652E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__7_matches_\",\n      \"target\": \"func_0x40C6D5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__7_matches_\",\n      \"target\": \"func_0x40C62F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__7_matches_\",\n      \"target\": \"func_0x4060FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__7_matches_\",\n      \"target\": \"func_0x40C853\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__7_matches_\",\n      \"target\": \"func_0x406170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4060D8\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40652E\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C6D5\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C62F\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4060FD\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C853\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406170\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4060D8\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40652E\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C6D5\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C62F\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4060FD\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C853\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406170\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4060D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40652E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40C6D5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40C62F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4060FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40C853\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x406170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4060D8\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40652E\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C6D5\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C62F\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4060FD\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C853\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406170\",\n      \"target\": \"api_GetPrivateProfileInt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4060D8\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40652E\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C6D5\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C62F\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4060FD\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C853\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406170\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__2_matches_\",\n      \"target\": \"func_0x405317\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__2_matches_\",\n      \"target\": \"func_0x404949\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405317\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404949\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405317\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404949\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405317\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404949\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__3_matches_\",\n      \"target\": \"func_0x404783\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__3_matches_\",\n      \"target\": \"func_0x40756E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__3_matches_\",\n      \"target\": \"func_0x405336\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404783\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40756E\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405336\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404783\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40756E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405336\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404783\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40756E\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405336\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_gui_resources\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_gui_resources\",\n      \"target\": \"func_0x40B84A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40B84A\",\n      \"target\": \"api_EnumResourceTypes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B84A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40B84A\",\n      \"target\": \"api_EnumResourceTypes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_graphical_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_graphical_window_text__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__2_matches_\",\n      \"target\": \"func_0x40630B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__2_matches_\",\n      \"target\": \"func_0x4063CA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40630B\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4063CA\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x40630B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4063CA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40630B\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4063CA\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hide_graphical_window__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__2_matches_\",\n      \"target\": \"bb_0x40127C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__2_matches_\",\n      \"target\": \"bb_0x40B2AA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x40127C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x40B2AA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows\",\n      \"target\": \"bb_0x4051A5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4051A5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process__2_matches_\",\n      \"target\": \"func_0x40D3D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__2_matches_\",\n      \"target\": \"func_0x401801\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40D3D0\",\n      \"target\": \"api_exit\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401801\",\n      \"target\": \"api_exit\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D3D0\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401801\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40D3D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401801\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40D3D0\",\n      \"target\": \"api_exit\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401801\",\n      \"target\": \"api_exit\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D3D0\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401801\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value\",\n      \"target\": \"func_0x40C721\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40C721\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40C721\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40C721\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread__2_matches_\",\n      \"target\": \"bb_0x4095D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__2_matches_\",\n      \"target\": \"bb_0x40A9DA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4095D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40A9DA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__35_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_many_functions_at_runtime__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__4_matches_\",\n      \"target\": \"func_0x40C976\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__4_matches_\",\n      \"target\": \"func_0x40D0B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__4_matches_\",\n      \"target\": \"func_0x40BE10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__4_matches_\",\n      \"target\": \"func_0x40BD8C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x40C976\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x40D0B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x40BE10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x40BD8C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header\",\n      \"target\": \"func_0x40D3D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x40D3D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__2_matches_\",\n      \"target\": \"func_0x40C1F3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__2_matches_\",\n      \"target\": \"func_0x4024E9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x40C1F3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x4024E9\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-05-25 11:31:29.560369\",\n    \"total_functions\": \"367\",\n    \"total_features\": \"17372\",\n    \"pdb_path\": \"c:\\\\\\\\Projects\\\\\\\\VS2005\\\\\\\\WirelessNetView\\\\\\\\Release\\\\\\\\WirelessNetView.pdb\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-05-25 11:31:30"}
{"_id":{"$oid":"6a14615f32de6bb6782baad6"},"sha256":"bc1363062c4f4aff514d71fd85fc9a5a08ad7fc2ea9a40298bb8865d041b8a3f","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_0i8nyn7z/zlib_offset_0x6aee8_7.bin_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_0i8nyn7z/zlib_offset_0x6aee8_7.bin_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_0i8nyn7z/zlib_offset_0x6aee8_7.bin_very_verbose.txt"}},"outputs":{"normal":"┌───────────┬──────────────────────────────────────────────────────────────────┐\n│ md5       │ 2ff9d894ba5e8f7880f0031866203995                                 │\n│ sha1      │ dd594003fb744f4b2b944e1b10b78a7026e72104                         │\n│ sha256    │ ab64835b63093c31975df2692756c8008e7ec190e4aa86f15a713bcc62e1d432 │\n│ analysis  │ static                                                           │\n│ os        │ windows                                                          │\n│ format    │ pe                                                               │\n│ arch      │ amd64                                                            │\n│ path      │ /tmp/sdm_decoded_3fi8jo5f/zlib_offset_0x6aee8_7.bin              │\n└───────────┴──────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic             ┃ ATT&CK Technique                                 ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION           │ Obfuscated Files or Information [T1027]          │\n└───────────────────────────┴──────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DATA                 │ Encode Data::XOR [C0026.002]                          │\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Encoding-Standard    │\n│                      │ Algorithm [E1027.m02]                                 │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                              ┃ Namespace                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ encode data using XOR (2 matches)       │ data-manipulation/encoding/xor     │\n└─────────────────────────────────────────┴────────────────────────────────────┘\n\n","verbose":"md5                     2ff9d894ba5e8f7880f0031866203995                        \nsha1                    dd594003fb744f4b2b944e1b10b78a7026e72104                \nsha256                  ab64835b63093c31975df2692756c8008e7ec190e4aa86f15a713bc…\npath                    /tmp/sdm_decoded_3fi8jo5f/zlib_offset_0x6aee8_7.bin     \ntimestamp               2026-05-25 20:18:47.663722                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x180000000                                             \nrules                   /tmp/_MEIz75NWf/rules                                   \nfunction count          410                                                     \nlibrary function count  32                                                      \ntotal feature count     24175                                                   \n\nencode data using XOR (2 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x1800039C0                   \n           0x180003A50                   \n\n\n\n","very_verbose":"md5                     2ff9d894ba5e8f7880f0031866203995                        \nsha1                    dd594003fb744f4b2b944e1b10b78a7026e72104                \nsha256                  ab64835b63093c31975df2692756c8008e7ec190e4aa86f15a713bc…\npath                    /tmp/sdm_decoded_3fi8jo5f/zlib_offset_0x6aee8_7.bin     \ntimestamp               2026-05-25 20:19:01.918327                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x180000000                                             \nrules                   /tmp/_MEIM49qV9/rules                                   \nfunction count          410                                                     \nlibrary function count  32                                                      \ntotal feature count     24175                                                   \n\ncontain loop (37 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x1800010C0\n  or:\n    characteristic: loop @ 0x1800010C0\n\nencode data using XOR (2 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x1800039C0 in function 0x1800034D0\n  and:\n    characteristic: tight loop @ 0x1800039C0\n    characteristic: nzxor @ 0x1800039DA, 0x1800039E9, 0x1800039FF, 0x180003A15\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x180003A50 in function 0x1800034D0\n  and:\n    characteristic: tight loop @ 0x180003A50\n    characteristic: nzxor @ 0x180003A62\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\n\n\n"},"hashes":{"md5":"2ff9d894ba5e8f7880f0031866203995","sha1":"dd594003fb744f4b2b944e1b10b78a7026e72104","sha256":"ab64835b63093c31975df2692756c8008e7ec190e4aa86f15a713bcc62e1d432"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 410</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 24175</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"zlib_offset_0x6aee8_7.bin\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"2ff9d894ba5e8f7880f0031866203995\",\n        \"sha256\": \"ab64835b63093c31975df2692756c8008e7ec190e4aa86f15a713bc\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__37_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (37 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1800010C0\",\n      \"label\": \"Function 0x1800010C0\",\n      \"type\": \"function\",\n      \"address\": \"0x1800010C0\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__37_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__37_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x1800010C0\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-05-25 20:19:01.918327\",\n    \"total_functions\": \"410\",\n    \"total_features\": \"24175\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-05-25 20:19:03"}
{"_id":{"$oid":"6a2eafceae36b72c92a10921"},"sha256":"ac4253e726af6a9b61ae53b915c49c031e65abdc03bcb81106ba0f422c61ec8d","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_sitw1_k2/NutanixVSSSWProvider-019ec65bb42e78e294f3218cc073c72e.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_sitw1_k2/NutanixVSSSWProvider-019ec65bb42e78e294f3218cc073c72e.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_sitw1_k2/NutanixVSSSWProvider-019ec65bb42e78e294f3218cc073c72e.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ e32293f7f8b5e06246801e3c2eea9731                                  │\n│ sha1     │ f3cffdd0982ef941bf1e83bc69cac27e0179ae36                          │\n│ sha256   │ ac4253e726af6a9b61ae53b915c49c031e65abdc03bcb81106ba0f422c61ec8d  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ amd64                                                             │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/NutanixVSSSWProv… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION      │ Modify Registry [T1112]                               │\n│                      │ Virtualization/Sandbox Evasion::System Checks         │\n│                      │ [T1497.001]                                           │\n│ DISCOVERY            │ Query Registry [T1012]                                │\n│                      │ System Information Discovery [T1082]                  │\n│ EXECUTION            │ Command and Scripting Interpreter [T1059]             │\n│                      │ Shared Modules [T1129]                                │\n│                      │ System Services::Service Execution [T1569.002]        │\n│ IMPACT               │ Service Stop [T1489]                                  │\n│ PERSISTENCE          │ Create or Modify System Process::Windows Service      │\n│                      │ [T1543.003]                                           │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Conditional Execution::Runs as Service            │\n│                          │ [B0025.007]                                       │\n│                          │ Virtual Machine Detection [B0009]                 │\n│ DISCOVERY                │ File and Directory Discovery::Log File            │\n│                          │ [E1083.m01]                                       │\n│                          │ System Information Discovery [E1082]              │\n│ EXECUTION                │ Command and Scripting Interpreter [E1059]         │\n│ OPERATING SYSTEM         │ Registry::Delete Registry Key [C0036.002]         │\n│                          │ Registry::Delete Registry Value [C0036.007]       │\n│                          │ Registry::Query Registry Key [C0036.005]          │\n│                          │ Registry::Query Registry Value [C0036.006]        │\n│                          │ Registry::Set Registry Key [C0036.001]            │\n│ PROCESS                  │ Create Thread [C0038]                             │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                              ┃ Namespace                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ reference anti-VM strings targeting     │ anti-analysis/anti-vm/vm-detection │\n│ VMWare                                  │                                    │\n│ contains PDB path                       │ executable/pe/pdb                  │\n│ contain a thread local storage (.tls)   │ executable/pe/section/tls          │\n│ section                                 │                                    │\n│ extract resource via kernel32 functions │ executable/resource                │\n│ (2 matches)                             │                                    │\n│ accept command line arguments           │ host-interaction/cli               │\n│ get storage device properties           │ host-interaction/hardware/storage  │\n│ access the Windows event log (4         │ host-interaction/log/winevt/access │\n│ matches)                                │                                    │\n│ get hostname                            │ host-interaction/os/hostname       │\n│ query or enumerate registry key         │ host-interaction/registry          │\n│ query or enumerate registry value       │ host-interaction/registry          │\n│ set registry value (5 matches)          │ host-interaction/registry/create   │\n│ delete registry key (2 matches)         │ host-interaction/registry/delete   │\n│ delete registry value (3 matches)       │ host-interaction/registry/delete   │\n│ run as service                          │ host-interaction/service           │\n│ create service                          │ host-interaction/service/create    │\n│ delete service                          │ host-interaction/service/delete    │\n│ modify service                          │ host-interaction/service/modify    │\n│ stop service                            │ host-interaction/service/stop      │\n│ create thread                           │ host-interaction/thread/create     │\n│ link function at runtime on Windows (7  │ linking/runtime-linking            │\n│ matches)                                │                                    │\n└─────────────────────────────────────────┴────────────────────────────────────┘\n\n","verbose":"md5                     e32293f7f8b5e06246801e3c2eea9731                        \nsha1                    f3cffdd0982ef941bf1e83bc69cac27e0179ae36                \nsha256                  ac4253e726af6a9b61ae53b915c49c031e65abdc03bcb81106ba0f4…\npath                    /home/apogean/projects/malware/windows/all_runs/Nutanix…\ntimestamp               2026-06-14 19:12:05.196394                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x140000000                                             \nrules                   /tmp/_MEIt2jTMY/rules                                   \nfunction count          307                                                     \nlibrary function count  80                                                      \ntotal feature count     16608                                                   \n\nreference anti-VM strings targeting VMWare\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\ncontains PDB path\nnamespace  executable/pe/pdb\nscope      file             \n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls\nscope      file                     \n\nextract resource via kernel32 functions (2 matches)\nnamespace  executable/resource\nscope      function           \nmatches    0x1400014D0        \n           0x1400090A0        \n\naccept command line arguments\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x14000B970         \n\ninteract with driver via IOCTL (4 matches)\nnamespace  host-interaction/driver\nscope      instruction            \nmatches    0x140001DB9            \n           0x140001E7A            \n           0x140001EF4            \n           0x140002D23            \n\nget storage device properties\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x140001E10                      \n\naccess the Windows event log (4 matches)\nnamespace  host-interaction/log/winevt/access\nscope      function                          \nmatches    0x1400074B0                       \n           0x140009CA0                       \n           0x14000B140                       \n           0x14000B240                       \n\nget hostname\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    0x14000BCD0                 \n\nquery or enumerate registry key\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x140008830              \n\nquery or enumerate registry value\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x140009F40              \n\nset registry value (5 matches)\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x1400053E0                     \n           0x140005692                     \n           0x140008A30                     \n           0x140009DC0                     \n           0x140009E00                     \n\ndelete registry key (2 matches)\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x140006A30                     \n           0x140008980                     \n\ndelete registry value (3 matches)\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x140008A30                     \n           0x140009290                     \n           0x14000A6D0                     \n\nrun as service\nnamespace  host-interaction/service\nscope      file                    \n\ncreate service\nnamespace  host-interaction/service/create\nscope      function                       \nmatches    0x140006FD0                    \n\ndelete service\nnamespace  host-interaction/service/delete\nscope      function                       \nmatches    0x14000A2F0                    \n\nmodify service\nnamespace  host-interaction/service/modify\nscope      function                       \nmatches    0x140008BF0                    \n\nstop service\nnamespace  host-interaction/service/stop\nscope      function                     \nmatches    0x14000A2F0                  \n\ncreate thread\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x14000A178                   \n\nlink function at runtime on Windows (7 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x1400064E2            \n           0x1400065D2            \n           0x140006A83            \n           0x1400089BA            \n           0x140007879            \n           0x1400089BA            \n           0x140009609            \n\n\n\n","very_verbose":"md5                     e32293f7f8b5e06246801e3c2eea9731                        \nsha1                    f3cffdd0982ef941bf1e83bc69cac27e0179ae36                \nsha256                  ac4253e726af6a9b61ae53b915c49c031e65abdc03bcb81106ba0f4…\npath                    /home/apogean/projects/malware/windows/all_runs/Nutanix…\ntimestamp               2026-06-14 19:12:35.923655                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x140000000                                             \nrules                   /tmp/_MEIq4iEoT/rules                                   \nfunction count          307                                                     \nlibrary function count  80                                                      \ntotal feature count     16608                                                   \n\ncontain loop (64 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x140001040\n  or:\n    characteristic: loop @ 0x140001040\n\ncreate or open file (library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x140001CC8\n  or:\n    api: CreateFile @ 0x140001CC8\n\ncreate or open registry key (3 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x1400078BC in function 0x140007820\n  or:\n    api: RegOpenKeyEx @ 0x1400078CF\n\ndelay execution (4 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x1400075B0 in function 0x1400075B0\n  or:\n    and:\n      os: windows\n      or:\n        api: WaitForSingleObject @ 0x1400075C0\n\nget service handle (4 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x140006FD0\n  or:\n    api: CreateService @ 0x140007177\n\nreference anti-VM strings targeting VMWare\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com, @johnk3r                              \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /VMWare/i\n    - \"VMware\" @ file+0x127A8\n    - \"VMware Virtual NVMe Disk\" @ file+0x12990\n\ncontains PDB path\nnamespace  executable/pe/pdb        \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nregex: /:\\\\.*\\.pdb/\n  - \"C:\\\\Users\\\\Administrator\\\\Documents\\\\NGT\\\\ngt_20241019_140230\\\\ngt\\\\vss\\\\window\ns\\\\source\\\\NutanixVSSSolution\\\\x64\\\\Release\\\\NutanixVSSSWProvider.pdb\" @ file+0x145AC\n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls   \nauthor     michael.hunhoff@mandiant.com\nscope      file                        \nsection: .tls @ 0x140020000\n\nextract resource via kernel32 functions (2 matches)\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x1400014D0\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x1400014E8\n        api: LockResource @ 0x14000150B\n      optional:\n        api: SizeofResource @ 0x14000151F\nfunction @ 0x1400090A0\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x140009155\n      optional:\n        or:\n          api: FindResource @ 0x140009137\n        api: SizeofResource @ 0x140009178\n\naccept command line arguments\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x14000B970\n  or:\n    api: GetCommandLine @ 0x14000B9AF\n\ninteract with driver via IOCTL (4 matches)\nnamespace  host-interaction/driver  \nauthor     moritz.raabe@mandiant.com\nscope      instruction              \ninstruction @ 0x140001DB9\n  or:\n    api: DeviceIoControl @ 0x140001DB9\ninstruction @ 0x140001E7A\n  or:\n    api: DeviceIoControl @ 0x140001E7A\ninstruction @ 0x140001EF4\n  or:\n    api: DeviceIoControl @ 0x140001EF4\ninstruction @ 0x140002D23\n  or:\n    api: DeviceIoControl @ 0x140002D23\n\nget storage device properties\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com                                        \nscope       function                                                            \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/winioctl/ni-wini…\nfunction @ 0x140001E10\n  and:\n    number: 0x2D1400 = IOCTL_STORAGE_QUERY_PROPERTY @ 0x140001E52, 0x140001EE3\n    or:\n      match: interact with driver via IOCTL @ 0x140001E7A, 0x140001EF4\n        or:\n          api: DeviceIoControl @ 0x140001E7A\n        or:\n          api: DeviceIoControl @ 0x140001EF4\n\naccess the Windows event log (4 matches)\nnamespace  host-interaction/log/winevt/access                           \nauthor     moritz.raabe@mandiant.com                                    \nscope      function                                                     \nmbc        Discovery::File and Directory Discovery::Log File [E1083.m01]\nfunction @ 0x1400074B0\n  or:\n    api: ReportEvent @ 0x14000757A\nfunction @ 0x140009CA0\n  or:\n    api: ReportEvent @ 0x14000757A\nfunction @ 0x14000B140\n  or:\n    api: ReportEvent @ 0x14000757A\nfunction @ 0x14000B240\n  or:\n    api: ReportEvent @ 0x14000757A\n\nget hostname\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ 0x14000BCD0\n  or:\n    api: GetComputerName @ 0x14000BDFC\n\nquery or enumerate registry key\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ 0x140008830\n  and:\n    or:\n      api: RegEnumKeyEx @ 0x1400088BE, 0x140008917\n\nquery or enumerate registry value\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x140009F40\n  and:\n    or:\n      api: RegQueryValueEx @ 0x14000A017\n\nset registry value (5 matches)\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x1400053E0\n  or:\n    and:\n      or:\n        api: RegSetValueEx @ 0x14000575D, 0x1400057C1\nfunction @ 0x140005692\n  or:\n    and:\n      or:\n        api: RegSetValueEx @ 0x14000575D\nfunction @ 0x140008A30\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x140008AE2\n          or:\n            api: RegCreateKeyEx @ 0x140008B2E\n      or:\n        api: RegSetValueEx @ 0x140008B90\nfunction @ 0x140009DC0\n  or:\n    and:\n      or:\n        api: RegSetValueEx @ 0x140009DE7\nfunction @ 0x140009E00\n  or:\n    and:\n      or:\n        api: RegSetValueEx @ 0x140009E54\n\ndelete registry key (2 matches)\nnamespace  host-interaction/registry/delete                                \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\nscope      function                                                        \natt&ck     Defense Evasion::Modify Registry [T1112]                        \nmbc        Operating System::Registry::Delete Registry Key [C0036.002]     \nfunction @ 0x140006A30\n  and:\n    or:\n      api: RegDeleteKey @ 0x140006AD9, 0x140008A0F\nfunction @ 0x140008980\n  and:\n    or:\n      api: RegDeleteKey @ 0x140008A0F\n\ndelete registry value (3 matches)\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ 0x140008A30\n  and:\n    optional:\n      match: create or open registry key @ 0x140008AE2\n        or:\n          api: RegCreateKeyEx @ 0x140008B2E\n    or:\n      api: RegDeleteValue @ 0x140008B4A\nfunction @ 0x140009290\n  and:\n    optional:\n      match: create or open registry key @ 0x140009667\n        or:\n          api: RegCreateKeyEx @ 0x140009699\n    or:\n      api: RegDeleteValue @ 0x14000951E\nfunction @ 0x14000A6D0\n  and:\n    or:\n      api: RegDeleteValue @ 0x14000A772\n\nrun as service\nnamespace  host-interaction/service                                             \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      file                                                                 \nmbc        Anti-Behavioral Analysis::Conditional Execution::Runs as Service     \n           [B0025.007]                                                          \nor:\n  function:\n    or:\n      api: RegisterServiceCtrlHandler @ 0x140009CCF\n    or:\n      api: StartServiceCtrlDispatcher @ 0x14000A0A0\n    or:\n      api: RegisterServiceCtrlHandler @ 0x140009CCF\n\ncreate service\nnamespace  host-interaction/service/create                                      \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003], Execution::System Services::Service Execution           \n           [T1569.002]                                                          \nfunction @ 0x140006FD0\n  and:\n    api: CreateService @ 0x140007177\n    optional:\n      api: OpenSCManager @ 0x140007070\n\ndelete service\nnamespace  host-interaction/service/delete                                      \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003]                                                          \nfunction @ 0x14000A2F0\n  and:\n    api: DeleteService @ 0x14000A577\n    optional:\n      match: get service handle @ 0x14000A2F0\n        or:\n          api: OpenService @ 0x14000A41A\n\nmodify service\nnamespace  host-interaction/service/modify                                      \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003], Execution::System Services::Service Execution           \n           [T1569.002]                                                          \nfunction @ 0x140008BF0\n  and:\n    optional:\n      match: get service handle @ 0x140008BF0\n        or:\n          api: OpenService @ 0x140008CAC\n    or:\n      api: ChangeServiceConfig @ 0x140008D67\n      api: ChangeServiceConfig2 @ 0x140008D0D\n\nstop service\nnamespace  host-interaction/service/stop                                        \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003], Impact::Service Stop [T1489]                            \nfunction @ 0x14000A2F0\n  and:\n    optional:\n      match: get service handle @ 0x14000A2F0\n        or:\n          api: OpenService @ 0x14000A41A\n    or:\n      basic block:\n        and:\n          number: 0x1 = SERVICE_CONTROL_STOP @ 0x14000A4D1\n          or:\n            api: ControlService @ 0x14000A4E0\n\ncreate thread\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x14000A178 in function 0x14000A150\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x14000A19D\n\nlink function at runtime on Windows (7 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x1400064E2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400064E2\ninstruction @ 0x1400065D2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400065D2\ninstruction @ 0x140006A83\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x140006A83\ninstruction @ 0x140007879\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x140007879\ninstruction @ 0x1400089BA\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400089BA\ninstruction @ 0x1400089BA\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400089BA\ninstruction @ 0x140009609\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x140009609\n\n\n\n"},"hashes":{"md5":"e32293f7f8b5e06246801e3c2eea9731","sha1":"f3cffdd0982ef941bf1e83bc69cac27e0179ae36","sha256":"ac4253e726af6a9b61ae53b915c49c031e65abdc03bcb81106ba0f422c61ec8d"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 307</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 16608</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Nutanix\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"e32293f7f8b5e06246801e3c2eea9731\",\n        \"sha256\": \"ac4253e726af6a9b61ae53b915c49c031e65abdc03bcb81106ba0f4\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__64_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (64 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x140001040\",\n      \"label\": \"Function 0x140001040\",\n      \"type\": \"function\",\n      \"address\": \"0x140001040\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1400078BC\",\n      \"label\": \"Block 0x1400078BC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400078BC\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1400075B0\",\n      \"label\": \"Block 0x1400075B0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400075B0\"\n    },\n    {\n      \"id\": \"api_WaitForSingleObject\",\n      \"label\": \"WaitForSingleObject\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_service_handle__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"get service handle (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x140006FD0\",\n      \"label\": \"Function 0x140006FD0\",\n      \"type\": \"function\",\n      \"address\": \"0x140006FD0\"\n    },\n    {\n      \"id\": \"api_CreateService\",\n      \"label\": \"CreateService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_vmware\",\n      \"label\": \"reference anti-VM strings targeting VMWare\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com___johnk3r\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, @johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contains_pdb_path\",\n      \"label\": \"contains PDB path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"label\": \"contain a thread local storage (.tls) section\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions__2_matches_\",\n      \"label\": \"extract resource via kernel32 functions (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1400014D0\",\n      \"label\": \"Function 0x1400014D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400014D0\"\n    },\n    {\n      \"id\": \"func_0x1400090A0\",\n      \"label\": \"Function 0x1400090A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400090A0\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments\",\n      \"label\": \"accept command line arguments\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14000B970\",\n      \"label\": \"Function 0x14000B970\",\n      \"type\": \"function\",\n      \"address\": \"0x14000B970\"\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_interact_with_driver_via_ioctl__4_matches_\",\n      \"label\": \"interact with driver via IOCTL (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_DeviceIoControl\",\n      \"label\": \"DeviceIoControl\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_storage_device_properties\",\n      \"label\": \"get storage device properties\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x140001E10\",\n      \"label\": \"Function 0x140001E10\",\n      \"type\": \"function\",\n      \"address\": \"0x140001E10\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_access_the_windows_event_log__4_matches_\",\n      \"label\": \"access the Windows event log (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery::Log File [E1083.m01]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14000B240\",\n      \"label\": \"Function 0x14000B240\",\n      \"type\": \"function\",\n      \"address\": \"0x14000B240\"\n    },\n    {\n      \"id\": \"func_0x14000B140\",\n      \"label\": \"Function 0x14000B140\",\n      \"type\": \"function\",\n      \"address\": \"0x14000B140\"\n    },\n    {\n      \"id\": \"func_0x1400074B0\",\n      \"label\": \"Function 0x1400074B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400074B0\"\n    },\n    {\n      \"id\": \"func_0x140009CA0\",\n      \"label\": \"Function 0x140009CA0\",\n      \"type\": \"function\",\n      \"address\": \"0x140009CA0\"\n    },\n    {\n      \"id\": \"api_ReportEvent\",\n      \"label\": \"ReportEvent\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_hostname\",\n      \"label\": \"get hostname\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14000BCD0\",\n      \"label\": \"Function 0x14000BCD0\",\n      \"type\": \"function\",\n      \"address\": \"0x14000BCD0\"\n    },\n    {\n      \"id\": \"api_GetComputerName\",\n      \"label\": \"GetComputerName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key\",\n      \"label\": \"query or enumerate registry key\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140008830\",\n      \"label\": \"Function 0x140008830\",\n      \"type\": \"function\",\n      \"address\": \"0x140008830\"\n    },\n    {\n      \"id\": \"api_RegEnumKeyEx\",\n      \"label\": \"RegEnumKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value\",\n      \"label\": \"query or enumerate registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140009F40\",\n      \"label\": \"Function 0x140009F40\",\n      \"type\": \"function\",\n      \"address\": \"0x140009F40\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value__5_matches_\",\n      \"label\": \"set registry value (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140009DC0\",\n      \"label\": \"Function 0x140009DC0\",\n      \"type\": \"function\",\n      \"address\": \"0x140009DC0\"\n    },\n    {\n      \"id\": \"func_0x140005692\",\n      \"label\": \"Function 0x140005692\",\n      \"type\": \"function\",\n      \"address\": \"0x140005692\"\n    },\n    {\n      \"id\": \"func_0x140009E00\",\n      \"label\": \"Function 0x140009E00\",\n      \"type\": \"function\",\n      \"address\": \"0x140009E00\"\n    },\n    {\n      \"id\": \"func_0x1400053E0\",\n      \"label\": \"Function 0x1400053E0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400053E0\"\n    },\n    {\n      \"id\": \"func_0x140008A30\",\n      \"label\": \"Function 0x140008A30\",\n      \"type\": \"function\",\n      \"address\": \"0x140008A30\"\n    },\n    {\n      \"id\": \"api_RegCreateKeyEx\",\n      \"label\": \"RegCreateKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_key__2_matches_\",\n      \"label\": \"delete registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140006A30\",\n      \"label\": \"Function 0x140006A30\",\n      \"type\": \"function\",\n      \"address\": \"0x140006A30\"\n    },\n    {\n      \"id\": \"func_0x140008980\",\n      \"label\": \"Function 0x140008980\",\n      \"type\": \"function\",\n      \"address\": \"0x140008980\"\n    },\n    {\n      \"id\": \"api_RegDeleteKey\",\n      \"label\": \"RegDeleteKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_value__3_matches_\",\n      \"label\": \"delete registry value (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14000A6D0\",\n      \"label\": \"Function 0x14000A6D0\",\n      \"type\": \"function\",\n      \"address\": \"0x14000A6D0\"\n    },\n    {\n      \"id\": \"func_0x140009290\",\n      \"label\": \"Function 0x140009290\",\n      \"type\": \"function\",\n      \"address\": \"0x140009290\"\n    },\n    {\n      \"id\": \"api_RegDeleteValue\",\n      \"label\": \"RegDeleteValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_run_as_service\",\n      \"label\": \"run as service\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Conditional Execution::Runs as Service\",\n        \"[B0025.007]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegisterServiceCtrlHandler\",\n      \"label\": \"RegisterServiceCtrlHandler\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_StartServiceCtrlDispatcher\",\n      \"label\": \"StartServiceCtrlDispatcher\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_service\",\n      \"label\": \"create service\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\",\n        \"Execution::System Services::Service Execution\",\n        \"[T1569.002]\"\n      ]\n    },\n    {\n      \"id\": \"api_OpenSCManager\",\n      \"label\": \"OpenSCManager\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_service\",\n      \"label\": \"delete service\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14000A2F0\",\n      \"label\": \"Function 0x14000A2F0\",\n      \"type\": \"function\",\n      \"address\": \"0x14000A2F0\"\n    },\n    {\n      \"id\": \"api_DeleteService\",\n      \"label\": \"DeleteService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_OpenService\",\n      \"label\": \"OpenService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_modify_service\",\n      \"label\": \"modify service\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\",\n        \"Execution::System Services::Service Execution\",\n        \"[T1569.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140008BF0\",\n      \"label\": \"Function 0x140008BF0\",\n      \"type\": \"function\",\n      \"address\": \"0x140008BF0\"\n    },\n    {\n      \"id\": \"api_ChangeServiceConfig2\",\n      \"label\": \"ChangeServiceConfig2\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_ChangeServiceConfig\",\n      \"label\": \"ChangeServiceConfig\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_stop_service\",\n      \"label\": \"stop service\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\",\n        \"Impact::Service Stop [T1489]\"\n      ]\n    },\n    {\n      \"id\": \"api_ControlService\",\n      \"label\": \"ControlService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_thread\",\n      \"label\": \"create thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x14000A178\",\n      \"label\": \"Block 0x14000A178\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14000A178\"\n    },\n    {\n      \"id\": \"api_CreateThread\",\n      \"label\": \"CreateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__7_matches_\",\n      \"label\": \"link function at runtime on Windows (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__64_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__64_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x140001040\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x1400078BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__4_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x1400075B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_service_handle__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_service_handle__4_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x140006FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140006FD0\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_vmware\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com___johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contains_pdb_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__2_matches_\",\n      \"target\": \"func_0x1400014D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__2_matches_\",\n      \"target\": \"func_0x1400090A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400014D0\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400090A0\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400014D0\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400090A0\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400014D0\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400090A0\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400014D0\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400090A0\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x1400014D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x1400090A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400014D0\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400090A0\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400014D0\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400090A0\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400014D0\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400090A0\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400014D0\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400090A0\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments\",\n      \"target\": \"func_0x14000B970\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000B970\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x14000B970\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000B970\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_interact_with_driver_via_ioctl__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_storage_device_properties\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_storage_device_properties\",\n      \"target\": \"func_0x140001E10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140001E10\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140001E10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140001E10\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_the_windows_event_log__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_access_the_windows_event_log__4_matches_\",\n      \"target\": \"func_0x14000B240\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_the_windows_event_log__4_matches_\",\n      \"target\": \"func_0x14000B140\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_the_windows_event_log__4_matches_\",\n      \"target\": \"func_0x1400074B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_the_windows_event_log__4_matches_\",\n      \"target\": \"func_0x140009CA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000B240\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000B140\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400074B0\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009CA0\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x14000B240\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x14000B140\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400074B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140009CA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000B240\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000B140\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400074B0\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009CA0\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_hostname\",\n      \"target\": \"func_0x14000BCD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000BCD0\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x14000BCD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000BCD0\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key\",\n      \"target\": \"func_0x140008830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140008830\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140008830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140008830\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value\",\n      \"target\": \"func_0x140009F40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140009F40\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140009F40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140009F40\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__5_matches_\",\n      \"target\": \"func_0x140009DC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__5_matches_\",\n      \"target\": \"func_0x140005692\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__5_matches_\",\n      \"target\": \"func_0x140009E00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__5_matches_\",\n      \"target\": \"func_0x1400053E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__5_matches_\",\n      \"target\": \"func_0x140008A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140009DC0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005692\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009E00\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400053E0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140008A30\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009DC0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005692\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009E00\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400053E0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140008A30\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140009DC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140005692\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140009E00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400053E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140008A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140009DC0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005692\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009E00\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400053E0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140008A30\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009DC0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005692\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009E00\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400053E0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140008A30\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key__2_matches_\",\n      \"target\": \"func_0x140006A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key__2_matches_\",\n      \"target\": \"func_0x140008980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140006A30\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140008980\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x140006A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x140008980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140006A30\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140008980\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value__3_matches_\",\n      \"target\": \"func_0x14000A6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value__3_matches_\",\n      \"target\": \"func_0x140009290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value__3_matches_\",\n      \"target\": \"func_0x140008A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000A6D0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009290\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140008A30\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000A6D0\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009290\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140008A30\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x14000A6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140009290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140008A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000A6D0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009290\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140008A30\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000A6D0\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009290\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140008A30\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_run_as_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_service\",\n      \"target\": \"func_0x140006FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140006FD0\",\n      \"target\": \"api_OpenSCManager\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006FD0\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140006FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140006FD0\",\n      \"target\": \"api_OpenSCManager\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006FD0\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_service\",\n      \"target\": \"func_0x14000A2F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000A2F0\",\n      \"target\": \"api_DeleteService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000A2F0\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x14000A2F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000A2F0\",\n      \"target\": \"api_DeleteService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000A2F0\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_modify_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_modify_service\",\n      \"target\": \"func_0x140008BF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140008BF0\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140008BF0\",\n      \"target\": \"api_ChangeServiceConfig2\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140008BF0\",\n      \"target\": \"api_ChangeServiceConfig\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140008BF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140008BF0\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140008BF0\",\n      \"target\": \"api_ChangeServiceConfig2\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140008BF0\",\n      \"target\": \"api_ChangeServiceConfig\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_stop_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_stop_service\",\n      \"target\": \"func_0x14000A2F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000A2F0\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000A2F0\",\n      \"target\": \"api_ControlService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x14000A2F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000A2F0\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000A2F0\",\n      \"target\": \"api_ControlService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread\",\n      \"target\": \"bb_0x14000A178\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x14000A178\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-06-14 19:12:35.923655\",\n    \"total_functions\": \"307\",\n    \"total_features\": \"16608\",\n    \"pdb_path\": \"C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\Documents\\\\\\\\NGT\\\\\\\\ngt_20241019_140230\\\\\\\\ngt\\\\\\\\vss\\\\\\\\window\\ns\\\\\\\\source\\\\\\\\NutanixVSSSolution\\\\\\\\x64\\\\\\\\Release\\\\\\\\NutanixVSSSWProvider.pdb\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-06-14 19:12:38"}
{"_id":{"$oid":"6a2eb5c6ae36b72c92a10925"},"sha256":"794cf7644115198db451431bca7c89ff9a97550482b1e3f7f13eb7aca6120a11","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_xmvj9par/NutanixVSSRequestor-019ec65bf02475e1ab1ed55c08a591d3.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_xmvj9par/NutanixVSSRequestor-019ec65bf02475e1ab1ed55c08a591d3.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_xmvj9par/NutanixVSSRequestor-019ec65bf02475e1ab1ed55c08a591d3.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 82f657b0aee67a6a560321cf0927f9f7                                  │\n│ sha1     │ 703175455354cdbd4244668c94704fee585a9228                          │\n│ sha256   │ 794cf7644115198db451431bca7c89ff9a97550482b1e3f7f13eb7aca6120a11  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/NutanixVSSReques… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic             ┃ ATT&CK Technique                                 ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DISCOVERY                 │ File and Directory Discovery [T1083]             │\n│                           │ Query Registry [T1012]                           │\n│ EXECUTION                 │ Command and Scripting Interpreter [T1059]        │\n│                           │ Shared Modules [T1129]                           │\n└───────────────────────────┴──────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DISCOVERY                │ File and Directory Discovery [E1083]              │\n│ EXECUTION                │ Command and Scripting Interpreter [E1059]         │\n│ OPERATING SYSTEM         │ Registry::Query Registry Value [C0036.006]        │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                                    ┃ Namespace                    ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ extract resource via kernel32 functions       │ executable/resource          │\n│ accept command line arguments                 │ host-interaction/cli         │\n│ get Program Files directory                   │ host-interaction/file-system │\n│ get common file path                          │ host-interaction/file-system │\n│ query or enumerate registry value             │ host-interaction/registry    │\n│ link function at runtime on Windows (4        │ linking/runtime-linking      │\n│ matches)                                      │                              │\n└───────────────────────────────────────────────┴──────────────────────────────┘\n\n","verbose":"md5                     82f657b0aee67a6a560321cf0927f9f7                        \nsha1                    703175455354cdbd4244668c94704fee585a9228                \nsha256                  794cf7644115198db451431bca7c89ff9a97550482b1e3f7f13eb7a…\npath                    /home/apogean/projects/malware/windows/all_runs/Nutanix…\ntimestamp               2026-06-14 19:37:43.935559                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIeiT9zR/rules                                   \nfunction count          187                                                     \nlibrary function count  298                                                     \ntotal feature count     6730                                                    \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x406079           \n\naccept command line arguments\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x406788            \n\nget Program Files directory\nnamespace  host-interaction/file-system\nscope      basic block                 \nmatches    0x40649E                    \n\nget common file path\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x40639F                    \n\nquery or enumerate registry value\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x40653B                 \n\nlink function at runtime on Windows (4 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x40679E               \n           0x406807               \n           0x40C17D               \n           0x40C17D               \n\n\n\n","very_verbose":"md5                     82f657b0aee67a6a560321cf0927f9f7                        \nsha1                    703175455354cdbd4244668c94704fee585a9228                \nsha256                  794cf7644115198db451431bca7c89ff9a97550482b1e3f7f13eb7a…\npath                    /home/apogean/projects/malware/windows/all_runs/Nutanix…\ntimestamp               2026-06-14 19:38:05.030141                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIatGuxn/rules                                   \nfunction count          187                                                     \nlibrary function count  298                                                     \ntotal feature count     6730                                                    \n\ncontain loop (12 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x406079\n  or:\n    characteristic: loop @ 0x406079\n\ncreate or open file (library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x411547\n  or:\n    api: CreateFile @ 0x411547\n\ncreate or open registry key (library rule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x40653B in function 0x40653B\n  or:\n    api: RegOpenKeyEx @ 0x406562\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x406079\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x406085\n        api: LockResource @ 0x406090\n      optional:\n        api: SizeofResource @ 0x40609E\n\naccept command line arguments\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x406788\n  or:\n    api: GetCommandLine @ 0x406816\n\nget Program Files directory\nnamespace  host-interaction/file-system                   \nauthor     moritz.raabe@mandiant.com                      \nscope      basic block                                    \natt&ck     Discovery::File and Directory Discovery [T1083]\nbasic block @ 0x40649E in function 0x40639F\n  and:\n    or:\n      number: 0x26 = CSIDL_PROGRAM_FILES @ 0x4064C3\n    or:\n      api: SHGetFolderPath @ 0x4064C9\n\nget common file path\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x40639F\n  or:\n    api: SHGetFolderPath @ 0x4064C9\n\nquery or enumerate registry value\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x40653B\n  and:\n    optional:\n      match: create or open registry key @ 0x40653B\n        or:\n          api: RegOpenKeyEx @ 0x406562\n    or:\n      api: SHQueryValueEx @ 0x4065A5\n\nlink function at runtime on Windows (4 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x40679E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40679E\ninstruction @ 0x406807\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x406807\ninstruction @ 0x40C17D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40C17D\ninstruction @ 0x40C17D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40C17D\n\n\n\n"},"hashes":{"md5":"82f657b0aee67a6a560321cf0927f9f7","sha1":"703175455354cdbd4244668c94704fee585a9228","sha256":"794cf7644115198db451431bca7c89ff9a97550482b1e3f7f13eb7aca6120a11"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 187</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 6730</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Nutanix\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"82f657b0aee67a6a560321cf0927f9f7\",\n        \"sha256\": \"794cf7644115198db451431bca7c89ff9a97550482b1e3f7f13eb7a\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__12_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (12 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x406079\",\n      \"label\": \"Function 0x406079\",\n      \"type\": \"function\",\n      \"address\": \"0x406079\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments\",\n      \"label\": \"accept command line arguments\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x406788\",\n      \"label\": \"Function 0x406788\",\n      \"type\": \"function\",\n      \"address\": \"0x406788\"\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_program_files_directory\",\n      \"label\": \"get Program Files directory\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40649E\",\n      \"label\": \"Block 0x40649E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40649E\"\n    },\n    {\n      \"id\": \"api_SHGetFolderPath\",\n      \"label\": \"SHGetFolderPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path\",\n      \"label\": \"get common file path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40639F\",\n      \"label\": \"Function 0x40639F\",\n      \"type\": \"function\",\n      \"address\": \"0x40639F\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value\",\n      \"label\": \"query or enumerate registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40653B\",\n      \"label\": \"Function 0x40653B\",\n      \"type\": \"function\",\n      \"address\": \"0x40653B\"\n    },\n    {\n      \"id\": \"api_SHQueryValueEx\",\n      \"label\": \"SHQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__4_matches_\",\n      \"label\": \"link function at runtime on Windows (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__12_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__12_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x406079\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x406079\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406079\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406079\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406079\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x406079\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406079\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406079\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406079\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments\",\n      \"target\": \"func_0x406788\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406788\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406788\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406788\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_program_files_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_program_files_directory\",\n      \"target\": \"bb_0x40649E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x40649E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path\",\n      \"target\": \"func_0x40639F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40639F\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40639F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40639F\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value\",\n      \"target\": \"func_0x40653B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40653B\",\n      \"target\": \"api_SHQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40653B\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40653B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40653B\",\n      \"target\": \"api_SHQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40653B\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-06-14 19:38:05.030141\",\n    \"total_functions\": \"187\",\n    \"total_features\": \"6730\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-06-14 19:38:06"}
{"_id":{"$oid":"6a2eb801ae36b72c92a10928"},"sha256":"de78577b54a8f71b2f6f4289cdabbfa971d5b7a1bd2ad8ef71b797e9c7d86e7a","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_1rwuas5c/NutanixVSSRequestor-019ec65c196b75e199a853889f4dd1f1.dll_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_1rwuas5c/NutanixVSSRequestor-019ec65c196b75e199a853889f4dd1f1.dll_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_1rwuas5c/NutanixVSSRequestor-019ec65c196b75e199a853889f4dd1f1.dll_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ cc42e0f5d91849390e399c1991905d1c                                  │\n│ sha1     │ 8e4cb20a026dacad99119046e58fefb73095c1f6                          │\n│ sha256   │ de78577b54a8f71b2f6f4289cdabbfa971d5b7a1bd2ad8ef71b797e9c7d86e7a  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ amd64                                                             │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/NutanixVSSReques… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic             ┃ ATT&CK Technique                                 ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION           │ Obfuscated Files or Information [T1027]          │\n│ DISCOVERY                 │ File and Directory Discovery [T1083]             │\n│                           │ System Information Discovery [T1082]             │\n│ PERSISTENCE               │ Pre-OS Boot::System Firmware [T1542.001]         │\n└───────────────────────────┴──────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DATA                 │ Encode Data::XOR [C0026.002]                          │\n│                      │ Non-Cryptographic Hash::FNV [C0030.005]               │\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Encoding-Standard    │\n│                      │ Algorithm [E1027.m02]                                 │\n│ DISCOVERY            │ File and Directory Discovery [E1083]                  │\n│                      │ System Information Discovery [E1082]                  │\n│ FILE SYSTEM          │ Create Directory [C0046]                              │\n│                      │ Delete Directory [C0048]                              │\n│                      │ Delete File [C0047]                                   │\n│                      │ Writes File [C0052]                                   │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ encode data using XOR (7 matches)     │ data-manipulation/encoding/xor       │\n│ hash data using fnv (10 matches)      │ data-manipulation/hashing/fnv        │\n│ contains PDB path                     │ executable/pe/pdb                    │\n│ get UEFI variable                     │ host-interaction/bootloader          │\n│ query environment variable            │ host-interaction/environment-variab… │\n│ create directory                      │ host-interaction/file-system/create  │\n│ delete directory                      │ host-interaction/file-system/delete  │\n│ delete file                           │ host-interaction/file-system/delete  │\n│ check if file exists (2 matches)      │ host-interaction/file-system/exists  │\n│ enumerate files recursively (2        │ host-interaction/file-system/files/… │\n│ matches)                              │                                      │\n│ get file version info                 │ host-interaction/file-system/meta    │\n│ write file on Windows (2 matches)     │ host-interaction/file-system/write   │\n│ enumerate disk volumes                │ host-interaction/hardware/storage    │\n│ get disk information (3 matches)      │ host-interaction/hardware/storage    │\n│ get storage device properties         │ host-interaction/hardware/storage    │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     cc42e0f5d91849390e399c1991905d1c                        \nsha1                    8e4cb20a026dacad99119046e58fefb73095c1f6                \nsha256                  de78577b54a8f71b2f6f4289cdabbfa971d5b7a1bd2ad8ef71b797e…\npath                    /home/apogean/projects/malware/windows/all_runs/Nutanix…\ntimestamp               2026-06-14 19:46:38.504306                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x180000000                                             \nrules                   /tmp/_MEIV6xDCB/rules                                   \nfunction count          517                                                     \nlibrary function count  74                                                      \ntotal feature count     34023                                                   \n\nencode data using XOR (7 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x1800194B0                   \n           0x180019670                   \n           0x18001A8C0                   \n           0x18001B3B1                   \n           0x18001BCE0                   \n           0x18001C530                   \n           0x18001CF80                   \n\nhash data using fnv (10 matches)\nnamespace    data-manipulation/hashing/fnv                                      \ndescription  can be any Fowler-Noll-Vo (FNV) hash variant, including FNV-1,     \n             FNV-1a, FNV-0                                                      \nscope        function                                                           \nmatches      0x18000CB60                                                        \n             0x18000CCE0                                                        \n             0x18000CEC0                                                        \n             0x180019450                                                        \n             0x180019610                                                        \n             0x18001A850                                                        \n             0x18001B360                                                        \n             0x18001BC70                                                        \n             0x18001C4C0                                                        \n             0x18001CF20                                                        \n\ncontains PDB path\nnamespace  executable/pe/pdb\nscope      file             \n\nget UEFI variable\nnamespace  host-interaction/bootloader\nscope      function                   \nmatches    0x1800032B0                \n\ninteract with driver via IOCTL (6 matches)\nnamespace  host-interaction/driver\nscope      instruction            \nmatches    0x180003A2F            \n           0x180003B46            \n           0x180004A8B            \n           0x180004E43            \n           0x180004F1A            \n           0x180004F94            \n\nquery environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x18000A390                          \n\ncreate directory\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x18000A7D0                        \n\ndelete directory\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x18000B6D0                        \n\ndelete file\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x18000B6D0                        \n\ncheck if file exists (2 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x18000AB70                        \n           0x18000B6D0                        \n\nenumerate files on Windows (2 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x18000AB70                            \n           0x18000B6D0                            \n\nenumerate files recursively (2 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x18000AB70                            \n           0x18000B6D0                            \n\nget file version info\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x180001260                      \n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x180009D70                       \n           0x180018200                       \n\nenumerate disk volumes\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x180003EB0                      \n\nget disk information (3 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x1800021C0                      \n           0x1800030D0                      \n           0x180004550                      \n\nget storage device properties\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x180004EB0                      \n\n\n\n","very_verbose":"md5                     cc42e0f5d91849390e399c1991905d1c                        \nsha1                    8e4cb20a026dacad99119046e58fefb73095c1f6                \nsha256                  de78577b54a8f71b2f6f4289cdabbfa971d5b7a1bd2ad8ef71b797e…\npath                    /home/apogean/projects/malware/windows/all_runs/Nutanix…\ntimestamp               2026-06-14 19:47:33.328434                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x180000000                                             \nrules                   /tmp/_MEIbifZBG/rules                                   \nfunction count          517                                                     \nlibrary function count  74                                                      \ntotal feature count     34023                                                   \n\ncontain loop (131 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x1800015E0\n  or:\n    characteristic: loop @ 0x1800015E0\n    characteristic: tight loop @ 0x1800017C0\n\ncreate or open file (4 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x1800039CB\n  or:\n    api: CreateFile @ 0x1800039CB\n\nencode data using XOR (7 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x1800194B0 in function 0x180019450\n  and:\n    characteristic: tight loop @ 0x1800194B0\n    characteristic: nzxor @ 0x1800194B8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x180019670 in function 0x180019610\n  and:\n    characteristic: tight loop @ 0x180019670\n    characteristic: nzxor @ 0x180019678\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x18001A8C0 in function 0x18001A850\n  and:\n    characteristic: tight loop @ 0x18001A8C0\n    characteristic: nzxor @ 0x18001A8C5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x18001B3B1 in function 0x18001B360\n  and:\n    characteristic: tight loop @ 0x18001B3B1\n    characteristic: nzxor @ 0x18001B3B9\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x18001BCE0 in function 0x18001BC70\n  and:\n    characteristic: tight loop @ 0x18001BCE0\n    characteristic: nzxor @ 0x18001BCE5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x18001C530 in function 0x18001C4C0\n  and:\n    characteristic: tight loop @ 0x18001C530\n    characteristic: nzxor @ 0x18001C535\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x18001CF80 in function 0x18001CF20\n  and:\n    characteristic: tight loop @ 0x18001CF80\n    characteristic: nzxor @ 0x18001CF88\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nhash data using fnv (10 matches)\nnamespace    data-manipulation/hashing/fnv                                      \nauthor       moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com  \nscope        function                                                           \nmbc          Data::Non-Cryptographic Hash::FNV [C0030.005]                      \nreferences   https://en.wikipedia.org/wiki/Fowler%E2%80%93Noll%E2%80%93Vo_hash_…\n             http://isthe.com/chongo/tech/comp/fnv/,                            \n             https://create.stephan-brumme.com/fnv-hash/                        \ndescription  can be any Fowler-Noll-Vo (FNV) hash variant, including FNV-1,     \n             FNV-1a, FNV-0                                                      \nfunction @ 0x18000CB60\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x18000CB9F, 0x18000CBB5\n        or:\n          mnemonic: imul @ 0x18000CBAC, 0x18000CBB8\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x18000CBA2\n    optional:\n      characteristic: loop @ 0x18000CB60\n      number: 0xCBF29CE484222325 = FNV_offset_basis, unused by FNV-0 @ 0x18000CB95\nfunction @ 0x18000CCE0\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x18000CD4B, 0x18000CD64\n        or:\n          mnemonic: imul @ 0x18000CD60, 0x18000CD67\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x18000CD2C\n    optional:\n      characteristic: loop @ 0x18000CCE0\n      number: 0xCBF29CE484222325 = FNV_offset_basis, unused by FNV-0 @ 0x18000CD1D\nfunction @ 0x18000CEC0\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x18000CF00, 0x18000CF10\n        or:\n          mnemonic: imul @ 0x18000CF0C, 0x18000CF13\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x18000CEEC\n    optional:\n      number: 0xCBF29CE484222325 = FNV_offset_basis, unused by FNV-0 @ 0x18000CEF6\nfunction @ 0x180019450\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x1800194B8\n        or:\n          mnemonic: imul @ 0x1800194BB\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x1800194A6\n    optional:\n      characteristic: loop @ 0x180019450\n      number: 0xCBF29CE484222325 = FNV_offset_basis, unused by FNV-0 @ 0x180019497\nfunction @ 0x180019610\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x180019678\n        or:\n          mnemonic: imul @ 0x18001967B\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x18001965E\n    optional:\n      characteristic: loop @ 0x180019610\n      number: 0xCBF29CE484222325 = FNV_offset_basis, unused by FNV-0 @ 0x18001964F\nfunction @ 0x18001A850\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x18001A8C5\n        or:\n          mnemonic: imul @ 0x18001A8C8\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x18001A8AC\n    optional:\n      characteristic: loop @ 0x18001A850\n      number: 0xCBF29CE484222325 = FNV_offset_basis, unused by FNV-0 @ 0x18001A897\nfunction @ 0x18001B360\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x18001B3B9\n        or:\n          mnemonic: imul @ 0x18001B3BC\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x18001B3A7\n    optional:\n      number: 0xCBF29CE484222325 = FNV_offset_basis, unused by FNV-0 @ 0x18001B398\nfunction @ 0x18001BC70\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x18001BCE5\n        or:\n          mnemonic: imul @ 0x18001BCE8\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x18001BCCF\n    optional:\n      characteristic: loop @ 0x18001BC70\n      number: 0xCBF29CE484222325 = FNV_offset_basis, unused by FNV-0 @ 0x18001BCBA\nfunction @ 0x18001C4C0\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x18001C535\n        or:\n          mnemonic: imul @ 0x18001C538\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x18001C51F\n    optional:\n      characteristic: loop @ 0x18001C4C0\n      number: 0xCBF29CE484222325 = FNV_offset_basis, unused by FNV-0 @ 0x18001C50A\nfunction @ 0x18001CF20\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x18001CF88\n        or:\n          mnemonic: imul @ 0x18001CF8B\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x18001CF6D\n    optional:\n      number: 0xCBF29CE484222325 = FNV_offset_basis, unused by FNV-0 @ 0x18001CF5E\n\ncontains PDB path\nnamespace  executable/pe/pdb        \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nregex: /:\\\\.*\\.pdb/\n  - \"C:\\\\Users\\\\Administrator\\\\Documents\\\\NGT\\\\ngt_20241019_140230\\\\ngt\\\\vss\\\\window\ns\\\\source\\\\NutanixVSSSolution\\\\x64\\\\Release\\\\NutanixVSSRequestor.pdb\" @ file+0x340B4\n\nget UEFI variable\nnamespace   host-interaction/bootloader                                         \nauthor      jakub.jozwiak@mandiant.com                                          \nscope       function                                                            \natt&ck      Persistence::Pre-OS Boot::System Firmware [T1542.001]               \nreferences  https://learn.microsoft.com/en-us/windows/win32/sysinfo/access-uefi…\nfunction @ 0x1800032B0\n  or:\n    api: GetFirmwareEnvironmentVariable @ 0x18000331E\n\ninteract with driver via IOCTL (6 matches)\nnamespace  host-interaction/driver  \nauthor     moritz.raabe@mandiant.com\nscope      instruction              \ninstruction @ 0x180003A2F\n  or:\n    api: DeviceIoControl @ 0x180003A2F\ninstruction @ 0x180003B46\n  or:\n    api: DeviceIoControl @ 0x180003B46\ninstruction @ 0x180004A8B\n  or:\n    api: DeviceIoControl @ 0x180004A8B\ninstruction @ 0x180004E43\n  or:\n    api: DeviceIoControl @ 0x180004E43\ninstruction @ 0x180004F1A\n  or:\n    api: DeviceIoControl @ 0x180004F1A\ninstruction @ 0x180004F94\n  or:\n    api: DeviceIoControl @ 0x180004F94\n\nquery environment variable\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x18000A390\n  or:\n    api: ExpandEnvironmentStrings @ 0x18000A41A\n\ncreate directory\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x18000A7D0\n  or:\n    api: CreateDirectory @ 0x18000A9B1\n\ndelete directory\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ 0x18000B6D0\n  or:\n    api: RemoveDirectory @ 0x18000B983\n\ndelete file\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x18000B6D0\n  or:\n    api: DeleteFile @ 0x18000B76C, 0x18000B8D0\n\ncheck if file exists (2 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x18000AB70\n  or:\n    api: PathFileExists @ 0x18000ABB6\nfunction @ 0x18000B6D0\n  or:\n    basic block:\n      and:\n        api: GetLastError @ 0x18000B991\n        instruction:\n          and:\n            mnemonic: cmp @ 0x18000B997\n            number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x18000B997\n      and:\n        api: GetLastError @ 0x18000B77A\n        instruction:\n          and:\n            mnemonic: cmp @ 0x18000B780\n            number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x18000B780\n\nenumerate files on Windows (2 matches)\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ 0x18000AB70\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x18000ACE8, 0x18000AF06\n      or:\n        api: FindNextFile @ 0x18000AEB7, 0x18000B051\n      optional:\n        api: FindClose @ 0x18000AECA, 0x18000B062\n        match: contain loop @ 0x18000AB70\n          or:\n            characteristic: loop @ 0x18000AB70\n            characteristic: tight loop @ 0x18000ABF7, 0x18000ADD0, 0x18000AF70\n            characteristic: recursive call @ 0x18000AB70\nfunction @ 0x18000B6D0\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x18000B83B\n      or:\n        api: FindNextFile @ 0x18000B8E1\n      optional:\n        api: FindClose @ 0x18000B97A\n        match: contain loop @ 0x18000B6D0\n          or:\n            characteristic: loop @ 0x18000B6D0\n            characteristic: tight loop @ 0x18000B730\n            characteristic: recursive call @ 0x18000B6D0\n\nenumerate files recursively (2 matches)\nnamespace  host-interaction/file-system/files/list        \nauthor     @_re_fox, anushka.virgaonkar@mandiant.com      \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nmbc        Discovery::File and Directory Discovery [E1083]\nfunction @ 0x18000AB70\n  and:\n    characteristic: recursive call @ 0x18000AB70\n    or:\n      match: enumerate files on Windows @ 0x18000AB70\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x18000ACE8, 0x18000AF06\n            or:\n              api: FindNextFile @ 0x18000AEB7, 0x18000B051\n            optional:\n              api: FindClose @ 0x18000AECA, 0x18000B062\n              match: contain loop @ 0x18000AB70\n                or:\n                  characteristic: loop @ 0x18000AB70\n                  characteristic: tight loop @ 0x18000ABF7, 0x18000ADD0, 0x18000AF70\n                  characteristic: recursive call @ 0x18000AB70\nfunction @ 0x18000B6D0\n  and:\n    characteristic: recursive call @ 0x18000B6D0\n    or:\n      match: enumerate files on Windows @ 0x18000B6D0\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x18000B83B\n            or:\n              api: FindNextFile @ 0x18000B8E1\n            optional:\n              api: FindClose @ 0x18000B97A\n              match: contain loop @ 0x18000B6D0\n                or:\n                  characteristic: loop @ 0x18000B6D0\n                  characteristic: tight loop @ 0x18000B730\n                  characteristic: recursive call @ 0x18000B6D0\n\nget file version info\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x180001260\n  and:\n    or:\n      api: GetFileVersionInfo @ 0x180001372\n    optional: = retrieve specified version information from the version-information resource\n      api: VerQueryValue @ 0x1800013AC\n      or:\n        api: GetFileVersionInfoSize @ 0x180001333\n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x180009D70\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x180009F88\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x18000A0A3\n            match: create or open file @ 0x18000A0AC\n              or:\n                api: CreateFile @ 0x18000A0AC\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x180009FB7\n      or:\n        api: WriteFile @ 0x18000A186\nfunction @ 0x180018200\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x180018443\n            match: create or open file @ 0x18001844C\n              or:\n                api: CreateFile @ 0x18001844C\n      or:\n        api: WriteFile @ 0x180018527\n\nenumerate disk volumes\nnamespace  host-interaction/hardware/storage              \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x180003EB0\n  and:\n    match: contain loop @ 0x180003EB0\n      or:\n        characteristic: loop @ 0x180003EB0\n        characteristic: tight loop @ 0x1800040D4, 0x180004170\n    or:\n      and:\n        api: FindFirstVolume @ 0x180004098\n        api: FindNextVolume @ 0x180004458\n        optional:\n          api: FindVolumeClose @ 0x1800044E9\n\nget disk information (3 matches)\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ 0x1800021C0\n  or:\n    api: GetVolumePathNamesForVolumeName @ 0x1800022C1\nfunction @ 0x1800030D0\n  or:\n    api: QueryDosDevice @ 0x1800031CB\nfunction @ 0x180004550\n  or:\n    api: GetVolumeNameForVolumeMountPoint @ 0x18000487D\n\nget storage device properties\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com                                        \nscope       function                                                            \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/winioctl/ni-wini…\nfunction @ 0x180004EB0\n  and:\n    number: 0x2D1400 = IOCTL_STORAGE_QUERY_PROPERTY @ 0x180004EF2, 0x180004F83\n    or:\n      match: interact with driver via IOCTL @ 0x180004F1A, 0x180004F94\n        or:\n          api: DeviceIoControl @ 0x180004F1A\n        or:\n          api: DeviceIoControl @ 0x180004F94\n\n\n\n"},"hashes":{"md5":"cc42e0f5d91849390e399c1991905d1c","sha1":"8e4cb20a026dacad99119046e58fefb73095c1f6","sha256":"de78577b54a8f71b2f6f4289cdabbfa971d5b7a1bd2ad8ef71b797e9c7d86e7a"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 517</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 34023</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Nutanix\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"cc42e0f5d91849390e399c1991905d1c\",\n        \"sha256\": \"de78577b54a8f71b2f6f4289cdabbfa971d5b7a1bd2ad8ef71b797e\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__131_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (131 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1800015E0\",\n      \"label\": \"Function 0x1800015E0\",\n      \"type\": \"function\",\n      \"address\": \"0x1800015E0\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_hash_data_using_fnv__10_matches_\",\n      \"label\": \"hash data using fnv (10 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::FNV [C0030.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x18000CB60\",\n      \"label\": \"Function 0x18000CB60\",\n      \"type\": \"function\",\n      \"address\": \"0x18000CB60\"\n    },\n    {\n      \"id\": \"func_0x180019610\",\n      \"label\": \"Function 0x180019610\",\n      \"type\": \"function\",\n      \"address\": \"0x180019610\"\n    },\n    {\n      \"id\": \"func_0x18001C4C0\",\n      \"label\": \"Function 0x18001C4C0\",\n      \"type\": \"function\",\n      \"address\": \"0x18001C4C0\"\n    },\n    {\n      \"id\": \"func_0x18001B360\",\n      \"label\": \"Function 0x18001B360\",\n      \"type\": \"function\",\n      \"address\": \"0x18001B360\"\n    },\n    {\n      \"id\": \"func_0x18000CEC0\",\n      \"label\": \"Function 0x18000CEC0\",\n      \"type\": \"function\",\n      \"address\": \"0x18000CEC0\"\n    },\n    {\n      \"id\": \"func_0x180019450\",\n      \"label\": \"Function 0x180019450\",\n      \"type\": \"function\",\n      \"address\": \"0x180019450\"\n    },\n    {\n      \"id\": \"func_0x18001A850\",\n      \"label\": \"Function 0x18001A850\",\n      \"type\": \"function\",\n      \"address\": \"0x18001A850\"\n    },\n    {\n      \"id\": \"func_0x18001BC70\",\n      \"label\": \"Function 0x18001BC70\",\n      \"type\": \"function\",\n      \"address\": \"0x18001BC70\"\n    },\n    {\n      \"id\": \"func_0x18000CCE0\",\n      \"label\": \"Function 0x18000CCE0\",\n      \"type\": \"function\",\n      \"address\": \"0x18000CCE0\"\n    },\n    {\n      \"id\": \"func_0x18001CF20\",\n      \"label\": \"Function 0x18001CF20\",\n      \"type\": \"function\",\n      \"address\": \"0x18001CF20\"\n    },\n    {\n      \"id\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author       moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::FNV [C0030.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contains_pdb_path\",\n      \"label\": \"contains PDB path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_uefi_variable\",\n      \"label\": \"get UEFI variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Pre-OS Boot::System Firmware [T1542.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1800032B0\",\n      \"label\": \"Function 0x1800032B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1800032B0\"\n    },\n    {\n      \"id\": \"api_GetFirmwareEnvironmentVariable\",\n      \"label\": \"GetFirmwareEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______jakub_jozwiak_mandiant_com\",\n      \"label\": \"author      jakub.jozwiak@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Pre-OS Boot::System Firmware [T1542.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_interact_with_driver_via_ioctl__6_matches_\",\n      \"label\": \"interact with driver via IOCTL (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_DeviceIoControl\",\n      \"label\": \"DeviceIoControl\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_environment_variable\",\n      \"label\": \"query environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x18000A390\",\n      \"label\": \"Function 0x18000A390\",\n      \"type\": \"function\",\n      \"address\": \"0x18000A390\"\n    },\n    {\n      \"id\": \"api_ExpandEnvironmentStrings\",\n      \"label\": \"ExpandEnvironmentStrings\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory\",\n      \"label\": \"create directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x18000A7D0\",\n      \"label\": \"Function 0x18000A7D0\",\n      \"type\": \"function\",\n      \"address\": \"0x18000A7D0\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_directory\",\n      \"label\": \"delete directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x18000B6D0\",\n      \"label\": \"Function 0x18000B6D0\",\n      \"type\": \"function\",\n      \"address\": \"0x18000B6D0\"\n    },\n    {\n      \"id\": \"api_RemoveDirectory\",\n      \"label\": \"RemoveDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_file\",\n      \"label\": \"delete file\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__2_matches_\",\n      \"label\": \"check if file exists (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x18000AB70\",\n      \"label\": \"Function 0x18000AB70\",\n      \"type\": \"function\",\n      \"address\": \"0x18000AB70\"\n    },\n    {\n      \"id\": \"api_GetLastError\",\n      \"label\": \"GetLastError\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_PathFileExists\",\n      \"label\": \"PathFileExists\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"label\": \"enumerate files on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindFirstFile\",\n      \"label\": \"FindFirstFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindClose\",\n      \"label\": \"FindClose\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindNextFile\",\n      \"label\": \"FindNextFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_recursively__2_matches_\",\n      \"label\": \"enumerate files recursively (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     @_re_fox, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_version_info\",\n      \"label\": \"get file version info\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180001260\",\n      \"label\": \"Function 0x180001260\",\n      \"type\": \"function\",\n      \"address\": \"0x180001260\"\n    },\n    {\n      \"id\": \"api_VerQueryValue\",\n      \"label\": \"VerQueryValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfo\",\n      \"label\": \"GetFileVersionInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfoSize\",\n      \"label\": \"GetFileVersionInfoSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__2_matches_\",\n      \"label\": \"write file on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180009D70\",\n      \"label\": \"Function 0x180009D70\",\n      \"type\": \"function\",\n      \"address\": \"0x180009D70\"\n    },\n    {\n      \"id\": \"func_0x180018200\",\n      \"label\": \"Function 0x180018200\",\n      \"type\": \"function\",\n      \"address\": \"0x180018200\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_disk_volumes\",\n      \"label\": \"enumerate disk volumes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180003EB0\",\n      \"label\": \"Function 0x180003EB0\",\n      \"type\": \"function\",\n      \"address\": \"0x180003EB0\"\n    },\n    {\n      \"id\": \"api_FindFirstVolume\",\n      \"label\": \"FindFirstVolume\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindVolumeClose\",\n      \"label\": \"FindVolumeClose\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindNextVolume\",\n      \"label\": \"FindNextVolume\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_disk_information__3_matches_\",\n      \"label\": \"get disk information (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1800030D0\",\n      \"label\": \"Function 0x1800030D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1800030D0\"\n    },\n    {\n      \"id\": \"func_0x1800021C0\",\n      \"label\": \"Function 0x1800021C0\",\n      \"type\": \"function\",\n      \"address\": \"0x1800021C0\"\n    },\n    {\n      \"id\": \"func_0x180004550\",\n      \"label\": \"Function 0x180004550\",\n      \"type\": \"function\",\n      \"address\": \"0x180004550\"\n    },\n    {\n      \"id\": \"api_GetVolumeNameForVolumeMountPoint\",\n      \"label\": \"GetVolumeNameForVolumeMountPoint\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_QueryDosDevice\",\n      \"label\": \"QueryDosDevice\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetVolumePathNamesForVolumeName\",\n      \"label\": \"GetVolumePathNamesForVolumeName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_storage_device_properties\",\n      \"label\": \"get storage device properties\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x180004EB0\",\n      \"label\": \"Function 0x180004EB0\",\n      \"type\": \"function\",\n      \"address\": \"0x180004EB0\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__131_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__131_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x1800015E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_fnv__10_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__10_matches_\",\n      \"target\": \"func_0x18000CB60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__10_matches_\",\n      \"target\": \"func_0x180019610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__10_matches_\",\n      \"target\": \"func_0x18001C4C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__10_matches_\",\n      \"target\": \"func_0x18001B360\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__10_matches_\",\n      \"target\": \"func_0x18000CEC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__10_matches_\",\n      \"target\": \"func_0x180019450\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__10_matches_\",\n      \"target\": \"func_0x18001A850\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__10_matches_\",\n      \"target\": \"func_0x18001BC70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__10_matches_\",\n      \"target\": \"func_0x18000CCE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__10_matches_\",\n      \"target\": \"func_0x18001CF20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18000CB60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180019610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18001C4C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18001B360\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18000CEC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180019450\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18001A850\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18001BC70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18000CCE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18001CF20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contains_pdb_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_uefi_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_uefi_variable\",\n      \"target\": \"func_0x1800032B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800032B0\",\n      \"target\": \"api_GetFirmwareEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______jakub_jozwiak_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______jakub_jozwiak_mandiant_com\",\n      \"target\": \"func_0x1800032B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800032B0\",\n      \"target\": \"api_GetFirmwareEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_interact_with_driver_via_ioctl__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable\",\n      \"target\": \"func_0x18000A390\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18000A390\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x18000A390\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18000A390\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory\",\n      \"target\": \"func_0x18000A7D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18000A7D0\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18000A7D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18000A7D0\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_directory\",\n      \"target\": \"func_0x18000B6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18000B6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file\",\n      \"target\": \"func_0x18000B6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18000B6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__2_matches_\",\n      \"target\": \"func_0x18000AB70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__2_matches_\",\n      \"target\": \"func_0x18000B6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18000AB70\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000AB70\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18000AB70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18000B6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18000AB70\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000AB70\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"target\": \"func_0x18000AB70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"target\": \"func_0x18000B6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18000AB70\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000AB70\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000AB70\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x18000AB70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x18000B6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18000AB70\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000AB70\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000AB70\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_recursively__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively__2_matches_\",\n      \"target\": \"func_0x18000AB70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively__2_matches_\",\n      \"target\": \"func_0x18000B6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18000AB70\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000AB70\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000AB70\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x18000AB70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x18000B6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18000AB70\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000AB70\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000AB70\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000B6D0\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_version_info\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_version_info\",\n      \"target\": \"func_0x180001260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180001260\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001260\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001260\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x180001260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180001260\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001260\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001260\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x180009D70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x180018200\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180009D70\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180018200\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180009D70\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180018200\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x180009D70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x180018200\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180009D70\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180018200\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180009D70\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180018200\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_disk_volumes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_disk_volumes\",\n      \"target\": \"func_0x180003EB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180003EB0\",\n      \"target\": \"api_FindFirstVolume\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180003EB0\",\n      \"target\": \"api_FindVolumeClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180003EB0\",\n      \"target\": \"api_FindNextVolume\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180003EB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180003EB0\",\n      \"target\": \"api_FindFirstVolume\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180003EB0\",\n      \"target\": \"api_FindVolumeClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180003EB0\",\n      \"target\": \"api_FindNextVolume\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__3_matches_\",\n      \"target\": \"func_0x1800030D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__3_matches_\",\n      \"target\": \"func_0x1800021C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__3_matches_\",\n      \"target\": \"func_0x180004550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800030D0\",\n      \"target\": \"api_GetVolumeNameForVolumeMountPoint\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800021C0\",\n      \"target\": \"api_GetVolumeNameForVolumeMountPoint\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180004550\",\n      \"target\": \"api_GetVolumeNameForVolumeMountPoint\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800030D0\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800021C0\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180004550\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800030D0\",\n      \"target\": \"api_GetVolumePathNamesForVolumeName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800021C0\",\n      \"target\": \"api_GetVolumePathNamesForVolumeName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180004550\",\n      \"target\": \"api_GetVolumePathNamesForVolumeName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1800030D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1800021C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x180004550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800030D0\",\n      \"target\": \"api_GetVolumeNameForVolumeMountPoint\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800021C0\",\n      \"target\": \"api_GetVolumeNameForVolumeMountPoint\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180004550\",\n      \"target\": \"api_GetVolumeNameForVolumeMountPoint\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800030D0\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800021C0\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180004550\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800030D0\",\n      \"target\": \"api_GetVolumePathNamesForVolumeName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800021C0\",\n      \"target\": \"api_GetVolumePathNamesForVolumeName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180004550\",\n      \"target\": \"api_GetVolumePathNamesForVolumeName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_storage_device_properties\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_storage_device_properties\",\n      \"target\": \"func_0x180004EB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180004EB0\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180004EB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180004EB0\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-06-14 19:47:33.328434\",\n    \"total_functions\": \"517\",\n    \"total_features\": \"34023\",\n    \"pdb_path\": \"C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\Documents\\\\\\\\NGT\\\\\\\\ngt_20241019_140230\\\\\\\\ngt\\\\\\\\vss\\\\\\\\window\\ns\\\\\\\\source\\\\\\\\NutanixVSSSolution\\\\\\\\x64\\\\\\\\Release\\\\\\\\NutanixVSSRequestor.pdb\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-06-14 19:47:37"}
{"_id":{"$oid":"6a2eba0aae36b72c92a1092b"},"sha256":"81d5cf4c95743f8fbff1801437aab774b572e7ab720f42678b7be0db422aced7","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_un7p1ydm/NutanixUtilityLibrary-019ec65c5ac27a3283d8b6fdbf5472e9.dll_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_un7p1ydm/NutanixUtilityLibrary-019ec65c5ac27a3283d8b6fdbf5472e9.dll_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_un7p1ydm/NutanixUtilityLibrary-019ec65c5ac27a3283d8b6fdbf5472e9.dll_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 45d6781630f760d4f0b464b003809059                                  │\n│ sha1     │ 86728e1eede28209aaab3b2275997f90c49b9f11                          │\n│ sha256   │ 81d5cf4c95743f8fbff1801437aab774b572e7ab720f42678b7be0db422aced7  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ amd64                                                             │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/NutanixUtilityLi… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic            ┃ ATT&CK Technique                                  ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION               │ Data from Information Repositories [T1213]        │\n│ DEFENSE EVASION          │ Modify Registry [T1112]                           │\n│                          │ Obfuscated Files or Information [T1027]           │\n│ DISCOVERY                │ File and Directory Discovery [T1083]              │\n│                          │ Query Registry [T1012]                            │\n│                          │ System Information Discovery [T1082]              │\n│ EXECUTION                │ Windows Management Instrumentation [T1047]        │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COMMAND AND CONTROL  │ C2 Communication::Receive Data [B0030.002]            │\n│                      │ C2 Communication::Send Data [B0030.001]               │\n│ COMMUNICATION        │ DNS Communication::Resolve [C0011.001]                │\n│                      │ Socket Communication::Initialize Winsock Library      │\n│                      │ [C0001.009]                                           │\n│                      │ Socket Communication::Receive Data [C0001.006]        │\n│                      │ Socket Communication::Send Data [C0001.007]           │\n│ CRYPTOGRAPHY         │ Encrypt Data [C0027]                                  │\n│ DISCOVERY            │ File and Directory Discovery [E1083]                  │\n│                      │ File and Directory Discovery::Log File [E1083.m01]    │\n│                      │ System Information Discovery [E1082]                  │\n│ FILE SYSTEM          │ Create Directory [C0046]                              │\n│                      │ Delete File [C0047]                                   │\n│                      │ Get File Attributes [C0049]                           │\n│                      │ Move File [C0063]                                     │\n│                      │ Read File [C0051]                                     │\n│                      │ Writes File [C0052]                                   │\n│ OPERATING SYSTEM     │ Registry::Delete Registry Value [C0036.007]           │\n│                      │ Registry::Query Registry Value [C0036.006]            │\n│                      │ Registry::Set Registry Key [C0036.001]                │\n│ PROCESS              │ Create Process [C0017]                                │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                           ┃ Namespace                             ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ reference WMI statements             │ collection/database/wmi               │\n│ receive data                         │ communication                         │\n│ send data                            │ communication                         │\n│ resolve DNS                          │ communication/dns                     │\n│ connect socket                       │ communication/socket                  │\n│ initialize Winsock library           │ communication/socket                  │\n│ encrypt data using DPAPI (2 matches) │ data-manipulation/encryption/dpapi    │\n│ contains PDB path                    │ executable/pe/pdb                     │\n│ query environment variable (4        │ host-interaction/environment-variable │\n│ matches)                             │                                       │\n│ get common file path                 │ host-interaction/file-system          │\n│ create directory (2 matches)         │ host-interaction/file-system/create   │\n│ delete file (2 matches)              │ host-interaction/file-system/delete   │\n│ check if file exists (4 matches)     │ host-interaction/file-system/exists   │\n│ get file attributes (2 matches)      │ host-interaction/file-system/meta     │\n│ move file                            │ host-interaction/file-system/move     │\n│ read file on Windows                 │ host-interaction/file-system/read     │\n│ write file on Windows                │ host-interaction/file-system/write    │\n│ print debug messages                 │ host-interaction/log/debug/write-eve… │\n│ access the Windows event log         │ host-interaction/log/winevt/access    │\n│ create process on Windows            │ host-interaction/process/create       │\n│ query or enumerate registry value    │ host-interaction/registry             │\n│ set registry value                   │ host-interaction/registry/create      │\n│ delete registry value                │ host-interaction/registry/delete      │\n│ connect to WMI namespace via         │ host-interaction/wmi                  │\n│ WbemLocator                          │                                       │\n└──────────────────────────────────────┴───────────────────────────────────────┘\n\n","verbose":"md5                     45d6781630f760d4f0b464b003809059                        \nsha1                    86728e1eede28209aaab3b2275997f90c49b9f11                \nsha256                  81d5cf4c95743f8fbff1801437aab774b572e7ab720f42678b7be0d…\npath                    /home/apogean/projects/malware/windows/all_runs/Nutanix…\ntimestamp               2026-06-14 19:55:21.268868                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x180000000                                             \nrules                   /tmp/_MEIWS5Sfe/rules                                   \nfunction count          772                                                     \nlibrary function count  115                                                     \ntotal feature count     47388                                                   \n\nreference WMI statements\nnamespace  collection/database/wmi\nscope      function               \nmatches    0x18002C700            \n\nreceive data\nnamespace    communication                                                     \ndescription  all known techniques for receiving data from a potential C2 server\nscope        function                                                          \nmatches      0x1800266F0                                                       \n\nsend data\nnamespace    communication                                                 \ndescription  all known techniques for sending data to a potential C2 server\nscope        function                                                      \nmatches      0x1800266F0                                                   \n\nresolve DNS\nnamespace  communication/dns\nscope      function         \nmatches    0x180026530      \n\nconnect socket\nnamespace    communication/socket                                               \ndescription  Detects socket connection attempts using common APIs or ConnectEx  \n             setup.                                                             \nscope        basic block                                                        \nmatches      0x18002661A                                                        \n\ninitialize Winsock library\nnamespace  communication/socket\nscope      function            \nmatches    0x180026370         \n\nreceive data on socket\nnamespace  communication/socket/receive\nscope      function                    \nmatches    0x1800266F0                 \n\nsend data on socket\nnamespace  communication/socket/send\nscope      function                 \nmatches    0x1800266F0              \n\nencrypt data using DPAPI (2 matches)\nnamespace  data-manipulation/encryption/dpapi\nscope      function                          \nmatches    0x180006810                       \n           0x180006C10                       \n\ncontains PDB path\nnamespace  executable/pe/pdb\nscope      file             \n\nquery environment variable (4 matches)\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x180007A40                          \n           0x180011940                          \n           0x180011A3E                          \n           0x180021270                          \n\nget common file path\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x1800029A0                 \n\ncreate directory (2 matches)\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x1800038A0                        \n           0x180007360                        \n\ndelete file (2 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x180002760                        \n           0x1800029A0                        \n\ncheck if file exists (4 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x180002760                        \n           0x180003B10                        \n           0x1800041D0                        \n           0x180007360                        \n\nget file attributes (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x180003D5D                      \n           0x1800073A3                      \n\nmove file\nnamespace  host-interaction/file-system/move\nscope      function                         \nmatches    0x1800123F0                      \n\nread file on Windows\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x1800020B0                      \n\nwrite file on Windows\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x180002210                       \n\nprint debug messages\nnamespace  host-interaction/log/debug/write-event\nscope      function                              \nmatches    0x1800135A0                           \n\naccess the Windows event log\nnamespace  host-interaction/log/winevt/access\nscope      function                          \nmatches    0x180013B00                       \n\ncreate process on Windows\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x180021D9F                    \n\nquery or enumerate registry value\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x180028CA0              \n\nset registry value\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x180029300                     \n\ndelete registry value\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x18002A080                     \n\nconnect to WMI namespace via WbemLocator\nnamespace  host-interaction/wmi\nscope      function            \nmatches    0x18002C260         \n\n\n\n","very_verbose":"md5                     45d6781630f760d4f0b464b003809059                        \nsha1                    86728e1eede28209aaab3b2275997f90c49b9f11                \nsha256                  81d5cf4c95743f8fbff1801437aab774b572e7ab720f42678b7be0d…\npath                    /home/apogean/projects/malware/windows/all_runs/Nutanix…\ntimestamp               2026-06-14 19:56:15.630438                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x180000000                                             \nrules                   /tmp/_MEIVPx5ej/rules                                   \nfunction count          772                                                     \nlibrary function count  115                                                     \ntotal feature count     47388                                                   \n\ncontain loop (179 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x180001140\n  or:\n    characteristic: tight loop @ 0x180001160\n\ncreate or open file (2 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x180001E1A\n  or:\n    api: CreateFile @ 0x180001E1A\n\ncreate or open registry key (2 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x1800287E0 in function 0x1800287E0\n  or:\n    api: RegOpenKeyEx @ 0x1800288B3\n\ndelay execution (library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x180021E93 in function 0x180021CD0\n  or:\n    and:\n      os: windows\n      or:\n        api: WaitForSingleObject @ 0x180021E9B\n\nreference WMI statements\nnamespace  collection/database/wmi                               \nauthor     michael.hunhoff@mandiant.com                          \nscope      function                                              \natt&ck     Collection::Data from Information Repositories [T1213]\nfunction @ 0x18002C700\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_Service where Name = \" @ 0x18002C7DC\n\nreceive data\nnamespace    communication                                                     \nauthor       william.ballenthin@mandiant.com                                   \nscope        function                                                          \nmbc          Command and Control::C2 Communication::Receive Data [B0030.002]   \ndescription  all known techniques for receiving data from a potential C2 server\nfunction @ 0x1800266F0\n  or:\n    match: receive data on socket @ 0x1800266F0\n      or:\n        api: recv @ 0x180026827\n\nsend data\nnamespace    communication                                                 \nauthor       william.ballenthin@mandiant.com, joakim@intezer.com           \nscope        function                                                      \nmbc          Command and Control::C2 Communication::Send Data [B0030.001]  \ndescription  all known techniques for sending data to a potential C2 server\nfunction @ 0x1800266F0\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x1800266F0\n          or:\n            api: send @ 0x1800267E8\n\nresolve DNS\nnamespace  communication/dns                                                    \nauthor     william.ballenthin@mandiant.com, johnk3r, joakim@intezer.com,        \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::DNS Communication::Resolve [C0011.001]                \nfunction @ 0x180026530\n  or:\n    api: getaddrinfo @ 0x1800265B3\n\nconnect socket\nnamespace    communication/socket                                               \nauthor       moritz.raabe@mandiant.com, joakim@intezer.com,                     \n             mrhafizfarhad@gmail.com                                            \nscope        basic block                                                        \ndescription  Detects socket connection attempts using common APIs or ConnectEx  \n             setup.                                                             \nbasic block @ 0x18002661A in function 0x180026530\n  or:\n    api: connect @ 0x180026625\n\ninitialize Winsock library\nnamespace  communication/socket                                                 \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Initialize Winsock Library      \n           [C0001.009]                                                          \nfunction @ 0x180026370\n  or:\n    api: WSAStartup @ 0x180026456\n\nreceive data on socket\nnamespace  communication/socket/receive                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Receive Data [C0001.006]        \nfunction @ 0x1800266F0\n  or:\n    api: recv @ 0x180026827\n\nsend data on socket\nnamespace  communication/socket/send                                            \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Communication::Socket Communication::Send Data [C0001.007]           \nfunction @ 0x1800266F0\n  or:\n    api: send @ 0x1800267E8\n\nencrypt data using DPAPI (2 matches)\nnamespace  data-manipulation/encryption/dpapi                           \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]     \nmbc        Cryptography::Encrypt Data [C0027]                           \nfunction @ 0x180006810\n  or:\n    api: CryptProtectData @ 0x180006A66\nfunction @ 0x180006C10\n  or:\n    api: CryptUnprotectData @ 0x180006DF7\n\ncontains PDB path\nnamespace  executable/pe/pdb        \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nregex: /:\\\\.*\\.pdb/\n  - \"C:\\\\Users\\\\Administrator\\\\Documents\\\\NGT\\\\ngt_20241019_140230\\\\ngt\\\\vss\\\\window\ns\\\\source\\\\NutanixVSSSolution\\\\x64\\\\Release\\\\NutanixUtilityLibrary.pdb\" @ file+0x45004\n\nquery environment variable (4 matches)\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x180007A40\n  or:\n    api: GetEnvironmentVariable @ 0x180007A74\nfunction @ 0x180011940\n  or:\n    api: GetEnvironmentVariable @ 0x180011ACB\nfunction @ 0x180011A3E\n  or:\n    api: GetEnvironmentVariable @ 0x180011ACB\nfunction @ 0x180021270\n  or:\n    api: ExpandEnvironmentStrings @ 0x1800212FD, 0x1800213BB\n\nget common file path\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x1800029A0\n  or:\n    api: GetTempPath @ 0x180002A04\n    api: GetTempFileName @ 0x180002A29\n\ncreate directory (2 matches)\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x1800038A0\n  or:\n    api: CreateDirectory @ 0x1800039B6\nfunction @ 0x180007360\n  or:\n    api: _mkdir @ 0x180007458\n\ndelete file (2 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x180002760\n  or:\n    api: DeleteFile @ 0x18000287B\nfunction @ 0x1800029A0\n  or:\n    api: DeleteFile @ 0x180002A3C\n\ncheck if file exists (4 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x180002760\n  or:\n    basic block:\n      and:\n        api: GetLastError @ 0x180002887\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1800028AA\n            number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x1800028AA\nfunction @ 0x180003B10\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x180003D8E\n        instruction:\n          and:\n            mnemonic: cmp @ 0x180003D94\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x180003D94\nfunction @ 0x1800041D0\n  or:\n    api: PathFileExists @ 0x180004243\nfunction @ 0x180007360\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x1800073A3\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1800073A9\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x1800073A9\n\nget file attributes (2 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x180003D5D in function 0x180003B10\n  or:\n    api: GetFileAttributes @ 0x180003D8E\nbasic block @ 0x1800073A3 in function 0x180007360\n  or:\n    api: GetFileAttributes @ 0x1800073A3\n\nmove file\nnamespace  host-interaction/file-system/move                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Move File [C0063]                         \nfunction @ 0x1800123F0\n  or:\n    api: rename @ 0x18001279E, 0x180012A35\n\nread file on Windows\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x1800020B0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x18000218D\n\nwrite file on Windows\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x180002210\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x1800022C9\n\nprint debug messages\nnamespace  host-interaction/log/debug/write-event\nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \nfunction @ 0x1800135A0\n  or:\n    api: OutputDebugString @ 0x1800135FB, 0x18001369B\n\naccess the Windows event log\nnamespace  host-interaction/log/winevt/access                           \nauthor     moritz.raabe@mandiant.com                                    \nscope      function                                                     \nmbc        Discovery::File and Directory Discovery::Log File [E1083.m01]\nfunction @ 0x180013B00\n  or:\n    api: ReportEvent @ 0x180013D2F\n\ncreate process on Windows\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x180021D9F in function 0x180021CD0\n  or:\n    api: CreateProcess @ 0x180021DE0\n\nquery or enumerate registry value\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x180028CA0\n  and:\n    or:\n      api: RegQueryValueEx @ 0x180028EB0, 0x180028F2F\n\nset registry value\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x180029300\n  or:\n    and:\n      or:\n        api: RegSetValueEx @ 0x180029464\n\ndelete registry value\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ 0x18002A080\n  and:\n    or:\n      api: RegDeleteKeyValue @ 0x18002A1CE\n\nconnect to WMI namespace via WbemLocator\nnamespace  host-interaction/wmi                                 \nauthor     michael.hunhoff@mandiant.com                         \nscope      function                                             \natt&ck     Execution::Windows Management Instrumentation [T1047]\nfunction @ 0x18002C260\n  or:\n    and: = static detection rule\n      basic block:\n        and:\n          api: CoCreateInstance @ 0x18002C4AD\n          or:\n            bytes: 11f890453a1dd011891f00aa004b2e24 = CLSID_WbemLocator as bytes @ 0x18002C4A6\n          or:\n            bytes: 87a612dc7f73cf11884d00aa004b2e24 = IID_IWbemLocator as bytes @ 0x18002C499\n      basic block:\n        or:\n          and:\n            arch: amd64\n            offset: 0x18 = ppv->ConnectServer @ 0x18002C2DC\n        or:\n          and:\n            arch: amd64\n            offset: 0x18 = ppv->ConnectServer @ 0x18002C562\n      optional:\n        regex: /ROOT\\\\CIMV2/i\n          - \"ROOT\\\\CIMV2\" @ 0x18002C503\n\n\n\n"},"hashes":{"md5":"45d6781630f760d4f0b464b003809059","sha1":"86728e1eede28209aaab3b2275997f90c49b9f11","sha256":"81d5cf4c95743f8fbff1801437aab774b572e7ab720f42678b7be0db422aced7"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 772</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 47388</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Nutanix\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"45d6781630f760d4f0b464b003809059\",\n        \"sha256\": \"81d5cf4c95743f8fbff1801437aab774b572e7ab720f42678b7be0d\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__179_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (179 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x180001140\",\n      \"label\": \"Function 0x180001140\",\n      \"type\": \"function\",\n      \"address\": \"0x180001140\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1800287E0\",\n      \"label\": \"Block 0x1800287E0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1800287E0\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_reference_wmi_statements\",\n      \"label\": \"reference WMI statements\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x18002C700\",\n      \"label\": \"Function 0x18002C700\",\n      \"type\": \"function\",\n      \"address\": \"0x18002C700\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_data\",\n      \"label\": \"receive data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1800266F0\",\n      \"label\": \"Function 0x1800266F0\",\n      \"type\": \"function\",\n      \"address\": \"0x1800266F0\"\n    },\n    {\n      \"id\": \"api_recv\",\n      \"label\": \"recv\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data\",\n      \"label\": \"send data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_send\",\n      \"label\": \"send\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_resolve_dns\",\n      \"label\": \"resolve DNS\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::DNS Communication::Resolve [C0011.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180026530\",\n      \"label\": \"Function 0x180026530\",\n      \"type\": \"function\",\n      \"address\": \"0x180026530\"\n    },\n    {\n      \"id\": \"api_getaddrinfo\",\n      \"label\": \"getaddrinfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::DNS Communication::Resolve [C0011.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_socket\",\n      \"label\": \"connect socket\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x18002661A\",\n      \"label\": \"Block 0x18002661A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x18002661A\"\n    },\n    {\n      \"id\": \"api_connect\",\n      \"label\": \"connect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_mrhafizfarhad_gmail_com\",\n      \"label\": \"mrhafizfarhad@gmail.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_initialize_winsock_library\",\n      \"label\": \"initialize Winsock library\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Initialize Winsock Library\",\n        \"[C0001.009]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180026370\",\n      \"label\": \"Function 0x180026370\",\n      \"type\": \"function\",\n      \"address\": \"0x180026370\"\n    },\n    {\n      \"id\": \"api_WSAStartup\",\n      \"label\": \"WSAStartup\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_receive_data_on_socket\",\n      \"label\": \"receive data on socket\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Receive Data [C0001.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data_on_socket\",\n      \"label\": \"send data on socket\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_dpapi__2_matches_\",\n      \"label\": \"encrypt data using DPAPI (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data [C0027]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180006C10\",\n      \"label\": \"Function 0x180006C10\",\n      \"type\": \"function\",\n      \"address\": \"0x180006C10\"\n    },\n    {\n      \"id\": \"func_0x180006810\",\n      \"label\": \"Function 0x180006810\",\n      \"type\": \"function\",\n      \"address\": \"0x180006810\"\n    },\n    {\n      \"id\": \"api_CryptProtectData\",\n      \"label\": \"CryptProtectData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CryptUnprotectData\",\n      \"label\": \"CryptUnprotectData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data [C0027]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contains_pdb_path\",\n      \"label\": \"contains PDB path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_query_environment_variable__4_matches_\",\n      \"label\": \"query environment variable (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180021270\",\n      \"label\": \"Function 0x180021270\",\n      \"type\": \"function\",\n      \"address\": \"0x180021270\"\n    },\n    {\n      \"id\": \"func_0x180011940\",\n      \"label\": \"Function 0x180011940\",\n      \"type\": \"function\",\n      \"address\": \"0x180011940\"\n    },\n    {\n      \"id\": \"func_0x180011A3E\",\n      \"label\": \"Function 0x180011A3E\",\n      \"type\": \"function\",\n      \"address\": \"0x180011A3E\"\n    },\n    {\n      \"id\": \"func_0x180007A40\",\n      \"label\": \"Function 0x180007A40\",\n      \"type\": \"function\",\n      \"address\": \"0x180007A40\"\n    },\n    {\n      \"id\": \"api_GetEnvironmentVariable\",\n      \"label\": \"GetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_ExpandEnvironmentStrings\",\n      \"label\": \"ExpandEnvironmentStrings\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path\",\n      \"label\": \"get common file path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1800029A0\",\n      \"label\": \"Function 0x1800029A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1800029A0\"\n    },\n    {\n      \"id\": \"api_GetTempFileName\",\n      \"label\": \"GetTempFileName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_directory__2_matches_\",\n      \"label\": \"create directory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1800038A0\",\n      \"label\": \"Function 0x1800038A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1800038A0\"\n    },\n    {\n      \"id\": \"func_0x180007360\",\n      \"label\": \"Function 0x180007360\",\n      \"type\": \"function\",\n      \"address\": \"0x180007360\"\n    },\n    {\n      \"id\": \"api__mkdir\",\n      \"label\": \"_mkdir\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_file__2_matches_\",\n      \"label\": \"delete file (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180002760\",\n      \"label\": \"Function 0x180002760\",\n      \"type\": \"function\",\n      \"address\": \"0x180002760\"\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__4_matches_\",\n      \"label\": \"check if file exists (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1800041D0\",\n      \"label\": \"Function 0x1800041D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1800041D0\"\n    },\n    {\n      \"id\": \"func_0x180003B10\",\n      \"label\": \"Function 0x180003B10\",\n      \"type\": \"function\",\n      \"address\": \"0x180003B10\"\n    },\n    {\n      \"id\": \"api_PathFileExists\",\n      \"label\": \"PathFileExists\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetLastError\",\n      \"label\": \"GetLastError\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_get_file_attributes__2_matches_\",\n      \"label\": \"get file attributes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x180003D5D\",\n      \"label\": \"Block 0x180003D5D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x180003D5D\"\n    },\n    {\n      \"id\": \"bb_0x1800073A3\",\n      \"label\": \"Block 0x1800073A3\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1800073A3\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_move_file\",\n      \"label\": \"move file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1800123F0\",\n      \"label\": \"Function 0x1800123F0\",\n      \"type\": \"function\",\n      \"address\": \"0x1800123F0\"\n    },\n    {\n      \"id\": \"api_rename\",\n      \"label\": \"rename\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_file_on_windows\",\n      \"label\": \"read file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1800020B0\",\n      \"label\": \"Function 0x1800020B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1800020B0\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows\",\n      \"label\": \"write file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180002210\",\n      \"label\": \"Function 0x180002210\",\n      \"type\": \"function\",\n      \"address\": \"0x180002210\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_print_debug_messages\",\n      \"label\": \"print debug messages\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1800135A0\",\n      \"label\": \"Function 0x1800135A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1800135A0\"\n    },\n    {\n      \"id\": \"api_OutputDebugString\",\n      \"label\": \"OutputDebugString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_access_the_windows_event_log\",\n      \"label\": \"access the Windows event log\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery::Log File [E1083.m01]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180013B00\",\n      \"label\": \"Function 0x180013B00\",\n      \"type\": \"function\",\n      \"address\": \"0x180013B00\"\n    },\n    {\n      \"id\": \"api_ReportEvent\",\n      \"label\": \"ReportEvent\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_process_on_windows\",\n      \"label\": \"create process on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x180021D9F\",\n      \"label\": \"Block 0x180021D9F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x180021D9F\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value\",\n      \"label\": \"query or enumerate registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180028CA0\",\n      \"label\": \"Function 0x180028CA0\",\n      \"type\": \"function\",\n      \"address\": \"0x180028CA0\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value\",\n      \"label\": \"set registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180029300\",\n      \"label\": \"Function 0x180029300\",\n      \"type\": \"function\",\n      \"address\": \"0x180029300\"\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delete_registry_value\",\n      \"label\": \"delete registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x18002A080\",\n      \"label\": \"Function 0x18002A080\",\n      \"type\": \"function\",\n      \"address\": \"0x18002A080\"\n    },\n    {\n      \"id\": \"api_RegDeleteKeyValue\",\n      \"label\": \"RegDeleteKeyValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_connect_to_wmi_namespace_via_wbemlocator\",\n      \"label\": \"connect to WMI namespace via WbemLocator\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Windows Management Instrumentation [T1047]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x18002C260\",\n      \"label\": \"Function 0x18002C260\",\n      \"type\": \"function\",\n      \"address\": \"0x18002C260\"\n    },\n    {\n      \"id\": \"api_CoCreateInstance\",\n      \"label\": \"CoCreateInstance\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__179_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__179_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x180001140\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x1800287E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_wmi_statements\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_reference_wmi_statements\",\n      \"target\": \"func_0x18002C700\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18002C700\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data\",\n      \"target\": \"func_0x1800266F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800266F0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x1800266F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800266F0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data\",\n      \"target\": \"func_0x1800266F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800266F0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x1800266F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800266F0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_dns\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_dns\",\n      \"target\": \"func_0x180026530\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180026530\",\n      \"target\": \"api_getaddrinfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180026530\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180026530\",\n      \"target\": \"api_getaddrinfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_socket\",\n      \"target\": \"bb_0x18002661A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mrhafizfarhad_gmail_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x18002661A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_initialize_winsock_library\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_initialize_winsock_library\",\n      \"target\": \"func_0x180026370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180026370\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180026370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180026370\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data_on_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket\",\n      \"target\": \"func_0x1800266F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800266F0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1800266F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800266F0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data_on_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket\",\n      \"target\": \"func_0x1800266F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800266F0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1800266F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800266F0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_dpapi__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_dpapi__2_matches_\",\n      \"target\": \"func_0x180006C10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_dpapi__2_matches_\",\n      \"target\": \"func_0x180006810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180006C10\",\n      \"target\": \"api_CryptProtectData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180006810\",\n      \"target\": \"api_CryptProtectData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180006C10\",\n      \"target\": \"api_CryptUnprotectData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180006810\",\n      \"target\": \"api_CryptUnprotectData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180006C10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180006810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180006C10\",\n      \"target\": \"api_CryptProtectData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180006810\",\n      \"target\": \"api_CryptProtectData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180006C10\",\n      \"target\": \"api_CryptUnprotectData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180006810\",\n      \"target\": \"api_CryptUnprotectData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contains_pdb_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__4_matches_\",\n      \"target\": \"func_0x180021270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__4_matches_\",\n      \"target\": \"func_0x180011940\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__4_matches_\",\n      \"target\": \"func_0x180011A3E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__4_matches_\",\n      \"target\": \"func_0x180007A40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180021270\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180011940\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180011A3E\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180007A40\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180021270\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180011940\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180011A3E\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180007A40\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x180021270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x180011940\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x180011A3E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x180007A40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180021270\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180011940\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180011A3E\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180007A40\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180021270\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180011940\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180011A3E\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180007A40\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path\",\n      \"target\": \"func_0x1800029A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800029A0\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800029A0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1800029A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800029A0\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800029A0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory__2_matches_\",\n      \"target\": \"func_0x1800038A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__2_matches_\",\n      \"target\": \"func_0x180007360\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800038A0\",\n      \"target\": \"api__mkdir\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180007360\",\n      \"target\": \"api__mkdir\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800038A0\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180007360\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1800038A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180007360\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800038A0\",\n      \"target\": \"api__mkdir\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180007360\",\n      \"target\": \"api__mkdir\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800038A0\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180007360\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__2_matches_\",\n      \"target\": \"func_0x1800029A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__2_matches_\",\n      \"target\": \"func_0x180002760\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800029A0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180002760\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1800029A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180002760\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800029A0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180002760\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__4_matches_\",\n      \"target\": \"func_0x1800041D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__4_matches_\",\n      \"target\": \"func_0x180003B10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__4_matches_\",\n      \"target\": \"func_0x180007360\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__4_matches_\",\n      \"target\": \"func_0x180002760\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800041D0\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180003B10\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180007360\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180002760\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800041D0\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180003B10\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180007360\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180002760\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800041D0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180003B10\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180007360\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180002760\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1800041D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180003B10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180007360\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180002760\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800041D0\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180003B10\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180007360\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180002760\",\n      \"target\": \"api_PathFileExists\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800041D0\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180003B10\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180007360\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180002760\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800041D0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180003B10\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180007360\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180002760\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__2_matches_\",\n      \"target\": \"bb_0x180003D5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__2_matches_\",\n      \"target\": \"bb_0x1800073A3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x180003D5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x1800073A3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_move_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_move_file\",\n      \"target\": \"func_0x1800123F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800123F0\",\n      \"target\": \"api_rename\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1800123F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800123F0\",\n      \"target\": \"api_rename\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows\",\n      \"target\": \"func_0x1800020B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800020B0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1800020B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800020B0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows\",\n      \"target\": \"func_0x180002210\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180002210\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x180002210\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180002210\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_print_debug_messages\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_print_debug_messages\",\n      \"target\": \"func_0x1800135A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800135A0\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1800135A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1800135A0\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_the_windows_event_log\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_access_the_windows_event_log\",\n      \"target\": \"func_0x180013B00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180013B00\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x180013B00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180013B00\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows\",\n      \"target\": \"bb_0x180021D9F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x180021D9F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value\",\n      \"target\": \"func_0x180028CA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180028CA0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x180028CA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180028CA0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value\",\n      \"target\": \"func_0x180029300\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180029300\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180029300\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180029300\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value\",\n      \"target\": \"func_0x18002A080\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18002A080\",\n      \"target\": \"api_RegDeleteKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x18002A080\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18002A080\",\n      \"target\": \"api_RegDeleteKeyValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_to_wmi_namespace_via_wbemlocator\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_to_wmi_namespace_via_wbemlocator\",\n      \"target\": \"func_0x18002C260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18002C260\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18002C260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18002C260\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-06-14 19:56:15.630438\",\n    \"total_functions\": \"772\",\n    \"total_features\": \"47388\",\n    \"pdb_path\": \"C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\Documents\\\\\\\\NGT\\\\\\\\ngt_20241019_140230\\\\\\\\ngt\\\\\\\\vss\\\\\\\\window\\ns\\\\\\\\source\\\\\\\\NutanixVSSSolution\\\\\\\\x64\\\\\\\\Release\\\\\\\\NutanixUtilityLibrary.pdb\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-06-14 19:56:18"}
{"_id":{"$oid":"6a2ebb3aae36b72c92a1092d"},"sha256":"5d902bd00a37c03539790f378dd557bcaab3dc85fd8ac30f57ad6d9644509dc4","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"43970f4d100f9658c1ededc2fb9183b7","sha1":"644dc51960e429c4564bf57ef032a53e0431127c","sha256":"5d902bd00a37c03539790f378dd557bcaab3dc85fd8ac30f57ad6d9644509dc4"}},"timestamp":"2026-06-14 20:01:22"}
{"_id":{"$oid":"6a2ebbd3ae36b72c92a10930"},"sha256":"50ff90147ed994daa56f18819e1dc34002be0a6150f358af629583e8d2c314e3","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_ewfpazo1/goopdate-019ec65ca5f57df1a10859b7d2a3a9b6.dll_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_ewfpazo1/goopdate-019ec65ca5f57df1a10859b7d2a3a9b6.dll_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_ewfpazo1/goopdate-019ec65ca5f57df1a10859b7d2a3a9b6.dll_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 57e87f284e837eed1a7983f2f9647128                                  │\n│ sha1     │ eff5168f7ae92463d71f5996c9b01aa5bd08a384                          │\n│ sha256   │ 50ff90147ed994daa56f18819e1dc34002be0a6150f358af629583e8d2c314e3  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/goopdate-019ec65… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic               ┃ ATT&CK Technique                               ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DISCOVERY                   │ File and Directory Discovery [T1083]           │\n│                             │ System Information Discovery [T1082]           │\n│ EXECUTION                   │ Shared Modules [T1129]                         │\n└─────────────────────────────┴────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective               ┃ MBC Behavior                                   ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DISCOVERY                   │ File and Directory Discovery [E1083]           │\n│ FILE SYSTEM                 │ Read File [C0051]                              │\n│ PROCESS                     │ Terminate Process [C0018]                      │\n└─────────────────────────────┴────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                              ┃ Namespace                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ contains PDB path                       │ executable/pe/pdb                  │\n│ get common file path                    │ host-interaction/file-system       │\n│ set current directory                   │ host-interaction/file-system       │\n│ read file on Windows (2 matches)        │ host-interaction/file-system/read  │\n│ get system information on Windows       │ host-interaction/os/info           │\n│ terminate process                       │ host-interaction/process/terminate │\n│ link function at runtime on Windows (3  │ linking/runtime-linking            │\n│ matches)                                │                                    │\n│ parse PE header                         │ load-code/pe                       │\n└─────────────────────────────────────────┴────────────────────────────────────┘\n\n","verbose":"md5                     57e87f284e837eed1a7983f2f9647128                        \nsha1                    eff5168f7ae92463d71f5996c9b01aa5bd08a384                \nsha256                  50ff90147ed994daa56f18819e1dc34002be0a6150f358af629583e…\npath                    /home/apogean/projects/malware/windows/all_runs/goopdat…\ntimestamp               2026-06-14 20:02:19.000579                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x10000000                                              \nrules                   /tmp/_MEIccX0VT/rules                                   \nfunction count          219                                                     \nlibrary function count  363                                                     \ntotal feature count     6763                                                    \n\ncontains PDB path\nnamespace  executable/pe/pdb\nscope      file             \n\nget common file path\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x10001170                  \n\nset current directory\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x10001170                  \n\nread file on Windows (2 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x10001170                       \n           0x10007CB7                       \n\nget system information on Windows\nnamespace  host-interaction/os/info\nscope      function                \nmatches    0x10001F00              \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x10001150                        \n\nlink function at runtime on Windows (3 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x10001157             \n           0x10001CD1             \n           0x10001ED9             \n\nparse PE header\nnamespace  load-code/pe\nscope      function    \nmatches    0x10001F00  \n\n\n\n","very_verbose":"md5                     57e87f284e837eed1a7983f2f9647128                        \nsha1                    eff5168f7ae92463d71f5996c9b01aa5bd08a384                \nsha256                  50ff90147ed994daa56f18819e1dc34002be0a6150f358af629583e…\npath                    /home/apogean/projects/malware/windows/all_runs/goopdat…\ntimestamp               2026-06-14 20:03:53.190008                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x10000000                                              \nrules                   /tmp/_MEIqfsV7P/rules                                   \nfunction count          219                                                     \nlibrary function count  363                                                     \ntotal feature count     6763                                                    \n\nallocate memory (4 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x10001E80 in function 0x10001E80\n  or:\n    api: VirtualAlloc @ 0x10001E8F\n\nallocate or change RW memory (3 matches, only showing first match of library \nrule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x10001FD6 in function 0x10001F00\n  and:\n    or:\n      match: allocate memory @ 0x10001FD6\n        or:\n          api: VirtualAlloc @ 0x10001FE7\n    or:\n      number: 0x4 = PAGE_READWRITE @ 0x10001FDC\n\nchange memory protection (library rule)\nauthor  @mr-tz                                  \nscope   basic block                             \nmbc     Memory::Change Memory Protection [C0008]\nbasic block @ 0x10001CCB in function 0x10001C10\n  or:\n    basic block:\n      and:\n        match: link function at runtime on Windows @ 0x10001CD1\n          and:\n            os: windows\n            or:\n              api: GetProcAddress @ 0x10001CD1\n        or:\n          string: \"VirtualProtect\" @ 0x10001CCB\n\ncontain loop (16 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x10001170\n  or:\n    characteristic: loop @ 0x10001170\n    characteristic: tight loop @ 0x10001200, 0x10001265, 0x10001275, 0x100012A4\n\ncreate or open file (2 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x10001395\n  or:\n    api: fopen @ 0x10001395\n\ncontains PDB path\nnamespace  executable/pe/pdb        \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nregex: /:\\\\.*\\.pdb/\n  - \"G:\\\\learn\\\\r3\\\\dllgoodate\\\\Release\\\\dllgoodate.pdb\" @ file+0x14294\n\nget common file path\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x10001170\n  or:\n    api: GetSystemDirectory @ 0x100011F2\n\nset current directory\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x10001170\n  or:\n    api: SetCurrentDirectory @ 0x100011CA\n\nread file on Windows (2 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x10001170\n  or:\n    and:\n      os: windows\n      or:\n        api: fread @ 0x10001430\nfunction @ 0x10007CB7\n  or:\n    and:\n      os: windows\n      or:\n        api: _read @ 0x10007BCB\n\nget system information on Windows\nnamespace  host-interaction/os/info                       \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com  \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x10001F00\n  and:\n    os: windows\n    or:\n      api: GetNativeSystemInfo @ 0x10001FB1\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x10001150\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x10001163\n\nlink function at runtime on Windows (3 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x10001157\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x10001157\ninstruction @ 0x10001CD1\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x10001CD1\ninstruction @ 0x10001ED9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x10001ED9\n\nparse PE header\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x10001F00\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x10001F1D, 0x10001F39, 0x10001F3D, 0x10001F56, and 15 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x10001F3D\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x10001F12\n      optional:\n        and:\n          operand[1].offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x10002246, 0x10002269, 0x1000227C, 0x100022B6\n          or:\n            and:\n              arch: i386\n              operand[1].offset: 0x50 = IMAGE_NT_HEADERS.OptionalHeader.SizeOfImage @ 0x10001FC2\n              operand[1].offset: 0x34 = IMAGE_NT_HEADERS.OptionalHeader.ImageBase @ 0x100021A4, 0x100021A7\n\n\n\n"},"hashes":{"md5":"57e87f284e837eed1a7983f2f9647128","sha1":"eff5168f7ae92463d71f5996c9b01aa5bd08a384","sha256":"50ff90147ed994daa56f18819e1dc34002be0a6150f358af629583e8d2c314e3"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 219</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 6763</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"goopdat\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"57e87f284e837eed1a7983f2f9647128\",\n        \"sha256\": \"50ff90147ed994daa56f18819e1dc34002be0a6150f358af629583e\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_allocate_memory__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"allocate memory (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x10001E80\",\n      \"label\": \"Block 0x10001E80\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x10001E80\"\n    },\n    {\n      \"id\": \"api_VirtualAlloc\",\n      \"label\": \"VirtualAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x10001FD6\",\n      \"label\": \"Block 0x10001FD6\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x10001FD6\"\n    },\n    {\n      \"id\": \"cap_contain_loop__16_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (16 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x10001170\",\n      \"label\": \"Function 0x10001170\",\n      \"type\": \"function\",\n      \"address\": \"0x10001170\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_fopen\",\n      \"label\": \"fopen\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_contains_pdb_path\",\n      \"label\": \"contains PDB path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path\",\n      \"label\": \"get common file path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_current_directory\",\n      \"label\": \"set current directory\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_SetCurrentDirectory\",\n      \"label\": \"SetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__2_matches_\",\n      \"label\": \"read file on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x10007CB7\",\n      \"label\": \"Function 0x10007CB7\",\n      \"type\": \"function\",\n      \"address\": \"0x10007CB7\"\n    },\n    {\n      \"id\": \"api__read\",\n      \"label\": \"_read\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_fread\",\n      \"label\": \"fread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_system_information_on_windows\",\n      \"label\": \"get system information on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x10001F00\",\n      \"label\": \"Function 0x10001F00\",\n      \"type\": \"function\",\n      \"address\": \"0x10001F00\"\n    },\n    {\n      \"id\": \"api_GetNativeSystemInfo\",\n      \"label\": \"GetNativeSystemInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x10001150\",\n      \"label\": \"Function 0x10001150\",\n      \"type\": \"function\",\n      \"address\": \"0x10001150\"\n    },\n    {\n      \"id\": \"api_ExitProcess\",\n      \"label\": \"ExitProcess\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__3_matches_\",\n      \"label\": \"link function at runtime on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header\",\n      \"label\": \"parse PE header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_memory__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_memory__4_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x10001E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x10001FD6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__16_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__16_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x10001170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contains_pdb_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path\",\n      \"target\": \"func_0x10001170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10001170\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10001170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10001170\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_current_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_current_directory\",\n      \"target\": \"func_0x10001170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10001170\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x10001170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10001170\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__2_matches_\",\n      \"target\": \"func_0x10007CB7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__2_matches_\",\n      \"target\": \"func_0x10001170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10007CB7\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10001170\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10007CB7\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10001170\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10007CB7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10001170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10007CB7\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10001170\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10007CB7\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10001170\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_system_information_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_system_information_on_windows\",\n      \"target\": \"func_0x10001F00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10001F00\",\n      \"target\": \"api_GetNativeSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x10001F00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10001F00\",\n      \"target\": \"api_GetNativeSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x10001150\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10001150\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10001150\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10001150\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header\",\n      \"target\": \"func_0x10001F00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x10001F00\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-06-14 20:03:53.190008\",\n    \"total_functions\": \"219\",\n    \"total_features\": \"6763\",\n    \"pdb_path\": \"G:\\\\\\\\learn\\\\\\\\r3\\\\\\\\dllgoodate\\\\\\\\Release\\\\\\\\dllgoodate.pdb\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-06-14 20:03:55"}
{"_id":{"$oid":"6a2ebcf1ae36b72c92a10935"},"sha256":"81b29996dc471e6437e81cd02f6b22c189b35c2ab075a009dec089c34e5117de","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"cb3a80799b2520d975f018e5e2dd2942","sha1":"44eb0c176d6d5efe045364a5cca208e3f0f3140a","sha256":"81b29996dc471e6437e81cd02f6b22c189b35c2ab075a009dec089c34e5117de"}},"timestamp":"2026-06-14 20:08:41"}
{"_id":{"$oid":"6a2ebd10ae36b72c92a10938"},"sha256":"30752d23aa8c73b8249316ac4dadf35296e9261959e6d993f15ce43b49914a4b","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"ab6a41f70cdc5b71d52240f0a64efce7","sha1":"dfe38e43eb0dd5d8fa5673982b2420f73cfe712c","sha256":"30752d23aa8c73b8249316ac4dadf35296e9261959e6d993f15ce43b49914a4b"}},"timestamp":"2026-06-14 20:09:12"}
{"_id":{"$oid":"6a2efe06ae36b72c92a1093c"},"sha256":"03cb208292e6522bf69771f4bf634a8da9f789710cddd792a53b30797ee9d689","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_kjtsmys2/amcompat.tlb.bin-019ec78c4dbd72f0bd534efa6358048f.decrypted_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_kjtsmys2/amcompat.tlb.bin-019ec78c4dbd72f0bd534efa6358048f.decrypted_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_kjtsmys2/amcompat.tlb.bin-019ec78c4dbd72f0bd534efa6358048f.decrypted_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ b117b5d523541863b1fe0403f157b9be                                  │\n│ sha1     │ f51b428b6e28e3d7f1ec6299c159d4d1af87eda2                          │\n│ sha256   │ 03cb208292e6522bf69771f4bf634a8da9f789710cddd792a53b30797ee9d689  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/amcompat.tlb.bin… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic           ┃ ATT&CK Technique                                   ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION              │ Clipboard Data [T1115]                             │\n│                         │ Input Capture::Keylogging [T1056.001]              │\n│ DEFENSE EVASION         │ Hide Artifacts::Hidden Window [T1564.003]          │\n│                         │ Indicator Removal::File Deletion [T1070.004]       │\n│ DISCOVERY               │ File and Directory Discovery [T1083]               │\n│                         │ System Information Discovery [T1082]               │\n│ EXECUTION               │ Shared Modules [T1129]                             │\n└─────────────────────────┴────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Keylogging::Polling [F0002.002]                       │\n│ DEFENSE EVASION      │ Self Deletion::COMSPEC Environment Variable           │\n│                      │ [F0007.001]                                           │\n│ DISCOVERY            │ Application Window Discovery [E1010]                  │\n│                      │ File and Directory Discovery [E1083]                  │\n│                      │ System Information Discovery [E1082]                  │\n│ FILE SYSTEM          │ Read File [C0051]                                     │\n│                      │ Writes File [C0052]                                   │\n│ OPERATING SYSTEM     │ Environment Variable [C0034]                          │\n│ PROCESS              │ Create Process [C0017]                                │\n│                      │ Resume Thread [C0054]                                 │\n│                      │ Terminate Process [C0018]                             │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ self delete (2 matches)               │ anti-analysis/anti-forensic/self-de… │\n│ log keystrokes via polling            │ collection/keylog                    │\n│ read clipboard data                   │ host-interaction/clipboard           │\n│ get common file path                  │ host-interaction/file-system         │\n│ get file size (2 matches)             │ host-interaction/file-system/meta    │\n│ read file on Windows                  │ host-interaction/file-system/read    │\n│ write file on Windows (2 matches)     │ host-interaction/file-system/write   │\n│ get graphical window text (2 matches) │ host-interaction/gui/window/get-text │\n│ hide graphical window                 │ host-interaction/gui/window/hide     │\n│ get disk information                  │ host-interaction/hardware/storage    │\n│ print debug messages                  │ host-interaction/log/debug/write-ev… │\n│ get process image filename            │ host-interaction/process             │\n│ create process on Windows             │ host-interaction/process/create      │\n│ terminate process                     │ host-interaction/process/terminate   │\n│ resume thread                         │ host-interaction/thread/resume       │\n│ link function at runtime on Windows   │ linking/runtime-linking              │\n│ (6 matches)                           │                                      │\n│ link many functions at runtime        │ linking/runtime-linking              │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     b117b5d523541863b1fe0403f157b9be                        \nsha1                    f51b428b6e28e3d7f1ec6299c159d4d1af87eda2                \nsha256                  03cb208292e6522bf69771f4bf634a8da9f789710cddd792a53b307…\npath                    /home/apogean/projects/malware/windows/all_runs/amcompa…\ntimestamp               2026-06-15 00:46:10.362768                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIjUh8EM/rules                                   \nfunction count          99                                                      \nlibrary function count  236                                                     \ntotal feature count     4409                                                    \n\nself delete (2 matches)\nnamespace  anti-analysis/anti-forensic/self-deletion\nscope      function                                 \nmatches    0x401C70                                 \n           0x401C70                                 \n\nlog keystrokes via polling\nnamespace  collection/keylog\nscope      function         \nmatches    0x401540         \n\nopen clipboard\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x4012D0                  \n\nread clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x4012D0                  \n\nget COMSPEC environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x401C70                             \n\nquery environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x401C70                             \n\nget common file path\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x401F40                    \n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x401BB0                         \n           0x401F40                         \n\nread file on Windows\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x401BB0                         \n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x401BB0                          \n           0x401F40                          \n\nget graphical window text (2 matches)\nnamespace  host-interaction/gui/window/get-text\nscope      function                            \nmatches    0x4012D0                            \n           0x4015E0                            \n\nhide graphical window\nnamespace  host-interaction/gui/window/hide\nscope      basic block                     \nmatches    0x402318                        \n\nget disk information\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x401190                         \n\nprint debug messages\nnamespace  host-interaction/log/debug/write-event\nscope      function                              \nmatches    0x408604                              \n\nget process image filename\nnamespace  host-interaction/process\nscope      basic block             \nmatches    0x40172D                \n\ncreate process on Windows\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x401CDB                       \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x401BB0                          \n\nresume thread\nnamespace  host-interaction/thread/resume\nscope      basic block                   \nmatches    0x401DC2                      \n\nlink function at runtime on Windows (6 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x40151D               \n           0x408688               \n           0x4086A4               \n           0x4086B8               \n           0x4086CC               \n           0x4086E4               \n\nlink many functions at runtime\nnamespace  linking/runtime-linking\nscope      function               \nmatches    0x408604               \n\n\n\n","very_verbose":"md5                     b117b5d523541863b1fe0403f157b9be                        \nsha1                    f51b428b6e28e3d7f1ec6299c159d4d1af87eda2                \nsha256                  03cb208292e6522bf69771f4bf634a8da9f789710cddd792a53b307…\npath                    /home/apogean/projects/malware/windows/all_runs/amcompa…\ntimestamp               2026-06-15 00:46:21.493894                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIrUV3Fp/rules                                   \nfunction count          99                                                      \nlibrary function count  236                                                     \ntotal feature count     4409                                                    \n\ncontain loop (15 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401000\n  or:\n    characteristic: loop @ 0x401000\n    characteristic: tight loop @ 0x401010, 0x401026, 0x401046, 0x401060, and 6 more...\n\ncreate or open file (3 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x4020A2\n  or:\n    api: CreateFile @ 0x4020A2\n\nopen process (library rule)\nauthor  0x534a@mailbox.org           \nscope   basic block                  \nmbc     Process::Open Process [C0065]\nbasic block @ 0x40172D in function 0x4015E0\n  or:\n    api: OpenProcess @ 0x401748\n\nself delete (2 matches)\nnamespace  anti-analysis/anti-forensic/self-deletion                            \nauthor     michael.hunhoff@mandiant.com, @mr-tz                                 \nscope      function                                                             \natt&ck     Defense Evasion::Indicator Removal::File Deletion [T1070.004]        \nmbc        Defense Evasion::Self Deletion::COMSPEC Environment Variable         \n           [F0007.001]                                                          \nfunction @ 0x401C70\n  and:\n    optional:\n      regex: /\\s*>\\s*nul\\s*/i\n        - \" > nul\" @ 0x401D03\n    or:\n      match: get COMSPEC environment variable @ 0x401C70\n        and:\n          match: query environment variable @ 0x401C70\n            or:\n              api: GetEnvironmentVariable @ 0x401CCD\n          or:\n            string: \"COMSPEC\" @ 0x401CC8\n      match: host-interaction/process/create @ 0x401CDB\n        or:\n          api: CreateProcess @ 0x401DB8\n    or:\n      regex: /\\/c\\s*del\\s*/\n        - \" /c del \" @ 0x401CDB\nfunction @ 0x401C70\n  and:\n    optional:\n      regex: /\\s*>\\s*nul\\s*/i\n        - \" > nul\" @ 0x401D03\n    or:\n      match: get COMSPEC environment variable @ 0x401C70\n        and:\n          match: query environment variable @ 0x401C70\n            or:\n              api: GetEnvironmentVariable @ 0x401CCD\n          or:\n            string: \"COMSPEC\" @ 0x401CC8\n      match: host-interaction/process/create @ 0x401CDB\n        or:\n          api: CreateProcess @ 0x401DB8\n    or:\n      regex: /\\/c\\s*del\\s*/\n        - \" /c del \" @ 0x401CDB\n\nlog keystrokes via polling\nnamespace  collection/keylog                                \nauthor     michael.hunhoff@mandiant.com                     \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nmbc        Collection::Keylogging::Polling [F0002.002]      \nfunction @ 0x401540\n  or:\n    api: GetKeyState @ 0x401585\n\nopen clipboard\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ 0x4012D0\n  and:\n    api: OpenClipboard @ 0x4012E9\n    optional:\n      api: CloseClipboard @ 0x4013EB, 0x401410, 0x401490\n\nread clipboard data\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Collection::Clipboard Data [T1115]                                  \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ 0x4012D0\n  and:\n    optional:\n      match: open clipboard @ 0x4012D0\n        and:\n          api: OpenClipboard @ 0x4012E9\n          optional:\n            api: CloseClipboard @ 0x4013EB, 0x401410, 0x401490\n      match: contain loop @ 0x4012D0\n        or:\n          characteristic: loop @ 0x4012D0\n          characteristic: tight loop @ 0x401464, 0x401473\n      api: GlobalLock @ 0x40145A\n      api: GlobalUnlock @ 0x40148A\n    or:\n      basic block:\n        and:\n          api: GetClipboardData @ 0x40142E\n          optional:\n            number: 0x1 = CF_TEXT @ 0x40142C\n\nget COMSPEC environment variable\nnamespace  host-interaction/environment-variable          \nauthor     matthew.williams@mandiant.com                  \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Operating System::Environment Variable [C0034] \nfunction @ 0x401C70\n  and:\n    match: query environment variable @ 0x401C70\n      or:\n        api: GetEnvironmentVariable @ 0x401CCD\n    or:\n      string: \"COMSPEC\" @ 0x401CC8\n\nquery environment variable\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x401C70\n  or:\n    api: GetEnvironmentVariable @ 0x401CCD\n\nget common file path\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x401F40\n  or:\n    api: GetWindowsDirectory @ 0x402051, 0x4021B1\n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x401BB0\n  or:\n    api: GetFileSize @ 0x401C43\nfunction @ 0x401F40\n  or:\n    api: GetFileSize @ 0x4020B9\n\nread file on Windows\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x401BB0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x401BEB\n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x401BB0\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401BD0\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401C12, 0x401C2E\n      or:\n        api: WriteFile @ 0x401C0C, 0x401C28\nfunction @ 0x401F40\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402220\n            match: create or open file @ 0x40224B\n              or:\n                api: CreateFile @ 0x40224B\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x402096\n            match: create or open file @ 0x4020A2\n              or:\n                api: CreateFile @ 0x4020A2\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4020E7\n      or:\n        api: WriteFile @ 0x40218C\n\nget graphical window text (2 matches)\nnamespace  host-interaction/gui/window/get-text           \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \nmbc        Discovery::Application Window Discovery [E1010]\nfunction @ 0x4012D0\n  or:\n    and:\n      optional:\n        api: GetForegroundWindow @ 0x401319\n      api: GetWindowText @ 0x4013E5\nfunction @ 0x4015E0\n  or:\n    and:\n      optional:\n        api: GetForegroundWindow @ 0x4016F1\n      api: GetWindowText @ 0x401706\n\nhide graphical window\nnamespace  host-interaction/gui/window/hide                          \nauthor     michael.hunhoff@mandiant.com                              \nscope      basic block                                               \natt&ck     Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\nbasic block @ 0x402318 in function 0x401F40\n  and:\n    number: 0x0 = SW_HIDE @ 0x402318, 0x402330\n    api: ShowWindow @ 0x40231B\n\nget disk information\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ 0x401190\n  or:\n    api: GetLogicalDriveStrings @ 0x4011CE\n    api: QueryDosDevice @ 0x401230\n\nprint debug messages\nnamespace  host-interaction/log/debug/write-event\nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \nfunction @ 0x408604\n  or:\n    api: OutputDebugString @ 0x408707\n\nget process image filename\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ 0x40172D in function 0x4015E0\n  or:\n    and:\n      os: windows\n      or:\n        api: GetProcessImageFileName @ 0x40175B\n\ncreate process on Windows\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x401CDB in function 0x401C70\n  or:\n    api: CreateProcess @ 0x401DB8\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x401BB0\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x401C63\n\nresume thread\nnamespace  host-interaction/thread/resume                     \nauthor     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\nscope      basic block                                        \nmbc        Process::Resume Thread [C0054]                     \nbasic block @ 0x401DC2 in function 0x401C70\n  or:\n    api: ResumeThread @ 0x401DDC\n\nlink function at runtime on Windows (6 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x40151D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40151D\ninstruction @ 0x408688\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x408688\ninstruction @ 0x4086A4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4086A4\ninstruction @ 0x4086B8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4086B8\ninstruction @ 0x4086CC\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4086CC\ninstruction @ 0x4086E4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4086E4\n\nlink many functions at runtime\nnamespace  linking/runtime-linking                      \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com\nscope      function                                     \natt&ck     Execution::Shared Modules [T1129]            \nfunction @ 0x408604\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x408688, 0x4086A4, 0x4086B8, 0x4086CC, and 1 more...\n\n\n\n"},"hashes":{"md5":"b117b5d523541863b1fe0403f157b9be","sha1":"f51b428b6e28e3d7f1ec6299c159d4d1af87eda2","sha256":"03cb208292e6522bf69771f4bf634a8da9f789710cddd792a53b30797ee9d689"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 99</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 4409</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"amcompa\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"b117b5d523541863b1fe0403f157b9be\",\n        \"sha256\": \"03cb208292e6522bf69771f4bf634a8da9f789710cddd792a53b307\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__15_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (15 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401000\",\n      \"label\": \"Function 0x401000\",\n      \"type\": \"function\",\n      \"address\": \"0x401000\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__3_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (3 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_self_delete__2_matches_\",\n      \"label\": \"self delete (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401C70\",\n      \"label\": \"Function 0x401C70\",\n      \"type\": \"function\",\n      \"address\": \"0x401C70\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_GetEnvironmentVariable\",\n      \"label\": \"GetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_polling\",\n      \"label\": \"log keystrokes via polling\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401540\",\n      \"label\": \"Function 0x401540\",\n      \"type\": \"function\",\n      \"address\": \"0x401540\"\n    },\n    {\n      \"id\": \"api_GetKeyState\",\n      \"label\": \"GetKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_open_clipboard\",\n      \"label\": \"open clipboard\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4012D0\",\n      \"label\": \"Function 0x4012D0\",\n      \"type\": \"function\",\n      \"address\": \"0x4012D0\"\n    },\n    {\n      \"id\": \"api_CloseClipboard\",\n      \"label\": \"CloseClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_OpenClipboard\",\n      \"label\": \"OpenClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_clipboard_data\",\n      \"label\": \"read clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"api_GlobalLock\",\n      \"label\": \"GlobalLock\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetClipboardData\",\n      \"label\": \"GetClipboardData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GlobalUnlock\",\n      \"label\": \"GlobalUnlock\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_comspec_environment_variable\",\n      \"label\": \"get COMSPEC environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable [C0034]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"label\": \"author     matthew.williams@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable [C0034]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable\",\n      \"label\": \"query environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path\",\n      \"label\": \"get common file path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401F40\",\n      \"label\": \"Function 0x401F40\",\n      \"type\": \"function\",\n      \"address\": \"0x401F40\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size__2_matches_\",\n      \"label\": \"get file size (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401BB0\",\n      \"label\": \"Function 0x401BB0\",\n      \"type\": \"function\",\n      \"address\": \"0x401BB0\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows\",\n      \"label\": \"read file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__2_matches_\",\n      \"label\": \"write file on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_graphical_window_text__2_matches_\",\n      \"label\": \"get graphical window text (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4015E0\",\n      \"label\": \"Function 0x4015E0\",\n      \"type\": \"function\",\n      \"address\": \"0x4015E0\"\n    },\n    {\n      \"id\": \"api_GetWindowText\",\n      \"label\": \"GetWindowText\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetForegroundWindow\",\n      \"label\": \"GetForegroundWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hide_graphical_window\",\n      \"label\": \"hide graphical window\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x402318\",\n      \"label\": \"Block 0x402318\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x402318\"\n    },\n    {\n      \"id\": \"api_ShowWindow\",\n      \"label\": \"ShowWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_information\",\n      \"label\": \"get disk information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401190\",\n      \"label\": \"Function 0x401190\",\n      \"type\": \"function\",\n      \"address\": \"0x401190\"\n    },\n    {\n      \"id\": \"api_GetLogicalDriveStrings\",\n      \"label\": \"GetLogicalDriveStrings\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_QueryDosDevice\",\n      \"label\": \"QueryDosDevice\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_print_debug_messages\",\n      \"label\": \"print debug messages\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x408604\",\n      \"label\": \"Function 0x408604\",\n      \"type\": \"function\",\n      \"address\": \"0x408604\"\n    },\n    {\n      \"id\": \"api_OutputDebugString\",\n      \"label\": \"OutputDebugString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_process_image_filename\",\n      \"label\": \"get process image filename\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x40172D\",\n      \"label\": \"Block 0x40172D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40172D\"\n    },\n    {\n      \"id\": \"api_GetProcessImageFileName\",\n      \"label\": \"GetProcessImageFileName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_process_on_windows\",\n      \"label\": \"create process on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401CDB\",\n      \"label\": \"Block 0x401CDB\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401CDB\"\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"api_ExitProcess\",\n      \"label\": \"ExitProcess\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_resume_thread\",\n      \"label\": \"resume thread\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Resume Thread [C0054]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401DC2\",\n      \"label\": \"Block 0x401DC2\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401DC2\"\n    },\n    {\n      \"id\": \"api_ResumeThread\",\n      \"label\": \"ResumeThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Resume Thread [C0054]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__6_matches_\",\n      \"label\": \"link function at runtime on Windows (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_many_functions_at_runtime\",\n      \"label\": \"link many functions at runtime\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__15_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__15_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__3_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_self_delete__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_self_delete__2_matches_\",\n      \"target\": \"func_0x401C70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401C70\",\n      \"target\": \"api_CreateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401C70\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"target\": \"func_0x401C70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401C70\",\n      \"target\": \"api_CreateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401C70\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_polling\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling\",\n      \"target\": \"func_0x401540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401540\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401540\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_clipboard\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_clipboard\",\n      \"target\": \"func_0x4012D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4012D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_clipboard_data\",\n      \"target\": \"func_0x4012D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_GlobalLock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_GetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_GlobalUnlock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4012D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_GlobalLock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_GetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_GlobalUnlock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_comspec_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_comspec_environment_variable\",\n      \"target\": \"func_0x401C70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401C70\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"target\": \"func_0x401C70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401C70\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable\",\n      \"target\": \"func_0x401C70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401C70\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x401C70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401C70\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path\",\n      \"target\": \"func_0x401F40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401F40\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401F40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401F40\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x401F40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x401BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401F40\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401BB0\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401F40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401F40\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401BB0\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows\",\n      \"target\": \"func_0x401BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401BB0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401BB0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x401F40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x401BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401F40\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401BB0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401F40\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401BB0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401F40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401F40\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401BB0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401F40\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401BB0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_graphical_window_text__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__2_matches_\",\n      \"target\": \"func_0x4012D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__2_matches_\",\n      \"target\": \"func_0x4015E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4015E0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_GetForegroundWindow\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4015E0\",\n      \"target\": \"api_GetForegroundWindow\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4012D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4015E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4015E0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4012D0\",\n      \"target\": \"api_GetForegroundWindow\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4015E0\",\n      \"target\": \"api_GetForegroundWindow\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hide_graphical_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window\",\n      \"target\": \"bb_0x402318\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x402318\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information\",\n      \"target\": \"func_0x401190\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401190\",\n      \"target\": \"api_GetLogicalDriveStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401190\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401190\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401190\",\n      \"target\": \"api_GetLogicalDriveStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401190\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_print_debug_messages\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_print_debug_messages\",\n      \"target\": \"func_0x408604\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408604\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408604\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408604\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_process_image_filename\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_process_image_filename\",\n      \"target\": \"bb_0x40172D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x40172D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows\",\n      \"target\": \"bb_0x401CDB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x401CDB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x401BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401BB0\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401BB0\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resume_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resume_thread\",\n      \"target\": \"bb_0x401DC2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x401DC2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_many_functions_at_runtime\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime\",\n      \"target\": \"func_0x408604\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x408604\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-06-15 00:46:21.493894\",\n    \"total_functions\": \"99\",\n    \"total_features\": \"4409\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-06-15 00:46:22"}
{"_id":{"$oid":"6a3d3b116c8e273a010a1921"},"sha256":"1e75fd701998008590a79fb60f57c6111ff3c6a3a23b584f061df96f17cdf6ff","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_jy57z3bm/Read-019eff2bd118752095707ab445f35507.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_jy57z3bm/Read-019eff2bd118752095707ab445f35507.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_jy57z3bm/Read-019eff2bd118752095707ab445f35507.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ da83bb554506a2218f69262f4d0b5df1                                  │\n│ sha1     │ 32e43a54521a41fedd6669debc94a7c28666d87c                          │\n│ sha256   │ 1e75fd701998008590a79fb60f57c6111ff3c6a3a23b584f061df96f17cdf6ff  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ amd64                                                             │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/Read-019eff2bd11… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic             ┃ ATT&CK Technique                                 ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DISCOVERY                 │ System Information Discovery [T1082]             │\n│ EXECUTION                 │ Command and Scripting Interpreter [T1059]        │\n│                           │ Shared Modules [T1129]                           │\n└───────────────────────────┴──────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective             ┃ MBC Behavior                                     ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DISCOVERY                 │ System Information Discovery [E1082]             │\n│ EXECUTION                 │ Command and Scripting Interpreter [E1059]        │\n│ PROCESS                   │ Terminate Process [C0018]                        │\n└───────────────────────────┴──────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                        ┃ Namespace                                ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ accept command line arguments     │ host-interaction/cli                     │\n│ query environment variable        │ host-interaction/environment-variable    │\n│ terminate process                 │ host-interaction/process/terminate       │\n│ parse PE header                   │ load-code/pe                             │\n└───────────────────────────────────┴──────────────────────────────────────────┘\n\n","verbose":"md5                     da83bb554506a2218f69262f4d0b5df1                        \nsha1                    32e43a54521a41fedd6669debc94a7c28666d87c                \nsha256                  1e75fd701998008590a79fb60f57c6111ff3c6a3a23b584f061df96…\npath                    /home/apogean/projects/malware/windows/all_runs/Read-01…\ntimestamp               2026-07-02 22:50:38.751248                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x140000000                                             \nrules                   /tmp/_MEI0HhvSJ/rules                                   \nfunction count          51                                                      \nlibrary function count  20                                                      \ntotal feature count     1483                                                    \n\naccept command line arguments\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x140001000         \n\nquery environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x140001000                          \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x140001000                       \n\nparse PE header\nnamespace  load-code/pe\nscope      function    \nmatches    0x1400019E4 \n\n\n\n","very_verbose":"md5                     da83bb554506a2218f69262f4d0b5df1                        \nsha1                    32e43a54521a41fedd6669debc94a7c28666d87c                \nsha256                  1e75fd701998008590a79fb60f57c6111ff3c6a3a23b584f061df96…\npath                    /home/apogean/projects/malware/windows/all_runs/Read-01…\ntimestamp               2026-07-02 22:50:43.418738                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x140000000                                             \nrules                   /tmp/_MEIOurfWC/rules                                   \nfunction count          51                                                      \nlibrary function count  20                                                      \ntotal feature count     1483                                                    \n\ncontain loop (3 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x140001000\n  or:\n    characteristic: tight loop @ 0x14000106B, 0x140001153\n\naccept command line arguments\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x140001000\n  or:\n    api: GetCommandLine @ 0x140001096\n\nquery environment variable\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x140001000\n  or:\n    api: getenv @ 0x140001040\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x140001000\n  or:\n    api: exit @ 0x140001112\n\nparse PE header\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x1400019E4\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1400019FA, 0x140001A03, 0x140001A11, 0x140001A18, and 1 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x140001A03\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x1400019F5\n\n\n\n"},"hashes":{"md5":"da83bb554506a2218f69262f4d0b5df1","sha1":"32e43a54521a41fedd6669debc94a7c28666d87c","sha256":"1e75fd701998008590a79fb60f57c6111ff3c6a3a23b584f061df96f17cdf6ff"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 51</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 1483</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Read-01\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"da83bb554506a2218f69262f4d0b5df1\",\n        \"sha256\": \"1e75fd701998008590a79fb60f57c6111ff3c6a3a23b584f061df96\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__3_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (3 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x140001000\",\n      \"label\": \"Function 0x140001000\",\n      \"type\": \"function\",\n      \"address\": \"0x140001000\"\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments\",\n      \"label\": \"accept command line arguments\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable\",\n      \"label\": \"query environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_getenv\",\n      \"label\": \"getenv\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"api_exit\",\n      \"label\": \"exit\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header\",\n      \"label\": \"parse PE header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400019E4\",\n      \"label\": \"Function 0x1400019E4\",\n      \"type\": \"function\",\n      \"address\": \"0x1400019E4\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__3_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__3_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x140001000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments\",\n      \"target\": \"func_0x140001000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140001000\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140001000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140001000\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable\",\n      \"target\": \"func_0x140001000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140001000\",\n      \"target\": \"api_getenv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x140001000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140001000\",\n      \"target\": \"api_getenv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x140001000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140001000\",\n      \"target\": \"api_exit\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140001000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140001000\",\n      \"target\": \"api_exit\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header\",\n      \"target\": \"func_0x1400019E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400019E4\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-02 22:50:43.418738\",\n    \"total_functions\": \"51\",\n    \"total_features\": \"1483\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-02 22:50:43"}
{"_id":{"$oid":"6a3d3b566c8e273a010a1924"},"sha256":"e63ac91d2bc21f0dd05f546f92112162ce8200cf97b59f6c46f608d1a6365502","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_o_u8vyje/jli-019eff2b84057d02a4e5c7dd15948c9b.dll_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_o_u8vyje/jli-019eff2b84057d02a4e5c7dd15948c9b.dll_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_o_u8vyje/jli-019eff2b84057d02a4e5c7dd15948c9b.dll_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ f9e94c847176b9e45fe5c9c4494a8ce0                                  │\n│ sha1     │ c67114237bb060c67ef101583d47d8847a3e1ee7                          │\n│ sha256   │ e63ac91d2bc21f0dd05f546f92112162ce8200cf97b59f6c46f608d1a6365502  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ amd64                                                             │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/jli-019eff2b8405… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic         ┃ ATT&CK Technique                                     ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION       │ Impair Defenses::Disable or Modify Tools [T1562.001] │\n│ DISCOVERY             │ File and Directory Discovery [T1083]                 │\n│ EXECUTION             │ Command and Scripting Interpreter [T1059]            │\n│                       │ Shared Modules [T1129]                               │\n└───────────────────────┴──────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Debugger Detection::Timing/Delay Check            │\n│                          │ GetTickCount [B0001.032]                          │\n│ DATA                     │ Non-Cryptographic Hash::FNV [C0030.005]           │\n│ DEFENSE EVASION          │ Disable or Evade Security Tools [F0004]           │\n│ DISCOVERY                │ Code Discovery::Enumerate PE Sections [B0046.001] │\n│                          │ File and Directory Discovery [E1083]              │\n│ EXECUTION                │ Command and Scripting Interpreter [E1059]         │\n│ FILE SYSTEM              │ Delete File [C0047]                               │\n│                          │ Read File [C0051]                                 │\n│                          │ Writes File [C0052]                               │\n│ MEMORY                   │ Allocate Memory [C0007]                           │\n│ PROCESS                  │ Terminate Process [C0018]                         │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ overwrite DLL .text section to remove │ anti-analysis/anti-av                │\n│ hooks                                 │                                      │\n│ check for time delay via GetTickCount │ anti-analysis/anti-debugging/debugg… │\n│ hash data using fnv (2 matches)       │ data-manipulation/hashing/fnv        │\n│ contain a thread local storage (.tls) │ executable/pe/section/tls            │\n│ section                               │                                      │\n│ accept command line arguments         │ host-interaction/cli                 │\n│ get common file path (3 matches)      │ host-interaction/file-system         │\n│ delete file                           │ host-interaction/file-system/delete  │\n│ write file on Windows                 │ host-interaction/file-system/write   │\n│ get thread local storage value        │ host-interaction/process             │\n│ terminate process                     │ host-interaction/process/terminate   │\n│ link function at runtime on Windows   │ linking/runtime-linking              │\n│ (8 matches)                           │                                      │\n│ link many functions at runtime        │ linking/runtime-linking              │\n│ parse PE header (2 matches)           │ load-code/pe                         │\n│ resolve function by parsing PE        │ load-code/pe                         │\n│ exports (2 matches)                   │                                      │\n│ execute shellcode via indirect call   │ load-code/shellcode                  │\n│ (2 matches)                           │                                      │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     f9e94c847176b9e45fe5c9c4494a8ce0                        \nsha1                    c67114237bb060c67ef101583d47d8847a3e1ee7                \nsha256                  e63ac91d2bc21f0dd05f546f92112162ce8200cf97b59f6c46f608d…\npath                    /home/apogean/projects/malware/windows/all_runs/jli-019…\ntimestamp               2026-07-02 22:51:35.842645                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x63EC0000                                              \nrules                   /tmp/_MEIjfBtUO/rules                                   \nfunction count          102                                                     \nlibrary function count  1                                                       \ntotal feature count     19843                                                   \n\noverwrite DLL .text section to remove hooks\nnamespace  anti-analysis/anti-av\nscope      function             \nmatches    0x63EC2E40           \n\ncheck for time delay via GetTickCount\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    0x63EC3720                                     \n\nhash data using fnv (2 matches)\nnamespace    data-manipulation/hashing/fnv                                      \ndescription  can be any Fowler-Noll-Vo (FNV) hash variant, including FNV-1,     \n             FNV-1a, FNV-0                                                      \nscope        function                                                           \nmatches      0x63EC31E0                                                         \n             0x63EC3230                                                         \n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls\nscope      file                     \n\naccept command line arguments\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x63EC3290          \n\nget common file path (3 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x63EC2E40                  \n           0x63EC3290                  \n           0x63EC3ED0                  \n\ndelete file\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x63EC3290                         \n\nget file size\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x63EC2E40                       \n\nread file via mapping\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x63EC2E40                       \n\nwrite file on Windows\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x63EC1470                        \n\nget thread local storage value\nnamespace  host-interaction/process\nscope      function                \nmatches    0x63EC2580              \n\nallocate or change RWX memory (2 matches)\nnamespace  host-interaction/process/inject\nscope      basic block                    \nmatches    0x63EC15B5                     \n           0x63EC30A3                     \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x63EC1AF0                        \n\nlink function at runtime on Windows (8 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x63EC450D             \n           0x63EC459C             \n           0x63EC45CC             \n           0x63EC45ED             \n           0x63EC460E             \n           0x63EC462F             \n           0x63EC472B             \n           0x63EC4AC3             \n\nlink many functions at runtime\nnamespace  linking/runtime-linking\nscope      function               \nmatches    0x63EC4300             \n\nenumerate PE sections (3 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x63EC2210  \n           0x63EC2300  \n           0x63EC2E40  \n\nparse PE header (2 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x63EC21F0  \n           0x63EC3610  \n\nresolve function by parsing PE exports (2 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x63EC38A0  \n           0x63EC3DC0  \n\nexecute shellcode via indirect call (2 matches)\nnamespace  load-code/shellcode\nscope      function           \nmatches    0x63EC14E0         \n           0x63EC2E40         \n\n\n\n","very_verbose":"md5                     f9e94c847176b9e45fe5c9c4494a8ce0                        \nsha1                    c67114237bb060c67ef101583d47d8847a3e1ee7                \nsha256                  e63ac91d2bc21f0dd05f546f92112162ce8200cf97b59f6c46f608d…\npath                    /home/apogean/projects/malware/windows/all_runs/jli-019…\ntimestamp               2026-07-02 22:51:45.422505                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x63EC0000                                              \nrules                   /tmp/_MEI25CTII/rules                                   \nfunction count          102                                                     \nlibrary function count  1                                                       \ntotal feature count     19843                                                   \n\nallocate or change RW memory (library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x63EC366F in function 0x63EC3610\n  and:\n    or:\n      match: change memory protection @ 0x63EC366F\n        or:\n          api: VirtualProtect @ 0x63EC368C\n    or:\n      number: 0x4 = PAGE_READWRITE @ 0x63EC3676\n\nchange memory protection (6 matches, only showing first match of library rule)\nauthor  @mr-tz                                  \nscope   basic block                             \nmbc     Memory::Change Memory Protection [C0008]\nbasic block @ 0x63EC15B5 in function 0x63EC14E0\n  or:\n    api: VirtualProtect @ 0x63EC15CF\n\ncontain loop (33 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x63EC1050\n  or:\n    characteristic: loop @ 0x63EC1050\n\ncreate or open file (4 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x63EC2F12\n  or:\n    api: CreateFile @ 0x63EC2F12\n\ncreate or open registry key (2 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x63EC351B in function 0x63EC3290\n  or:\n    api: RegOpenKeyEx @ 0x63EC3551\n\ndelay execution (5 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x63EC1094 in function 0x63EC1050\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x63EC1099\n\noverwrite DLL .text section to remove hooks\nnamespace   anti-analysis/anti-av                                               \nauthor      jakub.jozwiak@mandiant.com                                          \nscope       function                                                            \natt&ck      Defense Evasion::Impair Defenses::Disable or Modify Tools           \n            [T1562.001]                                                         \nmbc         Defense Evasion::Disable or Evade Security Tools [F0004]            \nreferences  https://www.ired.team/offensive-security/defense-evasion/how-to-unh…\nfunction @ 0x63EC2E40\n  and:\n    match: enumerate PE sections @ 0x63EC2E40\n      and:\n        os: windows\n        instruction:\n          and:\n            operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x63EC318B\n            or:\n              mnemonic: movzx @ 0x63EC318B\n        basic block:\n          or:\n            and: = IMAGE_FIRST_SECTION(nt_header)\n              instruction:\n                and:\n                  operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x63EC3050\n                  or:\n                    mnemonic: movzx @ 0x63EC3050\n              operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x63EC307A\n        count(basic block): 3 or more @ 0x63EC2E40, 0x63EC2E72, 0x63EC2E77, 0x63EC2F25, and 13 more...\n        optional:\n          offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x63EC3024\n        not:\n          characteristic: nzxor\n        2 or more:\n          operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x63EC30AA, 0x63EC30C7\n          operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x63EC3050\n    string: \".text\" @ 0x63EC308C\n    substring: .dll\n      - \"ntdll.dll\" @ 0x63EC2E51\n    or:\n      api: GetModuleHandle @ 0x63EC2E5F\n    or:\n      match: read file via mapping @ 0x63EC2E40\n        or:\n          and:\n            basic block:\n              and:\n                api: MapViewOfFile @ 0x63EC2FD1\n                or:\n                  number: 0x4 = FILE_MAP_READ @ 0x63EC2FC2\n            optional:\n              api: UnmapViewOfFile @ 0x63EC31AD\n              and:\n                match: get file size @ 0x63EC2E40\n                  or:\n                    api: GetFileSize @ 0x63EC2F40\n\ncheck for time delay via GetTickCount\nnamespace  anti-analysis/anti-debugging/debugger-detection                      \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check     \n           GetTickCount [B0001.032]                                             \nfunction @ 0x63EC3720\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x63EC3724\n        mnemonic: cmp @ 0x63EC372F\n    count(api(GetTickCount)): 2 or more @ 0x63EC3741, 0x63EC3769\n\nhash data using fnv (2 matches)\nnamespace    data-manipulation/hashing/fnv                                      \nauthor       moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com  \nscope        function                                                           \nmbc          Data::Non-Cryptographic Hash::FNV [C0030.005]                      \nreferences   https://en.wikipedia.org/wiki/Fowler%E2%80%93Noll%E2%80%93Vo_hash_…\n             http://isthe.com/chongo/tech/comp/fnv/,                            \n             https://create.stephan-brumme.com/fnv-hash/                        \ndescription  can be any Fowler-Noll-Vo (FNV) hash variant, including FNV-1,     \n             FNV-1a, FNV-0                                                      \nfunction @ 0x63EC31E0\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x63EC3207\n        or:\n          mnemonic: imul @ 0x63EC320D\n    or:\n      number: 0x1000193 = FNV prime @ 0x63EC320D\n    optional:\n      characteristic: loop @ 0x63EC31E0\n      number: 0x811C9DC5 = FNV_offset_basis, unused by FNV-0 @ 0x63EC31EC\nfunction @ 0x63EC3230\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x63EC326B\n        or:\n          mnemonic: imul @ 0x63EC3271\n    or:\n      number: 0x1000193 = FNV prime @ 0x63EC3271\n    optional:\n      characteristic: loop @ 0x63EC3230\n      number: 0x811C9DC5 = FNV_offset_basis, unused by FNV-0 @ 0x63EC323C\n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls   \nauthor     michael.hunhoff@mandiant.com\nscope      file                        \nsection: .tls @ 0x63F85000\n\naccept command line arguments\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x63EC3290\n  or:\n    api: GetCommandLine @ 0x63EC3522\n\nget common file path (3 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x63EC2E40\n  or:\n    api: GetSystemDirectory @ 0x63EC2E98\nfunction @ 0x63EC3290\n  or:\n    api: GetTempPath @ 0x63EC32B3, 0x63EC335D\n    api: GetTempFileName @ 0x63EC32D7, 0x63EC3387\nfunction @ 0x63EC3ED0\n  or:\n    api: SHGetFolderPath @ 0x63EC3F24\n\ndelete file\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x63EC3290\n  or:\n    api: DeleteFile @ 0x63EC3345, 0x63EC33FB\n\nget file size\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x63EC2E40\n  or:\n    api: GetFileSize @ 0x63EC2F40\n\nread file via mapping\nnamespace  host-interaction/file-system/read\nauthor     michael.hunhoff@mandiant.com     \nscope      function                         \nmbc        File System::Read File [C0051]   \nfunction @ 0x63EC2E40\n  or:\n    and:\n      basic block:\n        and:\n          api: MapViewOfFile @ 0x63EC2FD1\n          or:\n            number: 0x4 = FILE_MAP_READ @ 0x63EC2FC2\n      optional:\n        api: UnmapViewOfFile @ 0x63EC31AD\n        and:\n          match: get file size @ 0x63EC2E40\n            or:\n              api: GetFileSize @ 0x63EC2F40\n\nwrite file on Windows\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x63EC1470\n  or:\n    and:\n      os: windows\n      or:\n        api: fwrite @ 0x63EC14AD\n\nget thread local storage value\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x63EC2580\n  and:\n    api: TlsGetValue @ 0x63EC25B2\n\nallocate or change RWX memory (2 matches)\nnamespace  host-interaction/process/inject\nauthor     @mr-tz, mehunhoff@google.com   \nscope      basic block                    \nmbc        Memory::Allocate Memory [C0007]\nbasic block @ 0x63EC15B5 in function 0x63EC14E0\n  or:\n    basic block:\n      and:\n        or:\n          match: change memory protection @ 0x63EC15B5\n            or:\n              api: VirtualProtect @ 0x63EC15CF\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x63EC15BF\nbasic block @ 0x63EC30A3 in function 0x63EC2E40\n  or:\n    basic block:\n      and:\n        or:\n          match: change memory protection @ 0x63EC30A3\n            or:\n              api: VirtualProtect @ 0x63EC3118\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x63EC3108\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x63EC1AF0\n  or:\n    and:\n      or:\n        api: TerminateProcess @ 0x63EC1BC5\n\nlink function at runtime on Windows (8 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x63EC450D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x63EC450D\ninstruction @ 0x63EC459C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x63EC459C\ninstruction @ 0x63EC45CC\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x63EC45CC\ninstruction @ 0x63EC45ED\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x63EC45ED\ninstruction @ 0x63EC460E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x63EC460E\ninstruction @ 0x63EC462F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x63EC462F\ninstruction @ 0x63EC472B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x63EC472B\ninstruction @ 0x63EC4AC3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x63EC4AC3\n\nlink many functions at runtime\nnamespace  linking/runtime-linking                      \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com\nscope      function                                     \natt&ck     Execution::Shared Modules [T1129]            \nfunction @ 0x63EC4300\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x63EC450D, 0x63EC459C, 0x63EC45CC, 0x63EC45ED, and 4 more...\n\nenumerate PE sections (3 matches)\nnamespace   load-code/pe                                                        \nauthor      @Ana06, @mr-tz                                                      \nscope       function                                                            \nmbc         Discovery::Code Discovery::Enumerate PE Sections [B0046.001]        \nreferences  https://0x00sec.org/t/reflective-dll-injection/3080,                \n            https://www.ired.team/offensive-security/code-injection-process-inj…\nfunction @ 0x63EC2210\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x63EC2220\n        or:\n          mnemonic: movzx @ 0x63EC2220\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x63EC2217\n              or:\n                mnemonic: movzx @ 0x63EC2217\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x63EC221B\n    count(basic block): 3 or more @ 0x63EC2210, 0x63EC2228, 0x63EC2234, 0x63EC2240, and 3 more...\n    optional:\n      offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x63EC2210\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x63EC2234\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x63EC2217\nfunction @ 0x63EC2300\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x63EC2220\n        or:\n          mnemonic: movzx @ 0x63EC2220\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x63EC2217\n              or:\n                mnemonic: movzx @ 0x63EC2217\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x63EC221B\n    count(basic block): 3 or more @ 0x63EC2210, 0x63EC2228, 0x63EC2234, 0x63EC2240, and 7 more...\n    optional:\n      offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x63EC2210\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x63EC2234\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x63EC2217\nfunction @ 0x63EC2E40\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x63EC318B\n        or:\n          mnemonic: movzx @ 0x63EC318B\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x63EC3050\n              or:\n                mnemonic: movzx @ 0x63EC3050\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x63EC307A\n    count(basic block): 3 or more @ 0x63EC2E40, 0x63EC2E72, 0x63EC2E77, 0x63EC2F25, and 13 more...\n    optional:\n      offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x63EC3024\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x63EC30AA, 0x63EC30C7\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x63EC3050\n\nparse PE header (2 matches)\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x63EC21F0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x63EC21D9, 0x63EC21E5, 0x63EC21F0\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x63EC21D9\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x63EC21F0\nfunction @ 0x63EC3610\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x63EC3622, 0x63EC363D, 0x63EC3663, 0x63EC36EB\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x63EC3663\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x63EC363D\n\nresolve function by parsing PE exports (2 matches)\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x63EC38A0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x63EC38A0\n      mnemonic: movzx @ 0x63EC39BD, 0x63EC39C0\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x63EC38DC\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x63EC38F1\n      3 or more:\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x63EC391C\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x63EC3908\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x63EC3ABB\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x63EC3930\nfunction @ 0x63EC3DC0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x63EC3DC0\n      mnemonic: movzx @ 0x63EC3E8D, 0x63EC3E90\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x63EC3DDB\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x63EC3DF0\n      3 or more:\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x63EC3E2F\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x63EC3E07\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x63EC3EB7\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x63EC3E1B\n\nexecute shellcode via indirect call (2 matches)\nnamespace  load-code/shellcode            \nauthor     ronnie.salomonsen@mandiant.com \nscope      function                       \nmbc        Memory::Allocate Memory [C0007]\nfunction @ 0x63EC14E0\n  and:\n    match: allocate or change RWX memory @ 0x63EC15B5\n      or:\n        basic block:\n          and:\n            or:\n              match: change memory protection @ 0x63EC15B5\n                or:\n                  api: VirtualProtect @ 0x63EC15CF\n            or:\n              number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x63EC15BF\n    or:\n      characteristic: cross section flow @ 0x63EC2AA8\nfunction @ 0x63EC2E40\n  and:\n    match: allocate or change RWX memory @ 0x63EC30A3\n      or:\n        basic block:\n          and:\n            or:\n              match: change memory protection @ 0x63EC30A3\n                or:\n                  api: VirtualProtect @ 0x63EC3118\n            or:\n              number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x63EC3108\n    or:\n      characteristic: indirect call @ 0x63EC2E5F, 0x63EC2E98, 0x63EC2F12, 0x63EC2F40, and 10 more...\n\n\n\n"},"hashes":{"md5":"f9e94c847176b9e45fe5c9c4494a8ce0","sha1":"c67114237bb060c67ef101583d47d8847a3e1ee7","sha256":"e63ac91d2bc21f0dd05f546f92112162ce8200cf97b59f6c46f608d1a6365502"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 102</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 19843</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"jli-019\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"f9e94c847176b9e45fe5c9c4494a8ce0\",\n        \"sha256\": \"e63ac91d2bc21f0dd05f546f92112162ce8200cf97b59f6c46f608d\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_change_memory_protection__6_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"change memory protection (6 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Change Memory Protection [C0008]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x63EC15B5\",\n      \"label\": \"Block 0x63EC15B5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x63EC15B5\"\n    },\n    {\n      \"id\": \"api_VirtualProtect\",\n      \"label\": \"VirtualProtect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_contain_loop__33_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (33 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x63EC1050\",\n      \"label\": \"Function 0x63EC1050\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC1050\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x63EC351B\",\n      \"label\": \"Block 0x63EC351B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x63EC351B\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__5_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (5 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x63EC1094\",\n      \"label\": \"Block 0x63EC1094\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x63EC1094\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_overwrite_dll__text_section_to_remove_hooks\",\n      \"label\": \"overwrite DLL .text section to remove hooks\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Disable or Evade Security Tools [F0004]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x63EC2E40\",\n      \"label\": \"Function 0x63EC2E40\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC2E40\"\n    },\n    {\n      \"id\": \"api_UnmapViewOfFile\",\n      \"label\": \"UnmapViewOfFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetModuleHandle\",\n      \"label\": \"GetModuleHandle\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_MapViewOfFile\",\n      \"label\": \"MapViewOfFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______jakub_jozwiak_mandiant_com\",\n      \"label\": \"author      jakub.jozwiak@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Disable or Evade Security Tools [F0004]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_for_time_delay_via_gettickcount\",\n      \"label\": \"check for time delay via GetTickCount\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"GetTickCount [B0001.032]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x63EC3720\",\n      \"label\": \"Function 0x63EC3720\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC3720\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"GetTickCount [B0001.032]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_using_fnv__2_matches_\",\n      \"label\": \"hash data using fnv (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::FNV [C0030.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x63EC31E0\",\n      \"label\": \"Function 0x63EC31E0\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC31E0\"\n    },\n    {\n      \"id\": \"func_0x63EC3230\",\n      \"label\": \"Function 0x63EC3230\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC3230\"\n    },\n    {\n      \"id\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author       moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::FNV [C0030.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"label\": \"contain a thread local storage (.tls) section\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments\",\n      \"label\": \"accept command line arguments\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x63EC3290\",\n      \"label\": \"Function 0x63EC3290\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC3290\"\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path__3_matches_\",\n      \"label\": \"get common file path (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x63EC3ED0\",\n      \"label\": \"Function 0x63EC3ED0\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC3ED0\"\n    },\n    {\n      \"id\": \"api_GetTempFileName\",\n      \"label\": \"GetTempFileName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHGetFolderPath\",\n      \"label\": \"SHGetFolderPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_file\",\n      \"label\": \"delete file\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size\",\n      \"label\": \"get file size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_via_mapping\",\n      \"label\": \"read file via mapping\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows\",\n      \"label\": \"write file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x63EC1470\",\n      \"label\": \"Function 0x63EC1470\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC1470\"\n    },\n    {\n      \"id\": \"api_fwrite\",\n      \"label\": \"fwrite\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_thread_local_storage_value\",\n      \"label\": \"get thread local storage value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x63EC2580\",\n      \"label\": \"Function 0x63EC2580\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC2580\"\n    },\n    {\n      \"id\": \"api_TlsGetValue\",\n      \"label\": \"TlsGetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_allocate_or_change_rwx_memory__2_matches_\",\n      \"label\": \"allocate or change RWX memory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x63EC30A3\",\n      \"label\": \"Block 0x63EC30A3\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x63EC30A3\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"label\": \"author     @mr-tz, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x63EC1AF0\",\n      \"label\": \"Function 0x63EC1AF0\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC1AF0\"\n    },\n    {\n      \"id\": \"api_TerminateProcess\",\n      \"label\": \"TerminateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__8_matches_\",\n      \"label\": \"link function at runtime on Windows (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_many_functions_at_runtime\",\n      \"label\": \"link many functions at runtime\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x63EC4300\",\n      \"label\": \"Function 0x63EC4300\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC4300\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_pe_sections__3_matches_\",\n      \"label\": \"enumerate PE sections (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x63EC2300\",\n      \"label\": \"Function 0x63EC2300\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC2300\"\n    },\n    {\n      \"id\": \"func_0x63EC2210\",\n      \"label\": \"Function 0x63EC2210\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC2210\"\n    },\n    {\n      \"id\": \"cap_author_______ana06___mr_tz\",\n      \"label\": \"author      @Ana06, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header__2_matches_\",\n      \"label\": \"parse PE header (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x63EC3610\",\n      \"label\": \"Function 0x63EC3610\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC3610\"\n    },\n    {\n      \"id\": \"func_0x63EC21F0\",\n      \"label\": \"Function 0x63EC21F0\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC21F0\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports__2_matches_\",\n      \"label\": \"resolve function by parsing PE exports (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x63EC3DC0\",\n      \"label\": \"Function 0x63EC3DC0\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC3DC0\"\n    },\n    {\n      \"id\": \"func_0x63EC38A0\",\n      \"label\": \"Function 0x63EC38A0\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC38A0\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_execute_shellcode_via_indirect_call__2_matches_\",\n      \"label\": \"execute shellcode via indirect call (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x63EC14E0\",\n      \"label\": \"Function 0x63EC14E0\",\n      \"type\": \"function\",\n      \"address\": \"0x63EC14E0\"\n    },\n    {\n      \"id\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"label\": \"author     ronnie.salomonsen@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_change_memory_protection__6_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_change_memory_protection__6_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x63EC15B5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__33_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__33_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x63EC1050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x63EC351B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__5_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__5_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x63EC1094\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_overwrite_dll__text_section_to_remove_hooks\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_overwrite_dll__text_section_to_remove_hooks\",\n      \"target\": \"func_0x63EC2E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_UnmapViewOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_GetModuleHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_MapViewOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______jakub_jozwiak_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______jakub_jozwiak_mandiant_com\",\n      \"target\": \"func_0x63EC2E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_UnmapViewOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_GetModuleHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_MapViewOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_time_delay_via_gettickcount\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount\",\n      \"target\": \"func_0x63EC3720\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x63EC3720\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_fnv__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__2_matches_\",\n      \"target\": \"func_0x63EC31E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__2_matches_\",\n      \"target\": \"func_0x63EC3230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x63EC31E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x63EC3230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments\",\n      \"target\": \"func_0x63EC3290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC3290\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x63EC3290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC3290\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x63EC3ED0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x63EC2E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x63EC3290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC3ED0\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC3290\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC3ED0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC3290\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC3ED0\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC3290\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC3ED0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC3290\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x63EC3ED0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x63EC2E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x63EC3290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC3ED0\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC3290\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC3ED0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC3290\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC3ED0\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC3290\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC3ED0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC3290\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file\",\n      \"target\": \"func_0x63EC3290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC3290\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x63EC3290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC3290\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size\",\n      \"target\": \"func_0x63EC2E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x63EC2E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_via_mapping\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_via_mapping\",\n      \"target\": \"func_0x63EC2E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_UnmapViewOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_MapViewOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x63EC2E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_UnmapViewOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_MapViewOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows\",\n      \"target\": \"func_0x63EC1470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC1470\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x63EC1470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC1470\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_thread_local_storage_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value\",\n      \"target\": \"func_0x63EC2580\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC2580\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x63EC2580\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC2580\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_or_change_rwx_memory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__2_matches_\",\n      \"target\": \"bb_0x63EC15B5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__2_matches_\",\n      \"target\": \"bb_0x63EC30A3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x63EC15B5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x63EC30A3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x63EC1AF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC1AF0\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x63EC1AF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC1AF0\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_many_functions_at_runtime\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime\",\n      \"target\": \"func_0x63EC4300\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x63EC4300\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_pe_sections__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__3_matches_\",\n      \"target\": \"func_0x63EC2E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__3_matches_\",\n      \"target\": \"func_0x63EC2300\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__3_matches_\",\n      \"target\": \"func_0x63EC2210\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______ana06___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x63EC2E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x63EC2300\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x63EC2210\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__2_matches_\",\n      \"target\": \"func_0x63EC3610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__2_matches_\",\n      \"target\": \"func_0x63EC21F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x63EC3610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x63EC21F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__2_matches_\",\n      \"target\": \"func_0x63EC3DC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__2_matches_\",\n      \"target\": \"func_0x63EC38A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x63EC3DC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x63EC38A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_execute_shellcode_via_indirect_call__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_execute_shellcode_via_indirect_call__2_matches_\",\n      \"target\": \"func_0x63EC14E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_execute_shellcode_via_indirect_call__2_matches_\",\n      \"target\": \"func_0x63EC2E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC14E0\",\n      \"target\": \"api_VirtualProtect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_VirtualProtect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"target\": \"func_0x63EC14E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"target\": \"func_0x63EC2E40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x63EC14E0\",\n      \"target\": \"api_VirtualProtect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x63EC2E40\",\n      \"target\": \"api_VirtualProtect\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-02 22:51:45.422505\",\n    \"total_functions\": \"102\",\n    \"total_features\": \"19843\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-02 22:51:46"}
{"_id":{"$oid":"6a4129b2ef40726c21470d77"},"sha256":"be5dcbece8635a9753fa1a9e6df99e8f7f1f40d787ced52cf13a85ea9c045181","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_nq5lcsaq/simple_add-019f0e88427f739393f2488c24f373d8.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_nq5lcsaq/simple_add-019f0e88427f739393f2488c24f373d8.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_nq5lcsaq/simple_add-019f0e88427f739393f2488c24f373d8.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 119b4447ef7c52f1342daa9c614f10d0                                  │\n│ sha1     │ 014315a9373a1fcf61a937422b66dbb70eaf6ac1                          │\n│ sha256   │ be5dcbece8635a9753fa1a9e6df99e8f7f1f40d787ced52cf13a85ea9c045181  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ amd64                                                             │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/simple_add-019f0… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic                       ┃ ATT&CK Technique                       ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ EXECUTION                           │ Shared Modules [T1129]                 │\n└─────────────────────────────────────┴────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective          ┃ MBC Behavior                                        ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DISCOVERY              │ Code Discovery::Enumerate PE Sections [B0046.001]   │\n│ FILE SYSTEM            │ Writes File [C0052]                                 │\n│ MEMORY                 │ Allocate Memory [C0007]                             │\n└────────────────────────┴─────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                              ┃ Namespace                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ contain a thread local storage (.tls)   │ executable/pe/section/tls          │\n│ section                                 │                                    │\n│ write file on Windows                   │ host-interaction/file-system/write │\n│ get thread local storage value          │ host-interaction/process           │\n│ allocate or change RWX memory           │ host-interaction/process/inject    │\n│ enumerate PE sections (4 matches)       │ load-code/pe                       │\n│ parse PE header (2 matches)             │ load-code/pe                       │\n└─────────────────────────────────────────┴────────────────────────────────────┘\n\n","verbose":"md5                     119b4447ef7c52f1342daa9c614f10d0                        \nsha1                    014315a9373a1fcf61a937422b66dbb70eaf6ac1                \nsha256                  be5dcbece8635a9753fa1a9e6df99e8f7f1f40d787ced52cf13a85e…\npath                    /home/apogean/projects/malware/windows/all_runs/simple_…\ntimestamp               2026-06-28 19:33:22.706429                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x140000000                                             \nrules                   /tmp/_MEIcfvYSM/rules                                   \nfunction count          125                                                     \nlibrary function count  0                                                       \ntotal feature count     8719                                                    \n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls\nscope      file                     \n\nwrite file on Windows\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x140001890                       \n\nget thread local storage value\nnamespace  host-interaction/process\nscope      function                \nmatches    0x140002020             \n\nallocate or change RWX memory\nnamespace  host-interaction/process/inject\nscope      basic block                    \nmatches    0x140001A60                    \n\nenumerate PE sections (4 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x1400022C0 \n           0x1400023B0 \n           0x140002510 \n           0x1400025A0 \n\nparse PE header (2 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x140001010 \n           0x1400022A0 \n\n\n\n","very_verbose":"md5                     119b4447ef7c52f1342daa9c614f10d0                        \nsha1                    014315a9373a1fcf61a937422b66dbb70eaf6ac1                \nsha256                  be5dcbece8635a9753fa1a9e6df99e8f7f1f40d787ced52cf13a85e…\npath                    /home/apogean/projects/malware/windows/all_runs/simple_…\ntimestamp               2026-06-28 19:33:30.097613                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x140000000                                             \nrules                   /tmp/_MEIzQcoh6/rules                                   \nfunction count          125                                                     \nlibrary function count  0                                                       \ntotal feature count     8719                                                    \n\nallocate or change RW memory (library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x140001A60 in function 0x140001900\n  and:\n    or:\n      match: change memory protection @ 0x140001A60\n        or:\n          api: VirtualProtect @ 0x140001A8E\n    or:\n      number: 0x4 = PAGE_READWRITE @ 0x140001A6D\n\nchange memory protection (2 matches, only showing first match of library rule)\nauthor  @mr-tz                                  \nscope   basic block                             \nmbc     Memory::Change Memory Protection [C0008]\nbasic block @ 0x140001A60 in function 0x140001900\n  or:\n    api: VirtualProtect @ 0x140001A8E\n\ncontain loop (48 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x140001190\n  or:\n    characteristic: loop @ 0x140001190\n    characteristic: tight loop @ 0x140001350\n\ndelay execution (2 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x1400011F1 in function 0x140001190\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x1400011F6\n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls   \nauthor     michael.hunhoff@mandiant.com\nscope      file                        \nsection: .tls @ 0x14000F000\n\nwrite file on Windows\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x140001890\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x14000189F, 0x1400018DC\n      or:\n        api: fwrite @ 0x1400018D2\n\nget thread local storage value\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x140002020\n  and:\n    api: TlsGetValue @ 0x140002052\n\nallocate or change RWX memory\nnamespace  host-interaction/process/inject\nauthor     @mr-tz, mehunhoff@google.com   \nscope      basic block                    \nmbc        Memory::Allocate Memory [C0007]\nbasic block @ 0x140001A60 in function 0x140001900\n  or:\n    basic block:\n      and:\n        or:\n          match: change memory protection @ 0x140001A60\n            or:\n              api: VirtualProtect @ 0x140001A8E\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x140001A73\n\nenumerate PE sections (4 matches)\nnamespace   load-code/pe                                                        \nauthor      @Ana06, @mr-tz                                                      \nscope       function                                                            \nmbc         Discovery::Code Discovery::Enumerate PE Sections [B0046.001]        \nreferences  https://0x00sec.org/t/reflective-dll-injection/3080,                \n            https://www.ired.team/offensive-security/code-injection-process-inj…\nfunction @ 0x1400022C0\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x1400022D0\n        or:\n          mnemonic: movzx @ 0x1400022D0\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x1400022C7\n              or:\n                mnemonic: movzx @ 0x1400022C7\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x1400022CB\n    count(basic block): 3 or more @ 0x1400022C0, 0x1400022D8, 0x1400022E8, 0x1400022F4, and 3 more...\n    optional:\n      offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x1400022C0\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x1400022E8\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x1400022C7\nfunction @ 0x1400023B0\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x1400023EC\n        or:\n          mnemonic: movzx @ 0x1400023EC\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x1400023E2\n              or:\n                mnemonic: movzx @ 0x1400023E2\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x1400023E7\n    count(basic block): 3 or more @ 0x1400023B0, 0x1400023C9, 0x1400023D5, 0x1400023F5, and 5 more...\n    optional:\n      offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x1400023D5\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x140002408\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x1400023E2\nfunction @ 0x140002510\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x140002546\n        or:\n          mnemonic: movzx @ 0x140002546\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x140002541\n              or:\n                mnemonic: movzx @ 0x140002541\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x14000254B\n    count(basic block): 3 or more @ 0x140002510, 0x140002528, 0x140002534, 0x140002554, and 6 more...\n    optional:\n      offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x140002534\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x140002560\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x140002541\nfunction @ 0x1400025A0\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x1400025DF\n        or:\n          mnemonic: movzx @ 0x1400025DF\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x1400025D6\n              or:\n                mnemonic: movzx @ 0x1400025D6\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x1400025DA\n    count(basic block): 3 or more @ 0x1400025A0, 0x1400025B9, 0x1400025C5, 0x1400025D6, and 12 more...\n    optional:\n      offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x1400025C5\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x1400025F8, 0x140002637, 0x140002643\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x1400025D6, 0x14000262C\n\nparse PE header (2 matches)\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x140001010\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x140001051, 0x14000105F, 0x1400010B0, 0x1400010D4, and 3 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x14000105F\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x140001051\nfunction @ 0x1400022A0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x14000228A, 0x140002294, 0x1400022A0\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x14000228A\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x1400022A0\n\n\n\n"},"hashes":{"md5":"119b4447ef7c52f1342daa9c614f10d0","sha1":"014315a9373a1fcf61a937422b66dbb70eaf6ac1","sha256":"be5dcbece8635a9753fa1a9e6df99e8f7f1f40d787ced52cf13a85ea9c045181"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 125</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 8719</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"simple_\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"119b4447ef7c52f1342daa9c614f10d0\",\n        \"sha256\": \"be5dcbece8635a9753fa1a9e6df99e8f7f1f40d787ced52cf13a85e\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_change_memory_protection__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"change memory protection (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Change Memory Protection [C0008]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x140001A60\",\n      \"label\": \"Block 0x140001A60\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140001A60\"\n    },\n    {\n      \"id\": \"api_VirtualProtect\",\n      \"label\": \"VirtualProtect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_contain_loop__48_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (48 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x140001190\",\n      \"label\": \"Function 0x140001190\",\n      \"type\": \"function\",\n      \"address\": \"0x140001190\"\n    },\n    {\n      \"id\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1400011F1\",\n      \"label\": \"Block 0x1400011F1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400011F1\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"label\": \"contain a thread local storage (.tls) section\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_write_file_on_windows\",\n      \"label\": \"write file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140001890\",\n      \"label\": \"Function 0x140001890\",\n      \"type\": \"function\",\n      \"address\": \"0x140001890\"\n    },\n    {\n      \"id\": \"api_fwrite\",\n      \"label\": \"fwrite\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_thread_local_storage_value\",\n      \"label\": \"get thread local storage value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x140002020\",\n      \"label\": \"Function 0x140002020\",\n      \"type\": \"function\",\n      \"address\": \"0x140002020\"\n    },\n    {\n      \"id\": \"api_TlsGetValue\",\n      \"label\": \"TlsGetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_allocate_or_change_rwx_memory\",\n      \"label\": \"allocate or change RWX memory\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"label\": \"author     @mr-tz, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_pe_sections__4_matches_\",\n      \"label\": \"enumerate PE sections (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400022C0\",\n      \"label\": \"Function 0x1400022C0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400022C0\"\n    },\n    {\n      \"id\": \"func_0x1400025A0\",\n      \"label\": \"Function 0x1400025A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400025A0\"\n    },\n    {\n      \"id\": \"func_0x1400023B0\",\n      \"label\": \"Function 0x1400023B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400023B0\"\n    },\n    {\n      \"id\": \"func_0x140002510\",\n      \"label\": \"Function 0x140002510\",\n      \"type\": \"function\",\n      \"address\": \"0x140002510\"\n    },\n    {\n      \"id\": \"cap_author_______ana06___mr_tz\",\n      \"label\": \"author      @Ana06, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header__2_matches_\",\n      \"label\": \"parse PE header (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140001010\",\n      \"label\": \"Function 0x140001010\",\n      \"type\": \"function\",\n      \"address\": \"0x140001010\"\n    },\n    {\n      \"id\": \"func_0x1400022A0\",\n      \"label\": \"Function 0x1400022A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400022A0\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_change_memory_protection__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_change_memory_protection__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x140001A60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__48_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__48_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x140001190\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x1400011F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows\",\n      \"target\": \"func_0x140001890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140001890\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140001890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140001890\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_thread_local_storage_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value\",\n      \"target\": \"func_0x140002020\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140002020\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140002020\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140002020\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_or_change_rwx_memory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory\",\n      \"target\": \"bb_0x140001A60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x140001A60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_pe_sections__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__4_matches_\",\n      \"target\": \"func_0x1400022C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__4_matches_\",\n      \"target\": \"func_0x1400025A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__4_matches_\",\n      \"target\": \"func_0x1400023B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__4_matches_\",\n      \"target\": \"func_0x140002510\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______ana06___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x1400022C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x1400025A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x1400023B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x140002510\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__2_matches_\",\n      \"target\": \"func_0x140001010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__2_matches_\",\n      \"target\": \"func_0x1400022A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140001010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400022A0\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-06-28 19:33:30.097613\",\n    \"total_functions\": \"125\",\n    \"total_features\": \"8719\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-06-28 19:33:30"}
{"_id":{"$oid":"6a44e263ef40726c21470db2"},"sha256":"f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":false,"error":"WARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"WARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"ERROR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"3849f30b51a5c49e8d1546960cc206c7","sha1":"61c74136534b826059c63221a2373dc0613a47b7","sha256":"f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8"}},"timestamp":"2026-07-01 15:18:19"}
{"_id":{"$oid":"6a44e957ef40726c21470db5"},"sha256":"35bbf0234535438e8cbc25031e6501e259c847270467d45bc18af065d03fc537","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_atsagn8d/35bbf0234535438e8cbc25031e6501e259c847270467d45bc18af065d03fc537-019f1d2172a17831bd2148315a9b4d97.elf_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_atsagn8d/35bbf0234535438e8cbc25031e6501e259c847270467d45bc18af065d03fc537-019f1d2172a17831bd2148315a9b4d97.elf_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_atsagn8d/35bbf0234535438e8cbc25031e6501e259c847270467d45bc18af065d03fc537-019f1d2172a17831bd2148315a9b4d97.elf_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ d61fa7a3f2f85ddd1a35a6f542438cd4                                  │\n│ sha1     │ 755592000f4fc5f4abe1006e40ae7cfa883e6859                          │\n│ sha256   │ 35bbf0234535438e8cbc25031e6501e259c847270467d45bc18af065d03fc537  │\n│ analysis │ static                                                            │\n│ os       │ linux                                                             │\n│ format   │ elf                                                               │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/35bbf0234535438e… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION      │ Obfuscated Files or Information [T1027]               │\n│                      │ Obfuscated Files or Information::Indicator Removal    │\n│                      │ from Tools [T1027.005]                                │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-STATIC ANALYSIS │ Executable Code Obfuscation::Argument Obfuscation     │\n│                      │ [B0032.020]                                           │\n│                      │ Executable Code Obfuscation::Stack Strings            │\n│                      │ [B0032.017]                                           │\n│ CRYPTOGRAPHY         │ Encrypt Data::RC4 [C0027.009]                         │\n│                      │ Encryption Key::RC4 KSA [C0028.002]                   │\n│ DATA                 │ Encode Data::XOR [C0026.002]                          │\n│                      │ Non-Cryptographic Hash::MurmurHash [C0030.001]        │\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Encoding-Standard    │\n│                      │ Algorithm [E1027.m02]                                 │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                           ┃ Namespace                             ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ contain obfuscated stackstrings (4   │ anti-analysis/obfuscation/string/sta… │\n│ matches)                             │                                       │\n│ encode data using XOR (5 matches)    │ data-manipulation/encoding/xor        │\n│ encrypt data using RC4 KSA (2        │ data-manipulation/encryption/rc4      │\n│ matches)                             │                                       │\n│ encrypt data using Salsa20 or ChaCha │ data-manipulation/encryption/salsa20  │\n│ (2 matches)                          │                                       │\n│ hash data using murmur3 (3 matches)  │ data-manipulation/hashing/murmur      │\n└──────────────────────────────────────┴───────────────────────────────────────┘\n\n","verbose":"md5                     d61fa7a3f2f85ddd1a35a6f542438cd4                        \nsha1                    755592000f4fc5f4abe1006e40ae7cfa883e6859                \nsha256                  35bbf0234535438e8cbc25031e6501e259c847270467d45bc18af06…\npath                    /home/apogean/projects/malware/windows/all_runs/35bbf02…\ntimestamp               2026-07-01 15:47:53.276407                              \ncapa version            9.2.1                                                   \nos                      linux                                                   \nformat                  elf                                                     \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x8048000                                               \nrules                   /tmp/_MEIn2Sdee/rules                                   \nfunction count          233                                                     \nlibrary function count  0                                                       \ntotal feature count     18437                                                   \n\ncontain obfuscated stackstrings (4 matches)\nnamespace  anti-analysis/obfuscation/string/stackstring\nscope      basic block                                 \nmatches    0x8048A63                                   \n           0x8048DA5                                   \n           0x804973C                                   \n           0x80499FD                                   \n\nencode data using XOR (5 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x8049080                     \n           0x80494E8                     \n           0x804B160                     \n           0x804D590                     \n           0x8057067                     \n\nencrypt data using RC4 KSA (2 matches)\nnamespace  data-manipulation/encryption/rc4\nscope      function                        \nmatches    0x804AF00                       \n           0x804D330                       \n\nencrypt data using Salsa20 or ChaCha (2 matches)\nnamespace  data-manipulation/encryption/salsa20\nscope      function                            \nmatches    0x8048A10                           \n           0x8049420                           \n\nhash data using murmur3 (3 matches)\nnamespace  data-manipulation/hashing/murmur\nscope      function                        \nmatches    0x8048A10                       \n           0x8049420                       \n           0x804B2E0                       \n\n\n\n","very_verbose":"md5                     d61fa7a3f2f85ddd1a35a6f542438cd4                        \nsha1                    755592000f4fc5f4abe1006e40ae7cfa883e6859                \nsha256                  35bbf0234535438e8cbc25031e6501e259c847270467d45bc18af06…\npath                    /home/apogean/projects/malware/windows/all_runs/35bbf02…\ntimestamp               2026-07-01 15:47:59.009946                              \ncapa version            9.2.1                                                   \nos                      linux                                                   \nformat                  elf                                                     \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x8048000                                               \nrules                   /tmp/_MEI3c34mL/rules                                   \nfunction count          233                                                     \nlibrary function count  0                                                       \ntotal feature count     18437                                                   \n\ncalculate modulo 256 via x86 assembly (29 matches, only showing first match of \nlibrary rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x804BFED\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x804BFED\n    or:\n      number: 0xFF @ 0x804BFED\n\ncontain loop (94 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x80480B0\n  or:\n    characteristic: loop @ 0x80480B0\n\ncontain obfuscated stackstrings (4 matches)\nnamespace  anti-analysis/obfuscation/string/stackstring                         \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information::Indicator Removal  \n           from Tools [T1027.005]                                               \nmbc        Anti-Static Analysis::Executable Code Obfuscation::Argument          \n           Obfuscation [B0032.020], Anti-Static Analysis::Executable Code       \n           Obfuscation::Stack Strings [B0032.017]                               \nbasic block @ 0x8048A63 in function 0x8048A10\n  characteristic: stack string @ 0x8048A63\nbasic block @ 0x8048DA5 in function 0x8048A10\n  characteristic: stack string @ 0x8048DA5\nbasic block @ 0x804973C in function 0x8049420\n  characteristic: stack string @ 0x804973C\nbasic block @ 0x80499FD in function 0x8049420\n  characteristic: stack string @ 0x80499FD\n\nencode data using XOR (5 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x8049080 in function 0x8048A10\n  and:\n    characteristic: tight loop @ 0x8049080\n    characteristic: nzxor @ 0x80490C8, 0x80490CA, 0x8049108, 0x804910A, and 6 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x80494E8 in function 0x8049420\n  and:\n    characteristic: tight loop @ 0x80494E8\n    characteristic: nzxor @ 0x8049532, 0x8049534, 0x8049572, 0x8049574, and 6 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x804B160 in function 0x804AF00\n  and:\n    characteristic: tight loop @ 0x804B160\n    characteristic: nzxor @ 0x804B193, 0x804B198\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x804D590 in function 0x804D330\n  and:\n    characteristic: tight loop @ 0x804D590\n    characteristic: nzxor @ 0x804D5C3, 0x804D5C8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x8057067 in function 0x8056CB0\n  and:\n    characteristic: tight loop @ 0x8057067\n    characteristic: nzxor @ 0x805708A, 0x805708C, 0x80570B5, 0x80570B7, and 2 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nencrypt data using RC4 KSA (2 matches)\nnamespace  data-manipulation/encryption/rc4                                     \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Encrypt Data::RC4 [C0027.009], Cryptography::Encryption\n           Key::RC4 KSA [C0028.002]                                             \nfunction @ 0x804AF00\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x804B160\n          or:\n            number: 0x100 @ 0x804B1B2\n        and: = initialize S\n          characteristic: tight loop @ 0x804B105\n          or:\n            number: 0x100 @ 0x804B142\n      or: = modulo 256\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x804B107, 0x804B134, 0x804B137\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x804B1D7, 0x804B1E9, 0x804B1FB, 0x804B20D, and 11 more...\nfunction @ 0x804D330\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x804D590\n          or:\n            number: 0x100 @ 0x804D5E2\n        and: = initialize S\n          characteristic: tight loop @ 0x804D535\n          or:\n            number: 0x100 @ 0x804D572\n      or: = modulo 256\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x804D537, 0x804D564, 0x804D567\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x804D607, 0x804D619, 0x804D62B, 0x804D63D, and 11 more...\n\nencrypt data using Salsa20 or ChaCha (2 matches)\nnamespace   data-manipulation/encryption/salsa20                    \nauthor      moritz.raabe@mandiant.com                               \nscope       function                                                \natt&ck      Defense Evasion::Obfuscated Files or Information [T1027]\nreferences  http://cr.yp.to/snuffle/ecrypt.c                        \nfunction @ 0x8048A10\n  or: = part of key setup\n    and:\n      number: 0x61707865 = \"apxe\" @ 0x8048A63, 0x8048DA8\n      number: 0x3320646E = \"3 dn\" @ 0x8048A70, 0x8048DB3\n      number: 0x79622D32 = \"yb-2\" @ 0x8048A7B, 0x8048DBE\n      number: 0x6B206574 = \"k et\" @ 0x8048A86, 0x8048DD4\nfunction @ 0x8049420\n  or: = part of key setup\n    and:\n      number: 0x61707865 = \"apxe\" @ 0x804973C, 0x8049A01\n      number: 0x3320646E = \"3 dn\" @ 0x804974B, 0x8049A0F\n      number: 0x79622D32 = \"yb-2\" @ 0x8049756, 0x8049A1A\n      number: 0x6B206574 = \"k et\" @ 0x8049761, 0x8049A29\n\nhash data using murmur3 (3 matches)\nnamespace   data-manipulation/hashing/murmur                                    \nauthor      william.ballenthin@mandiant.com                                     \nscope       function                                                            \nmbc         Data::Non-Cryptographic Hash::MurmurHash [C0030.001]                \nreferences  https://github.com/aappleby/smhasher/blob/master/src/MurmurHash3.cpp\nfunction @ 0x8048A10\n  or:\n    and:\n      number: 0x85EBCA6B = 32-bit finalization mix constant 1 @ 0x80491D4, 0x80491D9\n      number: 0xC2B2AE35 = 32-bit finalization mix constant 2 @ 0x80491EE, 0x80491FE\nfunction @ 0x8049420\n  or:\n    and:\n      number: 0x85EBCA6B = 32-bit finalization mix constant 1 @ 0x804963E, 0x8049643\n      number: 0xC2B2AE35 = 32-bit finalization mix constant 2 @ 0x8049658, 0x8049668\nfunction @ 0x804B2E0\n  or:\n    and:\n      number: 0x85EBCA6B = 32-bit finalization mix constant 1 @ 0x804CBFE, 0x804CC03, 0x804D034, 0x804D039\n      number: 0xC2B2AE35 = 32-bit finalization mix constant 2 @ 0x804CC21, 0x804CC28, 0x804D057, 0x804D05E\n\n\n\n"},"hashes":{"md5":"d61fa7a3f2f85ddd1a35a6f542438cd4","sha1":"755592000f4fc5f4abe1006e40ae7cfa883e6859","sha256":"35bbf0234535438e8cbc25031e6501e259c847270467d45bc18af065d03fc537"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 233</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 18437</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"35bbf02\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"d61fa7a3f2f85ddd1a35a6f542438cd4\",\n        \"sha256\": \"35bbf0234535438e8cbc25031e6501e259c847270467d45bc18af06\",\n        \"arch\": \"i386\",\n        \"os\": \"linux\",\n        \"format\": \"elf\"\n      }\n    },\n    {\n      \"id\": \"cap_library_rule_\",\n      \"label\": \"library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Modulo [C0058]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_loop__94_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (94 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x80480B0\",\n      \"label\": \"Function 0x80480B0\",\n      \"type\": \"function\",\n      \"address\": \"0x80480B0\"\n    },\n    {\n      \"id\": \"cap_contain_obfuscated_stackstrings__4_matches_\",\n      \"label\": \"contain obfuscated stackstrings (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x80499FD\",\n      \"label\": \"Block 0x80499FD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x80499FD\"\n    },\n    {\n      \"id\": \"bb_0x804973C\",\n      \"label\": \"Block 0x804973C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x804973C\"\n    },\n    {\n      \"id\": \"bb_0x8048A63\",\n      \"label\": \"Block 0x8048A63\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x8048A63\"\n    },\n    {\n      \"id\": \"bb_0x8048DA5\",\n      \"label\": \"Block 0x8048DA5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x8048DA5\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_rc4_ksa__2_matches_\",\n      \"label\": \"encrypt data using RC4 KSA (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data::RC4 [C0027.009]\",\n        \"Cryptography::Encryption\",\n        \"Key::RC4 KSA [C0028.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x804D330\",\n      \"label\": \"Function 0x804D330\",\n      \"type\": \"function\",\n      \"address\": \"0x804D330\"\n    },\n    {\n      \"id\": \"func_0x804AF00\",\n      \"label\": \"Function 0x804AF00\",\n      \"type\": \"function\",\n      \"address\": \"0x804AF00\"\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_salsa20_or_chacha__2_matches_\",\n      \"label\": \"encrypt data using Salsa20 or ChaCha (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information [T1027]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x8049420\",\n      \"label\": \"Function 0x8049420\",\n      \"type\": \"function\",\n      \"address\": \"0x8049420\"\n    },\n    {\n      \"id\": \"func_0x8048A10\",\n      \"label\": \"Function 0x8048A10\",\n      \"type\": \"function\",\n      \"address\": \"0x8048A10\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information [T1027]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_using_murmur3__3_matches_\",\n      \"label\": \"hash data using murmur3 (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::MurmurHash [C0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x804B2E0\",\n      \"label\": \"Function 0x804B2E0\",\n      \"type\": \"function\",\n      \"address\": \"0x804B2E0\"\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::MurmurHash [C0030.001]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__94_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__94_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x80480B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_obfuscated_stackstrings__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__4_matches_\",\n      \"target\": \"bb_0x80499FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__4_matches_\",\n      \"target\": \"bb_0x804973C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__4_matches_\",\n      \"target\": \"bb_0x8048A63\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__4_matches_\",\n      \"target\": \"bb_0x8048DA5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x80499FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x804973C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x8048A63\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x8048DA5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_rc4_ksa__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__2_matches_\",\n      \"target\": \"func_0x804D330\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__2_matches_\",\n      \"target\": \"func_0x804AF00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x804D330\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x804AF00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_salsa20_or_chacha__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_salsa20_or_chacha__2_matches_\",\n      \"target\": \"func_0x8049420\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_salsa20_or_chacha__2_matches_\",\n      \"target\": \"func_0x8048A10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x8049420\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x8048A10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_murmur3__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_murmur3__3_matches_\",\n      \"target\": \"func_0x8049420\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_murmur3__3_matches_\",\n      \"target\": \"func_0x8048A10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_murmur3__3_matches_\",\n      \"target\": \"func_0x804B2E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x8049420\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x8048A10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x804B2E0\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-01 15:47:59.009946\",\n    \"total_functions\": \"233\",\n    \"total_features\": \"18437\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-01 15:47:59"}
{"_id":{"$oid":"6a44ede1ef40726c21470db9"},"sha256":"c480d1d8b50d9c94655b26755431d2d5a3c7d741a30047a21d1e13723109718f","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_9_kl0nk2/pf-019f1d172d3d7dd09ee0bacd4e900bc1.dll_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_9_kl0nk2/pf-019f1d172d3d7dd09ee0bacd4e900bc1.dll_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_9_kl0nk2/pf-019f1d172d3d7dd09ee0bacd4e900bc1.dll_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 3f1fa41a280d2e628aa2f4c7d5502518                                  │\n│ sha1     │ f320455de57557db3331e2e4abf26654a74065cf                          │\n│ sha256   │ c480d1d8b50d9c94655b26755431d2d5a3c7d741a30047a21d1e13723109718f  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/pf-019f1d172d3d7… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION      │ Obfuscated Files or Information [T1027]               │\n│                      │ Obfuscated Files or Information::Indicator Removal    │\n│                      │ from Tools [T1027.005]                                │\n│                      │ Obfuscated Files or Information::Software Packing     │\n│                      │ [T1027.002]                                           │\n│ EXECUTION            │ Shared Modules [T1129]                                │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Debugger Detection::Anti-debugging Instructions   │\n│                          │ [B0001.034]                                       │\n│ ANTI-STATIC ANALYSIS     │ Disassembler Evasion [B0012]                      │\n│                          │ Executable Code Obfuscation::Argument Obfuscation │\n│                          │ [B0032.020]                                       │\n│                          │ Executable Code Obfuscation::Stack Strings        │\n│                          │ [B0032.017]                                       │\n│                          │ Software Packing::Standard Compression            │\n│                          │ [F0001.002]                                       │\n│ CRYPTOGRAPHY             │ Encrypt Data::RC4 [C0027.009]                     │\n│                          │ Encryption Key::RC4 KSA [C0028.002]               │\n│                          │ Generate Pseudo-random Sequence::RC4 PRGA         │\n│                          │ [C0021.004]                                       │\n│                          │ Hashed Message Authentication Code [C0061]        │\n│ DATA                     │ Encode Data::Base64 [C0026.001]                   │\n│                          │ Encode Data::XOR [C0026.002]                      │\n│ DEFENSE EVASION          │ Obfuscated Files or                               │\n│                          │ Information::Encoding-Standard Algorithm          │\n│                          │ [E1027.m02]                                       │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ execute syscall (7 matches)           │ anti-analysis                        │\n│ execute anti-debugging instructions   │ anti-analysis/anti-debugging/debugg… │\n│ (4 matches)                           │                                      │\n│ contain anti-disasm techniques        │ anti-analysis/anti-disasm            │\n│ contain obfuscated stackstrings (2    │ anti-analysis/obfuscation/string/st… │\n│ matches)                              │                                      │\n│ packed with generic packer (84        │ anti-analysis/packer/generic         │\n│ matches)                              │                                      │\n│ encode data using Base64 (73 matches) │ data-manipulation/encoding/base64    │\n│ encode data using XOR (959 matches)   │ data-manipulation/encoding/xor       │\n│ encrypt data using RC4 KSA (24        │ data-manipulation/encryption/rc4     │\n│ matches)                              │                                      │\n│ encrypt data using RC4 PRGA           │ data-manipulation/encryption/rc4     │\n│ authenticate HMAC (92 matches)        │ data-manipulation/hmac               │\n│ contain a thread local storage (.tls) │ executable/pe/section/tls            │\n│ section                               │                                      │\n│ parse PE header (32 matches)          │ load-code/pe                         │\n│ resolve function by parsing PE        │ load-code/pe                         │\n│ exports                               │                                      │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     3f1fa41a280d2e628aa2f4c7d5502518                        \nsha1                    f320455de57557db3331e2e4abf26654a74065cf                \nsha256                  c480d1d8b50d9c94655b26755431d2d5a3c7d741a30047a21d1e137…\npath                    /home/apogean/projects/malware/windows/all_runs/pf-019f…\ntimestamp               2026-07-01 16:02:56.669018                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x70F00000                                              \nrules                   /tmp/_MEIynKwzG/rules                                   \nfunction count          3874                                                    \nlibrary function count  256                                                     \ntotal feature count     899400                                                  \n\nexecute syscall (7 matches)\nnamespace    anti-analysis                                \ndescription  may be used to evade hooks or hinder analysis\nscope        basic block                                  \nmatches      0x712A26C7                                   \n             0x719150CF                                   \n             0x719150CF                                   \n             0x719150CF                                   \n             0x719150CF                                   \n             0x719150CF                                   \n             0x719E082E                                   \n\nexecute anti-debugging instructions (4 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    0x7134C509                                     \n           0x71359729                                     \n           0x7135973B                                     \n           0x71359F62                                     \n\ncontain anti-disasm techniques\nnamespace  anti-analysis/anti-disasm\nscope      file                     \n\ncontain obfuscated stackstrings (2 matches)\nnamespace  anti-analysis/obfuscation/string/stackstring\nscope      basic block                                 \nmatches    0x711B0721                                  \n           0x711B727A                                  \n\npacked with generic packer (84 matches)\nnamespace  anti-analysis/packer/generic\nscope      function                    \nmatches    0x711AED60                  \n           0x711B0540                  \n           0x711B0FE0                  \n           0x711CFEC0                  \n           0x711CFEE0                  \n           0x711CFF20                  \n           0x711CFF40                  \n           0x711CFF90                  \n           0x711D0000                  \n           0x711D0050                  \n           0x711D0070                  \n           0x711D0090                  \n           0x711D0100                  \n           0x711D0120                  \n           0x711D0270                  \n           0x711D0290                  \n           0x711D02D0                  \n           0x711D0310                  \n           0x711D0350                  \n           0x711D03C0                  \n           0x711D03E0                  \n           0x711D0400                  \n           0x711D0420                  \n           0x711D0448                  \n           0x711D0460                  \n           0x711D0480                  \n           0x711D04A0                  \n           0x711D04C0                  \n           0x711D04E0                  \n           0x711D0500                  \n           0x711D0520                  \n           0x711D0540                  \n           0x711D0560                  \n           0x711D0580                  \n           0x711D05A8                  \n           0x711D05C0                  \n           0x711D0660                  \n           0x711D0680                  \n           0x711D06F0                  \n           0x71208C32                  \n           0x7120E885                  \n           0x7120E8BB                  \n           0x7120EB7C                  \n           0x7121E3D5                  \n           0x712242F1                  \n           0x71240F77                  \n           0x7124190A                  \n           0x71266D19                  \n           0x71272187                  \n           0x7127A1D9                  \n           0x7128CF3B                  \n           0x7128DD71                  \n           0x71292C5B                  \n           0x712A215C                  \n           0x712D059F                  \n           0x712DE086                  \n           0x712F0C17                  \n           0x712F8769                  \n           0x712FEC19                  \n           0x713021E7                  \n           0x7130A246                  \n           0x7130DDFF                  \n           0x713114DF                  \n           0x7131FA67                  \n           0x71320D95                  \n           0x71332F4D                  \n           0x71334DB8                  \n           0x71341096                  \n           0x71342CCA                  \n           0x713458D1                  \n           0x7134C509                  \n           0x7134E624                  \n           0x718BB4D8                  \n           0x718BFB8B                  \n           0x718CFBFB                  \n           0x718DEB2F                  \n           0x718E2FE8                  \n           0x718F2B4C                  \n           0x718F80F5                  \n           0x718F9DB2                  \n           0x7190F048                  \n           0x71915927                  \n           0x719240EF                  \n           0x71925DE8                  \n\nencode data using Base64 (73 matches)\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    0x711AED60                       \n           0x711B022F                       \n           0x711B0700                       \n           0x711B0FE0                       \n           0x711B651D                       \n           0x711B7150                       \n           0x711BF830                       \n           0x711D03A0                       \n           0x71223AF8                       \n           0x7123C11D                       \n           0x71248A5B                       \n           0x71266D19                       \n           0x7126E897                       \n           0x71272187                       \n           0x712776C4                       \n           0x7127A1D9                       \n           0x712851BE                       \n           0x7128CF3B                       \n           0x7128D3BE                       \n           0x71290357                       \n           0x7129C77B                       \n           0x7129E010                       \n           0x712BDD1F                       \n           0x712C2F33                       \n           0x712C2F59                       \n           0x712C3A71                       \n           0x712D059F                       \n           0x712DE086                       \n           0x712EFFFF                       \n           0x712F0C17                       \n           0x712F7FD6                       \n           0x712FEC19                       \n           0x7130DDFF                       \n           0x7131CCDB                       \n           0x7131CD70                       \n           0x7131CD80                       \n           0x7131CDA4                       \n           0x71334DB8                       \n           0x71341096                       \n           0x713458D1                       \n           0x7134C509                       \n           0x7134C517                       \n           0x7135973B                       \n           0x7135B38D                       \n           0x718B72FB                       \n           0x718BB4D8                       \n           0x718BFB8B                       \n           0x718C1401                       \n           0x718CF206                       \n           0x718F2B4C                       \n           0x718F80F5                       \n           0x718F9DB2                       \n           0x71906EBD                       \n           0x7190F048                       \n           0x7191305C                       \n           0x71913079                       \n           0x7191311B                       \n           0x71915927                       \n           0x7192583F                       \n           0x71925DE8                       \n           0x7193D2BE                       \n           0x7194F22E                       \n           0x719614AE                       \n           0x719830CF                       \n           0x7199FE4A                       \n           0x719D1E64                       \n           0x719DBB65                       \n           0x71A327C6                       \n           0x71A5B5A9                       \n           0x71A687DC                       \n           0x71A8BB73                       \n           0x71AB0D46                       \n           0x71AB78A8                       \n\nencode data using XOR (959 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x70F39EA8                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x711B3B36                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71208011                    \n           0x71208095                    \n           0x712080CF                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71208011                    \n           0x71208095                    \n           0x712080CF                    \n           0x71208011                    \n           0x71208095                    \n           0x712080CF                    \n           0x71310730                    \n           0x71208011                    \n           0x71208095                    \n           0x712080CF                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71225CA9                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x712367CB                    \n           0x71310730                    \n           0x712367CB                    \n           0x71310730                    \n           0x712367CB                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71252A89                    \n           0x71252BC2                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x712BB53F                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x718D6539                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71208011                    \n           0x71208095                    \n           0x712080CF                    \n           0x71310730                    \n           0x71208011                    \n           0x71208095                    \n           0x712080CF                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71225CA9                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x7133B4F2                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71208011                    \n           0x71208095                    \n           0x712080CF                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x712BB53F                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71225CA9                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71225CA9                    \n           0x71310730                    \n           0x71225CA9                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x7125F8A8                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71225CA9                    \n           0x71310730                    \n           0x71225CA9                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x712F4D3F                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x7133FDA3                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71303B4C                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x7190B40C                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71359A90                    \n           0x71359A90                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71233808                    \n           0x71310730                    \n           0x71233808                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71208011                    \n           0x71208095                    \n           0x712080CF                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x718CCFD3                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x718CFA94                    \n           0x718CFA94                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71208011                    \n           0x71208095                    \n           0x712080CF                    \n           0x71310730                    \n           0x71208011                    \n           0x71208095                    \n           0x712080CF                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x718D6539                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x713280B7                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x718DEC8C                    \n           0x718DEC8C                    \n           0x718DEC8C                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x712F4D3F                    \n           0x71310730                    \n           0x71310730                    \n           0x71225CA9                    \n           0x71310730                    \n           0x71225CA9                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x718FA3C2                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x712E1AA7                    \n           0x71310730                    \n           0x71310730                    \n           0x71225CA9                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71912749                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71310730                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x719503DB                    \n           0x71950438                    \n           0x719BD5BD                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72EFF                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A8FF68                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A8B4DE                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71AD9E8D                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x7197A49E                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A8B4DE                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71AEA76C                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71AF2FB9                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A42155                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x719BD5BD                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A822A9                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71A8B4DE                    \n           0x71A8B4DE                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71AA14F2                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71AB81B9                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A822A9                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71A822A9                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71AB81B9                    \n           0x71A72150                    \n           0x71A72EFF                    \n           0x71A72150                    \n           0x71AC4A0B                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71AB6FFE                    \n           0x71AF2FB9                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A8B4DE                    \n           0x71AB6FFE                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n           0x71A72150                    \n\nencrypt data using RC4 KSA (24 matches)\nnamespace  data-manipulation/encryption/rc4\nscope      function                        \nmatches    0x711B2290                      \n           0x7193D2BE                      \n           0x7194F22E                      \n           0x719536E2                      \n           0x7195371D                      \n           0x719614AE                      \n           0x7196BE5C                      \n           0x719830CF                      \n           0x7199FE4A                      \n           0x719D1E64                      \n           0x719DBB65                      \n           0x719F1BEA                      \n           0x719FA205                      \n           0x71A44304                      \n           0x71A4643A                      \n           0x71A5B5A9                      \n           0x71A68F00                      \n           0x71A6DEC2                      \n           0x71A8A20F                      \n           0x71A8BB73                      \n           0x71AB0D46                      \n           0x71AB78A8                      \n           0x71AD4366                      \n           0x71AF2280                      \n\nencrypt data using RC4 PRGA\nnamespace  data-manipulation/encryption/rc4\nscope      function                        \nmatches    0x711B23D0                      \n\nauthenticate HMAC (92 matches)\nnamespace  data-manipulation/hmac\nscope      function              \nmatches    0x711B022F            \n           0x711B0540            \n           0x711B0FE0            \n           0x711BF830            \n           0x711CFEC0            \n           0x711CFEE0            \n           0x711CFF20            \n           0x711CFF40            \n           0x711CFF90            \n           0x711D0000            \n           0x711D0050            \n           0x711D0070            \n           0x711D0090            \n           0x711D0100            \n           0x711D0120            \n           0x711D0270            \n           0x711D0290            \n           0x711D02D0            \n           0x711D0310            \n           0x711D0350            \n           0x711D03A0            \n           0x711D03C0            \n           0x711D03E0            \n           0x711D0400            \n           0x711D0420            \n           0x711D0448            \n           0x711D0460            \n           0x711D0480            \n           0x711D04A0            \n           0x711D04C0            \n           0x711D04E0            \n           0x711D0500            \n           0x711D0520            \n           0x711D0540            \n           0x711D0560            \n           0x711D0580            \n           0x711D05A8            \n           0x711D05C0            \n           0x711D0660            \n           0x711D0680            \n           0x711D06F0            \n           0x71208C32            \n           0x71219AE6            \n           0x7121D494            \n           0x712242F1            \n           0x712327F2            \n           0x71240F77            \n           0x71248A5B            \n           0x71266D19            \n           0x71272187            \n           0x7127A1D9            \n           0x7128DD71            \n           0x71292C5B            \n           0x712A0438            \n           0x712A215C            \n           0x712D059F            \n           0x712DE086            \n           0x712E5DF2            \n           0x712EFFFF            \n           0x712F0C17            \n           0x712F8769            \n           0x712FEC19            \n           0x713021E7            \n           0x7130A246            \n           0x713114DF            \n           0x7131CDA4            \n           0x7131FA67            \n           0x71320D95            \n           0x71332F4D            \n           0x71334DB8            \n           0x71341096            \n           0x71342CCA            \n           0x713458D1            \n           0x7134C509            \n           0x7134E624            \n           0x71353FC7            \n           0x718BB4D8            \n           0x718BFB8B            \n           0x718C5A00            \n           0x718CFBFB            \n           0x718D1964            \n           0x718E2FE8            \n           0x718F2B4C            \n           0x718F80F5            \n           0x718F9DB2            \n           0x7190F048            \n           0x7191305C            \n           0x71915927            \n           0x719240EF            \n           0x71925DE8            \n           0x719BDC70            \n           0x71A2715C            \n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls\nscope      file                     \n\nparse PE header (32 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x70F37E80  \n           0x70F37F00  \n           0x70F37FC0  \n           0x711AC75C  \n           0x711B0700  \n           0x7124D7E5  \n           0x712D2F0F  \n           0x712DE086  \n           0x71320D95  \n           0x7132BF4B  \n           0x7132BF5E  \n           0x718B052C  \n           0x7193D2BE  \n           0x719483BD  \n           0x7194F22E  \n           0x719536E2  \n           0x719614AE  \n           0x7196BE5C  \n           0x719830CF  \n           0x7199FE4A  \n           0x719D1E64  \n           0x719DBB65  \n           0x719F1BEA  \n           0x719FA205  \n           0x71A5B5A9  \n           0x71A68F00  \n           0x71A6DEC2  \n           0x71A8BB73  \n           0x71AB0D46  \n           0x71AB78A8  \n           0x71AD4366  \n           0x71AF2280  \n\nresolve function by parsing PE exports\nnamespace  load-code/pe\nscope      function    \nmatches    0x70F3ACD0  \n\n\n\n","very_verbose":"md5                     3f1fa41a280d2e628aa2f4c7d5502518                        \nsha1                    f320455de57557db3331e2e4abf26654a74065cf                \nsha256                  c480d1d8b50d9c94655b26755431d2d5a3c7d741a30047a21d1e137…\npath                    /home/apogean/projects/malware/windows/all_runs/pf-019f…\ntimestamp               2026-07-01 16:07:04.609837                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x70F00000                                              \nrules                   /tmp/_MEI8AsRzg/rules                                   \nfunction count          3874                                                    \nlibrary function count  256                                                     \ntotal feature count     899400                                                  \n\nPEB access (4 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Debugger Detection::Process Environment   \n            Block [B0001.019]                                                   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nbasic block @ 0x711C0AEA in function 0x711C0AEA\n  or:\n    and:\n      arch: i386\n      characteristic: fs access @ 0x711C0B27\n      or:\n        offset: 0x30 @ 0x711C0B02\n\ncalculate modulo 256 via x86 assembly (335 matches, only showing first match of \nlibrary rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x711AB8D9\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x711AB8D9\n    or:\n      number: 0xFF @ 0x711AB8D9\n\ncontain loop (1587 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x70F37520\n  or:\n    characteristic: tight loop @ 0x70F37530\n\ncontain pusha popa sequence (36 matches, only showing first match of library \nrule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x711AC069\n  and:\n    or:\n      count(mnemonic(pushad)): 2 or more @ 0x7130D1AC, 0x7135D953\n    or:\n      count(mnemonic(popad)): 2 or more @ 0x71241FCC, 0x71241FFE, 0x7130D1C0, 0x7135D8B2, and 1 more...\n\nexecute syscall (7 matches)\nnamespace    anti-analysis                                                      \nauthor       @kulinacs, @mr-tz, mehunhoff@google.com, still@teamt5.org          \nscope        basic block                                                        \nreferences   https://github.com/j00ru/windows-syscalls,                         \n             https://codemachine.com/articles/system_call_instructions.html,    \n             https://www.felixcloutier.com/x86/sysenter                         \ndescription  may be used to evade hooks or hinder analysis                      \nbasic block @ 0x712A26C7 in function 0x7121CFF3\n  or:\n    and:\n      or:\n        mnemonic: syscall @ 0x712A26CA\n      or:\n        mnemonic: ret @ 0x712A2710\nbasic block @ 0x719150CF in function 0x71915099\n  or:\n    and:\n      or:\n        mnemonic: sysenter @ 0x719150CF\n      or:\n        mnemonic: ret @ 0x719150D7\nbasic block @ 0x719150CF in function 0x71915099\n  or:\n    and:\n      or:\n        mnemonic: sysenter @ 0x719150CF\n      or:\n        mnemonic: ret @ 0x719150D7\nbasic block @ 0x719150CF in function 0x71915099\n  or:\n    and:\n      or:\n        mnemonic: sysenter @ 0x719150CF\n      or:\n        mnemonic: ret @ 0x719150D7\nbasic block @ 0x719150CF in function 0x71915099\n  or:\n    and:\n      or:\n        mnemonic: sysenter @ 0x719150CF\n      or:\n        mnemonic: ret @ 0x719150D7\nbasic block @ 0x719150CF in function 0x71915099\n  or:\n    and:\n      or:\n        mnemonic: sysenter @ 0x719150CF\n      or:\n        mnemonic: ret @ 0x719150D7\nbasic block @ 0x719E082E in function 0x719C0EB7\n  or:\n    and:\n      or:\n        mnemonic: sysenter @ 0x719E082E\n      or:\n        mnemonic: ret @ 0x719E086B\n\nexecute anti-debugging instructions (4 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection                      \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \nmbc        Anti-Behavioral Analysis::Debugger Detection::Anti-debugging         \n           Instructions [B0001.034]                                             \nfunction @ 0x7134C509\n  or:\n    count(mnemonic(rdtsc)): 2 or more @ 0x711AEDF9, 0x71336314\nfunction @ 0x71359729\n  or:\n    count(mnemonic(rdtsc)): 2 or more @ 0x7135977D, 0x713597AB\nfunction @ 0x7135973B\n  or:\n    count(mnemonic(rdtsc)): 2 or more @ 0x711AEDF9, 0x7135977D, 0x713597AB\nfunction @ 0x71359F62\n  or:\n    count(mnemonic(rdtsc)): 2 or more @ 0x7135977D, 0x713597AB\n\ncontain anti-disasm techniques\nnamespace  anti-analysis/anti-disasm                         \nauthor     moritz.raabe@mandiant.com                         \nscope      file                                              \nmbc        Anti-Static Analysis::Disassembler Evasion [B0012]\nor:\n  count(match(contain pusha popa sequence)): 10 or more @ 0x711AC069, 0x711B022F, 0x711B651D, 0x711BF830, and 32 more...\n\ncontain obfuscated stackstrings (2 matches)\nnamespace  anti-analysis/obfuscation/string/stackstring                         \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information::Indicator Removal  \n           from Tools [T1027.005]                                               \nmbc        Anti-Static Analysis::Executable Code Obfuscation::Argument          \n           Obfuscation [B0032.020], Anti-Static Analysis::Executable Code       \n           Obfuscation::Stack Strings [B0032.017]                               \nbasic block @ 0x711B0721 in function 0x711B0700\n  characteristic: stack string @ 0x711B0721\nbasic block @ 0x711B727A in function 0x711B7260\n  characteristic: stack string @ 0x711B727A\n\npacked with generic packer (84 matches)\nnamespace  anti-analysis/packer/generic                                         \nauthor     william.ballenthin@mandiant.com                                      \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information::Software Packing   \n           [T1027.002]                                                          \nmbc        Anti-Static Analysis::Software Packing::Standard Compression         \n           [F0001.002]                                                          \nfunction @ 0x711AED60\n  and:\n    characteristic: cross section flow @ 0x711B5B0D\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711B0540\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711B0FE0\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711CFEC0\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711CFEE0\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711CFF20\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711CFF40\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711CFF90\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0000\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0050\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0070\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0090\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0100\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0120\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0270\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0290\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D02D0\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0310\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0350\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D03C0\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D03E0\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0400\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0420\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0448\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0460\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0480\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D04A0\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D04C0\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D04E0\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0500\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0520\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0540\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0560\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0580\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D05A8\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D05C0\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0660\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D0680\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x711D06F0\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x71208C32\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x7120E885\n  and:\n    characteristic: cross section flow @ 0x711B5B0D\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x7120E8BB\n  and:\n    characteristic: cross section flow @ 0x711B5B0D\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x7120EB7C\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x718B3DC3\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE\nfunction @ 0x7121E3D5\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x719143C0\n    or:\n      mnemonic: popad @ 0x71229957\nfunction @ 0x712242F1\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x71240F77\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x7124190A\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x71266D19\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB, and 1 more...\nfunction @ 0x71272187\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x7127A1D9\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x7128CF3B\n  and:\n    characteristic: cross section flow @ 0x7127D537\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x7128DD71\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x71292C5B\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x712A215C\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x712D059F\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x712DE086\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x7126C601, 0x71317A7F, and 3 more...\nfunction @ 0x712F0C17\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x712F0C3E, 0x71317A7F, and 1 more...\nfunction @ 0x712F8769\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x712FEC19\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x713021E7\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x7130A246\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x7130DDFF\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x713114DF\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x7131FA67\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x71320D95\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x71332F4D\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x71334DB8\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x71341096\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x71342CCA\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x713458D1\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x7134C509\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x7134E624\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x718BB4D8\n  and:\n    characteristic: cross section flow @ 0x70F3D389, 0x711B5B0D, 0x7132DA7A, 0x718DEAFD\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x712AA8E9, 0x71317A7F, and 1 more...\nfunction @ 0x718BFB8B\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x718CFBFB\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x7124F9A6, 0x71317A7F, and 1 more...\nfunction @ 0x718DEB2F\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x718E2FE8\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x718F2B4C\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB, and 1 more...\nfunction @ 0x718F80F5\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB, and 1 more...\nfunction @ 0x718F9DB2\n  and:\n    characteristic: cross section flow @ 0x70F3D389, 0x711B5B0D, 0x7132DA7A, 0x718DEAFD\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x712AA8E9, 0x71317A7F, and 1 more...\nfunction @ 0x7190F048\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB, and 2 more...\nfunction @ 0x71915927\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x719240EF\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\nfunction @ 0x71925DE8\n  and:\n    characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n    not:\n      match: contain pusha popa sequence\n    or:\n      mnemonic: pushad @ 0x71317B1B\n    or:\n      mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n\nencode data using Base64 (73 matches)\nnamespace  data-manipulation/encoding/base64                                    \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::Base64 [C0026.001]         \nfunction @ 0x711AED60\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 15 more...\n      mnemonic: shr @ 0x711AED6E, 0x711AEE3D, 0x711B0166, 0x711B5AF2, and 7 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x711AED60\n        or:\n          characteristic: loop @ 0x711AED60\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x71317A24, 0x7134556A\n        number: 0x4 @ 0x7129CD69, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x711B022F\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711B02B1, 0x711FF98F, and 18 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 8 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x711B022F\n        or:\n          characteristic: loop @ 0x711B022F\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127220C, 0x7127BC34, 0x7129C6E0, and 2 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x711B0700\n  or:\n    and:\n      mnemonic: shl @ 0x711B0848, 0x711B085C\n      mnemonic: shr @ 0x711B0885, 0x711B0894, 0x711B08B2\n      number: 0x3F = modulo 64 @ 0x711B087B, 0x711B0888, 0x711B0897, 0x711B08B5\n      or:\n        number: 0x3D = '=' @ 0x711B08AD, 0x711B08C4\n      match: contain loop @ 0x711B0700\n        or:\n          characteristic: loop @ 0x711B0700\n      optional:\n        number: 0x2 @ 0x711B084F\n        number: 0x4 @ 0x711B083B\n        number: 0x6 @ 0x711B08B2\nfunction @ 0x711B0FE0\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 18 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 13 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7134E663, 0x7135DB95, 0x7192646F\n      match: contain loop @ 0x711B0FE0\n        or:\n          characteristic: loop @ 0x711B0FE0\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 2 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x711B651D\n  or:\n    and:\n      mnemonic: shl @ 0x711B6536, 0x7121DC12, 0x71241F9D, 0x71241FAD, and 22 more...\n      mnemonic: shr @ 0x711B0166, 0x712549FA, 0x71268908, 0x7127BC34, and 7 more...\n      number: 0x3F = modulo 64 @ 0x711B1119, 0x711B6584\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x711B651D\n        or:\n          characteristic: loop @ 0x711B651D\n          characteristic: tight loop @ 0x71299A55, 0x71310730, 0x7135DCAA, 0x71904931\n      optional:\n        number: 0x2 @ 0x71268943, 0x7127BC34, 0x71317A24, 0x718C1F01\n        number: 0x4 @ 0x712584C0, 0x713011FD, 0x718EA90C\n        number: 0x6 @ 0x711B016C, 0x7130210A\nfunction @ 0x711B7150\n  or:\n    and:\n      mnemonic: shl @ 0x711AD2F2, 0x711AD313, 0x7121DC12, 0x71241F9D, and 15 more...\n      mnemonic: shr @ 0x711AD30C, 0x711B0166, 0x71245751, 0x71245757, and 9 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x711C0145\n      match: contain loop @ 0x711B7150\n        or:\n          characteristic: loop @ 0x711B7150\n          characteristic: tight loop @ 0x71223B55, 0x71299A55, 0x71310730, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x7124CA59, 0x71268943, 0x71317A24\n        number: 0x4 @ 0x712DC80B, 0x718CE462\n        number: 0x6 @ 0x711B016C\nfunction @ 0x711BF830\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x71241E8D, 0x71241F9D, 0x71241FAD, and 21 more...\n      mnemonic: shr @ 0x711B0166, 0x711BA7D1, 0x711BF8BF, 0x71204161, and 15 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x711BF830\n        or:\n          characteristic: loop @ 0x711BF830\n          characteristic: tight loop @ 0x7120C6B7, 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x7127BC34, 0x712E0089, 0x71317A24, 0x718B7235, and 1 more...\n        number: 0x4 @ 0x711B59B1, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C, 0x7190B0AB\nfunction @ 0x711D03A0\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 24 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x711BA7D1, and 18 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x711D03A0\n        or:\n          characteristic: loop @ 0x711D03A0\n          characteristic: tight loop @ 0x7120C6B7, 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712E0089, and 4 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x711B59B1, 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C, 0x7190B0AB\nfunction @ 0x71223AF8\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x71241F9D, 0x71241FAD, 0x71241FBF, and 8 more...\n      mnemonic: shr @ 0x711B0166, 0x712DC81A, 0x712F2C39, 0x712F2C81, and 3 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x711C0145\n      match: contain loop @ 0x71223AF8\n        or:\n          characteristic: loop @ 0x71223AF8\n          characteristic: tight loop @ 0x71223B55, 0x71299A55, 0x71310730, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x7124CA59, 0x71317A24\n        number: 0x4 @ 0x712DC80B, 0x718CE462\n        number: 0x6 @ 0x711B016C\nfunction @ 0x7123C11D\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x71241F9D, 0x71241FAD, 0x71241FBF, and 20 more...\n      mnemonic: shr @ 0x711B0166, 0x7121617F, 0x7124950B, 0x7126B5E3, and 15 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x7123C11D\n        or:\n          characteristic: loop @ 0x7123C11D\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA, 0x718F7E4C\n      optional:\n        number: 0x2 @ 0x7127BC34, 0x712D0FD9, 0x7130A23B, 0x71317A24\n        number: 0x3 @ 0x718F50B7\n        number: 0x4 @ 0x712495A5, 0x712DB6A8, 0x718C7FBC, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x71248A5B\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x71230000, 0x71241F9D, 0x71241FAD, and 13 more...\n      mnemonic: shr @ 0x711B0166, 0x7122FFD5, 0x712300AB, 0x7127BC34, and 4 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x71248A5B\n        or:\n          characteristic: loop @ 0x71248A5B\n          characteristic: tight loop @ 0x71248A63, 0x71248B83, 0x71299A55, 0x71310730, and 1 more...\n      optional:\n        number: 0x2 @ 0x7122FFB7, 0x7122FFF5, 0x7127BC34\n        number: 0x4 @ 0x7135D868, 0x718EA90C\n        number: 0x6 @ 0x711B016C\n        number: 0xF @ 0x71248AB3\nfunction @ 0x71266D19\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 16 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 8 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x71266D19\n        or:\n          characteristic: loop @ 0x71266D19\n          characteristic: tight loop @ 0x71299A55, 0x71347D01, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 1 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x7126E897\n  or:\n    and:\n      mnemonic: shl @ 0x7126E8AC, 0x7126E8BF, 0x7126E924, 0x712F7F9D, and 2 more...\n      mnemonic: shr @ 0x711BBC8D, 0x7127BC34, 0x71926488, 0x719264AC\n      number: 0x3F = modulo 64 @ 0x7126E94C\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x7126E897\n        or:\n          characteristic: loop @ 0x7126E897\n      optional:\n        number: 0x2 @ 0x7127BC34\n        number: 0x4 @ 0x718EA90C\nfunction @ 0x71272187\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 15 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 7 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x71272187\n        or:\n          characteristic: loop @ 0x71272187\n          characteristic: tight loop @ 0x71299A55, 0x712F8070, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x71270049, 0x7127BC34, 0x7129C6E0, and 2 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x712776C4\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x71272229, 0x712776CC, 0x712776E1, and 9 more...\n      mnemonic: shr @ 0x711B0166, 0x7127BC34, 0x7135DCA8, 0x7135DCCF, and 2 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x712776C4\n        or:\n          characteristic: loop @ 0x712776C4\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x7127220C, 0x7127BC34\n        number: 0x4 @ 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x7127A1D9\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 15 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 7 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x7127A1D9\n        or:\n          characteristic: loop @ 0x7127A1D9\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 1 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x712851BE\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x71230000, 0x71241F9D, 0x71241FAD, and 16 more...\n      mnemonic: shr @ 0x711B0166, 0x7122FFD5, 0x712300AB, 0x7127BC34, and 4 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x712851BE\n        or:\n          characteristic: loop @ 0x712851BE\n          characteristic: tight loop @ 0x71299A55, 0x71310730, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x7122FFB7, 0x7122FFF5, 0x7127BC34\n        number: 0x4 @ 0x7135D868, 0x718EA90C, 0x7192643A\n        number: 0x6 @ 0x711B016C\nfunction @ 0x7128CF3B\n  or:\n    and:\n      mnemonic: shl @ 0x71207FFB, 0x71208104, 0x7121DC12, 0x71241F9D, and 10 more...\n      mnemonic: shr @ 0x711B0166, 0x7128CF6C, 0x71317AF8, 0x7135DCA8, and 1 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7127D48E\n      match: contain loop @ 0x7128CF3B\n        or:\n          characteristic: loop @ 0x7128CF3B\n          characteristic: tight loop @ 0x71208011, 0x71208095, 0x712080CF, 0x71299A55, and 2 more...\n      optional:\n        number: 0x2 @ 0x71207FF4, 0x71317A24\n        number: 0x6 @ 0x711B016C\nfunction @ 0x7128D3BE\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x712688E1, 0x7126C60E, 0x7128664F, and 9 more...\n      mnemonic: shr @ 0x711B0166, 0x7127BC34, 0x713410CC, 0x7135DCA8, and 9 more...\n      number: 0x3F = modulo 64 @ 0x7126C61B\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x7128D3BE\n        or:\n          characteristic: loop @ 0x7128D3BE\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA, 0x718BE7FC, 0x718F15A4, and 1 more...\n      optional:\n        number: 0x2 @ 0x7127BC34\n        number: 0x4 @ 0x7126C5EB, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x71290357\n  or:\n    and:\n      mnemonic: shl @ 0x711AC9FF, 0x7121DC12, 0x71225D99, 0x7123B842, and 19 more...\n      mnemonic: shr @ 0x711B0166, 0x71225BDB, 0x71268908, 0x7127BC34, and 8 more...\n      number: 0x3F = modulo 64 @ 0x711B1119, 0x71225BBA, 0x71225C6C\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x71290357\n        or:\n          characteristic: loop @ 0x71290357\n          characteristic: tight loop @ 0x71225CA9, 0x71299A55, 0x71310730, 0x71351585, and 1 more...\n      optional:\n        number: 0x2 @ 0x71268943, 0x7127BC34, 0x71317A24\n        number: 0x3 @ 0x71225C05, 0x71225DDE\n        number: 0x4 @ 0x71225BC3, 0x718EA90C, 0x718F5F0B\n        number: 0x6 @ 0x711B016C, 0x7130210A\n        number: 0xF @ 0x71351587\nfunction @ 0x7129C77B\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x71241F9D, 0x71241FAD, 0x71241FBF, and 15 more...\n      mnemonic: shr @ 0x711B0166, 0x71254430, 0x7127BC34, 0x71317AF8, and 8 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x7129C77B\n        or:\n          characteristic: loop @ 0x7129C77B\n          characteristic: tight loop @ 0x71299A55, 0x71310730, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x7127BC34, 0x712B9B31, 0x71317A24, 0x713362B6\n        number: 0x3 @ 0x71336221\n        number: 0x4 @ 0x7125444A, 0x7135D868, 0x718EA90C\n        number: 0x6 @ 0x711B016C, 0x712B9AD7\n        number: 0xF @ 0x7134C548\nfunction @ 0x7129E010\n  or:\n    and:\n      mnemonic: shl @ 0x71299A4B, 0x7129E052, 0x7129E0CD, 0x7129E104, and 6 more...\n      mnemonic: shr @ 0x7127BC34, 0x71926488, 0x719264AC\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x7129E010\n        or:\n          characteristic: loop @ 0x7129E010\n          characteristic: tight loop @ 0x71299A55, 0x71310730\n      optional:\n        number: 0x2 @ 0x7127BC34, 0x7129E095, 0x718D5EBC\n        number: 0x4 @ 0x712DB6A8, 0x718EA90C\nfunction @ 0x712BDD1F\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x71241F9D, 0x71241FAD, 0x71241FBF, and 13 more...\n      mnemonic: shr @ 0x711B0166, 0x7127BC34, 0x71317AF8, 0x7134DCB3, and 7 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x712BDD1F\n        or:\n          characteristic: loop @ 0x712BDD1F\n          characteristic: tight loop @ 0x71299A55, 0x71310730, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x7127BC34, 0x71317A24, 0x7134DC8C\n        number: 0x4 @ 0x7135D868, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x712C2F33\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x7126E8AC, 0x7126E8BF, 0x7126E924, and 8 more...\n      mnemonic: shr @ 0x711B0166, 0x711BBC8D, 0x7127BC34, 0x712A7973, and 4 more...\n      number: 0x3F = modulo 64 @ 0x7126E94C\n      or:\n        number: 0x3D = '=' @ 0x712A7981, 0x7192646F\n      match: contain loop @ 0x712C2F33\n        or:\n          characteristic: loop @ 0x712C2F33\n          characteristic: tight loop @ 0x71299A55, 0x71310730, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x7127BC34, 0x712A799C\n        number: 0x4 @ 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x712C2F59\n  or:\n    and:\n      mnemonic: shl @ 0x7126E8AC, 0x7126E8BF, 0x7126E924, 0x712F7F9D, and 2 more...\n      mnemonic: shr @ 0x711BBC8D, 0x7127BC34, 0x71926488, 0x719264AC\n      number: 0x3F = modulo 64 @ 0x7126E94C\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x712C2F59\n        or:\n          characteristic: loop @ 0x712C2F59\n      optional:\n        number: 0x2 @ 0x7127BC34\n        number: 0x4 @ 0x718EA90C\nfunction @ 0x712C3A71\n  or:\n    and:\n      mnemonic: shl @ 0x712F7F9D, 0x718BC068, 0x71926453, 0x719264BD\n      mnemonic: shr @ 0x71257687, 0x7127BC34, 0x71926488, 0x719264AC\n      number: 0x3F = modulo 64 @ 0x712C3A81\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x712C3A71\n        or:\n          characteristic: loop @ 0x712C3A71\n      optional:\n        number: 0x2 @ 0x7127BC34, 0x712E0089\n        number: 0x4 @ 0x718EA90C\nfunction @ 0x712D059F\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 15 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 7 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x712D059F\n        or:\n          characteristic: loop @ 0x712D059F\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 1 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x712DE086\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 17 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 15 more...\n      number: 0x3F = modulo 64 @ 0x711B1119, 0x7126C61B\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x712DE086\n        or:\n          characteristic: loop @ 0x712DE086\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA, 0x718BE7FC, 0x718F15A4, and 1 more...\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 1 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x7126C5EB, 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x712EFFFF\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 20 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 8 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x712EFFFF\n        or:\n          characteristic: loop @ 0x712EFFFF\n          characteristic: tight loop @ 0x71299A55, 0x712B3043, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 2 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\n        number: 0xF @ 0x712F00B1, 0x71347129\nfunction @ 0x712F0C17\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 15 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 7 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x712F0C17\n        or:\n          characteristic: loop @ 0x712F0C17\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 1 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x712F7FD6\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x71241F9D, 0x71241FAD, 0x71241FBF, and 11 more...\n      mnemonic: shr @ 0x711B0166, 0x7127BC34, 0x71317AF8, 0x7135DCA8, and 4 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x712F7FD6\n        or:\n          characteristic: loop @ 0x712F7FD6\n          characteristic: tight loop @ 0x71299A55, 0x712F8070, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x7127BC34, 0x71317A24\n        number: 0x4 @ 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x712FEC19\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 15 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 7 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x712FEC19\n        or:\n          characteristic: loop @ 0x712FEC19\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 1 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C, 0x712FEC6A\nfunction @ 0x7130DDFF\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 17 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 9 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x7130DDFF\n        or:\n          characteristic: loop @ 0x7130DDFF\n          characteristic: tight loop @ 0x71299A55, 0x7130DE88, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 1 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x7131CCDB\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x7128664F, 0x712866AA, 0x71299A4B, and 5 more...\n      mnemonic: shr @ 0x711B0166, 0x71263A11, 0x712D1B91, 0x712D1B97, and 4 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x71351D2A\n      match: contain loop @ 0x7131CCDB\n        or:\n          characteristic: loop @ 0x7131CCDB\n          characteristic: tight loop @ 0x71299A55, 0x71310730, 0x71351DAD, 0x7135DCAA, and 1 more...\n      optional:\n        number: 0x6 @ 0x711B016C\n        number: 0xF @ 0x71351D77\nfunction @ 0x7131CD70\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x7128664F, 0x712866AA, 0x71299A4B, and 4 more...\n      mnemonic: shr @ 0x711B0166, 0x712D1B91, 0x712D1B97, 0x7135DCA8, and 3 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x71351D2A\n      match: contain loop @ 0x7131CD70\n        or:\n          characteristic: loop @ 0x7131CD70\n          characteristic: tight loop @ 0x71299A55, 0x71310730, 0x71351DAD, 0x7135DCAA, and 1 more...\n      optional:\n        number: 0x6 @ 0x711B016C\n        number: 0xF @ 0x71351D77\nfunction @ 0x7131CD80\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x7128664F, 0x712866AA, 0x71299A4B, and 4 more...\n      mnemonic: shr @ 0x711B0166, 0x712D1B91, 0x712D1B97, 0x7135DCA8, and 3 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x71351D2A\n      match: contain loop @ 0x7131CD80\n        or:\n          characteristic: loop @ 0x7131CD80\n          characteristic: tight loop @ 0x71299A55, 0x71310730, 0x71351DAD, 0x7135DCAA, and 1 more...\n      optional:\n        number: 0x3 @ 0x713603D9\n        number: 0x4 @ 0x713603CB\n        number: 0x6 @ 0x711B016C\n        number: 0xF @ 0x71351D77\nfunction @ 0x7131CDA4\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 17 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 11 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x71351D2A, 0x7192646F\n      match: contain loop @ 0x7131CDA4\n        or:\n          characteristic: loop @ 0x7131CDA4\n          characteristic: tight loop @ 0x71299A55, 0x71351DAD, 0x7135DCAA, 0x7191309A\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 1 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\n        number: 0xF @ 0x71351D77\nfunction @ 0x71334DB8\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 15 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 8 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x71334DB8\n        or:\n          characteristic: loop @ 0x71334DB8\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 1 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x71341096\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 15 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 8 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x71341096\n        or:\n          characteristic: loop @ 0x71341096\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 1 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x713458D1\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 15 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 7 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x713458D1\n        or:\n          characteristic: loop @ 0x713458D1\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 1 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x7134C509\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 19 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71254430, and 12 more...\n      number: 0x3F = modulo 64 @ 0x711B1119, 0x713041A8\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x7134C509\n        or:\n          characteristic: loop @ 0x7134C509\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712B9B31, and 3 more...\n        number: 0x3 @ 0x712AC996, 0x71336221\n        number: 0x4 @ 0x7125444A, 0x712A5B3F, 0x712B4C4C, 0x712DB6A8, and 2 more...\n        number: 0x6 @ 0x711B016C, 0x712B9AD7\n        number: 0xF @ 0x71304144, 0x7134C548\nfunction @ 0x7134C517\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x71241F9D, 0x71241FAD, 0x71241FBF, and 13 more...\n      mnemonic: shr @ 0x711B0166, 0x71254430, 0x7127BC34, 0x71317AF8, and 8 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x7134C517\n        or:\n          characteristic: loop @ 0x7134C517\n          characteristic: tight loop @ 0x71299A55, 0x71310730, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x7127BC34, 0x712B9B31, 0x71317A24, 0x713362B6\n        number: 0x3 @ 0x71336221\n        number: 0x4 @ 0x7125444A, 0x718EA90C\n        number: 0x6 @ 0x711B016C, 0x712B9AD7\n        number: 0xF @ 0x7134C548\nfunction @ 0x7135973B\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 21 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x711B9DED, and 10 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7135DB95, 0x7192646F\n      match: contain loop @ 0x7135973B\n        or:\n          characteristic: loop @ 0x7135973B\n          characteristic: tight loop @ 0x71299A55, 0x712E1549, 0x7135DCAA, 0x718B1157\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 2 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x7135B38D\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x71241F9D, 0x71241FAD, 0x71241FBF, and 22 more...\n      mnemonic: shr @ 0x711B0166, 0x7127BC34, 0x7128520C, 0x71317AF8, and 7 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x7135B38D\n        or:\n          characteristic: loop @ 0x7135B38D\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA, 0x71904931\n      optional:\n        number: 0x2 @ 0x7127220C, 0x7127BC34, 0x71317A24, 0x718C1F01\n        number: 0x4 @ 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x718B72FB\n  or:\n    and:\n      mnemonic: shl @ 0x71213E23, 0x7121DC12, 0x712688E1, 0x7126894C, and 11 more...\n      mnemonic: shr @ 0x711B0166, 0x71268908, 0x7127BC34, 0x7135DCA8, and 7 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x718B72FB\n        or:\n          characteristic: loop @ 0x718B72FB\n          characteristic: tight loop @ 0x71299A55, 0x71310730, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x71268943, 0x7127BC34, 0x718B73DA\n        number: 0x3 @ 0x718B735B\n        number: 0x4 @ 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x718BB4D8\n  or:\n    and:\n      mnemonic: shl @ 0x711AD0AA, 0x711AD0C4, 0x711AEEA8, 0x711AEEAF, and 27 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71235B41, and 15 more...\n      number: 0x3F = modulo 64 @ 0x711B1119, 0x7191EFAE\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x718BB4D8\n        or:\n          characteristic: loop @ 0x718BB4D8\n          characteristic: tight loop @ 0x71299A55, 0x7134B97A, 0x7135DCAA\n          characteristic: recursive call @ 0x718BB4D8\n      optional:\n        number: 0x2 @ 0x711AD080, 0x711AD108, 0x711AEE37, 0x7127220C, and 6 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718DEB2C, 0x718EA90C\n        number: 0x6 @ 0x711AD0AA, 0x711B016C, 0x7134F0D3\nfunction @ 0x718BFB8B\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 15 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 7 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x718BFB8B\n        or:\n          characteristic: loop @ 0x718BFB8B\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 1 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x718C1401\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x71224D92, 0x71232B5F, 0x71241F9D, and 31 more...\n      mnemonic: shr @ 0x711B0166, 0x7120D2E3, 0x71232759, 0x71268908, and 14 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x718C1401\n        or:\n          characteristic: loop @ 0x718C1401\n          characteristic: tight loop @ 0x71299A55, 0x71310730, 0x71349022, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x71268943, 0x7127BC34, 0x712F3569, 0x7130BF84, and 1 more...\n        number: 0x4 @ 0x713480EC, 0x7135D868, 0x718EA90C, 0x718F5F0B\n        number: 0x6 @ 0x711B016C\nfunction @ 0x718CF206\n  or:\n    and:\n      mnemonic: shl @ 0x711C35D6, 0x7121DC12, 0x712688E1, 0x7126894C, and 6 more...\n      mnemonic: shr @ 0x711B0166, 0x71268908, 0x71277BEC, 0x71342BE1, and 8 more...\n      number: 0x3F = modulo 64 @ 0x712967AF\n      or:\n        number: 0x3D = '=' @ 0x7134E663\n      match: contain loop @ 0x718CF206\n        or:\n          characteristic: loop @ 0x718CF206\n          characteristic: tight loop @ 0x71299A55, 0x71310730, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x71268943, 0x71353C44\n        number: 0x6 @ 0x711B016C, 0x718C2180\nfunction @ 0x718F2B4C\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 18 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 9 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x718F2B4C\n        or:\n          characteristic: loop @ 0x718F2B4C\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 1 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\n        number: 0xF @ 0x71347129\nfunction @ 0x718F80F5\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 17 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 8 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x718F80F5\n        or:\n          characteristic: loop @ 0x718F80F5\n          characteristic: tight loop @ 0x71299A55, 0x712B3043, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 1 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718B3F59, 0x718EA90C\n        number: 0x6 @ 0x711B016C\n        number: 0xF @ 0x712F00B1, 0x71347129\nfunction @ 0x718F9DB2\n  or:\n    and:\n      mnemonic: shl @ 0x711AD0AA, 0x711AD0C4, 0x711AEEA8, 0x711AEEAF, and 30 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71235B41, and 17 more...\n      number: 0x3F = modulo 64 @ 0x711B1119, 0x7191EFAE\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x718F9DB2\n        or:\n          characteristic: loop @ 0x718F9DB2\n          characteristic: tight loop @ 0x71299A55, 0x7134B97A, 0x7135DCAA, 0x71909077\n      optional:\n        number: 0x2 @ 0x711AD080, 0x711AD108, 0x711AEE37, 0x7127220C, and 7 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x712EF2FE, 0x718DEB2C, and 1 more...\n        number: 0x6 @ 0x711AD0AA, 0x711B016C, 0x7134F0D3\n        number: 0xF @ 0x712A225F\nfunction @ 0x71906EBD\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x712688E1, 0x7126C60E, 0x7128664F, and 9 more...\n      mnemonic: shr @ 0x711B0166, 0x7127BC34, 0x713410CC, 0x7135DCA8, and 10 more...\n      number: 0x3F = modulo 64 @ 0x7126C61B\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x71906EBD\n        or:\n          characteristic: loop @ 0x71906EBD\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA, 0x718BE7FC, 0x718F15A4, and 1 more...\n      optional:\n        number: 0x2 @ 0x7127BC34\n        number: 0x4 @ 0x7126C5EB, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x7190F048\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711B1EB3, 0x711FF98F, and 31 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71226F26, and 16 more...\n      number: 0x3F = modulo 64 @ 0x711B1119, 0x713041A8\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x7190F048\n        or:\n          characteristic: loop @ 0x7190F048\n          characteristic: tight loop @ 0x71299A55, 0x71349022, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x71208C65, 0x71226ECB, 0x7127220C, and 5 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712B4C4C, 0x712DB6A8, 0x71304125, and 2 more...\n        number: 0x6 @ 0x711B016C\n        number: 0xF @ 0x71304144\nfunction @ 0x7191305C\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 17 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 11 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x71351D2A, 0x7192646F\n      match: contain loop @ 0x7191305C\n        or:\n          characteristic: loop @ 0x7191305C\n          characteristic: tight loop @ 0x71299A55, 0x71351DAD, 0x7135DCAA, 0x7191309A\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127BC34, 0x7129C6E0, 0x712FC005, and 1 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\n        number: 0xF @ 0x71351D77\nfunction @ 0x71913079\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x7128664F, 0x712866AA, 0x71299A4B, and 4 more...\n      mnemonic: shr @ 0x711B0166, 0x712D1B91, 0x712D1B97, 0x7135DCA8, and 3 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x71351D2A\n      match: contain loop @ 0x71913079\n        or:\n          characteristic: loop @ 0x71913079\n          characteristic: tight loop @ 0x71299A55, 0x71310730, 0x71351DAD, 0x7135DCAA, and 1 more...\n      optional:\n        number: 0x3 @ 0x713603D9\n        number: 0x4 @ 0x713603CB\n        number: 0x6 @ 0x711B016C\n        number: 0xF @ 0x71351D77\nfunction @ 0x7191311B\n  or:\n    and:\n      mnemonic: shl @ 0x712D1B94, 0x7191311F\n      mnemonic: shr @ 0x712D1B91, 0x712D1B97\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x71351D2A\n      match: contain loop @ 0x7191311B\n        or:\n          characteristic: loop @ 0x7191311B\n          characteristic: tight loop @ 0x71351DAD\n      optional:\n        number: 0xF @ 0x71351D77\nfunction @ 0x71915927\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x71213E23, and 17 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 7 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x71915927\n        or:\n          characteristic: loop @ 0x71915927\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127220C, 0x7127BC34, 0x7129C6E0, and 2 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x7192583F\n  or:\n    and:\n      mnemonic: shl @ 0x7121DC12, 0x712688E1, 0x7126894C, 0x7128664F, and 9 more...\n      mnemonic: shr @ 0x711B0166, 0x71268908, 0x7127BC34, 0x7135DCA8, and 3 more...\n      number: 0x3F = modulo 64 @ 0x719258BE\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x7192583F\n        or:\n          characteristic: loop @ 0x7192583F\n          characteristic: tight loop @ 0x71299A55, 0x71310730, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x71268943, 0x7127BC34\n        number: 0x4 @ 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x71925DE8\n  or:\n    and:\n      mnemonic: shl @ 0x711AEEA8, 0x711AEEAF, 0x711FF98F, 0x7121DC12, and 16 more...\n      mnemonic: shr @ 0x711AEE3D, 0x711B0166, 0x711B5AF2, 0x71270078, and 7 more...\n      number: 0x3F = modulo 64 @ 0x711B1119\n      or:\n        number: 0x3D = '=' @ 0x7192646F\n      match: contain loop @ 0x71925DE8\n        or:\n          characteristic: loop @ 0x71925DE8\n          characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n      optional:\n        number: 0x2 @ 0x711AEE37, 0x7127220C, 0x7127BC34, 0x7129C6E0, and 2 more...\n        number: 0x3 @ 0x712AC996\n        number: 0x4 @ 0x712A5B3F, 0x712DB6A8, 0x718EA90C\n        number: 0x6 @ 0x711B016C\nfunction @ 0x7193D2BE\n  or:\n    and:\n      mnemonic: shl @ 0x7193FA42, 0x71951A0F, 0x71955502, 0x7195B322, and 22 more...\n      mnemonic: shr @ 0x71951A12, 0x71991B98, 0x71A0ED8B, 0x71A37EDF, and 3 more...\n      number: 0x3F = modulo 64 @ 0x71A37F81\n      or:\n        number: 0x3D = '=' @ 0x71991D08\n      match: contain loop @ 0x7193D2BE\n        or:\n          characteristic: loop @ 0x7193D2BE\n          characteristic: tight loop @ 0x71939DDC, 0x71A37EDD, 0x71A72150, 0x71AB6FCC, and 1 more...\n      optional:\n        number: 0x2 @ 0x719B1A92, 0x719F300F, 0x71A0A884, 0x71A0A8CF, and 8 more...\n        number: 0x3 @ 0x71955752, 0x71955755, 0x719B62B4, 0x71A0A964, and 2 more...\n        number: 0x4 @ 0x71991B8E\n        number: 0x6 @ 0x71A88794\nfunction @ 0x7194F22E\n  or:\n    and:\n      mnemonic: shl @ 0x7193FA42, 0x71951A0F, 0x71955502, 0x7195B322, and 22 more...\n      mnemonic: shr @ 0x71951A12, 0x71991B98, 0x71A0ED8B, 0x71A37EDF, and 3 more...\n      number: 0x3F = modulo 64 @ 0x71A37F81\n      or:\n        number: 0x3D = '=' @ 0x71991D08\n      match: contain loop @ 0x7194F22E\n        or:\n          characteristic: loop @ 0x7194F22E\n          characteristic: tight loop @ 0x71939DDC, 0x71A37EDD, 0x71A72150, 0x71AB6FCC, and 1 more...\n      optional:\n        number: 0x2 @ 0x719B1A92, 0x719F300F, 0x71A0A884, 0x71A0A8CF, and 8 more...\n        number: 0x3 @ 0x71955752, 0x71955755, 0x719B62B4, 0x71A0A964, and 2 more...\n        number: 0x4 @ 0x71991B8E\n        number: 0x6 @ 0x71A88794\nfunction @ 0x719614AE\n  or:\n    and:\n      mnemonic: shl @ 0x7193FA42, 0x71951A0F, 0x71955502, 0x7195B322, and 22 more...\n      mnemonic: shr @ 0x71951A12, 0x71991B98, 0x71A0ED8B, 0x71A37EDF, and 4 more...\n      number: 0x3F = modulo 64 @ 0x71A37F81\n      or:\n        number: 0x3D = '=' @ 0x71991D08\n      match: contain loop @ 0x719614AE\n        or:\n          characteristic: loop @ 0x719614AE\n          characteristic: tight loop @ 0x71939DDC, 0x71A37EDD, 0x71A72150, 0x71AB6FCC, and 1 more...\n      optional:\n        number: 0x2 @ 0x719B1A92, 0x719F300F, 0x71A0A884, 0x71A0A8CF, and 8 more...\n        number: 0x3 @ 0x71955752, 0x71955755, 0x719B62B4, 0x71A0A964, and 2 more...\n        number: 0x4 @ 0x71991B8E\n        number: 0x6 @ 0x71A88794\nfunction @ 0x719830CF\n  or:\n    and:\n      mnemonic: shl @ 0x7193FA42, 0x71951A0F, 0x71955502, 0x7195B322, and 22 more...\n      mnemonic: shr @ 0x71951A12, 0x71991B98, 0x71A0ED8B, 0x71A37EDF, and 3 more...\n      number: 0x3F = modulo 64 @ 0x71A37F81\n      or:\n        number: 0x3D = '=' @ 0x71991D08\n      match: contain loop @ 0x719830CF\n        or:\n          characteristic: loop @ 0x719830CF\n          characteristic: tight loop @ 0x71939DDC, 0x71A37EDD, 0x71A72150, 0x71AB6FCC, and 1 more...\n      optional:\n        number: 0x2 @ 0x719B1A92, 0x719F300F, 0x71A0A884, 0x71A0A8CF, and 8 more...\n        number: 0x3 @ 0x71955752, 0x71955755, 0x719B62B4, 0x71A0A964, and 2 more...\n        number: 0x4 @ 0x71991B8E\n        number: 0x6 @ 0x71A88794\nfunction @ 0x7199FE4A\n  or:\n    and:\n      mnemonic: shl @ 0x7193FA42, 0x71951A0F, 0x71955502, 0x7195B322, and 23 more...\n      mnemonic: shr @ 0x71951A12, 0x71991B98, 0x7199FE8A, 0x71A0ED8B, and 4 more...\n      number: 0x3F = modulo 64 @ 0x71A37F81\n      or:\n        number: 0x3D = '=' @ 0x71991D08\n      match: contain loop @ 0x7199FE4A\n        or:\n          characteristic: loop @ 0x7199FE4A\n          characteristic: tight loop @ 0x71939DDC, 0x71A37EDD, 0x71A72150, 0x71AB6FCC, and 1 more...\n      optional:\n        number: 0x2 @ 0x719B1A92, 0x719F300F, 0x71A0A884, 0x71A0A8CF, and 8 more...\n        number: 0x3 @ 0x71955752, 0x71955755, 0x7199FE6C, 0x719B62B4, and 3 more...\n        number: 0x4 @ 0x71991B8E\n        number: 0x6 @ 0x71A88794\nfunction @ 0x719D1E64\n  or:\n    and:\n      mnemonic: shl @ 0x7193FA42, 0x71951A0F, 0x7195B322, 0x71991CCC, and 19 more...\n      mnemonic: shr @ 0x71951A12, 0x71991B98, 0x71A0ED8B, 0x71A58A0B, and 2 more...\n      number: 0x3F = modulo 64 @ 0x719A7C39\n      or:\n        number: 0x3D = '=' @ 0x71991D08\n      match: contain loop @ 0x719D1E64\n        or:\n          characteristic: loop @ 0x719D1E64\n          characteristic: tight loop @ 0x71939DDC, 0x71A72150, 0x71AB6FCC, 0x71AB6FFE\n      optional:\n        number: 0x2 @ 0x719B1A92, 0x719F300F, 0x71A0A884, 0x71A0A8CF, and 9 more...\n        number: 0x3 @ 0x71955752, 0x71955755, 0x719B62B4, 0x71A0A964, and 2 more...\n        number: 0x4 @ 0x71991B8E\nfunction @ 0x719DBB65\n  or:\n    and:\n      mnemonic: shl @ 0x7193FA42, 0x71951A0F, 0x71955502, 0x7195B322, and 22 more...\n      mnemonic: shr @ 0x71951A12, 0x71991B98, 0x71A0ED8B, 0x71A37EDF, and 3 more...\n      number: 0x3F = modulo 64 @ 0x71A37F81\n      or:\n        number: 0x3D = '=' @ 0x71991D08\n      match: contain loop @ 0x719DBB65\n        or:\n          characteristic: loop @ 0x719DBB65\n          characteristic: tight loop @ 0x71939DDC, 0x71A37EDD, 0x71A72150, 0x71AB6FCC, and 1 more...\n      optional:\n        number: 0x2 @ 0x719B1A92, 0x719F300F, 0x71A0A884, 0x71A0A8CF, and 8 more...\n        number: 0x3 @ 0x71955752, 0x71955755, 0x719B62B4, 0x71A0A964, and 2 more...\n        number: 0x4 @ 0x71991B8E\n        number: 0x6 @ 0x71A88794\nfunction @ 0x71A327C6\n  or:\n    and:\n      mnemonic: shl @ 0x7195B322, 0x7199FEF6, 0x719B1A88, 0x719BA2EA, and 4 more...\n      mnemonic: shr @ 0x7197EE5A, 0x71AC0BA5\n      number: 0x3F = modulo 64 @ 0x71A32877\n      or:\n        number: 0x3D = '=' @ 0x71A772AD\n      match: contain loop @ 0x71A327C6\n        or:\n          characteristic: loop @ 0x71A327C6\n          characteristic: tight loop @ 0x71A72150\n      optional:\n        number: 0x2 @ 0x719B1A92, 0x719F300F, 0x71AE5744\n        number: 0x3 @ 0x71955752, 0x71955755\nfunction @ 0x71A5B5A9\n  or:\n    and:\n      mnemonic: shl @ 0x71932134, 0x7193217C, 0x7193FA42, 0x71951A0F, and 67 more...\n      mnemonic: shr @ 0x7193DBDA, 0x7194E6D2, 0x71951A12, 0x71955402, and 43 more...\n      number: 0x3F = modulo 64 @ 0x71A37F81\n      or:\n        number: 0x3D = '=' @ 0x71991D08, 0x71A92F0F\n      match: contain loop @ 0x71A5B5A9\n        or:\n          characteristic: loop @ 0x71A5B5A9\n          characteristic: tight loop @ 0x71939DDC, 0x71A37EDD, 0x71A72150, 0x71AB6FCC, and 1 more...\n      optional:\n        number: 0x2 @ 0x719553C1, 0x719B1A92, 0x719F300F, 0x71A0A884, and 11 more...\n        number: 0x3 @ 0x71955752, 0x71955755, 0x719B62B4, 0x71A0A964, and 8 more...\n        number: 0x4 @ 0x7193217C, 0x7194A069, 0x7198BDDB, 0x71991B8E, and 10 more...\n        number: 0x6 @ 0x719BCD79, 0x71A155B1, 0x71A28591, 0x71A88794, and 1 more...\n        number: 0xF @ 0x71932171, 0x719F1767, 0x71ABCBFD\nfunction @ 0x71A687DC\n  or:\n    and:\n      mnemonic: shl @ 0x7193FA42, 0x71951A0F, 0x71955502, 0x7195B322, and 17 more...\n      mnemonic: shr @ 0x71951A12, 0x71991B98, 0x71A0ED8B, 0x71A37EDF, and 1 more...\n      number: 0x3F = modulo 64 @ 0x71A37F81\n      or:\n        number: 0x3D = '=' @ 0x71991D08\n      match: contain loop @ 0x71A687DC\n        or:\n          characteristic: loop @ 0x71A687DC\n          characteristic: tight loop @ 0x71939DDC, 0x71A37EDD\n      optional:\n        number: 0x2 @ 0x719B1A92, 0x719F300F, 0x71A0A884, 0x71A0A8CF, and 4 more...\n        number: 0x3 @ 0x71955752, 0x71955755, 0x719B62B4, 0x71A0A964, and 2 more...\n        number: 0x4 @ 0x71991B8E\nfunction @ 0x71A8BB73\n  or:\n    and:\n      mnemonic: shl @ 0x7193FA42, 0x71951A0F, 0x71955502, 0x7195B322, and 22 more...\n      mnemonic: shr @ 0x71951A12, 0x71991B98, 0x71A0ED8B, 0x71A37EDF, and 3 more...\n      number: 0x3F = modulo 64 @ 0x71A37F81\n      or:\n        number: 0x3D = '=' @ 0x71991D08\n      match: contain loop @ 0x71A8BB73\n        or:\n          characteristic: loop @ 0x71A8BB73\n          characteristic: tight loop @ 0x71939DDC, 0x71A37EDD, 0x71A72150, 0x71AB6FCC, and 1 more...\n      optional:\n        number: 0x2 @ 0x719B1A92, 0x719F300F, 0x71A0A884, 0x71A0A8CF, and 8 more...\n        number: 0x3 @ 0x71955752, 0x71955755, 0x719B62B4, 0x71A0A964, and 2 more...\n        number: 0x4 @ 0x71991B8E\n        number: 0x6 @ 0x71A88794\nfunction @ 0x71AB0D46\n  or:\n    and:\n      mnemonic: shl @ 0x71932134, 0x7193217C, 0x7193FA42, 0x71951A0F, and 67 more...\n      mnemonic: shr @ 0x7193DBDA, 0x7194E6D2, 0x71951A12, 0x71955402, and 44 more...\n      number: 0x3F = modulo 64 @ 0x71A37F81\n      or:\n        number: 0x3D = '=' @ 0x71991D08, 0x71A92F0F\n      match: contain loop @ 0x71AB0D46\n        or:\n          characteristic: loop @ 0x71AB0D46\n          characteristic: tight loop @ 0x71939DDC, 0x71A37EDD, 0x71A72150, 0x71AB6FCC, and 1 more...\n      optional:\n        number: 0x2 @ 0x719B1A92, 0x719F300F, 0x71A0A884, 0x71A0A8CF, and 10 more...\n        number: 0x3 @ 0x71955752, 0x71955755, 0x719B62B4, 0x71A0A964, and 9 more...\n        number: 0x4 @ 0x7193217C, 0x7194A069, 0x7198BDDB, 0x71991B8E, and 10 more...\n        number: 0x6 @ 0x719BCD79, 0x71A155B1, 0x71A28591, 0x71A88794, and 1 more...\n        number: 0xF @ 0x71932171, 0x719F1767, 0x71ABCBFD\nfunction @ 0x71AB78A8\n  or:\n    and:\n      mnemonic: shl @ 0x7193FA42, 0x71951A0F, 0x71955502, 0x7195B322, and 22 more...\n      mnemonic: shr @ 0x71951A12, 0x71991B98, 0x71A0ED8B, 0x71A37EDF, and 3 more...\n      number: 0x3F = modulo 64 @ 0x71A37F81\n      or:\n        number: 0x3D = '=' @ 0x71991D08\n      match: contain loop @ 0x71AB78A8\n        or:\n          characteristic: loop @ 0x71AB78A8\n          characteristic: tight loop @ 0x71939DDC, 0x71A37EDD, 0x71A72150, 0x71AB6FCC, and 1 more...\n      optional:\n        number: 0x2 @ 0x719B1A92, 0x719F300F, 0x71A0A884, 0x71A0A8CF, and 8 more...\n        number: 0x3 @ 0x71955752, 0x71955755, 0x719B62B4, 0x71A0A964, and 2 more...\n        number: 0x4 @ 0x71991B8E\n        number: 0x6 @ 0x71A88794\n\nencode data using XOR (959 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x70F39EA8 in function 0x70F399F0\n  and:\n    characteristic: tight loop @ 0x70F39EA8\n    characteristic: nzxor @ 0x70F39EB5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x711B3B36 in function 0x711B3B30\n  and:\n    characteristic: tight loop @ 0x711B3B36\n    characteristic: nzxor @ 0x711B3B36\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208011 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208011\n    characteristic: nzxor @ 0x7120802E, 0x71208032\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208011 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208011\n    characteristic: nzxor @ 0x7120802E, 0x71208032\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208011 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208011\n    characteristic: nzxor @ 0x7120802E, 0x71208032\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208011 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208011\n    characteristic: nzxor @ 0x7120802E, 0x71208032\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208011 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208011\n    characteristic: nzxor @ 0x7120802E, 0x71208032\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208011 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208011\n    characteristic: nzxor @ 0x7120802E, 0x71208032\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208011 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208011\n    characteristic: nzxor @ 0x7120802E, 0x71208032\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208011 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208011\n    characteristic: nzxor @ 0x7120802E, 0x71208032\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208011 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208011\n    characteristic: nzxor @ 0x7120802E, 0x71208032\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208011 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208011\n    characteristic: nzxor @ 0x7120802E, 0x71208032\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208095 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208095\n    characteristic: nzxor @ 0x71208095\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208095 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208095\n    characteristic: nzxor @ 0x71208095\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208095 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208095\n    characteristic: nzxor @ 0x71208095\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208095 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208095\n    characteristic: nzxor @ 0x71208095\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208095 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208095\n    characteristic: nzxor @ 0x71208095\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208095 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208095\n    characteristic: nzxor @ 0x71208095\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208095 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208095\n    characteristic: nzxor @ 0x71208095\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208095 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208095\n    characteristic: nzxor @ 0x71208095\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208095 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208095\n    characteristic: nzxor @ 0x71208095\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71208095 in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x71208095\n    characteristic: nzxor @ 0x71208095\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712080CF in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x712080CF\n    characteristic: nzxor @ 0x712080F0\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712080CF in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x712080CF\n    characteristic: nzxor @ 0x712080F0\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712080CF in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x712080CF\n    characteristic: nzxor @ 0x712080F0\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712080CF in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x712080CF\n    characteristic: nzxor @ 0x712080F0\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712080CF in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x712080CF\n    characteristic: nzxor @ 0x712080F0\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712080CF in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x712080CF\n    characteristic: nzxor @ 0x712080F0\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712080CF in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x712080CF\n    characteristic: nzxor @ 0x712080F0\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712080CF in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x712080CF\n    characteristic: nzxor @ 0x712080F0\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712080CF in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x712080CF\n    characteristic: nzxor @ 0x712080F0\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712080CF in function 0x718D16FA\n  and:\n    characteristic: tight loop @ 0x712080CF\n    characteristic: nzxor @ 0x712080F0\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71225CA9 in function 0x71902CA1\n  and:\n    characteristic: tight loop @ 0x71225CA9\n    characteristic: nzxor @ 0x71225CE4, 0x71225CF4\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71225CA9 in function 0x71902CA1\n  and:\n    characteristic: tight loop @ 0x71225CA9\n    characteristic: nzxor @ 0x71225CE4, 0x71225CF4\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71225CA9 in function 0x71902CA1\n  and:\n    characteristic: tight loop @ 0x71225CA9\n    characteristic: nzxor @ 0x71225CE4, 0x71225CF4\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71225CA9 in function 0x71902CA1\n  and:\n    characteristic: tight loop @ 0x71225CA9\n    characteristic: nzxor @ 0x71225CE4, 0x71225CF4\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71225CA9 in function 0x71902CA1\n  and:\n    characteristic: tight loop @ 0x71225CA9\n    characteristic: nzxor @ 0x71225CE4, 0x71225CF4\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71225CA9 in function 0x71902CA1\n  and:\n    characteristic: tight loop @ 0x71225CA9\n    characteristic: nzxor @ 0x71225CE4, 0x71225CF4\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71225CA9 in function 0x71902CA1\n  and:\n    characteristic: tight loop @ 0x71225CA9\n    characteristic: nzxor @ 0x71225CE4, 0x71225CF4\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71225CA9 in function 0x71902CA1\n  and:\n    characteristic: tight loop @ 0x71225CA9\n    characteristic: nzxor @ 0x71225CE4, 0x71225CF4\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71225CA9 in function 0x71902CA1\n  and:\n    characteristic: tight loop @ 0x71225CA9\n    characteristic: nzxor @ 0x71225CE4, 0x71225CF4\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71225CA9 in function 0x71902CA1\n  and:\n    characteristic: tight loop @ 0x71225CA9\n    characteristic: nzxor @ 0x71225CE4, 0x71225CF4\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71233808 in function 0x718B894D\n  and:\n    characteristic: tight loop @ 0x71233808\n    characteristic: nzxor @ 0x71233809\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71233808 in function 0x718B894D\n  and:\n    characteristic: tight loop @ 0x71233808\n    characteristic: nzxor @ 0x71233809\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712367CB in function 0x7123672A\n  and:\n    characteristic: tight loop @ 0x712367CB\n    characteristic: nzxor @ 0x712367D6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712367CB in function 0x7123672A\n  and:\n    characteristic: tight loop @ 0x712367CB\n    characteristic: nzxor @ 0x712367D6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712367CB in function 0x7123672A\n  and:\n    characteristic: tight loop @ 0x712367CB\n    characteristic: nzxor @ 0x712367D6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71252A89 in function 0x712529D4\n  and:\n    characteristic: tight loop @ 0x71252A89\n    characteristic: nzxor @ 0x71252A89\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71252BC2 in function 0x712529D4\n  and:\n    characteristic: tight loop @ 0x71252BC2\n    characteristic: nzxor @ 0x71252BC8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x7125F8A8 in function 0x712DAAD4\n  and:\n    characteristic: tight loop @ 0x7125F8A8\n    characteristic: nzxor @ 0x7125F8B9\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712BB53F in function 0x712BB420\n  and:\n    characteristic: tight loop @ 0x712BB53F\n    characteristic: nzxor @ 0x712BB53F\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712BB53F in function 0x712BB420\n  and:\n    characteristic: tight loop @ 0x712BB53F\n    characteristic: nzxor @ 0x712BB53F\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712E1AA7 in function 0x71901244\n  and:\n    characteristic: tight loop @ 0x712E1AA7\n    characteristic: nzxor @ 0x712E1AB1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712F4D3F in function 0x718EAB62\n  and:\n    characteristic: tight loop @ 0x712F4D3F\n    characteristic: nzxor @ 0x712F4D44\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x712F4D3F in function 0x718EAB62\n  and:\n    characteristic: tight loop @ 0x712F4D3F\n    characteristic: nzxor @ 0x712F4D44\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71303B4C in function 0x7134667C\n  and:\n    characteristic: tight loop @ 0x71303B4C\n    characteristic: nzxor @ 0x71303B54\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71310730 in function 0x71926532\n  and:\n    characteristic: tight loop @ 0x71310730\n    characteristic: nzxor @ 0x7131074B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x713280B7 in function 0x718DE7DA\n  and:\n    characteristic: tight loop @ 0x713280B7\n    characteristic: nzxor @ 0x713280BE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x7133B4F2 in function 0x7129675E\n  and:\n    characteristic: tight loop @ 0x7133B4F2\n    characteristic: nzxor @ 0x7133B4F4\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x7133FDA3 in function 0x7133FD87\n  and:\n    characteristic: tight loop @ 0x7133FDA3\n    characteristic: nzxor @ 0x7133FDA5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71359A90 in function 0x71359A82\n  and:\n    characteristic: tight loop @ 0x71359A90\n    characteristic: nzxor @ 0x71359A96, 0x71359AB1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71359A90 in function 0x71359A82\n  and:\n    characteristic: tight loop @ 0x71359A90\n    characteristic: nzxor @ 0x71359A96, 0x71359AB1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x718CCFD3 in function 0x718CCEC2\n  and:\n    characteristic: tight loop @ 0x718CCFD3\n    characteristic: nzxor @ 0x718CCFDA\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x718CFA94 in function 0x718CFA92\n  and:\n    characteristic: tight loop @ 0x718CFA94\n    characteristic: nzxor @ 0x718CFAA1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x718CFA94 in function 0x718CFA92\n  and:\n    characteristic: tight loop @ 0x718CFA94\n    characteristic: nzxor @ 0x718CFAA1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x718D6539 in function 0x718D653C\n  and:\n    characteristic: tight loop @ 0x718D6539\n    characteristic: nzxor @ 0x718D6589\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x718D6539 in function 0x718D653C\n  and:\n    characteristic: tight loop @ 0x718D6539\n    characteristic: nzxor @ 0x718D6589\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x718DEC8C in function 0x718DEC82\n  and:\n    characteristic: tight loop @ 0x718DEC8C\n    characteristic: nzxor @ 0x718DEC96\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x718DEC8C in function 0x718DEC82\n  and:\n    characteristic: tight loop @ 0x718DEC8C\n    characteristic: nzxor @ 0x718DEC96\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x718DEC8C in function 0x718DEC82\n  and:\n    characteristic: tight loop @ 0x718DEC8C\n    characteristic: nzxor @ 0x718DEC96\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x718FA3C2 in function 0x718FA379\n  and:\n    characteristic: tight loop @ 0x718FA3C2\n    characteristic: nzxor @ 0x718FA3C2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x7190B40C in function 0x713517DD\n  and:\n    characteristic: tight loop @ 0x7190B40C\n    characteristic: nzxor @ 0x7190B40E\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71912749 in function 0x71912653\n  and:\n    characteristic: tight loop @ 0x71912749\n    characteristic: nzxor @ 0x71912761\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x719503DB in function 0x71957D5B\n  and:\n    characteristic: tight loop @ 0x719503DB\n    characteristic: nzxor @ 0x7195040E\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71950438 in function 0x71957D5B\n  and:\n    characteristic: tight loop @ 0x71950438\n    characteristic: nzxor @ 0x7195044B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x7197A49E in function 0x719CB240\n  and:\n    characteristic: tight loop @ 0x7197A49E\n    characteristic: nzxor @ 0x7197A4B1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x719BD5BD in function 0x71A69E41\n  and:\n    characteristic: tight loop @ 0x719BD5BD\n    characteristic: nzxor @ 0x719BD5F8, 0x719BD607\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x719BD5BD in function 0x71A69E41\n  and:\n    characteristic: tight loop @ 0x719BD5BD\n    characteristic: nzxor @ 0x719BD5F8, 0x719BD607\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A42155 in function 0x71A42140\n  and:\n    characteristic: tight loop @ 0x71A42155\n    characteristic: nzxor @ 0x71A4215F, 0x71A4216F\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72150 in function 0x71AFF3AA\n  and:\n    characteristic: tight loop @ 0x71A72150\n    characteristic: nzxor @ 0x71A72165\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72EFF in function 0x71AC2ADD\n  and:\n    characteristic: tight loop @ 0x71A72EFF\n    characteristic: nzxor @ 0x71A72F06\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A72EFF in function 0x71AC2ADD\n  and:\n    characteristic: tight loop @ 0x71A72EFF\n    characteristic: nzxor @ 0x71A72F06\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A822A9 in function 0x71AB184A\n  and:\n    characteristic: tight loop @ 0x71A822A9\n    characteristic: nzxor @ 0x71A822A9\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A822A9 in function 0x71AB184A\n  and:\n    characteristic: tight loop @ 0x71A822A9\n    characteristic: nzxor @ 0x71A822A9\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A822A9 in function 0x71AB184A\n  and:\n    characteristic: tight loop @ 0x71A822A9\n    characteristic: nzxor @ 0x71A822A9\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A8B4DE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71A8B4DE\n    characteristic: nzxor @ 0x71A8B4F9\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A8B4DE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71A8B4DE\n    characteristic: nzxor @ 0x71A8B4F9\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A8B4DE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71A8B4DE\n    characteristic: nzxor @ 0x71A8B4F9\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A8B4DE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71A8B4DE\n    characteristic: nzxor @ 0x71A8B4F9\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A8B4DE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71A8B4DE\n    characteristic: nzxor @ 0x71A8B4F9\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71A8FF68 in function 0x7199D150\n  and:\n    characteristic: tight loop @ 0x71A8FF68\n    characteristic: nzxor @ 0x71A8FF6C\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AA14F2 in function 0x71AA14C6\n  and:\n    characteristic: tight loop @ 0x71AA14F2\n    characteristic: nzxor @ 0x71AA150A\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB6FFE in function 0x71AF2280\n  and:\n    characteristic: tight loop @ 0x71AB6FFE\n    characteristic: nzxor @ 0x71AB6FFE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB81B9 in function 0x71AC037C\n  and:\n    characteristic: tight loop @ 0x71AB81B9\n    characteristic: nzxor @ 0x71AB81BE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AB81B9 in function 0x71AC037C\n  and:\n    characteristic: tight loop @ 0x71AB81B9\n    characteristic: nzxor @ 0x71AB81BE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AC4A0B in function 0x71AC49AB\n  and:\n    characteristic: tight loop @ 0x71AC4A0B\n    characteristic: nzxor @ 0x71AC4A22\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AD9E8D in function 0x719BEE1C\n  and:\n    characteristic: tight loop @ 0x71AD9E8D\n    characteristic: nzxor @ 0x71AD9E9B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AEA76C in function 0x71A06A63\n  and:\n    characteristic: tight loop @ 0x71AEA76C\n    characteristic: nzxor @ 0x71AEA779\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AF2FB9 in function 0x71ADA930\n  and:\n    characteristic: tight loop @ 0x71AF2FB9\n    characteristic: nzxor @ 0x71AF2FC2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x71AF2FB9 in function 0x71ADA930\n  and:\n    characteristic: tight loop @ 0x71AF2FB9\n    characteristic: nzxor @ 0x71AF2FC2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nencrypt data using RC4 KSA (24 matches)\nnamespace  data-manipulation/encryption/rc4                                     \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Encrypt Data::RC4 [C0027.009], Cryptography::Encryption\n           Key::RC4 KSA [C0028.002]                                             \nfunction @ 0x711B2290\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x711B22A0\n          or:\n            number: 0x100 @ 0x711B22A4\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x711B22E6, 0x711B2317, 0x711B2351, 0x711B238B\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x711B2351\n            or:\n              number: 0xFF @ 0x711B2351\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x711B238B\n            or:\n              number: 0xFF @ 0x711B238B\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x711B22E6\n            or:\n              number: 0xFF @ 0x711B22E6\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x711B2317\n            or:\n              number: 0xFF @ 0x711B2317\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x711B22DB, 0x711B22DE\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x711B237C, 0x711B2380\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x711B2324, 0x711B232A\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x711B2342, 0x711B2346\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x711B2398, 0x711B239E\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x711B2308, 0x711B230C\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x711B235E, 0x711B2364\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x711B22D5, 0x711B2302, 0x711B233C, 0x711B2376\nfunction @ 0x7193D2BE\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x7194F22E\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x719536E2\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x7195371D\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A13458, 0x71A67D82, 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A13458\n            or:\n              number: 0xFF @ 0x71A13458\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A67D82\n            or:\n              number: 0xFF @ 0x71A67D82\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A443B9, 0x71A443CD\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x71A12A15, 0x71AADCBF\nfunction @ 0x719614AE\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A70568, 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A70568\n            or:\n              number: 0xFF @ 0x71A70568\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x7196BE5C\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x719830CF\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71983102, 0x71983105, 0x71983115, 0x7198311D\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x7199FE4A\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x719D1E64\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x719DBB65\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x719F1BEA\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x719FA205\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x719A9567, 0x71A13458, 0x71A67D82, 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A13458\n            or:\n              number: 0xFF @ 0x71A13458\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A67D82\n            or:\n              number: 0xFF @ 0x71A67D82\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x719A9567\n            or:\n              number: 0xFF @ 0x719A9567\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A443B9, 0x71A443CD\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x71A12A15, 0x71A187E4, 0x71A4B975, 0x71AADCBF\n        mnemonic: idiv @ 0x71A7CE54\nfunction @ 0x71A44304\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A13458, 0x71A67D82, 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A13458\n            or:\n              number: 0xFF @ 0x71A13458\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A67D82\n            or:\n              number: 0xFF @ 0x71A67D82\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A443B9, 0x71A443CD\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x71A12A15, 0x71AADCBF\nfunction @ 0x71A4643A\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x71A5B5A9\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198BDC3, 0x7198BDCC\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A17C43, 0x71A17C5A\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A5E8C5, 0x71A5E8CE\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AE3250, 0x71AE3253\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A6E713, 0x71A6E726\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x719553DF, 0x719553EC\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A163DC, 0x71A163E6\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A92F1D, 0x71A92F37\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A52564, 0x71A52575\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x719FD06C, 0x719FD074\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A5B5C7, 0x71A5B5CB\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A01642, 0x71A0164D\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x71A68F00\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\n        mnemonic: idiv @ 0x71A68F83\nfunction @ 0x71A6DEC2\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x71A8A20F\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A67D82, 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A67D82\n            or:\n              number: 0xFF @ 0x71A67D82\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A443B9, 0x71A443CD\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x71A12A15, 0x71AADCBF\nfunction @ 0x71A8BB73\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x71AB0D46\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198BDC3, 0x7198BDCC\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A17C43, 0x71A17C5A\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A52564, 0x71A52575\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x719FD06C, 0x719FD074\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A5E8C5, 0x71A5E8CE\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AE3250, 0x71AE3253\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A6E713, 0x71A6E726\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x719553DF, 0x719553EC\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A163DC, 0x71A163E6\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A92F1D, 0x71A92F37\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A01642, 0x71A0164D\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x71AB78A8\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x71AD4366\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71AAA4E1, 0x71AAA519, 0x71AAA530\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A0ED6A, 0x71A0ED91\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x7198A4EB, 0x7198A4F8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x719BA36A, 0x71A12A15, 0x71A187E4, 0x71AADCBF\nfunction @ 0x71AF2280\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x71AB6FCC\n          or:\n            number: 0xFF @ 0x71AB6FCC\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x719A9567, 0x71A13458, 0x71A67D82, 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A13458\n            or:\n              number: 0xFF @ 0x71A13458\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A67D82\n            or:\n              number: 0xFF @ 0x71A67D82\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x71A96B6C\n            or:\n              number: 0xFF @ 0x71A96B6C\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x719A9567\n            or:\n              number: 0xFF @ 0x719A9567\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A1BEB4, 0x71A1BEBF\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x71A443B9, 0x71A443CD\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x71A12A15, 0x71AADCBF\n\nencrypt data using RC4 PRGA\nnamespace  data-manipulation/encryption/rc4                                     \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Encrypt Data::RC4 [C0027.009], Cryptography::Generate  \n           Pseudo-random Sequence::RC4 PRGA [C0021.004]                         \nfunction @ 0x711B23D0\n  and:\n    match: contain loop @ 0x711B23D0\n      or:\n        characteristic: loop @ 0x711B23D0\n    count(characteristic(nzxor)): 1 @ 0x711B245C\n    count(characteristic(calls from)): 4 or fewer @ 0x711C4950\n    count(basic block): between 4 and 50 @ 0x711B23D0, 0x711B23FA, 0x711B2400, 0x711B242B, and 5 more...\n    or:\n      match: calculate modulo 256 via x86 assembly @ 0x711B2401, 0x711B2418, 0x711B2447\n        and:\n          or:\n            arch: i386\n          mnemonic: and @ 0x711B2418\n          or:\n            number: 0xFF @ 0x711B2418\n        and:\n          or:\n            arch: i386\n          mnemonic: and @ 0x711B2401\n          or:\n            number: 0xFF @ 0x711B2401\n        and:\n          or:\n            arch: i386\n          mnemonic: and @ 0x711B2447\n          or:\n            number: 0x800000FF @ 0x711B2447\n      count(mnemonic(movzx)): 4 or more @ 0x711B2407, 0x711B242B, 0x711B2431, 0x711B2436, and 2 more...\n    optional:\n      or:\n        number: 0xFF @ 0x711B2401, 0x711B2418\n        number: 0x100 @ 0x711B23DA\n\nauthenticate HMAC (92 matches)\nnamespace   data-manipulation/hmac                                              \nauthor      moritz.raabe@mandiant.com                                           \nscope       function                                                            \nmbc         Cryptography::Hashed Message Authentication Code [C0061]            \nreferences  https://tools.ietf.org/html/rfc2104,                                \n            https://tools.ietf.org/html/rfc4634, https://github.com/ogay/hmac   \nfunction @ 0x711B022F\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711B022F\n      or:\n        characteristic: loop @ 0x711B022F\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x711B02B0, and 50 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711B0540\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711B0540\n      or:\n        characteristic: loop @ 0x711B0540\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x71241F8D, 0x71241F92, 0x71241F94, 0x71241FA4, and 24 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711B0FE0\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711B0FE0\n      or:\n        characteristic: loop @ 0x711B0FE0\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 55 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4, 0x713498C7\nfunction @ 0x711BF830\n  and:\n    number: 0x36 = inner padding byte value @ 0x7120C6C9\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711BF830\n      or:\n        characteristic: loop @ 0x711BF830\n        characteristic: tight loop @ 0x7120C6B7, 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711B59C1, 0x711B59C9, 0x711BF8CB, 0x711BF8F4, and 53 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4, 0x712E00C1\nfunction @ 0x711CFEC0\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711CFEC0\n      or:\n        characteristic: loop @ 0x711CFEC0\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711CFEE0\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711CFEE0\n      or:\n        characteristic: loop @ 0x711CFEE0\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711CFF20\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711CFF20\n      or:\n        characteristic: loop @ 0x711CFF20\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711CFF40\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711CFF40\n      or:\n        characteristic: loop @ 0x711CFF40\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711CFF90\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711CFF90\n      or:\n        characteristic: loop @ 0x711CFF90\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0000\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0000\n      or:\n        characteristic: loop @ 0x711D0000\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0050\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0050\n      or:\n        characteristic: loop @ 0x711D0050\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0070\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0070\n      or:\n        characteristic: loop @ 0x711D0070\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0090\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0090\n      or:\n        characteristic: loop @ 0x711D0090\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0100\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0100\n      or:\n        characteristic: loop @ 0x711D0100\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0120\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0120\n      or:\n        characteristic: loop @ 0x711D0120\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0270\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0270\n      or:\n        characteristic: loop @ 0x711D0270\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0290\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0290\n      or:\n        characteristic: loop @ 0x711D0290\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D02D0\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D02D0\n      or:\n        characteristic: loop @ 0x711D02D0\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0310\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0310\n      or:\n        characteristic: loop @ 0x711D0310\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 32 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0350\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0350\n      or:\n        characteristic: loop @ 0x711D0350\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 32 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D03A0\n  and:\n    number: 0x36 = inner padding byte value @ 0x7120C6C9, 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D03A0\n      or:\n        characteristic: loop @ 0x711D03A0\n        characteristic: tight loop @ 0x7120C6B7, 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x711B59C1, and 62 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4, 0x712E00C1\nfunction @ 0x711D03C0\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D03C0\n      or:\n        characteristic: loop @ 0x711D03C0\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D03E0\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D03E0\n      or:\n        characteristic: loop @ 0x711D03E0\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0400\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0400\n      or:\n        characteristic: loop @ 0x711D0400\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0420\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0420\n      or:\n        characteristic: loop @ 0x711D0420\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0448\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0448\n      or:\n        characteristic: loop @ 0x711D0448\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0460\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0460\n      or:\n        characteristic: loop @ 0x711D0460\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0480\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0480\n      or:\n        characteristic: loop @ 0x711D0480\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D04A0\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D04A0\n      or:\n        characteristic: loop @ 0x711D04A0\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D04C0\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D04C0\n      or:\n        characteristic: loop @ 0x711D04C0\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D04E0\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D04E0\n      or:\n        characteristic: loop @ 0x711D04E0\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0500\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0500\n      or:\n        characteristic: loop @ 0x711D0500\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0520\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0520\n      or:\n        characteristic: loop @ 0x711D0520\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0540\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0540\n      or:\n        characteristic: loop @ 0x711D0540\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0560\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0560\n      or:\n        characteristic: loop @ 0x711D0560\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0580\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0580\n      or:\n        characteristic: loop @ 0x711D0580\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D05A8\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D05A8\n      or:\n        characteristic: loop @ 0x711D05A8\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D05C0\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D05C0\n      or:\n        characteristic: loop @ 0x711D05C0\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0660\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0660\n      or:\n        characteristic: loop @ 0x711D0660\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D0680\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D0680\n      or:\n        characteristic: loop @ 0x711D0680\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x711D06F0\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x711D06F0\n      or:\n        characteristic: loop @ 0x711D06F0\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71232B4F, and 36 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x71208C32\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x71208C32\n      or:\n        characteristic: loop @ 0x71208C32\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 32 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x71219AE6\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3, 0x71334F30\n    match: contain loop @ 0x71219AE6\n      or:\n        characteristic: loop @ 0x71219AE6\n        characteristic: tight loop @ 0x71219BC5, 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71219AF1, and 47 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x7121D494\n  and:\n    number: 0x36 = inner padding byte value @ 0x7120C6C9\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x7121D494\n      or:\n        characteristic: loop @ 0x7121D494\n        characteristic: tight loop @ 0x7120C6B7, 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x711B59C1, and 37 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x712242F1\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3, 0x712080A8\n    match: contain loop @ 0x712242F1\n      or:\n        characteristic: loop @ 0x712242F1\n        characteristic: tight loop @ 0x71208011, 0x71208095, 0x712080CF, 0x71299A55, and 1 more...\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x7120802E, and 41 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x712327F2\n  and:\n    number: 0x36 = inner padding byte value @ 0x712A04BA\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x712327F2\n      or:\n        characteristic: loop @ 0x712327F2\n        characteristic: tight loop @ 0x71299A55, 0x712B3043, 0x71310730, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x71241F8D, 0x71241F92, 0x71241F94, 0x71241FA4, and 23 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x71240F77\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x71240F77\n      or:\n        characteristic: loop @ 0x71240F77\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71240F7F, and 33 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x71248A5B\n  and:\n    number: 0x36 = inner padding byte value @ 0x71248AFD\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x71248A5B\n      or:\n        characteristic: loop @ 0x71248A5B\n        characteristic: tight loop @ 0x71248A63, 0x71248B83, 0x71299A55, 0x71310730, and 1 more...\n    count(characteristic(nzxor)): 2 or more @ 0x7122FFA9, 0x7122FFAB, 0x7122FFAD, 0x7123002F, and 43 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x71266D19\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3, 0x71347CCE\n    match: contain loop @ 0x71266D19\n      or:\n        characteristic: loop @ 0x71266D19\n        characteristic: tight loop @ 0x71299A55, 0x71347D01, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 46 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x71272187\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x71272187\n      or:\n        characteristic: loop @ 0x71272187\n        characteristic: tight loop @ 0x71299A55, 0x712F8070, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 47 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x7127A1D9\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x7127A1D9\n      or:\n        characteristic: loop @ 0x7127A1D9\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 44 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x7128DD71\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x7128DD71\n      or:\n        characteristic: loop @ 0x7128DD71\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x711FFC79, and 34 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x71292C5B\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x71292C5B\n      or:\n        characteristic: loop @ 0x71292C5B\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 32 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x712A0438\n  and:\n    number: 0x36 = inner padding byte value @ 0x712A04BA\n    number: 0x5C = outer padding byte value @ 0x711B10F3, 0x712080A8\n    match: contain loop @ 0x712A0438\n      or:\n        characteristic: loop @ 0x712A0438\n        characteristic: tight loop @ 0x71208011, 0x71208095, 0x712080CF, 0x71299A55, and 2 more...\n    count(characteristic(nzxor)): 2 or more @ 0x7120802E, 0x71208032, 0x71208095, 0x712080F0, and 24 more...\nfunction @ 0x712A215C\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x712A215C\n      or:\n        characteristic: loop @ 0x712A215C\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 39 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x712D059F\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x712D059F\n      or:\n        characteristic: loop @ 0x712D059F\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 43 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x712DE086\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x712DE086\n      or:\n        characteristic: loop @ 0x712DE086\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA, 0x718BE7FC, 0x718F15A4, and 1 more...\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 57 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x712E5DF2\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3, 0x71334F30\n    match: contain loop @ 0x712E5DF2\n      or:\n        characteristic: loop @ 0x712E5DF2\n        characteristic: tight loop @ 0x71219BC5, 0x712435C0, 0x71299A55, 0x712E5F67, and 1 more...\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71219B34, and 48 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x712EFFFF\n  and:\n    number: 0x36 = inner padding byte value @ 0x712A04BA, 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x712EFFFF\n      or:\n        characteristic: loop @ 0x712EFFFF\n        characteristic: tight loop @ 0x71299A55, 0x712B3043, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 55 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x712F0C17\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x712F0C17\n      or:\n        characteristic: loop @ 0x712F0C17\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 47 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x712F8769\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x712F8769\n      or:\n        characteristic: loop @ 0x712F8769\n        characteristic: tight loop @ 0x71225CA9, 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71225BCB, and 47 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x712FEC19\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x712FEC19\n      or:\n        characteristic: loop @ 0x712FEC19\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 44 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x713021E7\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x713021E7\n      or:\n        characteristic: loop @ 0x713021E7\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 35 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x7130A246\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x7130A246\n      or:\n        characteristic: loop @ 0x7130A246\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 32 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x713114DF\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x713114DF\n      or:\n        characteristic: loop @ 0x713114DF\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x71241F8D, 0x71241F92, 0x71241F94, 0x71241FA4, and 25 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x7131CDA4\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x7131CDA4\n      or:\n        characteristic: loop @ 0x7131CDA4\n        characteristic: tight loop @ 0x71299A55, 0x71351DAD, 0x7135DCAA, 0x7191309A\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 48 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4, 0x718E2785\nfunction @ 0x7131FA67\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x7131FA67\n      or:\n        characteristic: loop @ 0x7131FA67\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x712353C1, and 33 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x71320D95\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x71320D95\n      or:\n        characteristic: loop @ 0x71320D95\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x71241F8D, 0x71241F92, 0x71241F94, 0x71241FA4, and 24 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x71332F4D\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x71332F4D\n      or:\n        characteristic: loop @ 0x71332F4D\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x71241F8D, 0x71241F92, 0x71241F94, 0x71241FA4, and 26 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x71334DB8\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x71334DB8\n      or:\n        characteristic: loop @ 0x71334DB8\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 44 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x71341096\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x71341096\n      or:\n        characteristic: loop @ 0x71341096\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 44 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x71342CCA\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x71342CCA\n      or:\n        characteristic: loop @ 0x71342CCA\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x71241F8D, 0x71241F92, 0x71241F94, 0x71241FA4, and 32 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x713458D1\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x713458D1\n      or:\n        characteristic: loop @ 0x713458D1\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 44 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x7134C509\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x7134C509\n      or:\n        characteristic: loop @ 0x7134C509\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 65 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x7134E624\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x7134E624\n      or:\n        characteristic: loop @ 0x7134E624\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 32 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x71353FC7\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x71353FC7\n      or:\n        characteristic: loop @ 0x71353FC7\n        characteristic: tight loop @ 0x71299A55, 0x7134D09B, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x71241F8D, 0x71241F92, 0x71241F94, 0x71241FA4, and 28 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x718BB4D8\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x718BB4D8\n      or:\n        characteristic: loop @ 0x718BB4D8\n        characteristic: tight loop @ 0x71299A55, 0x7134B97A, 0x7135DCAA\n        characteristic: recursive call @ 0x718BB4D8\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71238353, and 79 more...\n    optional: = block size\n      number: 0x40 = MD5, SHA-1, SHA-224, or SHA-256 @ 0x7134BA12\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x718BFB8B\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x718BFB8B\n      or:\n        characteristic: loop @ 0x718BFB8B\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 44 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x718C5A00\n  and:\n    number: 0x36 = inner padding byte value @ 0x7120C6C9, 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x718C5A00\n      or:\n        characteristic: loop @ 0x718C5A00\n        characteristic: tight loop @ 0x7120C6B7, 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x711B59C1, and 42 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x718CFBFB\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x718CFBFB\n      or:\n        characteristic: loop @ 0x718CFBFB\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 33 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x718D1964\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x718D1964\n      or:\n        characteristic: loop @ 0x718D1964\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 34 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x718E2FE8\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x718E2FE8\n      or:\n        characteristic: loop @ 0x718E2FE8\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 34 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x718F2B4C\n  and:\n    number: 0x36 = inner padding byte value @ 0x712A04BA, 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x718F2B4C\n      or:\n        characteristic: loop @ 0x718F2B4C\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 46 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x718F80F5\n  and:\n    number: 0x36 = inner padding byte value @ 0x712A04BA, 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x718F80F5\n      or:\n        characteristic: loop @ 0x718F80F5\n        characteristic: tight loop @ 0x71299A55, 0x712B3043, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 49 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x718F9DB2\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x718F9DB2\n      or:\n        characteristic: loop @ 0x718F9DB2\n        characteristic: tight loop @ 0x71299A55, 0x7134B97A, 0x7135DCAA, 0x71909077\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71238353, and 88 more...\n    optional: = block size\n      number: 0x40 = MD5, SHA-1, SHA-224, or SHA-256 @ 0x7134BA12\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x7190F048\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x7190F048\n      or:\n        characteristic: loop @ 0x7190F048\n        characteristic: tight loop @ 0x71299A55, 0x71349022, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x711C1EE0, and 68 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x7191305C\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x7191305C\n      or:\n        characteristic: loop @ 0x7191305C\n        characteristic: tight loop @ 0x71299A55, 0x71351DAD, 0x7135DCAA, 0x7191309A\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 48 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4, 0x718E2785\nfunction @ 0x71915927\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x71915927\n      or:\n        characteristic: loop @ 0x71915927\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 44 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x719240EF\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x719240EF\n      or:\n        characteristic: loop @ 0x719240EF\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 32 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x71925DE8\n  and:\n    number: 0x36 = inner padding byte value @ 0x7191D431\n    number: 0x5C = outer padding byte value @ 0x711B10F3\n    match: contain loop @ 0x71925DE8\n      or:\n        characteristic: loop @ 0x71925DE8\n        characteristic: tight loop @ 0x71299A55, 0x7135DCAA\n    count(characteristic(nzxor)): 2 or more @ 0x711AEDB4, 0x711AEDBB, 0x711AEDCE, 0x71241F8D, and 44 more...\n    optional: = block size\n      number: 0x80 = SHA-384 or SHA-512 @ 0x71241FD4\nfunction @ 0x719BDC70\n  and:\n    number: 0x36 = inner padding byte value @ 0x719FF17C\n    number: 0x5C = outer padding byte value @ 0x719378D6\n    match: contain loop @ 0x719BDC70\n      or:\n        characteristic: loop @ 0x719BDC70\n        characteristic: tight loop @ 0x71A72150\n    count(characteristic(nzxor)): 2 or more @ 0x71932139, 0x7193213E, 0x719378D3, 0x7193DBBC, and 12 more...\n    optional: = block size\n      number: 0x40 = MD5, SHA-1, SHA-224, or SHA-256 @ 0x7194A066\n      number: 0x80 = SHA-384 or SHA-512 @ 0x719BCD67\nfunction @ 0x71A2715C\n  and:\n    number: 0x36 = inner padding byte value @ 0x719FF17C\n    number: 0x5C = outer padding byte value @ 0x71AC7575\n    match: contain loop @ 0x71A2715C\n      or:\n        characteristic: loop @ 0x71A2715C\n        characteristic: tight loop @ 0x71A72150, 0x71AAEB1C\n    count(characteristic(nzxor)): 2 or more @ 0x71932139, 0x7193213E, 0x7193DBBC, 0x7193FA28, and 25 more...\n    optional: = block size\n      number: 0x40 = MD5, SHA-1, SHA-224, or SHA-256 @ 0x7194A066\n      number: 0x80 = SHA-384 or SHA-512 @ 0x719BCD67\n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls   \nauthor     michael.hunhoff@mandiant.com\nscope      file                        \nsection: .tls @ 0x711AA000\n\n(internal) packer file limitation\nnamespace    internal/limitation/static                                         \nauthor       william.ballenthin@mandiant.com                                    \nscope        file                                                               \ndescription  This sample appears to be packed.                                  \n                                                                                \n             Packed samples have often been obfuscated to hide their logic.     \n             capa cannot handle obfuscation well using static analysis. This    \n             means the results may be misleading or incomplete.                 \n             If possible, you should try to unpack this input file before       \n             analyzing it with capa.                                            \n             Alternatively, run the sample in a supported sandbox and invoke    \n             capa against the report to obtain dynamic analysis results.        \n                                                                                \nor:\n  match: anti-analysis/packer @ 0x711AED60, 0x711B0540, 0x711B0FE0, 0x711CFEC0, and 80 more...\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x712F0C3E, 0x71317A7F, and 1 more...\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB, and 1 more...\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x7127D537\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB, and 2 more...\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB, and 1 more...\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x718B3DC3\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x7126C601, 0x71317A7F, and 3 more...\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x70F3D389, 0x711B5B0D, 0x7132DA7A, 0x718DEAFD\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x712AA8E9, 0x71317A7F, and 1 more...\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x719143C0\n      or:\n        mnemonic: popad @ 0x71229957\n    and:\n      characteristic: cross section flow @ 0x70F3D389, 0x711B5B0D, 0x7132DA7A, 0x718DEAFD\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x712AA8E9, 0x71317A7F, and 1 more...\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB, and 1 more...\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x7124F9A6, 0x71317A7F, and 1 more...\n    and:\n      characteristic: cross section flow @ 0x711B5B0D, 0x7132DA7A\n      not:\n        match: contain pusha popa sequence\n      or:\n        mnemonic: pushad @ 0x71317B1B\n      or:\n        mnemonic: popad @ 0x71241FCC, 0x71241FFE, 0x71317A7F, 0x71317AEB\n\nparse PE header (32 matches)\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x70F37E80\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x70F37E82, 0x70F37E93, 0x70F37EB0, 0x70F37EE3, and 2 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x70F37E93\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x70F37E82\nfunction @ 0x70F37F00\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x70F37F02, 0x70F37F13, 0x70F37F20\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x70F37F13\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x70F37F02\nfunction @ 0x70F37FC0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x70F37FC2, 0x70F37FD3, 0x70F37FE0\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x70F37FD3\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x70F37FC2\nfunction @ 0x711AC75C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x711AC285, 0x711AF707, 0x711B11FE, 0x711B129F, and 88 more...\n      or:\n        and:\n          number: 0x50 @ 0x711B5975, 0x712866B3, 0x7190A83A\n          number: 0x45 @ 0x71210812, 0x71251643\n      or:\n        and:\n          number: 0x4D @ 0x711B11FE, 0x7125164E, 0x712688C9\n          number: 0x5A @ 0x7133DB93\nfunction @ 0x711B0700\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x711B070E, 0x711B0719, 0x711B0833, 0x711B084B, and 4 more...\n      or:\n        and:\n          number: 0x50 @ 0x711B0767\n          number: 0x45 @ 0x711B073B\n      or:\n        and:\n          number: 0x4D @ 0x711B075B\n          number: 0x5A @ 0x711B078F\nfunction @ 0x7124D7E5\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x7126F985, 0x712721B7, 0x712866B3, 0x71299A73, and 1 more...\n      or:\n        and:\n          number: 0x50 @ 0x712866B3\n          number: 0x45 @ 0x7124D7F6\n      or:\n        and:\n          number: 0x4D @ 0x712688C9\n          number: 0x5A @ 0x7126A0CE\nfunction @ 0x712D2F0F\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x711AC285, 0x711AEB0C, 0x711AF707, 0x711B11FE, and 94 more...\n      or:\n        and:\n          number: 0x50 @ 0x711B5975, 0x712866B3, 0x7190A83A\n          number: 0x45 @ 0x71251643\n      or:\n        and:\n          number: 0x4D @ 0x711B11FE, 0x7125164E, 0x712688C9, 0x7132E82B\n          number: 0x5A @ 0x718C2B7D\nfunction @ 0x712DE086\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x711AC285, 0x711AF707, 0x711B10C4, 0x711B11FE, and 104 more...\n      or:\n        and:\n          number: 0x50 @ 0x711B5975, 0x712866B3, 0x7190A83A\n          number: 0x45 @ 0x71251643\n      or:\n        and:\n          number: 0x4D @ 0x711B11FE, 0x7125164E, 0x712688C9\n          number: 0x5A @ 0x718BE795\nfunction @ 0x71320D95\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x711AC285, 0x711AF707, 0x711B10C4, 0x711B11FE, and 90 more...\n      or:\n        and:\n          number: 0x50 @ 0x711B5975, 0x712866B3, 0x7190A83A\n          number: 0x45 @ 0x71251643\n      or:\n        and:\n          number: 0x4D @ 0x711B11FE, 0x7125164E\n          number: 0x5A @ 0x71320D94\nfunction @ 0x7132BF4B\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x711AD6BB, 0x711B0F27, 0x71210848, 0x7126F985, and 14 more...\n      or:\n        and:\n          number: 0x50 @ 0x712866B3\n          number: 0x45 @ 0x71210812\n      or:\n        and:\n          number: 0x4D @ 0x712688C9\n          number: 0x5A @ 0x7132C1C4\nfunction @ 0x7132BF5E\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x711AD6BB, 0x71210848, 0x7126F985, 0x712721B7, and 12 more...\n      or:\n        and:\n          number: 0x50 @ 0x712866B3\n          number: 0x45 @ 0x71210812\n      or:\n        and:\n          number: 0x4D @ 0x712688C9\n          number: 0x5A @ 0x7132C1C4\nfunction @ 0x718B052C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71253647, 0x712721B7, 0x712866B3, 0x71299A73, and 1 more...\n      or:\n        and:\n          number: 0x50 @ 0x712866B3\n          number: 0x45 @ 0x71253688\n      or:\n        and:\n          number: 0x4D @ 0x712688C9\n          number: 0x5A @ 0x7126A0CE\nfunction @ 0x7193D2BE\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71939DD1, 0x71939DDB, 0x71939DF2, 0x7193D2D4, and 97 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A37FC0, 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71955526, 0x71991BA9, 0x71A1867E, and 3 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x719483BD\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71939DD1, 0x71939DDB, 0x71939DF2, 0x7194B71F, and 73 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71A62F18, 0x71AF116D\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x7194F22E\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71939DD1, 0x71939DDB, 0x71939DF2, 0x7194B71F, and 98 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A37FC0, 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71955526, 0x71991BA9, 0x71A1867E, and 3 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x719536E2\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71939DD1, 0x71939DDB, 0x71939DF2, 0x7194B71F, and 92 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71991BA9, 0x71A1867E, 0x71A62F18, and 2 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x719614AE\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71939DD1, 0x71939DDB, 0x71939DF2, 0x7194B71F, and 95 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A37FC0, 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71955526, 0x71991BA9, 0x71A1867E, and 3 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x7196BE5C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71939DD1, 0x71939DDB, 0x71939DF2, 0x7194B71F, and 91 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71991BA9, 0x71A1867E, 0x71A62F18, and 2 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x719830CF\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71939DD1, 0x71939DDB, 0x71939DF2, 0x7194B71F, and 95 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A37FC0, 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71955526, 0x71991BA9, 0x71A1867E, and 3 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x7199FE4A\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71939DD1, 0x71939DDB, 0x71939DF2, 0x7194B71F, and 95 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A37FC0, 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71955526, 0x71991BA9, 0x71A1867E, and 3 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x719D1E64\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71939DD1, 0x71939DDB, 0x71939DF2, 0x7194B71F, and 95 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71991BA9, 0x71A1867E, 0x71A62F18, and 2 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x719DBB65\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71939DD1, 0x71939DDB, 0x71939DF2, 0x7194B71F, and 95 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A37FC0, 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71955526, 0x71991BA9, 0x71A1867E, and 3 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x719F1BEA\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71939DD1, 0x71939DDB, 0x71939DF2, 0x7194B71F, and 94 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71991BA9, 0x71A1867E, 0x71A62F18, and 2 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x719FA205\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x7194AB57, 0x7194B71F, 0x719514A7, 0x7195575C, and 99 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71A8B47B, 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71991BA9, 0x71A1867E, 0x71A62F18, and 2 more...\n          number: 0x5A @ 0x719961EC\nfunction @ 0x71A5B5A9\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71932153, 0x71932174, 0x7193217A, 0x7193218A, and 256 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A37FC0, 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71955526, 0x71991BA9, 0x71A1867E, and 3 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x71A68F00\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71939DD1, 0x71939DDB, 0x71939DF2, 0x7194B71F, and 91 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71991BA9, 0x71A1867E, 0x71A62F18, and 2 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x71A6DEC2\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71939DD1, 0x71939DDB, 0x71939DF2, 0x7194B71F, and 93 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71991BA9, 0x71A1867E, 0x71A62F18, and 2 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x71A8BB73\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71939DD1, 0x71939DDB, 0x71939DF2, 0x7194B71F, and 95 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A37FC0, 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71955526, 0x71991BA9, 0x71A1867E, and 3 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x71AB0D46\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71932153, 0x71932174, 0x7193217A, 0x7193218A, and 256 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A37FC0, 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71955526, 0x71991BA9, 0x71A1867E, and 3 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x71AB78A8\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71939DD1, 0x71939DDB, 0x71939DF2, 0x7194B71F, and 95 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A37FC0, 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71955526, 0x71991BA9, 0x71A1867E, and 3 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x71AD4366\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x71939DD1, 0x71939DDB, 0x71939DF2, 0x7194B71F, and 92 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71991BA9, 0x71A1867E, 0x71A62F18, and 2 more...\n          number: 0x5A @ 0x71939DC9\nfunction @ 0x71AF2280\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x7194AB57, 0x7194B71F, 0x719514A7, 0x7195575C, and 91 more...\n      or:\n        and:\n          number: 0x50 @ 0x71A8D5A7, 0x71AE5751\n          number: 0x45 @ 0x71A8B47B, 0x71AD4381\n      or:\n        and:\n          number: 0x4D @ 0x7193FA2A, 0x71991BA9, 0x71A62F18, 0x71AF116D\n          number: 0x5A @ 0x719961EC\n\nresolve function by parsing PE exports\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x70F3ACD0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x70F3ACD0\n      mnemonic: movzx @ 0x70F3AA49, 0x70F3AA60, 0x70F3B0AB, 0x70F3B280, and 15 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x70F3AD24, 0x70F3B5F9\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x70F3AF6B, 0x70F3B040, 0x70F3B16C, 0x70F3B2D4, and 1 more...\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x70F3AE3D, 0x70F3AE45, 0x70F3B36A, 0x70F3B714\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x70F3AA1E, 0x70F3AD0C, 0x70F3ADEE, 0x70F3AE0F, and 4 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x70F3AA1A, 0x70F3AD34, 0x70F3AD89, 0x70F3AF92, and 2 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x70F3AD28, 0x70F3AD7F, 0x70F3AF88, 0x70F3AFC0, and 1 more...\n\n\n\n"},"hashes":{"md5":"3f1fa41a280d2e628aa2f4c7d5502518","sha1":"f320455de57557db3331e2e4abf26654a74065cf","sha256":"c480d1d8b50d9c94655b26755431d2d5a3c7d741a30047a21d1e13723109718f"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 3874</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 899400</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"pf-019f\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"3f1fa41a280d2e628aa2f4c7d5502518\",\n        \"sha256\": \"c480d1d8b50d9c94655b26755431d2d5a3c7d741a30047a21d1e137\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_peb_access__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"PEB access (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Process Environment\",\n        \"Block [B0001.019]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x711C0AEA\",\n      \"label\": \"Block 0x711C0AEA\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x711C0AEA\"\n    },\n    {\n      \"id\": \"cap_library_rule_\",\n      \"label\": \"library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Modulo [C0058]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_loop__1587_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (1587 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x70F37520\",\n      \"label\": \"Function 0x70F37520\",\n      \"type\": \"function\",\n      \"address\": \"0x70F37520\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x711AC069\",\n      \"label\": \"Function 0x711AC069\",\n      \"type\": \"function\",\n      \"address\": \"0x711AC069\"\n    },\n    {\n      \"id\": \"cap_execute_syscall__7_matches_\",\n      \"label\": \"execute syscall (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x719150CF\",\n      \"label\": \"Block 0x719150CF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x719150CF\"\n    },\n    {\n      \"id\": \"bb_0x712A26C7\",\n      \"label\": \"Block 0x712A26C7\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x712A26C7\"\n    },\n    {\n      \"id\": \"bb_0x719E082E\",\n      \"label\": \"Block 0x719E082E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x719E082E\"\n    },\n    {\n      \"id\": \"cap_author________kulinacs___mr_tz__mehunhoff_google_com__still_teamt5_org\",\n      \"label\": \"author       @kulinacs, @mr-tz, mehunhoff@google.com, still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_execute_anti_debugging_instructions__4_matches_\",\n      \"label\": \"execute anti-debugging instructions (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Anti-debugging\",\n        \"Instructions [B0001.034]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x7135973B\",\n      \"label\": \"Function 0x7135973B\",\n      \"type\": \"function\",\n      \"address\": \"0x7135973B\"\n    },\n    {\n      \"id\": \"func_0x71359729\",\n      \"label\": \"Function 0x71359729\",\n      \"type\": \"function\",\n      \"address\": \"0x71359729\"\n    },\n    {\n      \"id\": \"func_0x71359F62\",\n      \"label\": \"Function 0x71359F62\",\n      \"type\": \"function\",\n      \"address\": \"0x71359F62\"\n    },\n    {\n      \"id\": \"func_0x7134C509\",\n      \"label\": \"Function 0x7134C509\",\n      \"type\": \"function\",\n      \"address\": \"0x7134C509\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Anti-debugging\",\n        \"Instructions [B0001.034]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_anti_disasm_techniques\",\n      \"label\": \"contain anti-disasm techniques\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Disassembler Evasion [B0012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_obfuscated_stackstrings__2_matches_\",\n      \"label\": \"contain obfuscated stackstrings (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x711B0721\",\n      \"label\": \"Block 0x711B0721\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x711B0721\"\n    },\n    {\n      \"id\": \"bb_0x711B727A\",\n      \"label\": \"Block 0x711B727A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x711B727A\"\n    },\n    {\n      \"id\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"label\": \"packed with generic packer (84 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Software Packing::Standard Compression\",\n        \"[F0001.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x713114DF\",\n      \"label\": \"Function 0x713114DF\",\n      \"type\": \"function\",\n      \"address\": \"0x713114DF\"\n    },\n    {\n      \"id\": \"func_0x71341096\",\n      \"label\": \"Function 0x71341096\",\n      \"type\": \"function\",\n      \"address\": \"0x71341096\"\n    },\n    {\n      \"id\": \"func_0x71332F4D\",\n      \"label\": \"Function 0x71332F4D\",\n      \"type\": \"function\",\n      \"address\": \"0x71332F4D\"\n    },\n    {\n      \"id\": \"func_0x711D0420\",\n      \"label\": \"Function 0x711D0420\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0420\"\n    },\n    {\n      \"id\": \"func_0x711D0400\",\n      \"label\": \"Function 0x711D0400\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0400\"\n    },\n    {\n      \"id\": \"func_0x711D0540\",\n      \"label\": \"Function 0x711D0540\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0540\"\n    },\n    {\n      \"id\": \"func_0x7128DD71\",\n      \"label\": \"Function 0x7128DD71\",\n      \"type\": \"function\",\n      \"address\": \"0x7128DD71\"\n    },\n    {\n      \"id\": \"func_0x718BFB8B\",\n      \"label\": \"Function 0x718BFB8B\",\n      \"type\": \"function\",\n      \"address\": \"0x718BFB8B\"\n    },\n    {\n      \"id\": \"func_0x718BB4D8\",\n      \"label\": \"Function 0x718BB4D8\",\n      \"type\": \"function\",\n      \"address\": \"0x718BB4D8\"\n    },\n    {\n      \"id\": \"func_0x711D0120\",\n      \"label\": \"Function 0x711D0120\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0120\"\n    },\n    {\n      \"id\": \"func_0x718F80F5\",\n      \"label\": \"Function 0x718F80F5\",\n      \"type\": \"function\",\n      \"address\": \"0x718F80F5\"\n    },\n    {\n      \"id\": \"func_0x71266D19\",\n      \"label\": \"Function 0x71266D19\",\n      \"type\": \"function\",\n      \"address\": \"0x71266D19\"\n    },\n    {\n      \"id\": \"func_0x71292C5B\",\n      \"label\": \"Function 0x71292C5B\",\n      \"type\": \"function\",\n      \"address\": \"0x71292C5B\"\n    },\n    {\n      \"id\": \"func_0x711D0460\",\n      \"label\": \"Function 0x711D0460\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0460\"\n    },\n    {\n      \"id\": \"func_0x718DEB2F\",\n      \"label\": \"Function 0x718DEB2F\",\n      \"type\": \"function\",\n      \"address\": \"0x718DEB2F\"\n    },\n    {\n      \"id\": \"func_0x711D0290\",\n      \"label\": \"Function 0x711D0290\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0290\"\n    },\n    {\n      \"id\": \"func_0x712DE086\",\n      \"label\": \"Function 0x712DE086\",\n      \"type\": \"function\",\n      \"address\": \"0x712DE086\"\n    },\n    {\n      \"id\": \"func_0x711D0680\",\n      \"label\": \"Function 0x711D0680\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0680\"\n    },\n    {\n      \"id\": \"func_0x7127A1D9\",\n      \"label\": \"Function 0x7127A1D9\",\n      \"type\": \"function\",\n      \"address\": \"0x7127A1D9\"\n    },\n    {\n      \"id\": \"func_0x711CFF40\",\n      \"label\": \"Function 0x711CFF40\",\n      \"type\": \"function\",\n      \"address\": \"0x711CFF40\"\n    },\n    {\n      \"id\": \"func_0x711D0270\",\n      \"label\": \"Function 0x711D0270\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0270\"\n    },\n    {\n      \"id\": \"func_0x718F2B4C\",\n      \"label\": \"Function 0x718F2B4C\",\n      \"type\": \"function\",\n      \"address\": \"0x718F2B4C\"\n    },\n    {\n      \"id\": \"func_0x711D0560\",\n      \"label\": \"Function 0x711D0560\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0560\"\n    },\n    {\n      \"id\": \"func_0x711CFF20\",\n      \"label\": \"Function 0x711CFF20\",\n      \"type\": \"function\",\n      \"address\": \"0x711CFF20\"\n    },\n    {\n      \"id\": \"func_0x711D0350\",\n      \"label\": \"Function 0x711D0350\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0350\"\n    },\n    {\n      \"id\": \"func_0x711D04A0\",\n      \"label\": \"Function 0x711D04A0\",\n      \"type\": \"function\",\n      \"address\": \"0x711D04A0\"\n    },\n    {\n      \"id\": \"func_0x71208C32\",\n      \"label\": \"Function 0x71208C32\",\n      \"type\": \"function\",\n      \"address\": \"0x71208C32\"\n    },\n    {\n      \"id\": \"func_0x711B0FE0\",\n      \"label\": \"Function 0x711B0FE0\",\n      \"type\": \"function\",\n      \"address\": \"0x711B0FE0\"\n    },\n    {\n      \"id\": \"func_0x7120E8BB\",\n      \"label\": \"Function 0x7120E8BB\",\n      \"type\": \"function\",\n      \"address\": \"0x7120E8BB\"\n    },\n    {\n      \"id\": \"func_0x711D0000\",\n      \"label\": \"Function 0x711D0000\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0000\"\n    },\n    {\n      \"id\": \"func_0x718CFBFB\",\n      \"label\": \"Function 0x718CFBFB\",\n      \"type\": \"function\",\n      \"address\": \"0x718CFBFB\"\n    },\n    {\n      \"id\": \"func_0x711D0520\",\n      \"label\": \"Function 0x711D0520\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0520\"\n    },\n    {\n      \"id\": \"func_0x712D059F\",\n      \"label\": \"Function 0x712D059F\",\n      \"type\": \"function\",\n      \"address\": \"0x712D059F\"\n    },\n    {\n      \"id\": \"func_0x711D0660\",\n      \"label\": \"Function 0x711D0660\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0660\"\n    },\n    {\n      \"id\": \"func_0x719240EF\",\n      \"label\": \"Function 0x719240EF\",\n      \"type\": \"function\",\n      \"address\": \"0x719240EF\"\n    },\n    {\n      \"id\": \"func_0x711CFEC0\",\n      \"label\": \"Function 0x711CFEC0\",\n      \"type\": \"function\",\n      \"address\": \"0x711CFEC0\"\n    },\n    {\n      \"id\": \"func_0x71915927\",\n      \"label\": \"Function 0x71915927\",\n      \"type\": \"function\",\n      \"address\": \"0x71915927\"\n    },\n    {\n      \"id\": \"func_0x711D0100\",\n      \"label\": \"Function 0x711D0100\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0100\"\n    },\n    {\n      \"id\": \"func_0x712FEC19\",\n      \"label\": \"Function 0x712FEC19\",\n      \"type\": \"function\",\n      \"address\": \"0x712FEC19\"\n    },\n    {\n      \"id\": \"func_0x71925DE8\",\n      \"label\": \"Function 0x71925DE8\",\n      \"type\": \"function\",\n      \"address\": \"0x71925DE8\"\n    },\n    {\n      \"id\": \"func_0x711D05C0\",\n      \"label\": \"Function 0x711D05C0\",\n      \"type\": \"function\",\n      \"address\": \"0x711D05C0\"\n    },\n    {\n      \"id\": \"func_0x711D04C0\",\n      \"label\": \"Function 0x711D04C0\",\n      \"type\": \"function\",\n      \"address\": \"0x711D04C0\"\n    },\n    {\n      \"id\": \"func_0x712242F1\",\n      \"label\": \"Function 0x712242F1\",\n      \"type\": \"function\",\n      \"address\": \"0x712242F1\"\n    },\n    {\n      \"id\": \"func_0x711D0580\",\n      \"label\": \"Function 0x711D0580\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0580\"\n    },\n    {\n      \"id\": \"func_0x711B0540\",\n      \"label\": \"Function 0x711B0540\",\n      \"type\": \"function\",\n      \"address\": \"0x711B0540\"\n    },\n    {\n      \"id\": \"func_0x7190F048\",\n      \"label\": \"Function 0x7190F048\",\n      \"type\": \"function\",\n      \"address\": \"0x7190F048\"\n    },\n    {\n      \"id\": \"func_0x71320D95\",\n      \"label\": \"Function 0x71320D95\",\n      \"type\": \"function\",\n      \"address\": \"0x71320D95\"\n    },\n    {\n      \"id\": \"func_0x711CFF90\",\n      \"label\": \"Function 0x711CFF90\",\n      \"type\": \"function\",\n      \"address\": \"0x711CFF90\"\n    },\n    {\n      \"id\": \"func_0x711D0090\",\n      \"label\": \"Function 0x711D0090\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0090\"\n    },\n    {\n      \"id\": \"func_0x711D05A8\",\n      \"label\": \"Function 0x711D05A8\",\n      \"type\": \"function\",\n      \"address\": \"0x711D05A8\"\n    },\n    {\n      \"id\": \"func_0x718E2FE8\",\n      \"label\": \"Function 0x718E2FE8\",\n      \"type\": \"function\",\n      \"address\": \"0x718E2FE8\"\n    },\n    {\n      \"id\": \"func_0x711D0310\",\n      \"label\": \"Function 0x711D0310\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0310\"\n    },\n    {\n      \"id\": \"func_0x711CFEE0\",\n      \"label\": \"Function 0x711CFEE0\",\n      \"type\": \"function\",\n      \"address\": \"0x711CFEE0\"\n    },\n    {\n      \"id\": \"func_0x711D06F0\",\n      \"label\": \"Function 0x711D06F0\",\n      \"type\": \"function\",\n      \"address\": \"0x711D06F0\"\n    },\n    {\n      \"id\": \"func_0x711D0070\",\n      \"label\": \"Function 0x711D0070\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0070\"\n    },\n    {\n      \"id\": \"func_0x7130DDFF\",\n      \"label\": \"Function 0x7130DDFF\",\n      \"type\": \"function\",\n      \"address\": \"0x7130DDFF\"\n    },\n    {\n      \"id\": \"func_0x7120E885\",\n      \"label\": \"Function 0x7120E885\",\n      \"type\": \"function\",\n      \"address\": \"0x7120E885\"\n    },\n    {\n      \"id\": \"func_0x712F0C17\",\n      \"label\": \"Function 0x712F0C17\",\n      \"type\": \"function\",\n      \"address\": \"0x712F0C17\"\n    },\n    {\n      \"id\": \"func_0x711D03E0\",\n      \"label\": \"Function 0x711D03E0\",\n      \"type\": \"function\",\n      \"address\": \"0x711D03E0\"\n    },\n    {\n      \"id\": \"func_0x7124190A\",\n      \"label\": \"Function 0x7124190A\",\n      \"type\": \"function\",\n      \"address\": \"0x7124190A\"\n    },\n    {\n      \"id\": \"func_0x7130A246\",\n      \"label\": \"Function 0x7130A246\",\n      \"type\": \"function\",\n      \"address\": \"0x7130A246\"\n    },\n    {\n      \"id\": \"func_0x711D0500\",\n      \"label\": \"Function 0x711D0500\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0500\"\n    },\n    {\n      \"id\": \"func_0x713021E7\",\n      \"label\": \"Function 0x713021E7\",\n      \"type\": \"function\",\n      \"address\": \"0x713021E7\"\n    },\n    {\n      \"id\": \"func_0x713458D1\",\n      \"label\": \"Function 0x713458D1\",\n      \"type\": \"function\",\n      \"address\": \"0x713458D1\"\n    },\n    {\n      \"id\": \"func_0x711D0480\",\n      \"label\": \"Function 0x711D0480\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0480\"\n    },\n    {\n      \"id\": \"func_0x7134E624\",\n      \"label\": \"Function 0x7134E624\",\n      \"type\": \"function\",\n      \"address\": \"0x7134E624\"\n    },\n    {\n      \"id\": \"func_0x7121E3D5\",\n      \"label\": \"Function 0x7121E3D5\",\n      \"type\": \"function\",\n      \"address\": \"0x7121E3D5\"\n    },\n    {\n      \"id\": \"func_0x718F9DB2\",\n      \"label\": \"Function 0x718F9DB2\",\n      \"type\": \"function\",\n      \"address\": \"0x718F9DB2\"\n    },\n    {\n      \"id\": \"func_0x7120EB7C\",\n      \"label\": \"Function 0x7120EB7C\",\n      \"type\": \"function\",\n      \"address\": \"0x7120EB7C\"\n    },\n    {\n      \"id\": \"func_0x71272187\",\n      \"label\": \"Function 0x71272187\",\n      \"type\": \"function\",\n      \"address\": \"0x71272187\"\n    },\n    {\n      \"id\": \"func_0x712F8769\",\n      \"label\": \"Function 0x712F8769\",\n      \"type\": \"function\",\n      \"address\": \"0x712F8769\"\n    },\n    {\n      \"id\": \"func_0x711D03C0\",\n      \"label\": \"Function 0x711D03C0\",\n      \"type\": \"function\",\n      \"address\": \"0x711D03C0\"\n    },\n    {\n      \"id\": \"func_0x711D0448\",\n      \"label\": \"Function 0x711D0448\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0448\"\n    },\n    {\n      \"id\": \"func_0x712A215C\",\n      \"label\": \"Function 0x712A215C\",\n      \"type\": \"function\",\n      \"address\": \"0x712A215C\"\n    },\n    {\n      \"id\": \"func_0x711D04E0\",\n      \"label\": \"Function 0x711D04E0\",\n      \"type\": \"function\",\n      \"address\": \"0x711D04E0\"\n    },\n    {\n      \"id\": \"func_0x71334DB8\",\n      \"label\": \"Function 0x71334DB8\",\n      \"type\": \"function\",\n      \"address\": \"0x71334DB8\"\n    },\n    {\n      \"id\": \"func_0x711D0050\",\n      \"label\": \"Function 0x711D0050\",\n      \"type\": \"function\",\n      \"address\": \"0x711D0050\"\n    },\n    {\n      \"id\": \"func_0x711AED60\",\n      \"label\": \"Function 0x711AED60\",\n      \"type\": \"function\",\n      \"address\": \"0x711AED60\"\n    },\n    {\n      \"id\": \"func_0x7131FA67\",\n      \"label\": \"Function 0x7131FA67\",\n      \"type\": \"function\",\n      \"address\": \"0x7131FA67\"\n    },\n    {\n      \"id\": \"func_0x711D02D0\",\n      \"label\": \"Function 0x711D02D0\",\n      \"type\": \"function\",\n      \"address\": \"0x711D02D0\"\n    },\n    {\n      \"id\": \"func_0x71240F77\",\n      \"label\": \"Function 0x71240F77\",\n      \"type\": \"function\",\n      \"address\": \"0x71240F77\"\n    },\n    {\n      \"id\": \"func_0x7128CF3B\",\n      \"label\": \"Function 0x7128CF3B\",\n      \"type\": \"function\",\n      \"address\": \"0x7128CF3B\"\n    },\n    {\n      \"id\": \"func_0x71342CCA\",\n      \"label\": \"Function 0x71342CCA\",\n      \"type\": \"function\",\n      \"address\": \"0x71342CCA\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Software Packing::Standard Compression\",\n        \"[F0001.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encode_data_using_base64__73_matches_\",\n      \"label\": \"encode data using Base64 (73 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x712F7FD6\",\n      \"label\": \"Function 0x712F7FD6\",\n      \"type\": \"function\",\n      \"address\": \"0x712F7FD6\"\n    },\n    {\n      \"id\": \"func_0x719DBB65\",\n      \"label\": \"Function 0x719DBB65\",\n      \"type\": \"function\",\n      \"address\": \"0x719DBB65\"\n    },\n    {\n      \"id\": \"func_0x7129C77B\",\n      \"label\": \"Function 0x7129C77B\",\n      \"type\": \"function\",\n      \"address\": \"0x7129C77B\"\n    },\n    {\n      \"id\": \"func_0x71290357\",\n      \"label\": \"Function 0x71290357\",\n      \"type\": \"function\",\n      \"address\": \"0x71290357\"\n    },\n    {\n      \"id\": \"func_0x71248A5B\",\n      \"label\": \"Function 0x71248A5B\",\n      \"type\": \"function\",\n      \"address\": \"0x71248A5B\"\n    },\n    {\n      \"id\": \"func_0x7131CD70\",\n      \"label\": \"Function 0x7131CD70\",\n      \"type\": \"function\",\n      \"address\": \"0x7131CD70\"\n    },\n    {\n      \"id\": \"func_0x7131CD80\",\n      \"label\": \"Function 0x7131CD80\",\n      \"type\": \"function\",\n      \"address\": \"0x7131CD80\"\n    },\n    {\n      \"id\": \"func_0x7135B38D\",\n      \"label\": \"Function 0x7135B38D\",\n      \"type\": \"function\",\n      \"address\": \"0x7135B38D\"\n    },\n    {\n      \"id\": \"func_0x718B72FB\",\n      \"label\": \"Function 0x718B72FB\",\n      \"type\": \"function\",\n      \"address\": \"0x718B72FB\"\n    },\n    {\n      \"id\": \"func_0x719614AE\",\n      \"label\": \"Function 0x719614AE\",\n      \"type\": \"function\",\n      \"address\": \"0x719614AE\"\n    },\n    {\n      \"id\": \"func_0x71A5B5A9\",\n      \"label\": \"Function 0x71A5B5A9\",\n      \"type\": \"function\",\n      \"address\": \"0x71A5B5A9\"\n    },\n    {\n      \"id\": \"func_0x7128D3BE\",\n      \"label\": \"Function 0x7128D3BE\",\n      \"type\": \"function\",\n      \"address\": \"0x7128D3BE\"\n    },\n    {\n      \"id\": \"func_0x7199FE4A\",\n      \"label\": \"Function 0x7199FE4A\",\n      \"type\": \"function\",\n      \"address\": \"0x7199FE4A\"\n    },\n    {\n      \"id\": \"func_0x71A8BB73\",\n      \"label\": \"Function 0x71A8BB73\",\n      \"type\": \"function\",\n      \"address\": \"0x71A8BB73\"\n    },\n    {\n      \"id\": \"func_0x7191311B\",\n      \"label\": \"Function 0x7191311B\",\n      \"type\": \"function\",\n      \"address\": \"0x7191311B\"\n    },\n    {\n      \"id\": \"func_0x7134C517\",\n      \"label\": \"Function 0x7134C517\",\n      \"type\": \"function\",\n      \"address\": \"0x7134C517\"\n    },\n    {\n      \"id\": \"func_0x7131CDA4\",\n      \"label\": \"Function 0x7131CDA4\",\n      \"type\": \"function\",\n      \"address\": \"0x7131CDA4\"\n    },\n    {\n      \"id\": \"func_0x718CF206\",\n      \"label\": \"Function 0x718CF206\",\n      \"type\": \"function\",\n      \"address\": \"0x718CF206\"\n    },\n    {\n      \"id\": \"func_0x71A687DC\",\n      \"label\": \"Function 0x71A687DC\",\n      \"type\": \"function\",\n      \"address\": \"0x71A687DC\"\n    },\n    {\n      \"id\": \"func_0x71AB0D46\",\n      \"label\": \"Function 0x71AB0D46\",\n      \"type\": \"function\",\n      \"address\": \"0x71AB0D46\"\n    },\n    {\n      \"id\": \"func_0x7123C11D\",\n      \"label\": \"Function 0x7123C11D\",\n      \"type\": \"function\",\n      \"address\": \"0x7123C11D\"\n    },\n    {\n      \"id\": \"func_0x7193D2BE\",\n      \"label\": \"Function 0x7193D2BE\",\n      \"type\": \"function\",\n      \"address\": \"0x7193D2BE\"\n    },\n    {\n      \"id\": \"func_0x711B022F\",\n      \"label\": \"Function 0x711B022F\",\n      \"type\": \"function\",\n      \"address\": \"0x711B022F\"\n    },\n    {\n      \"id\": \"func_0x711B0700\",\n      \"label\": \"Function 0x711B0700\",\n      \"type\": \"function\",\n      \"address\": \"0x711B0700\"\n    },\n    {\n      \"id\": \"func_0x712776C4\",\n      \"label\": \"Function 0x712776C4\",\n      \"type\": \"function\",\n      \"address\": \"0x712776C4\"\n    },\n    {\n      \"id\": \"func_0x711B7150\",\n      \"label\": \"Function 0x711B7150\",\n      \"type\": \"function\",\n      \"address\": \"0x711B7150\"\n    },\n    {\n      \"id\": \"func_0x712C3A71\",\n      \"label\": \"Function 0x712C3A71\",\n      \"type\": \"function\",\n      \"address\": \"0x712C3A71\"\n    },\n    {\n      \"id\": \"func_0x712EFFFF\",\n      \"label\": \"Function 0x712EFFFF\",\n      \"type\": \"function\",\n      \"address\": \"0x712EFFFF\"\n    },\n    {\n      \"id\": \"func_0x711BF830\",\n      \"label\": \"Function 0x711BF830\",\n      \"type\": \"function\",\n      \"address\": \"0x711BF830\"\n    },\n    {\n      \"id\": \"func_0x7192583F\",\n      \"label\": \"Function 0x7192583F\",\n      \"type\": \"function\",\n      \"address\": \"0x7192583F\"\n    },\n    {\n      \"id\": \"func_0x7131CCDB\",\n      \"label\": \"Function 0x7131CCDB\",\n      \"type\": \"function\",\n      \"address\": \"0x7131CCDB\"\n    },\n    {\n      \"id\": \"func_0x718C1401\",\n      \"label\": \"Function 0x718C1401\",\n      \"type\": \"function\",\n      \"address\": \"0x718C1401\"\n    },\n    {\n      \"id\": \"func_0x71913079\",\n      \"label\": \"Function 0x71913079\",\n      \"type\": \"function\",\n      \"address\": \"0x71913079\"\n    },\n    {\n      \"id\": \"func_0x71AB78A8\",\n      \"label\": \"Function 0x71AB78A8\",\n      \"type\": \"function\",\n      \"address\": \"0x71AB78A8\"\n    },\n    {\n      \"id\": \"func_0x71A327C6\",\n      \"label\": \"Function 0x71A327C6\",\n      \"type\": \"function\",\n      \"address\": \"0x71A327C6\"\n    },\n    {\n      \"id\": \"func_0x7191305C\",\n      \"label\": \"Function 0x7191305C\",\n      \"type\": \"function\",\n      \"address\": \"0x7191305C\"\n    },\n    {\n      \"id\": \"func_0x712C2F59\",\n      \"label\": \"Function 0x712C2F59\",\n      \"type\": \"function\",\n      \"address\": \"0x712C2F59\"\n    },\n    {\n      \"id\": \"func_0x7194F22E\",\n      \"label\": \"Function 0x7194F22E\",\n      \"type\": \"function\",\n      \"address\": \"0x7194F22E\"\n    },\n    {\n      \"id\": \"func_0x711B651D\",\n      \"label\": \"Function 0x711B651D\",\n      \"type\": \"function\",\n      \"address\": \"0x711B651D\"\n    },\n    {\n      \"id\": \"func_0x7129E010\",\n      \"label\": \"Function 0x7129E010\",\n      \"type\": \"function\",\n      \"address\": \"0x7129E010\"\n    },\n    {\n      \"id\": \"func_0x7126E897\",\n      \"label\": \"Function 0x7126E897\",\n      \"type\": \"function\",\n      \"address\": \"0x7126E897\"\n    },\n    {\n      \"id\": \"func_0x71906EBD\",\n      \"label\": \"Function 0x71906EBD\",\n      \"type\": \"function\",\n      \"address\": \"0x71906EBD\"\n    },\n    {\n      \"id\": \"func_0x712C2F33\",\n      \"label\": \"Function 0x712C2F33\",\n      \"type\": \"function\",\n      \"address\": \"0x712C2F33\"\n    },\n    {\n      \"id\": \"func_0x711D03A0\",\n      \"label\": \"Function 0x711D03A0\",\n      \"type\": \"function\",\n      \"address\": \"0x711D03A0\"\n    },\n    {\n      \"id\": \"func_0x719830CF\",\n      \"label\": \"Function 0x719830CF\",\n      \"type\": \"function\",\n      \"address\": \"0x719830CF\"\n    },\n    {\n      \"id\": \"func_0x719D1E64\",\n      \"label\": \"Function 0x719D1E64\",\n      \"type\": \"function\",\n      \"address\": \"0x719D1E64\"\n    },\n    {\n      \"id\": \"func_0x712BDD1F\",\n      \"label\": \"Function 0x712BDD1F\",\n      \"type\": \"function\",\n      \"address\": \"0x712BDD1F\"\n    },\n    {\n      \"id\": \"func_0x71223AF8\",\n      \"label\": \"Function 0x71223AF8\",\n      \"type\": \"function\",\n      \"address\": \"0x71223AF8\"\n    },\n    {\n      \"id\": \"func_0x712851BE\",\n      \"label\": \"Function 0x712851BE\",\n      \"type\": \"function\",\n      \"address\": \"0x712851BE\"\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"label\": \"encrypt data using RC4 KSA (24 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data::RC4 [C0027.009]\",\n        \"Cryptography::Encryption\",\n        \"Key::RC4 KSA [C0028.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x7195371D\",\n      \"label\": \"Function 0x7195371D\",\n      \"type\": \"function\",\n      \"address\": \"0x7195371D\"\n    },\n    {\n      \"id\": \"func_0x71A68F00\",\n      \"label\": \"Function 0x71A68F00\",\n      \"type\": \"function\",\n      \"address\": \"0x71A68F00\"\n    },\n    {\n      \"id\": \"func_0x71A8A20F\",\n      \"label\": \"Function 0x71A8A20F\",\n      \"type\": \"function\",\n      \"address\": \"0x71A8A20F\"\n    },\n    {\n      \"id\": \"func_0x71A6DEC2\",\n      \"label\": \"Function 0x71A6DEC2\",\n      \"type\": \"function\",\n      \"address\": \"0x71A6DEC2\"\n    },\n    {\n      \"id\": \"func_0x719F1BEA\",\n      \"label\": \"Function 0x719F1BEA\",\n      \"type\": \"function\",\n      \"address\": \"0x719F1BEA\"\n    },\n    {\n      \"id\": \"func_0x719FA205\",\n      \"label\": \"Function 0x719FA205\",\n      \"type\": \"function\",\n      \"address\": \"0x719FA205\"\n    },\n    {\n      \"id\": \"func_0x71AD4366\",\n      \"label\": \"Function 0x71AD4366\",\n      \"type\": \"function\",\n      \"address\": \"0x71AD4366\"\n    },\n    {\n      \"id\": \"func_0x7196BE5C\",\n      \"label\": \"Function 0x7196BE5C\",\n      \"type\": \"function\",\n      \"address\": \"0x7196BE5C\"\n    },\n    {\n      \"id\": \"func_0x71AF2280\",\n      \"label\": \"Function 0x71AF2280\",\n      \"type\": \"function\",\n      \"address\": \"0x71AF2280\"\n    },\n    {\n      \"id\": \"func_0x71A4643A\",\n      \"label\": \"Function 0x71A4643A\",\n      \"type\": \"function\",\n      \"address\": \"0x71A4643A\"\n    },\n    {\n      \"id\": \"func_0x71A44304\",\n      \"label\": \"Function 0x71A44304\",\n      \"type\": \"function\",\n      \"address\": \"0x71A44304\"\n    },\n    {\n      \"id\": \"func_0x719536E2\",\n      \"label\": \"Function 0x719536E2\",\n      \"type\": \"function\",\n      \"address\": \"0x719536E2\"\n    },\n    {\n      \"id\": \"func_0x711B2290\",\n      \"label\": \"Function 0x711B2290\",\n      \"type\": \"function\",\n      \"address\": \"0x711B2290\"\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_rc4_prga\",\n      \"label\": \"encrypt data using RC4 PRGA\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data::RC4 [C0027.009]\",\n        \"Cryptography::Generate\",\n        \"Pseudo-random Sequence::RC4 PRGA [C0021.004]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x711B23D0\",\n      \"label\": \"Function 0x711B23D0\",\n      \"type\": \"function\",\n      \"address\": \"0x711B23D0\"\n    },\n    {\n      \"id\": \"cap_authenticate_hmac__92_matches_\",\n      \"label\": \"authenticate HMAC (92 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Hashed Message Authentication Code [C0061]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x7121D494\",\n      \"label\": \"Function 0x7121D494\",\n      \"type\": \"function\",\n      \"address\": \"0x7121D494\"\n    },\n    {\n      \"id\": \"func_0x718C5A00\",\n      \"label\": \"Function 0x718C5A00\",\n      \"type\": \"function\",\n      \"address\": \"0x718C5A00\"\n    },\n    {\n      \"id\": \"func_0x712A0438\",\n      \"label\": \"Function 0x712A0438\",\n      \"type\": \"function\",\n      \"address\": \"0x712A0438\"\n    },\n    {\n      \"id\": \"func_0x712327F2\",\n      \"label\": \"Function 0x712327F2\",\n      \"type\": \"function\",\n      \"address\": \"0x712327F2\"\n    },\n    {\n      \"id\": \"func_0x71A2715C\",\n      \"label\": \"Function 0x71A2715C\",\n      \"type\": \"function\",\n      \"address\": \"0x71A2715C\"\n    },\n    {\n      \"id\": \"func_0x718D1964\",\n      \"label\": \"Function 0x718D1964\",\n      \"type\": \"function\",\n      \"address\": \"0x718D1964\"\n    },\n    {\n      \"id\": \"func_0x71219AE6\",\n      \"label\": \"Function 0x71219AE6\",\n      \"type\": \"function\",\n      \"address\": \"0x71219AE6\"\n    },\n    {\n      \"id\": \"func_0x71353FC7\",\n      \"label\": \"Function 0x71353FC7\",\n      \"type\": \"function\",\n      \"address\": \"0x71353FC7\"\n    },\n    {\n      \"id\": \"func_0x712E5DF2\",\n      \"label\": \"Function 0x712E5DF2\",\n      \"type\": \"function\",\n      \"address\": \"0x712E5DF2\"\n    },\n    {\n      \"id\": \"func_0x719BDC70\",\n      \"label\": \"Function 0x719BDC70\",\n      \"type\": \"function\",\n      \"address\": \"0x719BDC70\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Hashed Message Authentication Code [C0061]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"label\": \"contain a thread local storage (.tls) section\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap__internal__packer_file_limitation\",\n      \"label\": \"(internal) packer file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_parse_pe_header__32_matches_\",\n      \"label\": \"parse PE header (32 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x712D2F0F\",\n      \"label\": \"Function 0x712D2F0F\",\n      \"type\": \"function\",\n      \"address\": \"0x712D2F0F\"\n    },\n    {\n      \"id\": \"func_0x70F37FC0\",\n      \"label\": \"Function 0x70F37FC0\",\n      \"type\": \"function\",\n      \"address\": \"0x70F37FC0\"\n    },\n    {\n      \"id\": \"func_0x719483BD\",\n      \"label\": \"Function 0x719483BD\",\n      \"type\": \"function\",\n      \"address\": \"0x719483BD\"\n    },\n    {\n      \"id\": \"func_0x7124D7E5\",\n      \"label\": \"Function 0x7124D7E5\",\n      \"type\": \"function\",\n      \"address\": \"0x7124D7E5\"\n    },\n    {\n      \"id\": \"func_0x718B052C\",\n      \"label\": \"Function 0x718B052C\",\n      \"type\": \"function\",\n      \"address\": \"0x718B052C\"\n    },\n    {\n      \"id\": \"func_0x711AC75C\",\n      \"label\": \"Function 0x711AC75C\",\n      \"type\": \"function\",\n      \"address\": \"0x711AC75C\"\n    },\n    {\n      \"id\": \"func_0x7132BF5E\",\n      \"label\": \"Function 0x7132BF5E\",\n      \"type\": \"function\",\n      \"address\": \"0x7132BF5E\"\n    },\n    {\n      \"id\": \"func_0x7132BF4B\",\n      \"label\": \"Function 0x7132BF4B\",\n      \"type\": \"function\",\n      \"address\": \"0x7132BF4B\"\n    },\n    {\n      \"id\": \"func_0x70F37F00\",\n      \"label\": \"Function 0x70F37F00\",\n      \"type\": \"function\",\n      \"address\": \"0x70F37F00\"\n    },\n    {\n      \"id\": \"func_0x70F37E80\",\n      \"label\": \"Function 0x70F37E80\",\n      \"type\": \"function\",\n      \"address\": \"0x70F37E80\"\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"label\": \"resolve function by parsing PE exports\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x70F3ACD0\",\n      \"label\": \"Function 0x70F3ACD0\",\n      \"type\": \"function\",\n      \"address\": \"0x70F3ACD0\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_peb_access__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_peb_access__4_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x711C0AEA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__1587_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__1587_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x70F37520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"func_0x711AC069\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_execute_syscall__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_execute_syscall__7_matches_\",\n      \"target\": \"bb_0x719150CF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_execute_syscall__7_matches_\",\n      \"target\": \"bb_0x712A26C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_execute_syscall__7_matches_\",\n      \"target\": \"bb_0x719E082E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________kulinacs___mr_tz__mehunhoff_google_com__still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author________kulinacs___mr_tz__mehunhoff_google_com__still_teamt5_org\",\n      \"target\": \"bb_0x719150CF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author________kulinacs___mr_tz__mehunhoff_google_com__still_teamt5_org\",\n      \"target\": \"bb_0x712A26C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author________kulinacs___mr_tz__mehunhoff_google_com__still_teamt5_org\",\n      \"target\": \"bb_0x719E082E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_execute_anti_debugging_instructions__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_execute_anti_debugging_instructions__4_matches_\",\n      \"target\": \"func_0x7135973B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_execute_anti_debugging_instructions__4_matches_\",\n      \"target\": \"func_0x71359729\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_execute_anti_debugging_instructions__4_matches_\",\n      \"target\": \"func_0x71359F62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_execute_anti_debugging_instructions__4_matches_\",\n      \"target\": \"func_0x7134C509\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7135973B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71359729\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71359F62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7134C509\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_anti_disasm_techniques\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_obfuscated_stackstrings__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__2_matches_\",\n      \"target\": \"bb_0x711B0721\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__2_matches_\",\n      \"target\": \"bb_0x711B727A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x711B0721\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x711B727A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x713114DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x71341096\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x71332F4D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0420\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x7128DD71\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x718BFB8B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x718BB4D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0120\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x718F80F5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x71266D19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x71292C5B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0460\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x718DEB2F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x712DE086\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0680\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x7127A1D9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711CFF40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x718F2B4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711CFF20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0350\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D04A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x71208C32\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711B0FE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x7120E8BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x718CFBFB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x712D059F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0660\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x719240EF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711CFEC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x71915927\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0100\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x712FEC19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x71925DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D05C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D04C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x712242F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0580\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711B0540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x7190F048\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x71320D95\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711CFF90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0090\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D05A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x718E2FE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711CFEE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D06F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x7130DDFF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x7120E885\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x712F0C17\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D03E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x7124190A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x7130A246\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0500\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x713021E7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x713458D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x7134E624\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x7121E3D5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x718F9DB2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x7120EB7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x71272187\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x712F8769\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D03C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0448\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x712A215C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D04E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x71334DB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D0050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711AED60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x7131FA67\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x711D02D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x71240F77\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x7128CF3B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x71342CCA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_packed_with_generic_packer__84_matches_\",\n      \"target\": \"func_0x7134C509\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x713114DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x71341096\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x71332F4D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0420\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x7128DD71\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x718BFB8B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x718BB4D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0120\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x718F80F5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x71266D19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x71292C5B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0460\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x718DEB2F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x712DE086\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0680\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x7127A1D9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711CFF40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x718F2B4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711CFF20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0350\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D04A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x71208C32\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711B0FE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x7120E8BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x718CFBFB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x712D059F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0660\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x719240EF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711CFEC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x71915927\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0100\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x712FEC19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x71925DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D05C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D04C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x712242F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0580\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711B0540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x7190F048\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x71320D95\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711CFF90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0090\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D05A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x718E2FE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711CFEE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D06F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x7130DDFF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x7120E885\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x712F0C17\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D03E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x7124190A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x7130A246\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0500\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x713021E7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x713458D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x7134E624\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x7121E3D5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x718F9DB2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x7120EB7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x71272187\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x712F8769\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D03C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0448\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x712A215C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D04E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x71334DB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D0050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711AED60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x7131FA67\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x711D02D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x71240F77\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x7128CF3B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x71342CCA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x7134C509\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encode_data_using_base64__73_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x712F7FD6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x719DBB65\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7129C77B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71341096\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71290357\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71248A5B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7131CD70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7131CD80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7135973B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7135B38D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x718B72FB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x719614AE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71A5B5A9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7128D3BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x718F9DB2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7199FE4A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x718BFB8B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71A8BB73\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7191311B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7134C517\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7190F048\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7131CDA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x718CF206\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71A687DC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71AB0D46\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x718BB4D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x718F80F5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7123C11D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71272187\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7193D2BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x712D059F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71266D19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x711B022F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x711B0700\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x712776C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x711B7150\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x712C3A71\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x712EFFFF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x711BF830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7192583F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7131CCDB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x718C1401\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71915927\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71334DB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7130DDFF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71913079\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71AB78A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x712F0C17\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x712DE086\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71A327C6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7191305C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x712C2F59\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7127A1D9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x711AED60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7194F22E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x711B651D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7129E010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x718F2B4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7126E897\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7128CF3B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71906EBD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x712C2F33\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x712FEC19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x711D03A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71925DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x719830CF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x719D1E64\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x712BDD1F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x71223AF8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x713458D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x712851BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x711B0FE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__73_matches_\",\n      \"target\": \"func_0x7134C509\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x712F7FD6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x719DBB65\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7129C77B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71341096\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71290357\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71248A5B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7131CD70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7131CD80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7135973B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7135B38D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x718B72FB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x719614AE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71A5B5A9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7128D3BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x718F9DB2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7199FE4A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x718BFB8B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71A8BB73\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7191311B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7134C517\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7190F048\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7131CDA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x718CF206\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71A687DC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71AB0D46\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x718BB4D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x718F80F5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7123C11D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71272187\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7193D2BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x712D059F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71266D19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x711B022F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x711B0700\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x712776C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x711B7150\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x712C3A71\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x712EFFFF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x711BF830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7192583F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7131CCDB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x718C1401\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71915927\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71334DB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7130DDFF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71913079\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71AB78A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x712F0C17\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x712DE086\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71A327C6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7191305C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x712C2F59\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7127A1D9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x711AED60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7194F22E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x711B651D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7129E010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x718F2B4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7126E897\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7128CF3B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71906EBD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x712C2F33\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x712FEC19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x711D03A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71925DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x719830CF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x719D1E64\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x712BDD1F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x71223AF8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x713458D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x712851BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x711B0FE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x7134C509\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x7195371D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x719DBB65\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x719614AE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x71A5B5A9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x7199FE4A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x71A68F00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x71A8BB73\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x71A8A20F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x71A6DEC2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x71AB0D46\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x719F1BEA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x719FA205\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x7193D2BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x71AD4366\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x7196BE5C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x71AF2280\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x71A4643A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x71A44304\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x71AB78A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x7194F22E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x719536E2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x719830CF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x719D1E64\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__24_matches_\",\n      \"target\": \"func_0x711B2290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7195371D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719DBB65\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719614AE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71A5B5A9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7199FE4A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71A68F00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71A8BB73\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71A8A20F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71A6DEC2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71AB0D46\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719F1BEA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719FA205\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7193D2BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71AD4366\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7196BE5C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71AF2280\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71A4643A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71A44304\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71AB78A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7194F22E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719536E2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719830CF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719D1E64\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711B2290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_rc4_prga\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga\",\n      \"target\": \"func_0x711B23D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711B23D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_authenticate_hmac__92_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x713114DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x71341096\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x71332F4D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0420\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x7128DD71\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x718BFB8B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x718BB4D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0120\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x718F80F5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x71266D19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x7121D494\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x71292C5B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x718C5A00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0460\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x712DE086\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0680\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x7191305C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x7127A1D9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711CFF40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x718F2B4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711CFF20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0350\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D04A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D03A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x71208C32\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711B0FE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x712A0438\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x718CFBFB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x712D059F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0660\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x719240EF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711CFEC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x71915927\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x712327F2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0100\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x712FEC19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x71925DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D05C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D04C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x712242F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x71A2715C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0580\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711B0540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x7131CDA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x71320D95\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711CFF90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0090\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x7190F048\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D05A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x718E2FE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711B022F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x712EFFFF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711CFEE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D06F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x712F0C17\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D03E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x7130A246\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0500\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x713021E7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x713458D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x718D1964\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x71248A5B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x7134E624\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x71219AE6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x718F9DB2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x71353FC7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x71272187\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x712F8769\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D03C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0448\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x712A215C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D04E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711BF830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x71334DB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D0050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x712E5DF2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x719BDC70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x7131FA67\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x711D02D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x71240F77\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x71342CCA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__92_matches_\",\n      \"target\": \"func_0x7134C509\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x713114DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71341096\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71332F4D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0420\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7128DD71\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x718BFB8B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x718BB4D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0120\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x718F80F5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71266D19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7121D494\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71292C5B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x718C5A00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0460\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x712DE086\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0680\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7191305C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7127A1D9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711CFF40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x718F2B4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711CFF20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0350\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D04A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D03A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71208C32\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711B0FE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x712A0438\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x718CFBFB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x712D059F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0660\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719240EF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711CFEC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71915927\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x712327F2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0100\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x712FEC19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71925DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D05C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D04C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x712242F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71A2715C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0580\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711B0540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7131CDA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71320D95\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711CFF90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0090\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7190F048\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D05A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x718E2FE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711B022F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x712EFFFF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711CFEE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D06F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x712F0C17\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D03E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7130A246\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0500\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x713021E7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x713458D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x718D1964\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71248A5B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7134E624\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71219AE6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x718F9DB2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71353FC7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71272187\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x712F8769\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D03C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0448\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x712A215C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D04E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711BF830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71334DB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D0050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x712E5DF2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719BDC70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7131FA67\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711D02D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71240F77\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71342CCA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7134C509\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal__packer_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header__32_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x719DBB65\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x719614AE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x71A5B5A9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x7199FE4A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x71A68F00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x712D2F0F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x70F37FC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x71A8BB73\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x71A6DEC2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x71320D95\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x71AB0D46\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x719F1BEA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x719FA205\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x7193D2BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x719483BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x71AD4366\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x7196BE5C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x711B0700\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x71AF2280\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x7124D7E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x718B052C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x711AC75C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x71AB78A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x712DE086\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x7194F22E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x7132BF5E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x719536E2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x7132BF4B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x719830CF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x719D1E64\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x70F37F00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__32_matches_\",\n      \"target\": \"func_0x70F37E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719DBB65\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719614AE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71A5B5A9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7199FE4A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71A68F00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x712D2F0F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x70F37FC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71A8BB73\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71A6DEC2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71320D95\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71AB0D46\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719F1BEA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719FA205\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7193D2BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719483BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71AD4366\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7196BE5C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711B0700\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71AF2280\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7124D7E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x718B052C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x711AC75C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x71AB78A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x712DE086\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7194F22E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7132BF5E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719536E2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x7132BF4B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719830CF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x719D1E64\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x70F37F00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x70F37E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"target\": \"func_0x70F3ACD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x70F3ACD0\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-01 16:07:04.609837\",\n    \"total_functions\": \"3874\",\n    \"total_features\": \"899400\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-01 16:07:21"}
{"_id":{"$oid":"6a4f8b8a0108394cb24cdcac"},"sha256":"d0cca6601229f60c0cc2ece0de632c2787e9ed34ac64bff0114d507d6ced7f54","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"59405af1e74b9dceaaa9d2b31d10ab6e","sha1":"a4e1443e90d82d31f1873906b666c1f43aa72592","sha256":"d0cca6601229f60c0cc2ece0de632c2787e9ed34ac64bff0114d507d6ced7f54"}},"timestamp":"2026-07-09 17:22:42"}
{"_id":{"$oid":"6a4f8c570108394cb24cdcb0"},"sha256":"173671beefa95df1a34493514264da0506fe533c420a0b0f9920124ce8344a44","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"8b83ec5857bab115d01191fb3d45dd0e","sha1":"cdbbaabf66c19d7ed95ee33c78bfdd908697dca3","sha256":"173671beefa95df1a34493514264da0506fe533c420a0b0f9920124ce8344a44"}},"timestamp":"2026-07-09 17:26:07"}
{"_id":{"$oid":"6a4f90890108394cb24cdcb3"},"sha256":"427ece485005f1bd517b8f0c6c38a8f73bf32350795b83fb8cf937c86f99dfc8","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"ab2e178c77f6df518024a71d05e98451","sha1":"6863f15cd00af38d8693889dc10170107d75c8b6","sha256":"427ece485005f1bd517b8f0c6c38a8f73bf32350795b83fb8cf937c86f99dfc8"}},"timestamp":"2026-07-09 17:44:01"}
{"_id":{"$oid":"6a4f93fa0108394cb24cdcb8"},"sha256":"523d40c69b0972ddeff0682fcb569e8a346cf10b2894479ab227bbb24e19846e","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_0ogftsxa/001_upx_unpacked.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_0ogftsxa/001_upx_unpacked.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_0ogftsxa/001_upx_unpacked.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 0296ab9d97f11d941ccbbf06ac79c08f                                  │\n│ sha1     │ 981ec6b4658d603fcbf08aead7fc1a3039a451bb                          │\n│ sha256   │ d7d501e0aaeef3b9ed324d423b0309831f42dd8ab10e28a01f1238bddb5155d1  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /tmp/sdm_unpack_wzyogqu_/conficker-019f46bbbdcd7df3a29dcdf19949a… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\nno capabilities found\n\n","verbose":"md5                     0296ab9d97f11d941ccbbf06ac79c08f                        \nsha1                    981ec6b4658d603fcbf08aead7fc1a3039a451bb                \nsha256                  d7d501e0aaeef3b9ed324d423b0309831f42dd8ab10e28a01f1238b…\npath                    /tmp/sdm_unpack_wzyogqu_/conficker-019f46bbbdcd7df3a29d…\ntimestamp               2026-07-09 17:58:36.538624                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x10000000                                              \nrules                   /tmp/_MEI5EFK5c/rules                                   \nfunction count          11                                                      \nlibrary function count  2                                                       \ntotal feature count     1422                                                    \n\nno capabilities found\n\n\n","very_verbose":"md5                     0296ab9d97f11d941ccbbf06ac79c08f                        \nsha1                    981ec6b4658d603fcbf08aead7fc1a3039a451bb                \nsha256                  d7d501e0aaeef3b9ed324d423b0309831f42dd8ab10e28a01f1238b…\npath                    /tmp/sdm_unpack_wzyogqu_/conficker-019f46bbbdcd7df3a29d…\ntimestamp               2026-07-09 17:58:41.596766                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x10000000                                              \nrules                   /tmp/_MEIO4AUu9/rules                                   \nfunction count          11                                                      \nlibrary function count  2                                                       \ntotal feature count     1422                                                    \n\nno capabilities found\n\n\n"},"hashes":{"md5":"0296ab9d97f11d941ccbbf06ac79c08f","sha1":"981ec6b4658d603fcbf08aead7fc1a3039a451bb","sha256":"d7d501e0aaeef3b9ed324d423b0309831f42dd8ab10e28a01f1238bddb5155d1"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 11</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 1422</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"conficker-019f46bbbdcd7df3a29d\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"0296ab9d97f11d941ccbbf06ac79c08f\",\n        \"sha256\": \"d7d501e0aaeef3b9ed324d423b0309831f42dd8ab10e28a01f1238b\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    }\n  ],\n  \"edges\": [],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 17:58:41.596766\",\n    \"total_functions\": \"11\",\n    \"total_features\": \"1422\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 17:58:42"}
{"_id":{"$oid":"6a4f95b30108394cb24cdcbc"},"sha256":"62dd0d4b0ac16f65e363b601e65cbc171d0c48c528fd9bf71f5561f0b3f877a2","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_41dmhl4b/build_4_17_2014_id29303-019f46bc185f7221be9bef7b7fcaadfe.bin_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_41dmhl4b/build_4_17_2014_id29303-019f46bc185f7221be9bef7b7fcaadfe.bin_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_41dmhl4b/build_4_17_2014_id29303-019f46bc185f7221be9bef7b7fcaadfe.bin_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ e9a2d2b26f5f267ccc00806bc7d3963a                                  │\n│ sha1     │ b92338b6db3810880824529e227a6650d529af4a                          │\n│ sha256   │ 62dd0d4b0ac16f65e363b601e65cbc171d0c48c528fd9bf71f5561f0b3f877a2  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/build_4_17_2014_… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic             ┃ ATT&CK Technique                                 ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION           │ Obfuscated Files or Information [T1027]          │\n│ EXECUTION                 │ Shared Modules [T1129]                           │\n└───────────────────────────┴──────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DATA                 │ Decompress Data::aPLib [C0025.003]                    │\n│                      │ Encode Data::XOR [C0026.002]                          │\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Encoding-Standard    │\n│                      │ Algorithm [E1027.m02]                                 │\n│ MEMORY               │ Allocate Memory [C0007]                               │\n│ PROCESS              │ Terminate Process [C0018]                             │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                              ┃ Namespace                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ decompress data using aPLib             │ data-manipulation/compression      │\n│ encode data using XOR                   │ data-manipulation/encoding/xor     │\n│ allocate or change RWX memory (3        │ host-interaction/process/inject    │\n│ matches)                                │                                    │\n│ terminate process                       │ host-interaction/process/terminate │\n│ access PEB ldr_data                     │ linking/runtime-linking            │\n│ parse PE header (3 matches)             │ load-code/pe                       │\n└─────────────────────────────────────────┴────────────────────────────────────┘\n\n","verbose":"md5                     e9a2d2b26f5f267ccc00806bc7d3963a                        \nsha1                    b92338b6db3810880824529e227a6650d529af4a                \nsha256                  62dd0d4b0ac16f65e363b601e65cbc171d0c48c528fd9bf71f5561f…\npath                    /home/apogean/projects/malware/windows/all_runs/build_4…\ntimestamp               2026-07-09 18:05:56.963035                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIBTGFWm/rules                                   \nfunction count          14                                                      \nlibrary function count  0                                                       \ntotal feature count     1985                                                    \n\ndecompress data using aPLib\nnamespace    data-manipulation/compression                  \ndescription  detects decompression function of library aPLib\nscope        function                                       \nmatches      0x4012EB                                       \n\nencode data using XOR\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x401179                      \n\nallocate or change RWX memory (3 matches)\nnamespace  host-interaction/process/inject\nscope      basic block                    \nmatches    0x40114A                       \n           0x401184                       \n           0x4016F6                       \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x40120A                          \n\naccess PEB ldr_data\nnamespace  linking/runtime-linking\nscope      basic block            \nmatches    0x4016A9               \n\nparse PE header (3 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x401024    \n           0x401098    \n           0x401133    \n\n\n\n","very_verbose":"md5                     e9a2d2b26f5f267ccc00806bc7d3963a                        \nsha1                    b92338b6db3810880824529e227a6650d529af4a                \nsha256                  62dd0d4b0ac16f65e363b601e65cbc171d0c48c528fd9bf71f5561f…\npath                    /home/apogean/projects/malware/windows/all_runs/build_4…\ntimestamp               2026-07-09 18:06:02.626617                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIHkAgM8/rules                                   \nfunction count          14                                                      \nlibrary function count  0                                                       \ntotal feature count     1985                                                    \n\nPEB access (2 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Debugger Detection::Process Environment   \n            Block [B0001.019]                                                   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nbasic block @ 0x40120A in function 0x40120A\n  or:\n    characteristic: peb access @ 0x40120E\n\nallocate memory (2 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x401184 in function 0x401133\n  or:\n    api: VirtualAllocEx @ 0x401192\n\nchange memory protection (library rule)\nauthor  @mr-tz                                  \nscope   basic block                             \nmbc     Memory::Change Memory Protection [C0008]\nbasic block @ 0x40114A in function 0x401133\n  or:\n    api: VirtualProtectEx @ 0x401169\n\ncontain loop (11 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401000\n  or:\n    characteristic: loop @ 0x401000\n\ndecompress data using aPLib\nnamespace    data-manipulation/compression                                      \nauthor       @r3c0nst (Frank Boldewin), moritz.raabe@mandiant.com,              \n             cdong49@gatech.edu, still@teamt5.org                               \nscope        function                                                           \nmbc          Data::Decompress Data::aPLib [C0025.003]                           \nreferences   https://ibsensoftware.com/files/aPLib-1.1.1.zip                    \ndescription  detects decompression function of library aPLib                    \nfunction @ 0x4012EB\n  and: = aP_depack\n    match: contain loop @ 0x4012EB\n      or:\n        characteristic: loop @ 0x4012EB\n        characteristic: tight loop @ 0x40148F, 0x40151F, 0x4015C4\n    instruction:\n      and:\n        mnemonic: cmp @ 0x40157C\n        or:\n          number: 0x7D00 @ 0x40157C\n    instruction:\n      and:\n        mnemonic: cmp @ 0x401594\n        or:\n          number: 0x80 @ 0x401594\n    instruction:\n      and:\n        mnemonic: shl @ 0x401556\n        number: 0x8 @ 0x401556\n    instruction:\n      and:\n        mnemonic: shr @ 0x40145C\n        number: 0x1 @ 0x40145C\n    optional:\n      count(characteristic(calls from)): 2 or more @ 0x401259, 0x4012A6\n\nencode data using XOR\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x401179 in function 0x401133\n  and:\n    characteristic: tight loop @ 0x401179\n    characteristic: nzxor @ 0x40117C\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nallocate or change RWX memory (3 matches)\nnamespace  host-interaction/process/inject\nauthor     @mr-tz, mehunhoff@google.com   \nscope      basic block                    \nmbc        Memory::Allocate Memory [C0007]\nbasic block @ 0x40114A in function 0x401133\n  or:\n    basic block:\n      and:\n        or:\n          match: change memory protection @ 0x40114A\n            or:\n              api: VirtualProtectEx @ 0x401169\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x401160\nbasic block @ 0x401184 in function 0x401133\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x401184\n            or:\n              api: VirtualAllocEx @ 0x401192\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x401184\nbasic block @ 0x4016F6 in function 0x4016E9\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x4016F6\n            or:\n              api: VirtualAllocEx @ 0x40170F\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x4016FB\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x40120A\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x401252\n\naccess PEB ldr_data\nnamespace   linking/runtime-linking                                             \nauthor      moritz.raabe@mandiant.com                                           \nscope       basic block                                                         \natt&ck      Execution::Shared Modules [T1129]                                   \nreferences  https://www.geoffchappell.com/studies/windows/km/ntoskrnl/inc/api/n…\n            https://github.com/d35ha/CallObfuscator/blob/5834aff9ff4511f1408ae4…\nbasic block @ 0x4016A9 in function 0x401698\n  or:\n    and: = x32\n      arch: i386\n      match: PEB access @ 0x4016A9\n        or:\n          characteristic: peb access @ 0x4016A9\n      offset: 0xC = PEB.LDR_DATA @ 0x4016B2\n      or: = resolve a module list\n        offset: 0xC = PEB.LDR_DATA.InLoadOrderModuleList @ 0x4016B2\n\nparse PE header (3 matches)\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x401024\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x401039, 0x401045, 0x401075, 0x401089\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x401045\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x401034\nfunction @ 0x401098\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x4010A9, 0x4010B1, 0x4010ED, 0x401109\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x4010B1\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x4010A4\nfunction @ 0x401133\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x401180, 0x4011B0, 0x4011E1, 0x4011E9\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x4011E9\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x4011D9\n\n\n\n"},"hashes":{"md5":"e9a2d2b26f5f267ccc00806bc7d3963a","sha1":"b92338b6db3810880824529e227a6650d529af4a","sha256":"62dd0d4b0ac16f65e363b601e65cbc171d0c48c528fd9bf71f5561f0b3f877a2"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 14</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 1985</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"build_4\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"e9a2d2b26f5f267ccc00806bc7d3963a\",\n        \"sha256\": \"62dd0d4b0ac16f65e363b601e65cbc171d0c48c528fd9bf71f5561f\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_peb_access__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"PEB access (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Process Environment\",\n        \"Block [B0001.019]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40120A\",\n      \"label\": \"Block 0x40120A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40120A\"\n    },\n    {\n      \"id\": \"cap_allocate_memory__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"allocate memory (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401184\",\n      \"label\": \"Block 0x401184\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401184\"\n    },\n    {\n      \"id\": \"api_VirtualAllocEx\",\n      \"label\": \"VirtualAllocEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_contain_loop__11_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (11 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401000\",\n      \"label\": \"Function 0x401000\",\n      \"type\": \"function\",\n      \"address\": \"0x401000\"\n    },\n    {\n      \"id\": \"cap_decompress_data_using_aplib\",\n      \"label\": \"decompress data using aPLib\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decompress Data::aPLib [C0025.003]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4012EB\",\n      \"label\": \"Function 0x4012EB\",\n      \"type\": \"function\",\n      \"address\": \"0x4012EB\"\n    },\n    {\n      \"id\": \"cap_cdong49_gatech_edu__still_teamt5_org\",\n      \"label\": \"cdong49@gatech.edu, still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decompress Data::aPLib [C0025.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_allocate_or_change_rwx_memory__3_matches_\",\n      \"label\": \"allocate or change RWX memory (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40114A\",\n      \"label\": \"Block 0x40114A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40114A\"\n    },\n    {\n      \"id\": \"bb_0x4016F6\",\n      \"label\": \"Block 0x4016F6\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4016F6\"\n    },\n    {\n      \"id\": \"api_VirtualProtectEx\",\n      \"label\": \"VirtualProtectEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"label\": \"author     @mr-tz, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40120A\",\n      \"label\": \"Function 0x40120A\",\n      \"type\": \"function\",\n      \"address\": \"0x40120A\"\n    },\n    {\n      \"id\": \"api_ExitProcess\",\n      \"label\": \"ExitProcess\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_access_peb_ldr_data\",\n      \"label\": \"access PEB ldr_data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4016A9\",\n      \"label\": \"Block 0x4016A9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4016A9\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header__3_matches_\",\n      \"label\": \"parse PE header (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401024\",\n      \"label\": \"Function 0x401024\",\n      \"type\": \"function\",\n      \"address\": \"0x401024\"\n    },\n    {\n      \"id\": \"func_0x401098\",\n      \"label\": \"Function 0x401098\",\n      \"type\": \"function\",\n      \"address\": \"0x401098\"\n    },\n    {\n      \"id\": \"func_0x401133\",\n      \"label\": \"Function 0x401133\",\n      \"type\": \"function\",\n      \"address\": \"0x401133\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_peb_access__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_peb_access__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x40120A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_memory__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_memory__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x401184\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__11_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__11_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decompress_data_using_aplib\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_decompress_data_using_aplib\",\n      \"target\": \"func_0x4012EB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_cdong49_gatech_edu__still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_cdong49_gatech_edu__still_teamt5_org\",\n      \"target\": \"func_0x4012EB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_or_change_rwx_memory__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__3_matches_\",\n      \"target\": \"bb_0x401184\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__3_matches_\",\n      \"target\": \"bb_0x40114A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__3_matches_\",\n      \"target\": \"bb_0x4016F6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x401184\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x40114A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x4016F6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x40120A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40120A\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40120A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40120A\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_peb_ldr_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data\",\n      \"target\": \"bb_0x4016A9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4016A9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__3_matches_\",\n      \"target\": \"func_0x401024\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__3_matches_\",\n      \"target\": \"func_0x401098\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__3_matches_\",\n      \"target\": \"func_0x401133\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x401024\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x401098\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x401133\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 18:06:02.626617\",\n    \"total_functions\": \"14\",\n    \"total_features\": \"1985\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 18:06:03"}
{"_id":{"$oid":"6a4f97230108394cb24cdcbf"},"sha256":"2a1f5a04025b7837d187ed8e9aaab7b5fff607327866e9bc9e5da83a84b56dda","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_fj1t1gdy/2a1f5a04025b7837d187ed8e9aaab7b5fff607327866e9bc9e5da83a84b56dda-019f46bc651d7072bb5082e562c6cc13.bin_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_fj1t1gdy/2a1f5a04025b7837d187ed8e9aaab7b5fff607327866e9bc9e5da83a84b56dda-019f46bc651d7072bb5082e562c6cc13.bin_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_fj1t1gdy/2a1f5a04025b7837d187ed8e9aaab7b5fff607327866e9bc9e5da83a84b56dda-019f46bc651d7072bb5082e562c6cc13.bin_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ b3962f61a4819593233aa5893421c4d1                                  │\n│ sha1     │ 1deb651f9cded42d32b9167167a091ff88bff75e                          │\n│ sha256   │ 2a1f5a04025b7837d187ed8e9aaab7b5fff607327866e9bc9e5da83a84b56dda  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/2a1f5a04025b7837… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic               ┃ ATT&CK Technique                               ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DISCOVERY                   │ File and Directory Discovery [T1083]           │\n│ EXECUTION                   │ Shared Modules [T1129]                         │\n└─────────────────────────────┴────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ CRYPTOGRAPHY             │ Hashed Message Authentication Code [C0061]        │\n│ DISCOVERY                │ File and Directory Discovery [E1083]              │\n│ PROCESS                  │ Allocate Thread Local Storage [C0040]             │\n│                          │ Terminate Process [C0018]                         │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                              ┃ Namespace                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ authenticate HMAC                       │ data-manipulation/hmac             │\n│ get file size                           │ host-interaction/file-system/meta  │\n│ terminate process                       │ host-interaction/process/terminate │\n│ allocate thread local storage           │ host-interaction/thread/tls        │\n│ link function at runtime on Windows (5  │ linking/runtime-linking            │\n│ matches)                                │                                    │\n│ link many functions at runtime          │ linking/runtime-linking            │\n│ parse PE header                         │ load-code/pe                       │\n└─────────────────────────────────────────┴────────────────────────────────────┘\n\n","verbose":"md5                     b3962f61a4819593233aa5893421c4d1                        \nsha1                    1deb651f9cded42d32b9167167a091ff88bff75e                \nsha256                  2a1f5a04025b7837d187ed8e9aaab7b5fff607327866e9bc9e5da83…\npath                    /home/apogean/projects/malware/windows/all_runs/2a1f5a0…\ntimestamp               2026-07-09 18:12:01.456778                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIHJnjVk/rules                                   \nfunction count          33                                                      \nlibrary function count  165                                                     \ntotal feature count     2646                                                    \n\nauthenticate HMAC\nnamespace  data-manipulation/hmac\nscope      function              \nmatches    0x401430              \n\nget file size\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x401430                         \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x432A3E                          \n\nallocate thread local storage\nnamespace  host-interaction/thread/tls\nscope      function                   \nmatches    0x432D19                   \n\nlink function at runtime on Windows (5 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x435937               \n           0x435954               \n           0x435969               \n           0x43597E               \n           0x435996               \n\nlink many functions at runtime\nnamespace  linking/runtime-linking\nscope      function               \nmatches    0x4358F3               \n\nparse PE header\nnamespace  load-code/pe\nscope      function    \nmatches    0x401430    \n\n\n\n","very_verbose":"md5                     b3962f61a4819593233aa5893421c4d1                        \nsha1                    1deb651f9cded42d32b9167167a091ff88bff75e                \nsha256                  2a1f5a04025b7837d187ed8e9aaab7b5fff607327866e9bc9e5da83…\npath                    /home/apogean/projects/malware/windows/all_runs/2a1f5a0…\ntimestamp               2026-07-09 18:12:11.173716                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIcSCzeX/rules                                   \nfunction count          33                                                      \nlibrary function count  165                                                     \ntotal feature count     2646                                                    \n\ncontain loop (3 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401430\n  or:\n    characteristic: loop @ 0x401430\n\nauthenticate HMAC\nnamespace   data-manipulation/hmac                                              \nauthor      moritz.raabe@mandiant.com                                           \nscope       function                                                            \nmbc         Cryptography::Hashed Message Authentication Code [C0061]            \nreferences  https://tools.ietf.org/html/rfc2104,                                \n            https://tools.ietf.org/html/rfc4634, https://github.com/ogay/hmac   \nfunction @ 0x401430\n  and:\n    number: 0x36 = inner padding byte value @ 0x401841\n    number: 0x5C = outer padding byte value @ 0x40155E, 0x401590, 0x401A5E, 0x401C75, and 1 more...\n    match: contain loop @ 0x401430\n      or:\n        characteristic: loop @ 0x401430\n    count(characteristic(nzxor)): 2 or more @ 0x401691, 0x4016CE, 0x4019DB, 0x401B71, and 38 more...\n    optional: = block size\n      number: 0x40 = MD5, SHA-1, SHA-224, or SHA-256 @ 0x40158E\n      number: 0x80 = SHA-384 or SHA-512 @ 0x401BDD\n\nget file size\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x401430\n  or:\n    api: GetFileSize @ 0x402CE1\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x432A3E\n  or:\n    and:\n      or:\n        api: TerminateProcess @ 0x4332C7\n\nallocate thread local storage\nnamespace  host-interaction/thread/tls                   \nauthor     michael.hunhoff@mandiant.com                  \nscope      function                                      \nmbc        Process::Allocate Thread Local Storage [C0040]\nfunction @ 0x432D19\n  or:\n    api: TlsAlloc @ 0x432D19\n\nlink function at runtime on Windows (5 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x435937\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x435937\ninstruction @ 0x435954\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x435954\ninstruction @ 0x435969\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x435969\ninstruction @ 0x43597E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x43597E\ninstruction @ 0x435996\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x435996\n\nlink many functions at runtime\nnamespace  linking/runtime-linking                      \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com\nscope      function                                     \natt&ck     Execution::Shared Modules [T1129]            \nfunction @ 0x4358F3\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x435937, 0x435954, 0x435969, 0x43597E, and 1 more...\n\nparse PE header\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x401430\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x401552, 0x401A5E, 0x40229A, 0x402413, and 15 more...\n      or:\n        and:\n          number: 0x50 @ 0x402789\n          number: 0x45 @ 0x4019FE, 0x401B7A, 0x401D38, 0x402B9E\n      or:\n        and:\n          number: 0x4D @ 0x4018B0, 0x401FFB, 0x402558\n          number: 0x5A @ 0x4015CD, 0x401C94, 0x4024FC\n\n\n\n"},"hashes":{"md5":"b3962f61a4819593233aa5893421c4d1","sha1":"1deb651f9cded42d32b9167167a091ff88bff75e","sha256":"2a1f5a04025b7837d187ed8e9aaab7b5fff607327866e9bc9e5da83a84b56dda"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 33</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 2646</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"2a1f5a0\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"b3962f61a4819593233aa5893421c4d1\",\n        \"sha256\": \"2a1f5a04025b7837d187ed8e9aaab7b5fff607327866e9bc9e5da83\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__3_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (3 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401430\",\n      \"label\": \"Function 0x401430\",\n      \"type\": \"function\",\n      \"address\": \"0x401430\"\n    },\n    {\n      \"id\": \"cap_authenticate_hmac\",\n      \"label\": \"authenticate HMAC\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Hashed Message Authentication Code [C0061]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Hashed Message Authentication Code [C0061]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size\",\n      \"label\": \"get file size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x432A3E\",\n      \"label\": \"Function 0x432A3E\",\n      \"type\": \"function\",\n      \"address\": \"0x432A3E\"\n    },\n    {\n      \"id\": \"api_TerminateProcess\",\n      \"label\": \"TerminateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_allocate_thread_local_storage\",\n      \"label\": \"allocate thread local storage\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Allocate Thread Local Storage [C0040]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x432D19\",\n      \"label\": \"Function 0x432D19\",\n      \"type\": \"function\",\n      \"address\": \"0x432D19\"\n    },\n    {\n      \"id\": \"api_TlsAlloc\",\n      \"label\": \"TlsAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Allocate Thread Local Storage [C0040]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__5_matches_\",\n      \"label\": \"link function at runtime on Windows (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_many_functions_at_runtime\",\n      \"label\": \"link many functions at runtime\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4358F3\",\n      \"label\": \"Function 0x4358F3\",\n      \"type\": \"function\",\n      \"address\": \"0x4358F3\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header\",\n      \"label\": \"parse PE header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__3_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__3_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_authenticate_hmac\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac\",\n      \"target\": \"func_0x401430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x401430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size\",\n      \"target\": \"func_0x401430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401430\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401430\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x432A3E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x432A3E\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x432A3E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x432A3E\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_thread_local_storage\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_thread_local_storage\",\n      \"target\": \"func_0x432D19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x432D19\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x432D19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x432D19\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_many_functions_at_runtime\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime\",\n      \"target\": \"func_0x4358F3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x4358F3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header\",\n      \"target\": \"func_0x401430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x401430\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 18:12:11.173716\",\n    \"total_functions\": \"33\",\n    \"total_features\": \"2646\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 18:12:11"}
{"_id":{"$oid":"6a4f98d70108394cb24cdcc3"},"sha256":"eea059174127860154f4dce1a7d8995a9a5056febf73819d63ddadb522ed6c8f","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_b40z8nfs/Nivdort-019f46ced0397a61b6eb666f648767ac.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_b40z8nfs/Nivdort-019f46ced0397a61b6eb666f648767ac.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_b40z8nfs/Nivdort-019f46ced0397a61b6eb666f648767ac.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ ed2cd14a28ff2d00a5cefcf6a074af8d                                  │\n│ sha1     │ 5b3e04f8208d3de912413efce27372255d6b3fe9                          │\n│ sha256   │ eea059174127860154f4dce1a7d8995a9a5056febf73819d63ddadb522ed6c8f  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/Nivdort-019f46ce… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION      │ Obfuscated Files or Information [T1027]               │\n│                      │ Obfuscated Files or Information::Indicator Removal    │\n│                      │ from Tools [T1027.005]                                │\n│ DISCOVERY            │ File and Directory Discovery [T1083]                  │\n│                      │ System Network Configuration Discovery [T1016]        │\n│ EXECUTION            │ Shared Modules [T1129]                                │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MAEC Category                                    ┃ MAEC Value                ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ malware-category                                 │ downloader                │\n└──────────────────────────────────────────────────┴───────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-STATIC ANALYSIS │ Executable Code Obfuscation::Argument Obfuscation     │\n│                      │ [B0032.020]                                           │\n│                      │ Executable Code Obfuscation::Stack Strings            │\n│                      │ [B0032.017]                                           │\n│ COMMAND AND CONTROL  │ C2 Communication::Receive Data [B0030.002]            │\n│                      │ C2 Communication::Send Data [B0030.001]               │\n│ COMMUNICATION        │ DNS Communication::Resolve [C0011.001]                │\n│                      │ Socket Communication::Connect Socket [C0001.004]      │\n│                      │ Socket Communication::Create TCP Socket [C0001.011]   │\n│                      │ Socket Communication::Create UDP Socket [C0001.010]   │\n│                      │ Socket Communication::Get Socket Status [C0001.012]   │\n│                      │ Socket Communication::Initialize Winsock Library      │\n│                      │ [C0001.009]                                           │\n│                      │ Socket Communication::Receive Data [C0001.006]        │\n│                      │ Socket Communication::Send Data [C0001.007]           │\n│                      │ Socket Communication::Start TCP Server [C0001.005]    │\n│                      │ Socket Communication::TCP Client [C0001.008]          │\n│                      │ Socket Communication::UDP Client [C0001.013]          │\n│ CRYPTOGRAPHY         │ Encrypt Data::HC-128 [C0027.006]                      │\n│                      │ Encrypt Data::RC4 [C0027.009]                         │\n│                      │ Generate Pseudo-random Sequence::RC4 PRGA [C0021.004] │\n│ DATA                 │ Checksum::Luhn [C0032.002]                            │\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Encryption-Standard  │\n│                      │ Algorithm [E1027.m05]                                 │\n│ DISCOVERY            │ File and Directory Discovery [E1083]                  │\n│ FILE SYSTEM          │ Get File Attributes [C0049]                           │\n│                      │ Read File [C0051]                                     │\n│                      │ Writes File [C0052]                                   │\n│ PROCESS              │ Allocate Thread Local Storage [C0040]                 │\n│                      │ Terminate Process [C0018]                             │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                           ┃ Namespace                             ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ contain obfuscated stackstrings (2   │ anti-analysis/obfuscation/string/sta… │\n│ matches)                             │                                       │\n│ read and send data from client to    │ communication/c2/file-transfer        │\n│ server                               │                                       │\n│ receive and write data from server   │ communication/c2/file-transfer        │\n│ to client                            │                                       │\n│ resolve DNS (4 matches)              │ communication/dns                     │\n│ get socket status (2 matches)        │ communication/socket                  │\n│ initialize Winsock library (2        │ communication/socket                  │\n│ matches)                             │                                       │\n│ connect UDP socket (4 matches)       │ communication/socket/udp              │\n│ act as TCP client (6 matches)        │ communication/tcp/client              │\n│ start TCP server (3 matches)         │ communication/tcp/serve               │\n│ validate payment card number using   │ data-manipulation/checksum/luhn       │\n│ luhn algorithm                       │                                       │\n│ encrypt data using HC-128            │ data-manipulation/encryption/hc-128   │\n│ encrypt data using RC4 PRGA (2       │ data-manipulation/encryption/rc4      │\n│ matches)                             │                                       │\n│ check if file exists                 │ host-interaction/file-system/exists   │\n│ get file attributes                  │ host-interaction/file-system/meta     │\n│ read file on Windows (3 matches)     │ host-interaction/file-system/read     │\n│ write file on Windows (7 matches)    │ host-interaction/file-system/write    │\n│ terminate process                    │ host-interaction/process/terminate    │\n│ allocate thread local storage        │ host-interaction/thread/tls           │\n│ link function at runtime on Windows  │ linking/runtime-linking               │\n│ (164 matches)                        │                                       │\n│ link many functions at runtime (5    │ linking/runtime-linking               │\n│ matches)                             │                                       │\n│ linked against CPP standard library  │ linking/static                        │\n└──────────────────────────────────────┴───────────────────────────────────────┘\n\n","verbose":"md5                     ed2cd14a28ff2d00a5cefcf6a074af8d                        \nsha1                    5b3e04f8208d3de912413efce27372255d6b3fe9                \nsha256                  eea059174127860154f4dce1a7d8995a9a5056febf73819d63ddadb…\npath                    /home/apogean/projects/malware/windows/all_runs/Nivdort…\ntimestamp               2026-07-10 01:18:15.667452                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIJWqu72/rules                                   \nfunction count          1002                                                    \nlibrary function count  565                                                     \ntotal feature count     56215                                                   \n\ncontain obfuscated stackstrings (2 matches)\nnamespace  anti-analysis/obfuscation/string/stackstring\nscope      basic block                                 \nmatches    0x413C01                                    \n           0x471C80                                    \n\nreceive data (11 matches)\nnamespace    communication                                                     \ndescription  all known techniques for receiving data from a potential C2 server\nscope        function                                                          \nmatches      0x401000                                                          \n             0x40C6D0                                                          \n             0x427A30                                                          \n             0x430F30                                                          \n             0x438B80                                                          \n             0x444590                                                          \n             0x44FF20                                                          \n             0x453FB0                                                          \n             0x454550                                                          \n             0x46C620                                                          \n             0x47ED20                                                          \n\nsend data (10 matches)\nnamespace    communication                                                 \ndescription  all known techniques for sending data to a potential C2 server\nscope        function                                                      \nmatches      0x427A30                                                      \n             0x430F30                                                      \n             0x438AD0                                                      \n             0x438B80                                                      \n             0x452930                                                      \n             0x454550                                                      \n             0x46C620                                                      \n             0x472DA0                                                      \n             0x479520                                                      \n             0x47ED20                                                      \n\nread and send data from client to server\nnamespace  communication/c2/file-transfer\nscope      function                      \nmatches    0x427A30                      \n\nreceive and write data from server to client\nnamespace  communication/c2/file-transfer\nscope      function                      \nmatches    0x427A30                      \n\nresolve DNS (4 matches)\nnamespace  communication/dns\nscope      function         \nmatches    0x4242F0         \n           0x4631A0         \n           0x478270         \n           0x47ED20         \n\nconnect socket (7 matches)\nnamespace    communication/socket                                               \ndescription  Detects socket connection attempts using common APIs or ConnectEx  \n             setup.                                                             \nscope        basic block                                                        \nmatches      0x43114A                                                           \n             0x45636D                                                           \n             0x46C90A                                                           \n             0x46D1B4                                                           \n             0x478466                                                           \n             0x47F4D7                                                           \n             0x480DC1                                                           \n\nget socket status (2 matches)\nnamespace  communication/socket\nscope      function            \nmatches    0x438B80            \n           0x46C620            \n\ninitialize Winsock library (2 matches)\nnamespace  communication/socket\nscope      function            \nmatches    0x417D50            \n           0x427A30            \n\nreceive data on socket (11 matches)\nnamespace  communication/socket/receive\nscope      function                    \nmatches    0x401000                    \n           0x40C6D0                    \n           0x427A30                    \n           0x430F30                    \n           0x438B80                    \n           0x444590                    \n           0x44FF20                    \n           0x453FB0                    \n           0x454550                    \n           0x46C620                    \n           0x47ED20                    \n\nsend data on socket (10 matches)\nnamespace  communication/socket/send\nscope      function                 \nmatches    0x427A30                 \n           0x430F30                 \n           0x438AD0                 \n           0x438B80                 \n           0x452930                 \n           0x454550                 \n           0x46C620                 \n           0x472DA0                 \n           0x479520                 \n           0x47ED20                 \n\nconnect TCP socket (6 matches)\nnamespace  communication/socket/tcp\nscope      function                \nmatches    0x430F30                \n           0x454550                \n           0x46C620                \n           0x478270                \n           0x47ED20                \n           0x480C50                \n\ncreate TCP socket (12 matches)\nnamespace  communication/socket/tcp\nscope      basic block             \nmatches    0x416DB0                \n           0x41CD34                \n           0x41CE38                \n           0x42C187                \n           0x43111B                \n           0x454797                \n           0x46B215                \n           0x46C8E4                \n           0x46D0C8                \n           0x478270                \n           0x47F3AF                \n           0x480D19                \n\nconnect UDP socket (4 matches)\nnamespace    communication/socket/udp                                           \ndescription  Detects UDP socket connections by combining UDP socket creation    \n             with connection attempts.                                          \nscope        function                                                           \nmatches      0x430F30                                                           \n             0x46C620                                                           \n             0x478270                                                           \n             0x480C50                                                           \n\ncreate UDP socket (10 matches)\nnamespace  communication/socket/udp/send\nscope      basic block                  \nmatches    0x416DB0                     \n           0x41CD34                     \n           0x41CE38                     \n           0x42C187                     \n           0x43111B                     \n           0x46B215                     \n           0x46C8E4                     \n           0x46D0C8                     \n           0x478270                     \n           0x480D19                     \n\nact as TCP client (6 matches)\nnamespace  communication/tcp/client\nscope      function                \nmatches    0x430F30                \n           0x454550                \n           0x46C620                \n           0x478270                \n           0x47ED20                \n           0x480C50                \n\nstart TCP server (3 matches)\nnamespace  communication/tcp/serve\nscope      function               \nmatches    0x416DB0               \n           0x427A30               \n           0x46B0F0               \n\nvalidate payment card number using luhn algorithm\nnamespace  data-manipulation/checksum/luhn\nscope      function                       \nmatches    0x40C280                       \n\nencrypt data using HC-128\nnamespace    data-manipulation/encryption/hc-128                                \ndescription  Looks for instruction mnemonics associated with initialization of  \n             the HC-128 stream cipher                                           \nscope        basic block                                                        \nmatches      0x4731AA                                                           \n\nencrypt data using RC4 PRGA (2 matches)\nnamespace  data-manipulation/encryption/rc4\nscope      function                        \nmatches    0x41A3D0                        \n           0x479620                        \n\ncheck if file exists\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x4A620D                           \n\nget file attributes\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x4A6247                         \n\nread file on Windows (3 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x414C50                         \n           0x427A30                         \n           0x43C060                         \n\nwrite file on Windows (7 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x414C50                          \n           0x41D340                          \n           0x4236B0                          \n           0x427A30                          \n           0x43C060                          \n           0x468670                          \n           0x4796C0                          \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x4962A9                          \n\nallocate thread local storage\nnamespace  host-interaction/thread/tls\nscope      function                   \nmatches    0x49E1C5                   \n\nlink function at runtime on Windows (164 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x40F402               \n           0x40F552               \n           0x40F591               \n           0x413D72               \n           0x413DFE               \n           0x413E13               \n           0x413E29               \n           0x413E58               \n           0x413E6E               \n           0x427C7B               \n           0x427CBA               \n           0x427CF9               \n           0x427D38               \n           0x427D77               \n           0x427E13               \n           0x427E6F               \n           0x427EEB               \n           0x427FA0               \n           0x428029               \n           0x4280BA               \n           0x428123               \n           0x428174               \n           0x428207               \n           0x428245               \n           0x428283               \n           0x4282C1               \n           0x4282FF               \n           0x42833D               \n           0x428375               \n           0x4283B0               \n           0x4283EE               \n           0x42842C               \n           0x428464               \n           0x42849F               \n           0x4284DD               \n           0x42854D               \n           0x42858B               \n           0x4285F1               \n           0x4286D2               \n           0x42873D               \n           0x42877B               \n           0x4287B9               \n           0x428804               \n           0x428856               \n           0x4288C0               \n           0x428948               \n           0x428986               \n           0x4289F8               \n           0x428A36               \n           0x428A74               \n           0x428AB2               \n           0x428B44               \n           0x428B83               \n           0x428C0D               \n           0x428C5E               \n           0x428C9D               \n           0x428CD6               \n           0x428D12               \n           0x428D51               \n           0x428D90               \n           0x428DC9               \n           0x428E05               \n           0x428EAB               \n           0x428EF6               \n           0x429021               \n           0x429060               \n           0x429099               \n           0x4290D5               \n           0x429131               \n           0x42916F               \n           0x4291A7               \n           0x42920B               \n           0x4292D2               \n           0x429310               \n           0x429375               \n           0x4293FD               \n           0x42943C               \n           0x429499               \n           0x4295E0               \n           0x4296C6               \n           0x429726               \n           0x429790               \n           0x4298A5               \n           0x4298E4               \n           0x429948               \n           0x4299A0               \n           0x429A3D               \n           0x429A7B               \n           0x429AD9               \n           0x429B30               \n           0x429B7E               \n           0x429CAE               \n           0x429D04               \n           0x429D62               \n           0x429DA0               \n           0x429E00               \n           0x429E4E               \n           0x429EAC               \n           0x429F0C               \n           0x429F4B               \n           0x429F8A               \n           0x429FD9               \n           0x42A018               \n           0x42A0B5               \n           0x42A1AC               \n           0x42A1E4               \n           0x42A21F               \n           0x42A25D               \n           0x42A2D7               \n           0x42A3D5               \n           0x42A411               \n           0x42A450               \n           0x42A501               \n           0x42A53F               \n           0x42A57D               \n           0x42A5E6               \n           0x42A66B               \n           0x42A6C6               \n           0x42A73D               \n           0x42A7B5               \n           0x42A800               \n           0x42A852               \n           0x42A89D               \n           0x42A936               \n           0x42A98D               \n           0x42A9CB               \n           0x42AA03               \n           0x42AAD0               \n           0x42AB0F               \n           0x42D726               \n           0x44009F               \n           0x443724               \n           0x446B97               \n           0x446BFB               \n           0x446C7D               \n           0x446CEE               \n           0x446DEA               \n           0x446E2F               \n           0x446E77               \n           0x446F37               \n           0x446FC7               \n           0x4470E7               \n           0x44716A               \n           0x44DACD               \n           0x451789               \n           0x4517BE               \n           0x4654E3               \n           0x465652               \n           0x465768               \n           0x4669A3               \n           0x4669D8               \n           0x467481               \n           0x46750B               \n           0x46755D               \n           0x4675CD               \n           0x467631               \n           0x467701               \n           0x4677C2               \n           0x47D244               \n           0x4AA838               \n           0x4AA855               \n           0x4AA86A               \n           0x4AA87F               \n           0x4AA897               \n\nlink many functions at runtime (5 matches)\nnamespace  linking/runtime-linking\nscope      function               \nmatches    0x413B70               \n           0x427A30               \n           0x4464D0               \n           0x466F90               \n           0x4AA7F4               \n\nlinked against CPP standard library\nnamespace  linking/static\nscope      file          \n\n\n\n","very_verbose":"md5                     ed2cd14a28ff2d00a5cefcf6a074af8d                        \nsha1                    5b3e04f8208d3de912413efce27372255d6b3fe9                \nsha256                  eea059174127860154f4dce1a7d8995a9a5056febf73819d63ddadb…\npath                    /home/apogean/projects/malware/windows/all_runs/Nivdort…\ntimestamp               2026-07-10 01:19:00.892155                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIt4RZsY/rules                                   \nfunction count          1002                                                    \nlibrary function count  565                                                     \ntotal feature count     56215                                                   \n\ncalculate modulo 256 via x86 assembly (10 matches, only showing first match of \nlibrary rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x4222E3\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x4222E3\n    or:\n      number: 0xFF @ 0x4222E3\n\ncontain loop (273 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401000\n  or:\n    characteristic: loop @ 0x401000\n\ncreate or open file (library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x4AE809\n  or:\n    api: CreateFile @ 0x4AE809\n\nvalidate payment card number using luhn algorithm with no lookup table (library \nrule)\nauthor  @_re_fox                        \nscope   function                        \nmbc     Data::Checksum::Luhn [C0032.002]\nfunction @ 0x40C280\n  and:\n    characteristic: loop = Iterate over CC digits @ 0x40C280\n    basic block:\n      or:\n        and: = Final section returning checkum % 10\n          or:\n            and:\n              mnemonic: idiv @ 0x40C46C\n              mnemonic: cdq @ 0x40C466\n          number: 0xA @ 0x40C467\n    or:\n      instruction:\n        and:\n          offset: -0x30 @ 0x40C444\n          mnemonic: lea @ 0x40C444\n    or:\n      basic block:\n        and: = Digital Root check number*2 < 0x9\n          instruction:\n            and:\n              mnemonic: cmp @ 0x40C3CD\n              number: 0x9 @ 0x40C3CD\n          or:\n            mnemonic: add = add al, al @ 0x40C3A1, 0x40C3C4\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x40C3CD\n            number: 0x9 @ 0x40C3CD\n        basic block:\n          or: = 2*Number for Digital Root\n            mnemonic: add = add al, al @ 0x40C29C, 0x40C2B5\n          or: = 2*Number for Digital Root\n            mnemonic: add = add al, al @ 0x40C2E7\n          or: = 2*Number for Digital Root\n            mnemonic: add = add al, al @ 0x40C419\n          or: = 2*Number for Digital Root\n            mnemonic: add = add al, al @ 0x40C34B, 0x40C351\n          or: = 2*Number for Digital Root\n            mnemonic: add = add al, al @ 0x40C2FE, 0x40C313, 0x40C31F\n          or: = 2*Number for Digital Root\n            mnemonic: add = add al, al @ 0x40C33A\n          or: = 2*Number for Digital Root\n            mnemonic: add = add al, al @ 0x40C43B\n          or: = 2*Number for Digital Root\n            mnemonic: add = add al, al @ 0x40C3DF\n          or: = 2*Number for Digital Root\n            mnemonic: add = add al, al @ 0x40C3A1, 0x40C3C4\n\ncontain obfuscated stackstrings (2 matches)\nnamespace  anti-analysis/obfuscation/string/stackstring                         \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information::Indicator Removal  \n           from Tools [T1027.005]                                               \nmbc        Anti-Static Analysis::Executable Code Obfuscation::Argument          \n           Obfuscation [B0032.020], Anti-Static Analysis::Executable Code       \n           Obfuscation::Stack Strings [B0032.017]                               \nbasic block @ 0x413C01 in function 0x413B70\n  characteristic: stack string @ 0x413C01\nbasic block @ 0x471C80 in function 0x471870\n  characteristic: stack string @ 0x471C80\n\nreceive data (11 matches)\nnamespace    communication                                                     \nauthor       william.ballenthin@mandiant.com                                   \nscope        function                                                          \nmbc          Command and Control::C2 Communication::Receive Data [B0030.002]   \ndescription  all known techniques for receiving data from a potential C2 server\nfunction @ 0x401000\n  or:\n    match: receive data on socket @ 0x401000\n      or:\n        api: recv @ 0x4010A1\nfunction @ 0x40C6D0\n  or:\n    match: receive data on socket @ 0x40C6D0\n      or:\n        api: recv @ 0x40C747\nfunction @ 0x427A30\n  or:\n    match: receive data on socket @ 0x427A30\n      or:\n        api: recv @ 0x42C3C1, 0x42C4A9\nfunction @ 0x430F30\n  or:\n    match: receive data on socket @ 0x430F30\n      or:\n        api: recv @ 0x43157F\nfunction @ 0x438B80\n  or:\n    match: receive data on socket @ 0x438B80\n      or:\n        api: recv @ 0x438FFD, 0x439108\nfunction @ 0x444590\n  or:\n    match: receive data on socket @ 0x444590\n      or:\n        api: recv @ 0x4445EB, 0x444636\nfunction @ 0x44FF20\n  or:\n    match: receive data on socket @ 0x44FF20\n      or:\n        api: recv @ 0x44FFE7\nfunction @ 0x453FB0\n  or:\n    match: receive data on socket @ 0x453FB0\n      or:\n        api: recv @ 0x454049\nfunction @ 0x454550\n  or:\n    match: receive data on socket @ 0x454550\n      or:\n        api: recv @ 0x462291, 0x462364\nfunction @ 0x46C620\n  or:\n    match: receive data on socket @ 0x46C620\n      or:\n        api: recv @ 0x46CBE9, 0x46D6EE, 0x46D791\nfunction @ 0x47ED20\n  or:\n    match: receive data on socket @ 0x47ED20\n      or:\n        api: recv @ 0x47F600\n\nsend data (10 matches)\nnamespace    communication                                                 \nauthor       william.ballenthin@mandiant.com, joakim@intezer.com           \nscope        function                                                      \nmbc          Command and Control::C2 Communication::Send Data [B0030.001]  \ndescription  all known techniques for sending data to a potential C2 server\nfunction @ 0x427A30\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x427A30\n          or:\n            api: send @ 0x42C42D\nfunction @ 0x430F30\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x430F30\n          or:\n            api: send @ 0x4311A5, 0x4312ED\nfunction @ 0x438AD0\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x438AD0\n          or:\n            api: send @ 0x438B6E\nfunction @ 0x438B80\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x438B80\n          or:\n            api: send @ 0x43902B, 0x439136\nfunction @ 0x452930\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x452930\n          or:\n            api: send @ 0x452A2E, 0x452AD4, 0x452B5C\nfunction @ 0x454550\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x454550\n          or:\n            api: send @ 0x46205D, 0x4622F8, 0x462D3D, 0x462F52\nfunction @ 0x46C620\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x46C620\n          or:\n            api: send @ 0x46C949, 0x46C9FD, 0x46CF5C, 0x46CF90, and 69 more...\nfunction @ 0x472DA0\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x472DA0\n          or:\n            api: send @ 0x472DE6\nfunction @ 0x479520\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x479520\n          or:\n            api: send @ 0x47955A\nfunction @ 0x47ED20\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x47ED20\n          or:\n            api: send @ 0x47F548\n\ndownload and write a file\nnamespace              communication/c2/file-transfer                           \nmaec/malware-category  downloader                                               \nauthor                 moritz.raabe@mandiant.com                                \nscope                  function                                                 \natt&ck                 Command and Control::Ingress Tool Transfer [T1105]       \nmbc                    Command and Control::C2 Communication::Server to Client  \n                       File Transfer [B0030.003]                                \nfunction @ 0x427A30\n  and:\n    match: receive data @ 0x427A30\n      or:\n        match: receive data on socket @ 0x427A30\n          or:\n            api: recv @ 0x42C3C1, 0x42C4A9\n    match: host-interaction/file-system/write @ 0x427A30\n      or:\n        and:\n          os: windows\n          optional:\n            basic block:\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x427C1A\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42B327\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42C18B\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42E5C5\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42B29E, 0x42B2EC\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42F01D\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x427B61\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42C7A9, 0x42C81C\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42E6A6\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42D8A4, 0x42D8DF\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42C1A7\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42D4A8\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42CDAA, 0x42CDE5\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42B42B\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42C240\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42B7DB\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42B23A, 0x42B275\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x428BA1\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42DCCA\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42F2FB\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42E86D\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42CCC0\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42D74C\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42EED4\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42B063\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42C710\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42C780\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42BF5D\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42C040\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42CA60\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42DEFC\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42CA6A\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42D979\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42B103, 0x42B133\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42ED2B\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42D905, 0x42D953\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42CE0E, 0x42CE72\n          or:\n            api: _fwrite @ 0x42E437, 0x42E590\n            api: fwrite @ 0x42E437, 0x42E590\n\nread and send data from client to server\nnamespace  communication/c2/file-transfer \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x427A30\n  and:\n    match: host-interaction/file-system/read @ 0x427A30\n      or:\n        and:\n          os: windows\n          or:\n            api: fread @ 0x42CFE4\n    match: send data @ 0x427A30\n      or:\n        and:\n          os: windows\n          or:\n            match: send data on socket @ 0x427A30\n              or:\n                api: send @ 0x42C42D\n\nreceive and write data from server to client\nnamespace  communication/c2/file-transfer \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x427A30\n  and:\n    match: receive data @ 0x427A30\n      or:\n        match: receive data on socket @ 0x427A30\n          or:\n            api: recv @ 0x42C3C1, 0x42C4A9\n    match: host-interaction/file-system/write @ 0x427A30\n      or:\n        and:\n          os: windows\n          optional:\n            basic block:\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x427C1A\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42B327\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42C18B\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42E5C5\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42B29E, 0x42B2EC\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42F01D\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x427B61\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42C7A9, 0x42C81C\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42E6A6\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42D8A4, 0x42D8DF\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42C1A7\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42D4A8\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42CDAA, 0x42CDE5\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42B42B\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42C240\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42B7DB\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42B23A, 0x42B275\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x428BA1\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42DCCA\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42F2FB\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42E86D\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42CCC0\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42D74C\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42EED4\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42B063\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42C710\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42C780\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42BF5D\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42C040\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42CA60\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42DEFC\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42CA6A\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42D979\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42B103, 0x42B133\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42ED2B\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42D905, 0x42D953\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x42CE0E, 0x42CE72\n          or:\n            api: _fwrite @ 0x42E437, 0x42E590\n            api: fwrite @ 0x42E437, 0x42E590\n\nresolve DNS (4 matches)\nnamespace  communication/dns                                                    \nauthor     william.ballenthin@mandiant.com, johnk3r, joakim@intezer.com,        \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::DNS Communication::Resolve [C0011.001]                \nfunction @ 0x4242F0\n  or:\n    api: gethostbyname @ 0x424ABB\nfunction @ 0x4631A0\n  or:\n    api: gethostbyname @ 0x4633B6\nfunction @ 0x478270\n  or:\n    api: gethostbyname @ 0x4783D9\nfunction @ 0x47ED20\n  or:\n    api: gethostbyname @ 0x47F3E5\n\nconnect socket (7 matches)\nnamespace    communication/socket                                               \nauthor       moritz.raabe@mandiant.com, joakim@intezer.com,                     \n             mrhafizfarhad@gmail.com                                            \nscope        basic block                                                        \ndescription  Detects socket connection attempts using common APIs or ConnectEx  \n             setup.                                                             \nbasic block @ 0x43114A in function 0x430F30\n  or:\n    api: connect @ 0x431154\nbasic block @ 0x45636D in function 0x454550\n  or:\n    api: connect @ 0x45637A\nbasic block @ 0x46C90A in function 0x46C620\n  or:\n    api: connect @ 0x46C914\nbasic block @ 0x46D1B4 in function 0x46C620\n  or:\n    api: connect @ 0x46D24E\nbasic block @ 0x478466 in function 0x478270\n  or:\n    api: connect @ 0x478476\nbasic block @ 0x47F4D7 in function 0x47ED20\n  or:\n    api: connect @ 0x47F4F0\nbasic block @ 0x480DC1 in function 0x480C50\n  or:\n    api: connect @ 0x480DEA\n\nget socket status (2 matches)\nnamespace  communication/socket                                              \nauthor     michael.hunhoff@mandiant.com                                      \nscope      function                                                          \natt&ck     Discovery::System Network Configuration Discovery [T1016]         \nmbc        Communication::Socket Communication::Get Socket Status [C0001.012]\nfunction @ 0x438B80\n  or:\n    api: select @ 0x438F0D\nfunction @ 0x46C620\n  or:\n    api: select @ 0x46D6AE\n\ninitialize Winsock library (2 matches)\nnamespace  communication/socket                                                 \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Initialize Winsock Library      \n           [C0001.009]                                                          \nfunction @ 0x417D50\n  or:\n    api: WSAStartup @ 0x417DED\nfunction @ 0x427A30\n  or:\n    api: WSAStartup @ 0x42C159, 0x42ECDB\n\nreceive data on socket (11 matches)\nnamespace  communication/socket/receive                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Receive Data [C0001.006]        \nfunction @ 0x401000\n  or:\n    api: recv @ 0x4010A1\nfunction @ 0x40C6D0\n  or:\n    api: recv @ 0x40C747\nfunction @ 0x427A30\n  or:\n    api: recv @ 0x42C3C1, 0x42C4A9\nfunction @ 0x430F30\n  or:\n    api: recv @ 0x43157F\nfunction @ 0x438B80\n  or:\n    api: recv @ 0x438FFD, 0x439108\nfunction @ 0x444590\n  or:\n    api: recv @ 0x4445EB, 0x444636\nfunction @ 0x44FF20\n  or:\n    api: recv @ 0x44FFE7\nfunction @ 0x453FB0\n  or:\n    api: recv @ 0x454049\nfunction @ 0x454550\n  or:\n    api: recv @ 0x462291, 0x462364\nfunction @ 0x46C620\n  or:\n    api: recv @ 0x46CBE9, 0x46D6EE, 0x46D791\nfunction @ 0x47ED20\n  or:\n    api: recv @ 0x47F600\n\nsend data on socket (10 matches)\nnamespace  communication/socket/send                                            \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Communication::Socket Communication::Send Data [C0001.007]           \nfunction @ 0x427A30\n  or:\n    api: send @ 0x42C42D\nfunction @ 0x430F30\n  or:\n    api: send @ 0x4311A5, 0x4312ED\nfunction @ 0x438AD0\n  or:\n    api: send @ 0x438B6E\nfunction @ 0x438B80\n  or:\n    api: send @ 0x43902B, 0x439136\nfunction @ 0x452930\n  or:\n    api: send @ 0x452A2E, 0x452AD4, 0x452B5C\nfunction @ 0x454550\n  or:\n    api: send @ 0x46205D, 0x4622F8, 0x462D3D, 0x462F52\nfunction @ 0x46C620\n  or:\n    api: send @ 0x46C949, 0x46C9FD, 0x46CF5C, 0x46CF90, and 69 more...\nfunction @ 0x472DA0\n  or:\n    api: send @ 0x472DE6\nfunction @ 0x479520\n  or:\n    api: send @ 0x47955A\nfunction @ 0x47ED20\n  or:\n    api: send @ 0x47F548\n\nconnect TCP socket (6 matches)\nnamespace  communication/socket/tcp                                             \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           mrhafizfarhad@gmail.com                                              \nscope      function                                                             \nmbc        Communication::Socket Communication::Connect Socket [C0001.004]      \nfunction @ 0x430F30\n  and:\n    match: create TCP socket @ 0x43111B\n      or:\n        and:\n          or:\n            number: 0x0 = protocol (default) @ 0x43111B\n          number: 0x1 = SOCK_STREAM @ 0x43111D\n          number: 0x2 = AF_INET @ 0x43111F\n          or:\n            api: socket @ 0x431121\n    match: connect socket @ 0x43114A\n      or:\n        api: connect @ 0x431154\nfunction @ 0x454550\n  and:\n    match: create TCP socket @ 0x454797\n      or:\n        and:\n          or:\n            number: 0x6 = IPPROTO_TCP @ 0x454797\n          number: 0x1 = SOCK_STREAM @ 0x454799\n          number: 0x2 = AF_INET @ 0x45479B\n          or:\n            api: socket @ 0x45479D\n    match: connect socket @ 0x45636D\n      or:\n        api: connect @ 0x45637A\nfunction @ 0x46C620\n  and:\n    match: create TCP socket @ 0x46C8E4, 0x46D0C8\n      or:\n        and:\n          or:\n            number: 0x0 = protocol (default) @ 0x46D0C8\n          number: 0x1 = SOCK_STREAM @ 0x46D0CA\n          number: 0x2 = AF_INET @ 0x46D0CC\n          or:\n            api: socket @ 0x46D0CE\n      or:\n        and:\n          or:\n            number: 0x0 = protocol (default) @ 0x46C8EE\n          number: 0x1 = SOCK_STREAM @ 0x46C8E4, 0x46C8F0\n          number: 0x2 = AF_INET @ 0x46C8F2\n          or:\n            api: socket @ 0x46C8F4\n    match: connect socket @ 0x46C90A, 0x46D1B4\n      or:\n        api: connect @ 0x46C914\n      or:\n        api: connect @ 0x46D24E\nfunction @ 0x478270\n  and:\n    match: create TCP socket @ 0x478270\n      or:\n        and:\n          or:\n            number: 0x0 = protocol (default) @ 0x478293\n            number: 0x6 = IPPROTO_TCP @ 0x47829A\n          number: 0x1 = SOCK_STREAM @ 0x47829C, 0x4782D3\n          number: 0x2 = AF_INET @ 0x47829E\n          or:\n            api: socket @ 0x4782A0\n    match: connect socket @ 0x478466\n      or:\n        api: connect @ 0x478476\nfunction @ 0x47ED20\n  and:\n    match: create TCP socket @ 0x47F3AF\n      or:\n        and:\n          or:\n            number: 0x6 = IPPROTO_TCP @ 0x47F3AF\n          number: 0x1 = SOCK_STREAM @ 0x47F3B1\n          number: 0x2 = AF_INET @ 0x47F3B3\n          or:\n            api: socket @ 0x47F3B5\n    match: connect socket @ 0x47F4D7\n      or:\n        api: connect @ 0x47F4F0\nfunction @ 0x480C50\n  and:\n    match: create TCP socket @ 0x480D19\n      or:\n        and:\n          or:\n            number: 0x0 = protocol (default) @ 0x480D21, 0x480D56, 0x480D89\n          number: 0x1 = SOCK_STREAM @ 0x480D8B\n          number: 0x2 = AF_INET @ 0x480D2F, 0x480D8D\n          or:\n            api: socket @ 0x480D8F\n    match: connect socket @ 0x480DC1\n      or:\n        api: connect @ 0x480DEA\n\ncreate TCP socket (12 matches)\nnamespace   communication/socket/tcp                                            \nauthor      william.ballenthin@mandiant.com, joakim@intezer.com,                \n            anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com       \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create TCP Socket [C0001.011]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ 0x416DB0 in function 0x416DB0\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ 0x416DFB\n      number: 0x1 = SOCK_STREAM @ 0x416DC5, 0x416DF2, 0x416DFD\n      number: 0x2 = AF_INET @ 0x416DFF\n      or:\n        api: socket @ 0x416E01\nbasic block @ 0x41CD34 in function 0x41CCE0\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ 0x41CD34\n      number: 0x1 = SOCK_STREAM @ 0x41CD36\n      number: 0x2 = AF_INET @ 0x41CD38\n      or:\n        api: socket @ 0x41CD3A\nbasic block @ 0x41CE38 in function 0x41CCE0\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ 0x41CE38\n      number: 0x1 = SOCK_STREAM @ 0x41CE3A\n      number: 0x2 = AF_INET @ 0x41CE3C\n      or:\n        api: socket @ 0x41CE3E\nbasic block @ 0x42C187 in function 0x427A30\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ 0x42C187\n      number: 0x1 = SOCK_STREAM @ 0x42C189\n      number: 0x2 = AF_INET @ 0x42C18B\n      or:\n        api: socket @ 0x42C18D\nbasic block @ 0x43111B in function 0x430F30\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ 0x43111B\n      number: 0x1 = SOCK_STREAM @ 0x43111D\n      number: 0x2 = AF_INET @ 0x43111F\n      or:\n        api: socket @ 0x431121\nbasic block @ 0x454797 in function 0x454550\n  or:\n    and:\n      or:\n        number: 0x6 = IPPROTO_TCP @ 0x454797\n      number: 0x1 = SOCK_STREAM @ 0x454799\n      number: 0x2 = AF_INET @ 0x45479B\n      or:\n        api: socket @ 0x45479D\nbasic block @ 0x46B215 in function 0x46B0F0\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ 0x46B21A\n      number: 0x1 = SOCK_STREAM @ 0x46B21C, 0x46B24C\n      number: 0x2 = AF_INET @ 0x46B21E\n      or:\n        api: socket @ 0x46B220\nbasic block @ 0x46C8E4 in function 0x46C620\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ 0x46C8EE\n      number: 0x1 = SOCK_STREAM @ 0x46C8E4, 0x46C8F0\n      number: 0x2 = AF_INET @ 0x46C8F2\n      or:\n        api: socket @ 0x46C8F4\nbasic block @ 0x46D0C8 in function 0x46C620\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ 0x46D0C8\n      number: 0x1 = SOCK_STREAM @ 0x46D0CA\n      number: 0x2 = AF_INET @ 0x46D0CC\n      or:\n        api: socket @ 0x46D0CE\nbasic block @ 0x478270 in function 0x478270\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ 0x478293\n        number: 0x6 = IPPROTO_TCP @ 0x47829A\n      number: 0x1 = SOCK_STREAM @ 0x47829C, 0x4782D3\n      number: 0x2 = AF_INET @ 0x47829E\n      or:\n        api: socket @ 0x4782A0\nbasic block @ 0x47F3AF in function 0x47ED20\n  or:\n    and:\n      or:\n        number: 0x6 = IPPROTO_TCP @ 0x47F3AF\n      number: 0x1 = SOCK_STREAM @ 0x47F3B1\n      number: 0x2 = AF_INET @ 0x47F3B3\n      or:\n        api: socket @ 0x47F3B5\nbasic block @ 0x480D19 in function 0x480C50\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ 0x480D21, 0x480D56, 0x480D89\n      number: 0x1 = SOCK_STREAM @ 0x480D8B\n      number: 0x2 = AF_INET @ 0x480D2F, 0x480D8D\n      or:\n        api: socket @ 0x480D8F\n\nconnect UDP socket (4 matches)\nnamespace    communication/socket/udp                                           \nauthor       mrhafizfarhad@gmail.com                                            \nscope        function                                                           \nmbc          Communication::Socket Communication::UDP Client [C0001.013]        \ndescription  Detects UDP socket connections by combining UDP socket creation    \n             with connection attempts.                                          \nfunction @ 0x430F30\n  and:\n    match: create UDP socket @ 0x43111B\n      or:\n        and:\n          number: 0x2 = AF_INET @ 0x43111F\n          or:\n            number: 0x0 = protocol (default) @ 0x43111B\n          or:\n            api: socket @ 0x431121\n    match: connect socket @ 0x43114A\n      or:\n        api: connect @ 0x431154\nfunction @ 0x46C620\n  and:\n    match: create UDP socket @ 0x46C8E4, 0x46D0C8\n      or:\n        and:\n          number: 0x2 = AF_INET @ 0x46D0CC\n          or:\n            number: 0x0 = protocol (default) @ 0x46D0C8\n          or:\n            api: socket @ 0x46D0CE\n      or:\n        and:\n          number: 0x2 = AF_INET @ 0x46C8F2\n          or:\n            number: 0x0 = protocol (default) @ 0x46C8EE\n          or:\n            api: socket @ 0x46C8F4\n    match: connect socket @ 0x46C90A, 0x46D1B4\n      or:\n        api: connect @ 0x46C914\n      or:\n        api: connect @ 0x46D24E\nfunction @ 0x478270\n  and:\n    match: create UDP socket @ 0x478270\n      or:\n        and:\n          number: 0x2 = AF_INET @ 0x47829E\n          or:\n            number: 0x0 = protocol (default) @ 0x478293\n          or:\n            api: socket @ 0x4782A0\n    match: connect socket @ 0x478466\n      or:\n        api: connect @ 0x478476\nfunction @ 0x480C50\n  and:\n    match: create UDP socket @ 0x480D19\n      or:\n        and:\n          number: 0x2 = AF_INET @ 0x480D2F, 0x480D8D\n          or:\n            number: 0x0 = protocol (default) @ 0x480D21, 0x480D56, 0x480D89\n          or:\n            api: socket @ 0x480D8F\n    match: connect socket @ 0x480DC1\n      or:\n        api: connect @ 0x480DEA\n\ncreate UDP socket (10 matches)\nnamespace   communication/socket/udp/send                                       \nauthor      moritz.raabe@mandiant.com, joakim@intezer.com,                      \n            michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create UDP Socket [C0001.010]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ 0x416DB0 in function 0x416DB0\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x416DFF\n      or:\n        number: 0x0 = protocol (default) @ 0x416DFB\n      or:\n        api: socket @ 0x416E01\nbasic block @ 0x41CD34 in function 0x41CCE0\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x41CD38\n      or:\n        number: 0x0 = protocol (default) @ 0x41CD34\n      or:\n        api: socket @ 0x41CD3A\nbasic block @ 0x41CE38 in function 0x41CCE0\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x41CE3C\n      or:\n        number: 0x0 = protocol (default) @ 0x41CE38\n      or:\n        api: socket @ 0x41CE3E\nbasic block @ 0x42C187 in function 0x427A30\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x42C18B\n      or:\n        number: 0x0 = protocol (default) @ 0x42C187\n      or:\n        api: socket @ 0x42C18D\nbasic block @ 0x43111B in function 0x430F30\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x43111F\n      or:\n        number: 0x0 = protocol (default) @ 0x43111B\n      or:\n        api: socket @ 0x431121\nbasic block @ 0x46B215 in function 0x46B0F0\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x46B21E\n      or:\n        number: 0x0 = protocol (default) @ 0x46B21A\n      or:\n        api: socket @ 0x46B220\nbasic block @ 0x46C8E4 in function 0x46C620\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x46C8F2\n      or:\n        number: 0x0 = protocol (default) @ 0x46C8EE\n      or:\n        api: socket @ 0x46C8F4\nbasic block @ 0x46D0C8 in function 0x46C620\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x46D0CC\n      or:\n        number: 0x0 = protocol (default) @ 0x46D0C8\n      or:\n        api: socket @ 0x46D0CE\nbasic block @ 0x478270 in function 0x478270\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x47829E\n      or:\n        number: 0x0 = protocol (default) @ 0x478293\n      or:\n        api: socket @ 0x4782A0\nbasic block @ 0x480D19 in function 0x480C50\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x480D2F, 0x480D8D\n      or:\n        number: 0x0 = protocol (default) @ 0x480D21, 0x480D56, 0x480D89\n      or:\n        api: socket @ 0x480D8F\n\nact as TCP client (6 matches)\nnamespace  communication/tcp/client                                     \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                                     \nmbc        Communication::Socket Communication::TCP Client [C0001.008]  \nfunction @ 0x430F30\n  or:\n    match: connect TCP socket @ 0x430F30\n      and:\n        match: create TCP socket @ 0x43111B\n          or:\n            and:\n              or:\n                number: 0x0 = protocol (default) @ 0x43111B\n              number: 0x1 = SOCK_STREAM @ 0x43111D\n              number: 0x2 = AF_INET @ 0x43111F\n              or:\n                api: socket @ 0x431121\n        match: connect socket @ 0x43114A\n          or:\n            api: connect @ 0x431154\nfunction @ 0x454550\n  or:\n    match: connect TCP socket @ 0x454550\n      and:\n        match: create TCP socket @ 0x454797\n          or:\n            and:\n              or:\n                number: 0x6 = IPPROTO_TCP @ 0x454797\n              number: 0x1 = SOCK_STREAM @ 0x454799\n              number: 0x2 = AF_INET @ 0x45479B\n              or:\n                api: socket @ 0x45479D\n        match: connect socket @ 0x45636D\n          or:\n            api: connect @ 0x45637A\nfunction @ 0x46C620\n  or:\n    match: connect TCP socket @ 0x46C620\n      and:\n        match: create TCP socket @ 0x46C8E4, 0x46D0C8\n          or:\n            and:\n              or:\n                number: 0x0 = protocol (default) @ 0x46D0C8\n              number: 0x1 = SOCK_STREAM @ 0x46D0CA\n              number: 0x2 = AF_INET @ 0x46D0CC\n              or:\n                api: socket @ 0x46D0CE\n          or:\n            and:\n              or:\n                number: 0x0 = protocol (default) @ 0x46C8EE\n              number: 0x1 = SOCK_STREAM @ 0x46C8E4, 0x46C8F0\n              number: 0x2 = AF_INET @ 0x46C8F2\n              or:\n                api: socket @ 0x46C8F4\n        match: connect socket @ 0x46C90A, 0x46D1B4\n          or:\n            api: connect @ 0x46C914\n          or:\n            api: connect @ 0x46D24E\nfunction @ 0x478270\n  or:\n    match: connect TCP socket @ 0x478270\n      and:\n        match: create TCP socket @ 0x478270\n          or:\n            and:\n              or:\n                number: 0x0 = protocol (default) @ 0x478293\n                number: 0x6 = IPPROTO_TCP @ 0x47829A\n              number: 0x1 = SOCK_STREAM @ 0x47829C, 0x4782D3\n              number: 0x2 = AF_INET @ 0x47829E\n              or:\n                api: socket @ 0x4782A0\n        match: connect socket @ 0x478466\n          or:\n            api: connect @ 0x478476\nfunction @ 0x47ED20\n  or:\n    match: connect TCP socket @ 0x47ED20\n      and:\n        match: create TCP socket @ 0x47F3AF\n          or:\n            and:\n              or:\n                number: 0x6 = IPPROTO_TCP @ 0x47F3AF\n              number: 0x1 = SOCK_STREAM @ 0x47F3B1\n              number: 0x2 = AF_INET @ 0x47F3B3\n              or:\n                api: socket @ 0x47F3B5\n        match: connect socket @ 0x47F4D7\n          or:\n            api: connect @ 0x47F4F0\nfunction @ 0x480C50\n  or:\n    match: connect TCP socket @ 0x480C50\n      and:\n        match: create TCP socket @ 0x480D19\n          or:\n            and:\n              or:\n                number: 0x0 = protocol (default) @ 0x480D21, 0x480D56, 0x480D89\n              number: 0x1 = SOCK_STREAM @ 0x480D8B\n              number: 0x2 = AF_INET @ 0x480D2F, 0x480D8D\n              or:\n                api: socket @ 0x480D8F\n        match: connect socket @ 0x480DC1\n          or:\n            api: connect @ 0x480DEA\n\nstart TCP server (3 matches)\nnamespace  communication/tcp/serve                                          \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com    \nscope      function                                                         \nmbc        Communication::Socket Communication::Start TCP Server [C0001.005]\nfunction @ 0x416DB0\n  or:\n    and:\n      match: create TCP socket @ 0x416DB0\n        or:\n          and:\n            or:\n              number: 0x0 = protocol (default) @ 0x416DFB\n            number: 0x1 = SOCK_STREAM @ 0x416DC5, 0x416DF2, 0x416DFD\n            number: 0x2 = AF_INET @ 0x416DFF\n            or:\n              api: socket @ 0x416E01\n      api: listen @ 0x416EB4\n      or:\n        api: accept @ 0x417026\nfunction @ 0x427A30\n  or:\n    and:\n      match: create TCP socket @ 0x42C187\n        or:\n          and:\n            or:\n              number: 0x0 = protocol (default) @ 0x42C187\n            number: 0x1 = SOCK_STREAM @ 0x42C189\n            number: 0x2 = AF_INET @ 0x42C18B\n            or:\n              api: socket @ 0x42C18D\n      api: listen @ 0x42C26A\n      or:\n        api: accept @ 0x42C392\nfunction @ 0x46B0F0\n  or:\n    and:\n      match: create TCP socket @ 0x46B215\n        or:\n          and:\n            or:\n              number: 0x0 = protocol (default) @ 0x46B21A\n            number: 0x1 = SOCK_STREAM @ 0x46B21C, 0x46B24C\n            number: 0x2 = AF_INET @ 0x46B21E\n            or:\n              api: socket @ 0x46B220\n      api: listen @ 0x46B2DA\n      or:\n        api: accept @ 0x46B335\n\nvalidate payment card number using luhn algorithm\nnamespace  data-manipulation/checksum/luhn \nauthor     @_re_fox                        \nscope      function                        \nmbc        Data::Checksum::Luhn [C0032.002]\nfunction @ 0x40C280\n  or:\n    match: validate payment card number using luhn algorithm with no lookup table @ 0x40C280\n      and:\n        characteristic: loop = Iterate over CC digits @ 0x40C280\n        basic block:\n          or:\n            and: = Final section returning checkum % 10\n              or:\n                and:\n                  mnemonic: idiv @ 0x40C46C\n                  mnemonic: cdq @ 0x40C466\n              number: 0xA @ 0x40C467\n        or:\n          instruction:\n            and:\n              offset: -0x30 @ 0x40C444\n              mnemonic: lea @ 0x40C444\n        or:\n          basic block:\n            and: = Digital Root check number*2 < 0x9\n              instruction:\n                and:\n                  mnemonic: cmp @ 0x40C3CD\n                  number: 0x9 @ 0x40C3CD\n              or:\n                mnemonic: add = add al, al @ 0x40C3A1, 0x40C3C4\n          and:\n            instruction:\n              and:\n                mnemonic: cmp @ 0x40C3CD\n                number: 0x9 @ 0x40C3CD\n            basic block:\n              or: = 2*Number for Digital Root\n                mnemonic: add = add al, al @ 0x40C29C, 0x40C2B5\n              or: = 2*Number for Digital Root\n                mnemonic: add = add al, al @ 0x40C2E7\n              or: = 2*Number for Digital Root\n                mnemonic: add = add al, al @ 0x40C419\n              or: = 2*Number for Digital Root\n                mnemonic: add = add al, al @ 0x40C34B, 0x40C351\n              or: = 2*Number for Digital Root\n                mnemonic: add = add al, al @ 0x40C2FE, 0x40C313, 0x40C31F\n              or: = 2*Number for Digital Root\n                mnemonic: add = add al, al @ 0x40C33A\n              or: = 2*Number for Digital Root\n                mnemonic: add = add al, al @ 0x40C43B\n              or: = 2*Number for Digital Root\n                mnemonic: add = add al, al @ 0x40C3DF\n              or: = 2*Number for Digital Root\n                mnemonic: add = add al, al @ 0x40C3A1, 0x40C3C4\n\nencrypt data using HC-128\nnamespace    data-manipulation/encryption/hc-128                                \nauthor       awillia2@cisco.com                                                 \nscope        basic block                                                        \natt&ck       Defense Evasion::Obfuscated Files or Information [T1027]           \nmbc          Defense Evasion::Obfuscated Files or                               \n             Information::Encryption-Standard Algorithm [E1027.m05],            \n             Cryptography::Encrypt Data::HC-128 [C0027.006]                     \nreferences   https://download.bitdefender.com/resources/files/News/CaseStudies/…\n             https://github.com/rost1993/hc128/blob/master/hc128.c              \ndescription  Looks for instruction mnemonics associated with initialization of  \n             the HC-128 stream cipher                                           \nbasic block @ 0x4731AA in function 0x472FC0\n  and:\n    instruction:\n      and:\n        mnemonic: shl @ 0x4731C7\n        number: 0xF = (v << (32 - 17)) from ROTR32(x, 17) in F2(x) @ 0x4731C7\n    instruction:\n      and:\n        mnemonic: shr @ 0x4731B7\n        number: 0x11 = (v >> 17) from ROTR32(x, 17) in F2(x) @ 0x4731B7\n    instruction:\n      and:\n        mnemonic: shl @ 0x4731E9\n        number: 0xD = (v << (32 - 19)) from ROTR32(x, 19) in F2(x) @ 0x4731E9\n    instruction:\n      and:\n        mnemonic: shr @ 0x4731D9\n        number: 0x13 = (v >> 19) from ROTR32(x, 19) in F2(x) @ 0x4731D9\n    instruction:\n      and:\n        mnemonic: shr @ 0x4731FD\n        number: 0xA = (v >> 10) in F2(x) @ 0x4731FD\n    instruction:\n      and:\n        mnemonic: shl @ 0x473253\n        number: 0x19 = (v << (32 - 7)) from ROTR32(x, 7) in F1(x) @ 0x473253\n    instruction:\n      and:\n        mnemonic: shr @ 0x473243\n        number: 0x7 = (v >> 7) from ROTR32(x, 7) in F1(x) @ 0x473243\n    instruction:\n      and:\n        mnemonic: shl @ 0x473275\n        number: 0xE = (v << (32 - 18)) from ROTR32(x, 18) in F1(x) @ 0x473275\n    instruction:\n      and:\n        mnemonic: shr @ 0x473265\n        number: 0x12 = (v >> 18) from ROTR32(x, 18) in F1(X) @ 0x473265\n    instruction:\n      and:\n        mnemonic: shr @ 0x473289\n        number: 0x3 = (x >> 3) in F1(x) @ 0x473289\n    count(mnemonic(shl)): 4 @ 0x4731C7, 0x4731E9, 0x473253, 0x473275\n    count(mnemonic(shr)): 6 @ 0x4731B7, 0x4731D9, 0x4731FD, 0x473243, and 2 more...\n    count(mnemonic(or)): 4 @ 0x4731CA, 0x4731EC, 0x473256, 0x473278\n    count(characteristic(nzxor)): 4 @ 0x4731EE, 0x473200, 0x47327A, 0x47328C\n\nencrypt data using RC4 PRGA (2 matches)\nnamespace  data-manipulation/encryption/rc4                                     \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Encrypt Data::RC4 [C0027.009], Cryptography::Generate  \n           Pseudo-random Sequence::RC4 PRGA [C0021.004]                         \nfunction @ 0x41A3D0\n  and:\n    match: contain loop @ 0x41A3D0\n      or:\n        characteristic: loop @ 0x41A3D0\n    count(characteristic(nzxor)): 1 @ 0x41A459\n    count(characteristic(calls from)): 4 or fewer\n    count(basic block): between 4 and 50 @ 0x41A3D0, 0x41A415, 0x41A425, 0x41A43F, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x41A4F2, 0x41A4F6, 0x41A51E, 0x41A522\nfunction @ 0x479620\n  and:\n    match: contain loop @ 0x479620\n      or:\n        characteristic: loop @ 0x479620\n    count(characteristic(nzxor)): 1 @ 0x479672\n    count(characteristic(calls from)): 4 or fewer @ 0x443D10\n    count(basic block): between 4 and 50 @ 0x479620, 0x47963F, 0x47964B, 0x479659, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x47964E, 0x47965C, 0x479693, 0x4796A0\n\ncheck if file exists\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x4A620D\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x4A624A\n        instruction:\n          and:\n            mnemonic: cmp @ 0x4A6250\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x4A6250\n\nget file attributes\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x4A6247 in function 0x4A620D\n  or:\n    api: GetFileAttributes @ 0x4A624A\n\nread file on Windows (3 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x414C50\n  or:\n    and:\n      os: windows\n      or:\n        api: fread @ 0x414D6F\nfunction @ 0x427A30\n  or:\n    and:\n      os: windows\n      or:\n        api: fread @ 0x42CFE4\nfunction @ 0x43C060\n  or:\n    and:\n      os: windows\n      or:\n        api: fread @ 0x43C134\n\nwrite file on Windows (7 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x414C50\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4151CC\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x41517E\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4160A8, 0x416105\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x416358\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4166CA\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x415B32\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4156B8\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4150D8\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x414D0C\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x41583C\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x415B9E\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4155DF\n      or:\n        api: _fwrite @ 0x416AF5\n        api: fwrite @ 0x416AF5\nfunction @ 0x41D340\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x41D51E\n        api: fwrite @ 0x41D51E\nfunction @ 0x4236B0\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x42390E\n        api: fwrite @ 0x42390E\nfunction @ 0x427A30\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x427C1A\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42B327\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42C18B\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42E5C5\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42B29E, 0x42B2EC\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42F01D\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x427B61\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42C7A9, 0x42C81C\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42E6A6\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42D8A4, 0x42D8DF\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42C1A7\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42D4A8\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42CDAA, 0x42CDE5\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42B42B\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42C240\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42B7DB\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42B23A, 0x42B275\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x428BA1\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42DCCA\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42F2FB\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42E86D\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42CCC0\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42D74C\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42EED4\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42B063\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42C710\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42C780\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42BF5D\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42C040\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42CA60\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42DEFC\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42CA6A\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42D979\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42B103, 0x42B133\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42ED2B\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42D905, 0x42D953\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x42CE0E, 0x42CE72\n      or:\n        api: _fwrite @ 0x42E437, 0x42E590\n        api: fwrite @ 0x42E437, 0x42E590\nfunction @ 0x43C060\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x43C18E\n        api: fwrite @ 0x43C18E\nfunction @ 0x468670\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x468BA0\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x46872F\n      or:\n        api: _fwrite @ 0x4688C3\n        api: fwrite @ 0x4688C3\nfunction @ 0x4796C0\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x479789, 0x4797A5\n        api: fwrite @ 0x479789, 0x4797A5\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x4962A9\n  or:\n    and:\n      or:\n        api: TerminateProcess @ 0x49E85A\n\nallocate thread local storage\nnamespace  host-interaction/thread/tls                   \nauthor     michael.hunhoff@mandiant.com                  \nscope      function                                      \nmbc        Process::Allocate Thread Local Storage [C0040]\nfunction @ 0x49E1C5\n  or:\n    api: TlsAlloc @ 0x49E1C5\n\nlink function at runtime on Windows (164 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x40F402\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40F402\ninstruction @ 0x40F552\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40F552\ninstruction @ 0x40F591\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40F591\ninstruction @ 0x413D72\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x413D72\ninstruction @ 0x413DFE\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x413DFE\ninstruction @ 0x413E13\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x413E13\ninstruction @ 0x413E29\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x413E29\ninstruction @ 0x413E58\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x413E58\ninstruction @ 0x413E6E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x413E6E\ninstruction @ 0x427C7B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x427C7B\ninstruction @ 0x427CBA\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x427CBA\ninstruction @ 0x427CF9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x427CF9\ninstruction @ 0x427D38\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x427D38\ninstruction @ 0x427D77\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x427D77\ninstruction @ 0x427E13\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x427E13\ninstruction @ 0x427E6F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x427E6F\ninstruction @ 0x427EEB\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x427EEB\ninstruction @ 0x427FA0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x427FA0\ninstruction @ 0x428029\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428029\ninstruction @ 0x4280BA\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4280BA\ninstruction @ 0x428123\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428123\ninstruction @ 0x428174\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428174\ninstruction @ 0x428207\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428207\ninstruction @ 0x428245\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428245\ninstruction @ 0x428283\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428283\ninstruction @ 0x4282C1\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4282C1\ninstruction @ 0x4282FF\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4282FF\ninstruction @ 0x42833D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42833D\ninstruction @ 0x428375\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428375\ninstruction @ 0x4283B0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4283B0\ninstruction @ 0x4283EE\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4283EE\ninstruction @ 0x42842C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42842C\ninstruction @ 0x428464\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428464\ninstruction @ 0x42849F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42849F\ninstruction @ 0x4284DD\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4284DD\ninstruction @ 0x42854D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42854D\ninstruction @ 0x42858B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42858B\ninstruction @ 0x4285F1\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4285F1\ninstruction @ 0x4286D2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4286D2\ninstruction @ 0x42873D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42873D\ninstruction @ 0x42877B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42877B\ninstruction @ 0x4287B9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4287B9\ninstruction @ 0x428804\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428804\ninstruction @ 0x428856\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428856\ninstruction @ 0x4288C0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4288C0\ninstruction @ 0x428948\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428948\ninstruction @ 0x428986\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428986\ninstruction @ 0x4289F8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4289F8\ninstruction @ 0x428A36\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428A36\ninstruction @ 0x428A74\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428A74\ninstruction @ 0x428AB2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428AB2\ninstruction @ 0x428B44\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428B44\ninstruction @ 0x428B83\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428B83\ninstruction @ 0x428C0D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428C0D\ninstruction @ 0x428C5E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428C5E\ninstruction @ 0x428C9D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428C9D\ninstruction @ 0x428CD6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428CD6\ninstruction @ 0x428D12\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428D12\ninstruction @ 0x428D51\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428D51\ninstruction @ 0x428D90\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428D90\ninstruction @ 0x428DC9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428DC9\ninstruction @ 0x428E05\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428E05\ninstruction @ 0x428EAB\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428EAB\ninstruction @ 0x428EF6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x428EF6\ninstruction @ 0x429021\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429021\ninstruction @ 0x429060\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429060\ninstruction @ 0x429099\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429099\ninstruction @ 0x4290D5\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4290D5\ninstruction @ 0x429131\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429131\ninstruction @ 0x42916F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42916F\ninstruction @ 0x4291A7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4291A7\ninstruction @ 0x42920B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42920B\ninstruction @ 0x4292D2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4292D2\ninstruction @ 0x429310\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429310\ninstruction @ 0x429375\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429375\ninstruction @ 0x4293FD\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4293FD\ninstruction @ 0x42943C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42943C\ninstruction @ 0x429499\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429499\ninstruction @ 0x4295E0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4295E0\ninstruction @ 0x4296C6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4296C6\ninstruction @ 0x429726\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429726\ninstruction @ 0x429790\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429790\ninstruction @ 0x4298A5\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4298A5\ninstruction @ 0x4298E4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4298E4\ninstruction @ 0x429948\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429948\ninstruction @ 0x4299A0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4299A0\ninstruction @ 0x429A3D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429A3D\ninstruction @ 0x429A7B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429A7B\ninstruction @ 0x429AD9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429AD9\ninstruction @ 0x429B30\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429B30\ninstruction @ 0x429B7E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429B7E\ninstruction @ 0x429CAE\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429CAE\ninstruction @ 0x429D04\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429D04\ninstruction @ 0x429D62\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429D62\ninstruction @ 0x429DA0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429DA0\ninstruction @ 0x429E00\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429E00\ninstruction @ 0x429E4E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429E4E\ninstruction @ 0x429EAC\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429EAC\ninstruction @ 0x429F0C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429F0C\ninstruction @ 0x429F4B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429F4B\ninstruction @ 0x429F8A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429F8A\ninstruction @ 0x429FD9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x429FD9\ninstruction @ 0x42A018\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A018\ninstruction @ 0x42A0B5\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A0B5\ninstruction @ 0x42A1AC\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A1AC\ninstruction @ 0x42A1E4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A1E4\ninstruction @ 0x42A21F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A21F\ninstruction @ 0x42A25D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A25D\ninstruction @ 0x42A2D7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A2D7\ninstruction @ 0x42A3D5\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A3D5\ninstruction @ 0x42A411\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A411\ninstruction @ 0x42A450\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A450\ninstruction @ 0x42A501\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A501\ninstruction @ 0x42A53F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A53F\ninstruction @ 0x42A57D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A57D\ninstruction @ 0x42A5E6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A5E6\ninstruction @ 0x42A66B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A66B\ninstruction @ 0x42A6C6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A6C6\ninstruction @ 0x42A73D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A73D\ninstruction @ 0x42A7B5\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A7B5\ninstruction @ 0x42A800\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A800\ninstruction @ 0x42A852\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A852\ninstruction @ 0x42A89D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A89D\ninstruction @ 0x42A936\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A936\ninstruction @ 0x42A98D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A98D\ninstruction @ 0x42A9CB\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42A9CB\ninstruction @ 0x42AA03\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42AA03\ninstruction @ 0x42AAD0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42AAD0\ninstruction @ 0x42AB0F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42AB0F\ninstruction @ 0x42D726\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42D726\ninstruction @ 0x44009F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x44009F\ninstruction @ 0x443724\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x443724\ninstruction @ 0x446B97\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x446B97\ninstruction @ 0x446BFB\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x446BFB\ninstruction @ 0x446C7D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x446C7D\ninstruction @ 0x446CEE\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x446CEE\ninstruction @ 0x446DEA\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x446DEA\ninstruction @ 0x446E2F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x446E2F\ninstruction @ 0x446E77\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x446E77\ninstruction @ 0x446F37\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x446F37\ninstruction @ 0x446FC7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x446FC7\ninstruction @ 0x4470E7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4470E7\ninstruction @ 0x44716A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x44716A\ninstruction @ 0x44DACD\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x44DACD\ninstruction @ 0x451789\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x451789\ninstruction @ 0x4517BE\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4517BE\ninstruction @ 0x4654E3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4654E3\ninstruction @ 0x465652\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x465652\ninstruction @ 0x465768\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x465768\ninstruction @ 0x4669A3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4669A3\ninstruction @ 0x4669D8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4669D8\ninstruction @ 0x467481\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x467481\ninstruction @ 0x46750B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46750B\ninstruction @ 0x46755D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x46755D\ninstruction @ 0x4675CD\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4675CD\ninstruction @ 0x467631\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x467631\ninstruction @ 0x467701\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x467701\ninstruction @ 0x4677C2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4677C2\ninstruction @ 0x47D244\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x47D244\ninstruction @ 0x4AA838\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4AA838\ninstruction @ 0x4AA855\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4AA855\ninstruction @ 0x4AA86A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4AA86A\ninstruction @ 0x4AA87F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4AA87F\ninstruction @ 0x4AA897\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4AA897\n\nlink many functions at runtime (5 matches)\nnamespace  linking/runtime-linking                      \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com\nscope      function                                     \natt&ck     Execution::Shared Modules [T1129]            \nfunction @ 0x413B70\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x413D72, 0x413DFE, 0x413E13, 0x413E29, and 2 more...\nfunction @ 0x427A30\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x427C7B, 0x427CBA, 0x427CF9, 0x427D38, and 117 more...\nfunction @ 0x4464D0\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x446B97, 0x446BFB, 0x446C7D, 0x446CEE, and 7 more...\nfunction @ 0x466F90\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x467481, 0x46750B, 0x46755D, 0x4675CD, and 3 more...\nfunction @ 0x4AA7F4\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x4AA838, 0x4AA855, 0x4AA86A, 0x4AA87F, and 1 more...\n\nlinked against CPP standard library\nnamespace   linking/static                                                      \nauthor      @mr-tz                                                              \nscope       file                                                                \nreferences  https://en.wikipedia.org/wiki/P._J._Plauger,                        \n            https://www.dinkumware.com/                                         \nor:\n  string: \"Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL \nRIGHTS RESERVED.\" @ file+0xD88A0\n\n\n\n"},"hashes":{"md5":"ed2cd14a28ff2d00a5cefcf6a074af8d","sha1":"5b3e04f8208d3de912413efce27372255d6b3fe9","sha256":"eea059174127860154f4dce1a7d8995a9a5056febf73819d63ddadb522ed6c8f"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 1002</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 56215</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Nivdort\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"ed2cd14a28ff2d00a5cefcf6a074af8d\",\n        \"sha256\": \"eea059174127860154f4dce1a7d8995a9a5056febf73819d63ddadb\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_library_rule_\",\n      \"label\": \"library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Modulo [C0058]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_loop__273_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (273 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401000\",\n      \"label\": \"Function 0x401000\",\n      \"type\": \"function\",\n      \"address\": \"0x401000\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::Luhn [C0032.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40C280\",\n      \"label\": \"Function 0x40C280\",\n      \"type\": \"function\",\n      \"address\": \"0x40C280\"\n    },\n    {\n      \"id\": \"cap_contain_obfuscated_stackstrings__2_matches_\",\n      \"label\": \"contain obfuscated stackstrings (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x471C80\",\n      \"label\": \"Block 0x471C80\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x471C80\"\n    },\n    {\n      \"id\": \"bb_0x413C01\",\n      \"label\": \"Block 0x413C01\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x413C01\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_data__11_matches_\",\n      \"label\": \"receive data (11 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x427A30\",\n      \"label\": \"Function 0x427A30\",\n      \"type\": \"function\",\n      \"address\": \"0x427A30\"\n    },\n    {\n      \"id\": \"func_0x44FF20\",\n      \"label\": \"Function 0x44FF20\",\n      \"type\": \"function\",\n      \"address\": \"0x44FF20\"\n    },\n    {\n      \"id\": \"func_0x453FB0\",\n      \"label\": \"Function 0x453FB0\",\n      \"type\": \"function\",\n      \"address\": \"0x453FB0\"\n    },\n    {\n      \"id\": \"func_0x40C6D0\",\n      \"label\": \"Function 0x40C6D0\",\n      \"type\": \"function\",\n      \"address\": \"0x40C6D0\"\n    },\n    {\n      \"id\": \"func_0x438B80\",\n      \"label\": \"Function 0x438B80\",\n      \"type\": \"function\",\n      \"address\": \"0x438B80\"\n    },\n    {\n      \"id\": \"func_0x430F30\",\n      \"label\": \"Function 0x430F30\",\n      \"type\": \"function\",\n      \"address\": \"0x430F30\"\n    },\n    {\n      \"id\": \"func_0x444590\",\n      \"label\": \"Function 0x444590\",\n      \"type\": \"function\",\n      \"address\": \"0x444590\"\n    },\n    {\n      \"id\": \"func_0x46C620\",\n      \"label\": \"Function 0x46C620\",\n      \"type\": \"function\",\n      \"address\": \"0x46C620\"\n    },\n    {\n      \"id\": \"func_0x454550\",\n      \"label\": \"Function 0x454550\",\n      \"type\": \"function\",\n      \"address\": \"0x454550\"\n    },\n    {\n      \"id\": \"func_0x47ED20\",\n      \"label\": \"Function 0x47ED20\",\n      \"type\": \"function\",\n      \"address\": \"0x47ED20\"\n    },\n    {\n      \"id\": \"api_recv\",\n      \"label\": \"recv\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data__10_matches_\",\n      \"label\": \"send data (10 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x479520\",\n      \"label\": \"Function 0x479520\",\n      \"type\": \"function\",\n      \"address\": \"0x479520\"\n    },\n    {\n      \"id\": \"func_0x452930\",\n      \"label\": \"Function 0x452930\",\n      \"type\": \"function\",\n      \"address\": \"0x452930\"\n    },\n    {\n      \"id\": \"func_0x438AD0\",\n      \"label\": \"Function 0x438AD0\",\n      \"type\": \"function\",\n      \"address\": \"0x438AD0\"\n    },\n    {\n      \"id\": \"func_0x472DA0\",\n      \"label\": \"Function 0x472DA0\",\n      \"type\": \"function\",\n      \"address\": \"0x472DA0\"\n    },\n    {\n      \"id\": \"api_send\",\n      \"label\": \"send\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_download_and_write_a_file\",\n      \"label\": \"download and write a file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"downloader\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Server to Client\",\n        \"File Transfer [B0030.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_fwrite\",\n      \"label\": \"fwrite\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api__fwrite\",\n      \"label\": \"_fwrite\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_maec_malware_category__downloader\",\n      \"label\": \"maec/malware-category  downloader\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"downloader\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Server to Client\",\n        \"File Transfer [B0030.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_and_send_data_from_client_to_server\",\n      \"label\": \"read and send data from client to server\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_fread\",\n      \"label\": \"fread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_receive_and_write_data_from_server_to_client\",\n      \"label\": \"receive and write data from server to client\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_resolve_dns__4_matches_\",\n      \"label\": \"resolve DNS (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::DNS Communication::Resolve [C0011.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x478270\",\n      \"label\": \"Function 0x478270\",\n      \"type\": \"function\",\n      \"address\": \"0x478270\"\n    },\n    {\n      \"id\": \"func_0x4242F0\",\n      \"label\": \"Function 0x4242F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4242F0\"\n    },\n    {\n      \"id\": \"func_0x4631A0\",\n      \"label\": \"Function 0x4631A0\",\n      \"type\": \"function\",\n      \"address\": \"0x4631A0\"\n    },\n    {\n      \"id\": \"api_gethostbyname\",\n      \"label\": \"gethostbyname\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::DNS Communication::Resolve [C0011.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_socket__7_matches_\",\n      \"label\": \"connect socket (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x478466\",\n      \"label\": \"Block 0x478466\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x478466\"\n    },\n    {\n      \"id\": \"bb_0x45636D\",\n      \"label\": \"Block 0x45636D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x45636D\"\n    },\n    {\n      \"id\": \"bb_0x480DC1\",\n      \"label\": \"Block 0x480DC1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x480DC1\"\n    },\n    {\n      \"id\": \"bb_0x47F4D7\",\n      \"label\": \"Block 0x47F4D7\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x47F4D7\"\n    },\n    {\n      \"id\": \"bb_0x46D1B4\",\n      \"label\": \"Block 0x46D1B4\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46D1B4\"\n    },\n    {\n      \"id\": \"bb_0x43114A\",\n      \"label\": \"Block 0x43114A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x43114A\"\n    },\n    {\n      \"id\": \"bb_0x46C90A\",\n      \"label\": \"Block 0x46C90A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46C90A\"\n    },\n    {\n      \"id\": \"api_connect\",\n      \"label\": \"connect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_mrhafizfarhad_gmail_com\",\n      \"label\": \"mrhafizfarhad@gmail.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_socket_status__2_matches_\",\n      \"label\": \"get socket status (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Get Socket Status [C0001.012]\"\n      ]\n    },\n    {\n      \"id\": \"api_select\",\n      \"label\": \"select\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Get Socket Status [C0001.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_initialize_winsock_library__2_matches_\",\n      \"label\": \"initialize Winsock library (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Initialize Winsock Library\",\n        \"[C0001.009]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x417D50\",\n      \"label\": \"Function 0x417D50\",\n      \"type\": \"function\",\n      \"address\": \"0x417D50\"\n    },\n    {\n      \"id\": \"api_WSAStartup\",\n      \"label\": \"WSAStartup\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_receive_data_on_socket__11_matches_\",\n      \"label\": \"receive data on socket (11 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Receive Data [C0001.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data_on_socket__10_matches_\",\n      \"label\": \"send data on socket (10 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_tcp_socket__6_matches_\",\n      \"label\": \"connect TCP socket (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Connect Socket [C0001.004]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x480C50\",\n      \"label\": \"Function 0x480C50\",\n      \"type\": \"function\",\n      \"address\": \"0x480C50\"\n    },\n    {\n      \"id\": \"api_socket\",\n      \"label\": \"socket\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_tcp_socket__12_matches_\",\n      \"label\": \"create TCP socket (12 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x454797\",\n      \"label\": \"Block 0x454797\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x454797\"\n    },\n    {\n      \"id\": \"bb_0x416DB0\",\n      \"label\": \"Block 0x416DB0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x416DB0\"\n    },\n    {\n      \"id\": \"bb_0x46D0C8\",\n      \"label\": \"Block 0x46D0C8\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46D0C8\"\n    },\n    {\n      \"id\": \"bb_0x46C8E4\",\n      \"label\": \"Block 0x46C8E4\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46C8E4\"\n    },\n    {\n      \"id\": \"bb_0x41CE38\",\n      \"label\": \"Block 0x41CE38\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x41CE38\"\n    },\n    {\n      \"id\": \"bb_0x480D19\",\n      \"label\": \"Block 0x480D19\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x480D19\"\n    },\n    {\n      \"id\": \"bb_0x43111B\",\n      \"label\": \"Block 0x43111B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x43111B\"\n    },\n    {\n      \"id\": \"bb_0x46B215\",\n      \"label\": \"Block 0x46B215\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46B215\"\n    },\n    {\n      \"id\": \"bb_0x47F3AF\",\n      \"label\": \"Block 0x47F3AF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x47F3AF\"\n    },\n    {\n      \"id\": \"bb_0x41CD34\",\n      \"label\": \"Block 0x41CD34\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x41CD34\"\n    },\n    {\n      \"id\": \"bb_0x42C187\",\n      \"label\": \"Block 0x42C187\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x42C187\"\n    },\n    {\n      \"id\": \"bb_0x478270\",\n      \"label\": \"Block 0x478270\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x478270\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_udp_socket__4_matches_\",\n      \"label\": \"connect UDP socket (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::UDP Client [C0001.013]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______mrhafizfarhad_gmail_com\",\n      \"label\": \"author       mrhafizfarhad@gmail.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::UDP Client [C0001.013]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_udp_socket__10_matches_\",\n      \"label\": \"create UDP socket (10 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create UDP Socket [C0001.010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_act_as_tcp_client__6_matches_\",\n      \"label\": \"act as TCP client (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_start_tcp_server__3_matches_\",\n      \"label\": \"start TCP server (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Start TCP Server [C0001.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46B0F0\",\n      \"label\": \"Function 0x46B0F0\",\n      \"type\": \"function\",\n      \"address\": \"0x46B0F0\"\n    },\n    {\n      \"id\": \"func_0x416DB0\",\n      \"label\": \"Function 0x416DB0\",\n      \"type\": \"function\",\n      \"address\": \"0x416DB0\"\n    },\n    {\n      \"id\": \"api_listen\",\n      \"label\": \"listen\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_accept\",\n      \"label\": \"accept\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_validate_payment_card_number_using_luhn_algorithm\",\n      \"label\": \"validate payment card number using luhn algorithm\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::Luhn [C0032.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______re_fox\",\n      \"label\": \"author     @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::Luhn [C0032.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_hc_128\",\n      \"label\": \"encrypt data using HC-128\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or\",\n        \"Information::Encryption-Standard Algorithm [E1027.m05]\",\n        \"Cryptography::Encrypt Data::HC-128 [C0027.006]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4731AA\",\n      \"label\": \"Block 0x4731AA\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4731AA\"\n    },\n    {\n      \"id\": \"cap_author_______awillia2_cisco_com\",\n      \"label\": \"author       awillia2@cisco.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or\",\n        \"Information::Encryption-Standard Algorithm [E1027.m05]\",\n        \"Cryptography::Encrypt Data::HC-128 [C0027.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_rc4_prga__2_matches_\",\n      \"label\": \"encrypt data using RC4 PRGA (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data::RC4 [C0027.009]\",\n        \"Cryptography::Generate\",\n        \"Pseudo-random Sequence::RC4 PRGA [C0021.004]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x479620\",\n      \"label\": \"Function 0x479620\",\n      \"type\": \"function\",\n      \"address\": \"0x479620\"\n    },\n    {\n      \"id\": \"func_0x41A3D0\",\n      \"label\": \"Function 0x41A3D0\",\n      \"type\": \"function\",\n      \"address\": \"0x41A3D0\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists\",\n      \"label\": \"check if file exists\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4A620D\",\n      \"label\": \"Function 0x4A620D\",\n      \"type\": \"function\",\n      \"address\": \"0x4A620D\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes\",\n      \"label\": \"get file attributes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4A6247\",\n      \"label\": \"Block 0x4A6247\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4A6247\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__3_matches_\",\n      \"label\": \"read file on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x414C50\",\n      \"label\": \"Function 0x414C50\",\n      \"type\": \"function\",\n      \"address\": \"0x414C50\"\n    },\n    {\n      \"id\": \"func_0x43C060\",\n      \"label\": \"Function 0x43C060\",\n      \"type\": \"function\",\n      \"address\": \"0x43C060\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__7_matches_\",\n      \"label\": \"write file on Windows (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x468670\",\n      \"label\": \"Function 0x468670\",\n      \"type\": \"function\",\n      \"address\": \"0x468670\"\n    },\n    {\n      \"id\": \"func_0x4796C0\",\n      \"label\": \"Function 0x4796C0\",\n      \"type\": \"function\",\n      \"address\": \"0x4796C0\"\n    },\n    {\n      \"id\": \"func_0x41D340\",\n      \"label\": \"Function 0x41D340\",\n      \"type\": \"function\",\n      \"address\": \"0x41D340\"\n    },\n    {\n      \"id\": \"func_0x4236B0\",\n      \"label\": \"Function 0x4236B0\",\n      \"type\": \"function\",\n      \"address\": \"0x4236B0\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4962A9\",\n      \"label\": \"Function 0x4962A9\",\n      \"type\": \"function\",\n      \"address\": \"0x4962A9\"\n    },\n    {\n      \"id\": \"api_TerminateProcess\",\n      \"label\": \"TerminateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_allocate_thread_local_storage\",\n      \"label\": \"allocate thread local storage\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Allocate Thread Local Storage [C0040]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x49E1C5\",\n      \"label\": \"Function 0x49E1C5\",\n      \"type\": \"function\",\n      \"address\": \"0x49E1C5\"\n    },\n    {\n      \"id\": \"api_TlsAlloc\",\n      \"label\": \"TlsAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__164_matches_\",\n      \"label\": \"link function at runtime on Windows (164 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_many_functions_at_runtime__5_matches_\",\n      \"label\": \"link many functions at runtime (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x466F90\",\n      \"label\": \"Function 0x466F90\",\n      \"type\": \"function\",\n      \"address\": \"0x466F90\"\n    },\n    {\n      \"id\": \"func_0x4AA7F4\",\n      \"label\": \"Function 0x4AA7F4\",\n      \"type\": \"function\",\n      \"address\": \"0x4AA7F4\"\n    },\n    {\n      \"id\": \"func_0x4464D0\",\n      \"label\": \"Function 0x4464D0\",\n      \"type\": \"function\",\n      \"address\": \"0x4464D0\"\n    },\n    {\n      \"id\": \"func_0x413B70\",\n      \"label\": \"Function 0x413B70\",\n      \"type\": \"function\",\n      \"address\": \"0x413B70\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_linked_against_cpp_standard_library\",\n      \"label\": \"linked against CPP standard library\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______mr_tz\",\n      \"label\": \"author      @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__273_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__273_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"func_0x40C280\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_obfuscated_stackstrings__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__2_matches_\",\n      \"target\": \"bb_0x471C80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__2_matches_\",\n      \"target\": \"bb_0x413C01\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x471C80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x413C01\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data__11_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data__11_matches_\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__11_matches_\",\n      \"target\": \"func_0x44FF20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__11_matches_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__11_matches_\",\n      \"target\": \"func_0x453FB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__11_matches_\",\n      \"target\": \"func_0x40C6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__11_matches_\",\n      \"target\": \"func_0x438B80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__11_matches_\",\n      \"target\": \"func_0x430F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__11_matches_\",\n      \"target\": \"func_0x444590\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__11_matches_\",\n      \"target\": \"func_0x46C620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__11_matches_\",\n      \"target\": \"func_0x454550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__11_matches_\",\n      \"target\": \"func_0x47ED20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x44FF20\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x453FB0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C6D0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438B80\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x444590\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454550\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x44FF20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x453FB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40C6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x438B80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x430F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x444590\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x46C620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x454550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x47ED20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x44FF20\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x453FB0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C6D0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438B80\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x444590\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454550\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data__10_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data__10_matches_\",\n      \"target\": \"func_0x479520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__10_matches_\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__10_matches_\",\n      \"target\": \"func_0x452930\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__10_matches_\",\n      \"target\": \"func_0x438AD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__10_matches_\",\n      \"target\": \"func_0x472DA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__10_matches_\",\n      \"target\": \"func_0x438B80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__10_matches_\",\n      \"target\": \"func_0x430F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__10_matches_\",\n      \"target\": \"func_0x46C620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__10_matches_\",\n      \"target\": \"func_0x454550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__10_matches_\",\n      \"target\": \"func_0x47ED20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x479520\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x452930\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438AD0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472DA0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438B80\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454550\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x479520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x452930\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x438AD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x472DA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x438B80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x430F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x46C620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x454550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x47ED20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x479520\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x452930\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438AD0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472DA0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438B80\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454550\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_download_and_write_a_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_download_and_write_a_file\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_maec_malware_category__downloader\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_maec_malware_category__downloader\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_and_send_data_from_client_to_server\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_and_send_data_from_client_to_server\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_and_write_data_from_server_to_client\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_and_write_data_from_server_to_client\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_dns__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_dns__4_matches_\",\n      \"target\": \"func_0x47ED20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_dns__4_matches_\",\n      \"target\": \"func_0x478270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_dns__4_matches_\",\n      \"target\": \"func_0x4242F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_dns__4_matches_\",\n      \"target\": \"func_0x4631A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478270\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4242F0\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4631A0\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47ED20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x478270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4242F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4631A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478270\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4242F0\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4631A0\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_socket__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_socket__7_matches_\",\n      \"target\": \"bb_0x478466\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_socket__7_matches_\",\n      \"target\": \"bb_0x45636D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_socket__7_matches_\",\n      \"target\": \"bb_0x480DC1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_socket__7_matches_\",\n      \"target\": \"bb_0x47F4D7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_socket__7_matches_\",\n      \"target\": \"bb_0x46D1B4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_socket__7_matches_\",\n      \"target\": \"bb_0x43114A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_socket__7_matches_\",\n      \"target\": \"bb_0x46C90A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mrhafizfarhad_gmail_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x478466\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x45636D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x480DC1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x47F4D7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x46D1B4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x43114A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x46C90A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_socket_status__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_socket_status__2_matches_\",\n      \"target\": \"func_0x438B80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_socket_status__2_matches_\",\n      \"target\": \"func_0x46C620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x438B80\",\n      \"target\": \"api_select\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_select\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x438B80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46C620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x438B80\",\n      \"target\": \"api_select\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_select\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_initialize_winsock_library__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_initialize_winsock_library__2_matches_\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_initialize_winsock_library__2_matches_\",\n      \"target\": \"func_0x417D50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x417D50\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x417D50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x417D50\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data_on_socket__11_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__11_matches_\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__11_matches_\",\n      \"target\": \"func_0x44FF20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__11_matches_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__11_matches_\",\n      \"target\": \"func_0x453FB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__11_matches_\",\n      \"target\": \"func_0x40C6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__11_matches_\",\n      \"target\": \"func_0x438B80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__11_matches_\",\n      \"target\": \"func_0x430F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__11_matches_\",\n      \"target\": \"func_0x444590\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__11_matches_\",\n      \"target\": \"func_0x46C620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__11_matches_\",\n      \"target\": \"func_0x454550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__11_matches_\",\n      \"target\": \"func_0x47ED20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x44FF20\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x453FB0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C6D0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438B80\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x444590\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454550\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x44FF20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x453FB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40C6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x438B80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x430F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x444590\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46C620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x454550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47ED20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x44FF20\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x453FB0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C6D0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438B80\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x444590\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454550\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data_on_socket__10_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__10_matches_\",\n      \"target\": \"func_0x479520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__10_matches_\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__10_matches_\",\n      \"target\": \"func_0x452930\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__10_matches_\",\n      \"target\": \"func_0x438AD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__10_matches_\",\n      \"target\": \"func_0x472DA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__10_matches_\",\n      \"target\": \"func_0x438B80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__10_matches_\",\n      \"target\": \"func_0x430F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__10_matches_\",\n      \"target\": \"func_0x46C620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__10_matches_\",\n      \"target\": \"func_0x454550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__10_matches_\",\n      \"target\": \"func_0x47ED20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x479520\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x452930\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438AD0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472DA0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438B80\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454550\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x479520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x452930\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x438AD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472DA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x438B80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x430F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46C620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x454550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47ED20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x479520\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x452930\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438AD0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472DA0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x438B80\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454550\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_tcp_socket__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_tcp_socket__6_matches_\",\n      \"target\": \"func_0x478270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_tcp_socket__6_matches_\",\n      \"target\": \"func_0x430F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_tcp_socket__6_matches_\",\n      \"target\": \"func_0x480C50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_tcp_socket__6_matches_\",\n      \"target\": \"func_0x46C620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_tcp_socket__6_matches_\",\n      \"target\": \"func_0x454550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_tcp_socket__6_matches_\",\n      \"target\": \"func_0x47ED20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x478270\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480C50\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454550\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478270\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480C50\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454550\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x478270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x430F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x480C50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x46C620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x454550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x47ED20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x478270\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480C50\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454550\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478270\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480C50\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454550\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_tcp_socket__12_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__12_matches_\",\n      \"target\": \"bb_0x454797\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__12_matches_\",\n      \"target\": \"bb_0x416DB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__12_matches_\",\n      \"target\": \"bb_0x46D0C8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__12_matches_\",\n      \"target\": \"bb_0x46C8E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__12_matches_\",\n      \"target\": \"bb_0x41CE38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__12_matches_\",\n      \"target\": \"bb_0x480D19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__12_matches_\",\n      \"target\": \"bb_0x43111B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__12_matches_\",\n      \"target\": \"bb_0x46B215\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__12_matches_\",\n      \"target\": \"bb_0x47F3AF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__12_matches_\",\n      \"target\": \"bb_0x41CD34\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__12_matches_\",\n      \"target\": \"bb_0x42C187\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__12_matches_\",\n      \"target\": \"bb_0x478270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x454797\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x416DB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x46D0C8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x46C8E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x41CE38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x480D19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x43111B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x46B215\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x47F3AF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x41CD34\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x42C187\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x478270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_udp_socket__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_udp_socket__4_matches_\",\n      \"target\": \"func_0x430F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_udp_socket__4_matches_\",\n      \"target\": \"func_0x478270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_udp_socket__4_matches_\",\n      \"target\": \"func_0x480C50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_udp_socket__4_matches_\",\n      \"target\": \"func_0x46C620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478270\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480C50\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478270\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480C50\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______mrhafizfarhad_gmail_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x430F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x478270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x480C50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x46C620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478270\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480C50\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478270\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480C50\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_udp_socket__10_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__10_matches_\",\n      \"target\": \"bb_0x416DB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__10_matches_\",\n      \"target\": \"bb_0x46D0C8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__10_matches_\",\n      \"target\": \"bb_0x46C8E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__10_matches_\",\n      \"target\": \"bb_0x41CE38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__10_matches_\",\n      \"target\": \"bb_0x480D19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__10_matches_\",\n      \"target\": \"bb_0x43111B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__10_matches_\",\n      \"target\": \"bb_0x46B215\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__10_matches_\",\n      \"target\": \"bb_0x41CD34\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__10_matches_\",\n      \"target\": \"bb_0x42C187\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__10_matches_\",\n      \"target\": \"bb_0x478270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x416DB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x46D0C8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x46C8E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x41CE38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x480D19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x43111B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x46B215\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x41CD34\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x42C187\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x478270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_act_as_tcp_client__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_act_as_tcp_client__6_matches_\",\n      \"target\": \"func_0x478270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_act_as_tcp_client__6_matches_\",\n      \"target\": \"func_0x430F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_act_as_tcp_client__6_matches_\",\n      \"target\": \"func_0x480C50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_act_as_tcp_client__6_matches_\",\n      \"target\": \"func_0x46C620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_act_as_tcp_client__6_matches_\",\n      \"target\": \"func_0x454550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_act_as_tcp_client__6_matches_\",\n      \"target\": \"func_0x47ED20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x478270\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480C50\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454550\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478270\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480C50\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454550\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x478270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x430F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x480C50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46C620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x454550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47ED20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x478270\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480C50\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454550\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478270\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x430F30\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480C50\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46C620\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x454550\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47ED20\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_start_tcp_server__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_start_tcp_server__3_matches_\",\n      \"target\": \"func_0x46B0F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_start_tcp_server__3_matches_\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_start_tcp_server__3_matches_\",\n      \"target\": \"func_0x416DB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46B0F0\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x416DB0\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B0F0\",\n      \"target\": \"api_listen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_listen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x416DB0\",\n      \"target\": \"api_listen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B0F0\",\n      \"target\": \"api_accept\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_accept\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x416DB0\",\n      \"target\": \"api_accept\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46B0F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x416DB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46B0F0\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x416DB0\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B0F0\",\n      \"target\": \"api_listen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_listen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x416DB0\",\n      \"target\": \"api_listen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B0F0\",\n      \"target\": \"api_accept\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_accept\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x416DB0\",\n      \"target\": \"api_accept\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_validate_payment_card_number_using_luhn_algorithm\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_validate_payment_card_number_using_luhn_algorithm\",\n      \"target\": \"func_0x40C280\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox\",\n      \"target\": \"func_0x40C280\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_hc_128\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_hc_128\",\n      \"target\": \"bb_0x4731AA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______awillia2_cisco_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______awillia2_cisco_com\",\n      \"target\": \"bb_0x4731AA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_rc4_prga__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__2_matches_\",\n      \"target\": \"func_0x479620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__2_matches_\",\n      \"target\": \"func_0x41A3D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x479620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x41A3D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists\",\n      \"target\": \"func_0x4A620D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4A620D\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4A620D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4A620D\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes\",\n      \"target\": \"bb_0x4A6247\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4A6247\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__3_matches_\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__3_matches_\",\n      \"target\": \"func_0x414C50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__3_matches_\",\n      \"target\": \"func_0x43C060\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x414C50\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43C060\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x414C50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x43C060\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x414C50\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43C060\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x43C060\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x414C50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x468670\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x4796C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x41D340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x4236B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43C060\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x414C50\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x468670\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796C0\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D340\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4236B0\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43C060\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x414C50\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x468670\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796C0\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D340\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4236B0\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x43C060\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x414C50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x468670\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4796C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41D340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4236B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43C060\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x414C50\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x468670\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796C0\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D340\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4236B0\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x427A30\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43C060\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x414C50\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x468670\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4796C0\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41D340\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4236B0\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x4962A9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4962A9\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4962A9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4962A9\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_thread_local_storage\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_thread_local_storage\",\n      \"target\": \"func_0x49E1C5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x49E1C5\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x49E1C5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x49E1C5\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__164_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_many_functions_at_runtime__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__5_matches_\",\n      \"target\": \"func_0x466F90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__5_matches_\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__5_matches_\",\n      \"target\": \"func_0x4AA7F4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__5_matches_\",\n      \"target\": \"func_0x4464D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__5_matches_\",\n      \"target\": \"func_0x413B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x466F90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x427A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x4AA7F4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x4464D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x413B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_cpp_standard_library\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______mr_tz\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-10 01:19:00.892155\",\n    \"total_functions\": \"1002\",\n    \"total_features\": \"56215\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-10 01:19:05"}
{"_id":{"$oid":"6a4fa06f0108394cb24cdcc7"},"sha256":"ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_kt2a8499/Ransomware.WannaCry-019f46cfccf079c1b11d424031280861.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_kt2a8499/Ransomware.WannaCry-019f46cfccf079c1b11d424031280861.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_kt2a8499/Ransomware.WannaCry-019f46cfccf079c1b11d424031280861.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 84c82835a5d21bbcf75a61706d8ab549                                  │\n│ sha1     │ 5ff465afaabcbf0150d1a3ab2c2e74f3a4426467                          │\n│ sha256   │ ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/Ransomware.Wanna… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION      │ File and Directory Permissions Modification [T1222]   │\n│                      │ Obfuscated Files or Information [T1027]               │\n│ DISCOVERY            │ File and Directory Discovery [T1083]                  │\n│                      │ Query Registry [T1012]                                │\n│                      │ System Information Discovery [T1082]                  │\n│ EXECUTION            │ Shared Modules [T1129]                                │\n│                      │ System Services::Service Execution [T1569.002]        │\n│ PERSISTENCE          │ Create or Modify System Process::Windows Service      │\n│                      │ [T1543.003]                                           │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ CRYPTOGRAPHY         │ Encrypt Data::AES [C0027.001]                         │\n│                      │ Encrypt Data::RC4 [C0027.009]                         │\n│                      │ Encryption Key::RC4 KSA [C0028.002]                   │\n│                      │ Generate Pseudo-random Sequence [C0021]               │\n│ DATA                 │ Checksum::CRC32 [C0032.001]                           │\n│                      │ Compression Library [C0060]                           │\n│                      │ Encode Data::XOR [C0026.002]                          │\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Encoding-Standard    │\n│                      │ Algorithm [E1027.m02]                                 │\n│                      │ Obfuscated Files or Information::Encryption-Standard  │\n│                      │ Algorithm [E1027.m05]                                 │\n│ DISCOVERY            │ Code Discovery::Enumerate PE Sections [B0046.001]     │\n│                      │ File and Directory Discovery [E1083]                  │\n│                      │ System Information Discovery [E1082]                  │\n│ FILE SYSTEM          │ Copy File [C0045]                                     │\n│                      │ Create Directory [C0046]                              │\n│                      │ Get File Attributes [C0049]                           │\n│                      │ Read File [C0051]                                     │\n│                      │ Set File Attributes [C0050]                           │\n│                      │ Writes File [C0052]                                   │\n│ OPERATING SYSTEM     │ Registry::Query Registry Value [C0036.006]            │\n│                      │ Registry::Set Registry Key [C0036.001]                │\n│ PROCESS              │ Create Mutex [C0042]                                  │\n│                      │ Create Process [C0017]                                │\n│                      │ Terminate Process [C0018]                             │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                             ┃ Namespace                           ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ hash data with CRC32 (2 matches)       │ data-manipulation/checksum/crc32    │\n│ encode data using XOR (15 matches)     │ data-manipulation/encoding/xor      │\n│ encrypt data using AES (5 matches)     │ data-manipulation/encryption/aes    │\n│ reference AES constants (5 matches)    │ data-manipulation/encryption/aes    │\n│ encrypt data using RC4 KSA (3 matches) │ data-manipulation/encryption/rc4    │\n│ generate random numbers using the      │ data-manipulation/prng/lcg          │\n│ Delphi LCG                             │                                     │\n│ extract resource via kernel32          │ executable/resource                 │\n│ functions                              │                                     │\n│ get common file path (3 matches)       │ host-interaction/file-system        │\n│ set current directory (3 matches)      │ host-interaction/file-system        │\n│ copy file                              │ host-interaction/file-system/copy   │\n│ create directory (2 matches)           │ host-interaction/file-system/create │\n│ check if file exists (4 matches)       │ host-interaction/file-system/exists │\n│ get file attributes (6 matches)        │ host-interaction/file-system/meta   │\n│ get file size (2 matches)              │ host-interaction/file-system/meta   │\n│ set file attributes                    │ host-interaction/file-system/meta   │\n│ read file on Windows (3 matches)       │ host-interaction/file-system/read   │\n│ write file on Windows (2 matches)      │ host-interaction/file-system/write  │\n│ create or open mutex on Windows        │ host-interaction/mutex              │\n│ get hostname                           │ host-interaction/os/hostname        │\n│ create process on Windows              │ host-interaction/process/create     │\n│ terminate process                      │ host-interaction/process/terminate  │\n│ query or enumerate registry value      │ host-interaction/registry           │\n│ set registry value                     │ host-interaction/registry/create    │\n│ create service                         │ host-interaction/service/create     │\n│ start service                          │ host-interaction/service/start      │\n│ link function at runtime on Windows    │ linking/runtime-linking             │\n│ (13 matches)                           │                                     │\n│ link many functions at runtime (2      │ linking/runtime-linking             │\n│ matches)                               │                                     │\n│ linked against ZLIB                    │ linking/static/zlib                 │\n│ enumerate PE sections (2 matches)      │ load-code/pe                        │\n│ parse PE header                        │ load-code/pe                        │\n│ persist via Windows service            │ persistence/service                 │\n└────────────────────────────────────────┴─────────────────────────────────────┘\n\n","verbose":"md5                     84c82835a5d21bbcf75a61706d8ab549                        \nsha1                    5ff465afaabcbf0150d1a3ab2c2e74f3a4426467                \nsha256                  ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8…\npath                    /home/apogean/projects/malware/windows/all_runs/Ransomw…\ntimestamp               2026-07-10 12:35:03.557289                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIi0QTNe/rules                                   \nfunction count          130                                                     \nlibrary function count  7                                                       \ntotal feature count     50772                                                   \n\nhash data with CRC32 (2 matches)\nnamespace  data-manipulation/checksum/crc32\nscope      function                        \nmatches    0x40541F                        \n           0x405535                        \n\nencode data using XOR (15 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x402D25                      \n           0x402D3B                      \n           0x402D9C                      \n           0x402E25                      \n           0x402F5F                      \n           0x4032AC                      \n           0x4035A6                      \n           0x40361F                      \n           0x4036F2                      \n           0x403831                      \n           0x4038AD                      \n           0x403980                      \n           0x403A62                      \n           0x40544A                      \n           0x405514                      \n\nencrypt data using AES (5 matches)\nnamespace  data-manipulation/encryption/aes\nscope      function                        \nmatches    0x402A76                        \n           0x402E7E                        \n           0x4031BC                        \n           0x40350F                        \n           0x403797                        \n\nreference AES constants (5 matches)\nnamespace  data-manipulation/encryption/aes\nscope      function                        \nmatches    0x402A76                        \n           0x402E7E                        \n           0x4031BC                        \n           0x40350F                        \n           0x403797                        \n\nencrypt data using RC4 KSA (3 matches)\nnamespace  data-manipulation/encryption/rc4\nscope      function                        \nmatches    0x402A76                        \n           0x40350F                        \n           0x403797                        \n\ngenerate random numbers using the Delphi LCG\nnamespace  data-manipulation/prng/lcg\nscope      basic block               \nmatches    0x405535                  \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x401DAB           \n\nget common file path (3 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x4010FD                    \n           0x401B5F                    \n           0x406B8E                    \n\nset current directory (3 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x4010FD                    \n           0x401AF6                    \n           0x401FE7                    \n\ncopy file\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    0x401FE7                         \n\ncreate directory (2 matches)\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x401AF6                           \n           0x407070                           \n\ncheck if file exists (4 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x401B5F                           \n           0x401DAB                           \n           0x401FE7                           \n           0x407070                           \n\nget file attributes (6 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x401B2B                         \n           0x401B5F                         \n           0x401E67                         \n           0x402061                         \n           0x407082                         \n           0x407102                         \n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x4014A6                         \n           0x4018F9                         \n\nset file attributes\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x401B2B                         \n\nread file on Windows (3 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x401000                         \n           0x4018F9                         \n           0x405D8A                         \n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x401000                          \n           0x407136                          \n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex\nscope      instruction           \nmatches    0x401F31              \n\nget hostname\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    0x401225                    \n\ncreate process on Windows\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x401064                       \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x401064                          \n\nquery or enumerate registry value\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x4010FD                 \n\nset registry value\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x4010FD                        \n\ncreate service\nnamespace  host-interaction/service/create\nscope      function                       \nmatches    0x401CE8                       \n\nstart service\nnamespace  host-interaction/service/start\nscope      function                      \nmatches    0x401CE8                      \n\nlink function at runtime on Windows (13 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x401749               \n           0x401756               \n           0x401763               \n           0x401770               \n           0x40177D               \n           0x40178A               \n           0x401797               \n           0x401A77               \n           0x401A84               \n           0x401A91               \n           0x401A9E               \n           0x401AAB               \n           0x401AB8               \n\nlink many functions at runtime (2 matches)\nnamespace  linking/runtime-linking\nscope      function               \nmatches    0x40170A               \n           0x401A45               \n\nlinked against ZLIB\nnamespace  linking/static/zlib\nscope      file               \n\nenumerate PE sections (2 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x4021E9    \n           0x402470    \n\nparse PE header\nnamespace  load-code/pe\nscope      function    \nmatches    0x4021E9    \n\npersist via Windows service\nnamespace  persistence/service\nscope      function           \nmatches    0x401CE8           \n\n\n\n","very_verbose":"md5                     84c82835a5d21bbcf75a61706d8ab549                        \nsha1                    5ff465afaabcbf0150d1a3ab2c2e74f3a4426467                \nsha256                  ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8…\npath                    /home/apogean/projects/malware/windows/all_runs/Ransomw…\ntimestamp               2026-07-10 12:35:19.814041                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEITwWvP8/rules                                   \nfunction count          130                                                     \nlibrary function count  7                                                       \ntotal feature count     50772                                                   \n\nallocate memory (library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x40216E in function 0x40216E\n  or:\n    api: VirtualAlloc @ 0x40217E\n\ncalculate modulo 256 via x86 assembly (7 matches, only showing first match of \nlibrary rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x402CD7\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x402CD7\n    or:\n      number: 0xFF @ 0x402CD7\n\nchange memory protection (library rule)\nauthor  @mr-tz                                  \nscope   basic block                             \nmbc     Memory::Change Memory Protection [C0008]\nbasic block @ 0x402705 in function 0x40267B\n  or:\n    api: VirtualProtect @ 0x40270D\n\ncontain loop (33 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x4010FD\n  or:\n    characteristic: loop @ 0x4010FD\n\ncreate or open file (5 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x40101B\n  or:\n    api: fopen @ 0x40101B\n\ncreate or open registry key (2 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x40116E in function 0x4010FD\n  or:\n    api: RegCreateKey @ 0x401173\n\ndelay execution (2 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x4010B7 in function 0x401064\n  or:\n    and:\n      os: windows\n      or:\n        api: WaitForSingleObject @ 0x4010BD\n\nget service handle (library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401CE8\n  or:\n    api: CreateService @ 0x401D75\n    api: OpenService @ 0x401D21\n\nhash data with CRC32 (2 matches)\nnamespace  data-manipulation/checksum/crc32 \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \nmbc        Data::Checksum::CRC32 [C0032.001]\nfunction @ 0x40541F\n  or:\n    bytes: 00000000963007772c610eeeba51099919c46d078ff46a7035a563e9a395649e = crc32_tab @ 0x40545C, 0x405473, 0x40548A, 0x4054A1, and 5 more...\nfunction @ 0x405535\n  or:\n    bytes: 00000000963007772c610eeeba51099919c46d078ff46a7035a563e9a395649e = crc32_tab @ 0x405550, 0x40557A\n\nencode data using XOR (15 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x402D25 in function 0x402A76\n  and:\n    characteristic: tight loop @ 0x402D25\n    characteristic: nzxor @ 0x402D28\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x402D3B in function 0x402A76\n  and:\n    characteristic: tight loop @ 0x402D3B\n    characteristic: nzxor @ 0x402D3E\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x402D9C in function 0x402A76\n  and:\n    characteristic: tight loop @ 0x402D9C\n    characteristic: nzxor @ 0x402D9F\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x402E25 in function 0x402A76\n  and:\n    characteristic: tight loop @ 0x402E25\n    characteristic: nzxor @ 0x402E3B, 0x402E4B, 0x402E52\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x402F5F in function 0x402E7E\n  and:\n    characteristic: tight loop @ 0x402F5F\n    characteristic: nzxor @ 0x402F72, 0x402F7E, 0x402F8C, 0x402F96, and 12 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4032AC in function 0x4031BC\n  and:\n    characteristic: tight loop @ 0x4032AC\n    characteristic: nzxor @ 0x4032BF, 0x4032CB, 0x4032DA, 0x4032E6, and 12 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4035A6 in function 0x40350F\n  and:\n    characteristic: tight loop @ 0x4035A6\n    characteristic: nzxor @ 0x4035D3\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x40361F in function 0x40350F\n  and:\n    characteristic: tight loop @ 0x40361F\n    characteristic: nzxor @ 0x403656, 0x40366C, 0x403678, 0x403686\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4036F2 in function 0x40350F\n  and:\n    characteristic: tight loop @ 0x4036F2\n    characteristic: nzxor @ 0x40371D, 0x40373F, 0x40375E, 0x40377D\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403831 in function 0x403797\n  and:\n    characteristic: tight loop @ 0x403831\n    characteristic: nzxor @ 0x40385E\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4038AD in function 0x403797\n  and:\n    characteristic: tight loop @ 0x4038AD\n    characteristic: nzxor @ 0x4038E4, 0x4038FA, 0x403906, 0x403914\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403980 in function 0x403797\n  and:\n    characteristic: tight loop @ 0x403980\n    characteristic: nzxor @ 0x4039AE, 0x4039D0, 0x4039EF, 0x403A0E\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403A62 in function 0x403A28\n  and:\n    characteristic: tight loop @ 0x403A62\n    characteristic: nzxor @ 0x403A64\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x40544A in function 0x40541F\n  and:\n    characteristic: tight loop @ 0x40544A\n    characteristic: nzxor @ 0x405455, 0x405463, 0x40546D, 0x40547D, and 12 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405514 in function 0x40541F\n  and:\n    characteristic: tight loop @ 0x405514\n    characteristic: nzxor @ 0x40551B, 0x405527\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nencrypt data using AES (5 matches)\nnamespace   data-manipulation/encryption/aes                                    \nauthor      william.ballenthin@mandiant.com, Ivan Kwiatkowski (@JusticeRage)    \nscope       function                                                            \natt&ck      Defense Evasion::Obfuscated Files or Information [T1027]            \nmbc         Defense Evasion::Obfuscated Files or                                \n            Information::Encryption-Standard Algorithm [E1027.m05],             \n            Cryptography::Encrypt Data::AES [C0027.001]                         \nreferences  https://github.com/JusticeRage/Manalyze/blob/8e77642c911d5d82b5f43b…\n            https://github.com/creaktive/tsh/blob/53b822b9a07d8cc65f1f31c915cf8…\nfunction @ 0x402A76\n  or:\n    bytes: 637c777bf26b6fc53001672bfed7ab76 = AES_SBOX_ENC @ 0x402CCA, 0x402CDF, 0x402CE6, 0x402CFC, and 4 more...\nfunction @ 0x402E7E\n  or:\n    bytes: 637c777bf26b6fc53001672bfed7ab76 = AES_SBOX_ENC @ 0x40306E, 0x403085, 0x40309A, 0x4030AF, and 12 more...\n    bytes: a56363c6847c7cf8997777ee8d7b7bf6 = AES_T0_ENC @ 0x402F7E, 0x402FA5, 0x402FDE, 0x403025\n    bytes: 6363c6a57c7cf8847777ee997b7bf68d = AES_T1_ENC @ 0x402F72, 0x402F9E, 0x402FF1, 0x403019\n    bytes: 63c6a5637cf8847c77ee99777bf68d7b = AES_T2_ENC @ 0x402F69, 0x402FB5, 0x402FE5, 0x40300F\n    bytes: c6a56363f8847c7cee997777f68d7b7b = AES_T3_ENC @ 0x402F8C, 0x402FC2, 0x402FFC, 0x403034\nfunction @ 0x4031BC\n  or:\n    bytes: 52096ad53036a538bf40a39e81f3d7fb = AES_SBOX_DEC @ 0x4033C1, 0x4033D8, 0x4033EB, 0x403403, and 12 more...\n    bytes: 50a7f4515365417ec3a4171a965e273a = AES_T0_DEC @ 0x4032BF, 0x4032E9, 0x40331C, 0x40336F\n    bytes: a7f4515065417e53a4171ac35e273a96 = AES_T1_DEC @ 0x4032CB, 0x4032F0, 0x403323, 0x403353\n    bytes: f45150a7417e5365171ac3a4273a965e = AES_T2_DEC @ 0x4032B6, 0x4032FD, 0x403332, 0x403360\n    bytes: 5150a7f47e5365411ac3a4173a965e27 = AES_T3_DEC @ 0x4032DA, 0x403309, 0x403339, 0x40337E\nfunction @ 0x40350F\n  or:\n    bytes: 637c777bf26b6fc53001672bfed7ab76 = AES_SBOX_ENC @ 0x403717, 0x403739, 0x403758, 0x403777\n    bytes: a56363c6847c7cf8997777ee8d7b7bf6 = AES_T0_ENC @ 0x403678\n    bytes: 6363c6a57c7cf8847777ee997b7bf68d = AES_T1_ENC @ 0x40366C\n    bytes: 63c6a5637cf8847c77ee99777bf68d7b = AES_T2_ENC @ 0x40364F\n    bytes: c6a56363f8847c7cee997777f68d7b7b = AES_T3_ENC @ 0x403656\nfunction @ 0x403797\n  or:\n    bytes: 52096ad53036a538bf40a39e81f3d7fb = AES_SBOX_DEC @ 0x4039A8, 0x4039CA, 0x4039E9, 0x403A08\n    bytes: 50a7f4515365417ec3a4171a965e273a = AES_T0_DEC @ 0x403906\n    bytes: a7f4515065417e53a4171ac35e273a96 = AES_T1_DEC @ 0x4038FA\n    bytes: f45150a7417e5365171ac3a4273a965e = AES_T2_DEC @ 0x4038DD\n    bytes: 5150a7f47e5365411ac3a4173a965e27 = AES_T3_DEC @ 0x4038E4\n\nreference AES constants (5 matches)\nnamespace  data-manipulation/encryption/aes                        \nauthor     william.ballenthin@mandiant.com                         \nscope      function                                                \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]\nfunction @ 0x402A76\n  or:\n    bytes: 637c777bf26b6fc5 = s-box @ 0x402CCA, 0x402CDF, 0x402CE6, 0x402CFC, and 4 more...\nfunction @ 0x402E7E\n  or:\n    bytes: 637c777bf26b6fc5 = s-box @ 0x40306E, 0x403085, 0x40309A, 0x4030AF, and 12 more...\nfunction @ 0x4031BC\n  or:\n    bytes: 50a7f4515365417e = d-0 @ 0x4032BF, 0x4032E9, 0x40331C, 0x40336F\n    bytes: 52096ad53036a538 = inv-s-box @ 0x4033C1, 0x4033D8, 0x4033EB, 0x403403, and 12 more...\nfunction @ 0x40350F\n  or:\n    bytes: 637c777bf26b6fc5 = s-box @ 0x403717, 0x403739, 0x403758, 0x403777\nfunction @ 0x403797\n  or:\n    bytes: 50a7f4515365417e = d-0 @ 0x403906\n    bytes: 52096ad53036a538 = inv-s-box @ 0x4039A8, 0x4039CA, 0x4039E9, 0x403A08\n\nencrypt data using RC4 KSA (3 matches)\nnamespace  data-manipulation/encryption/rc4                                     \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Encrypt Data::RC4 [C0027.009], Cryptography::Encryption\n           Key::RC4 KSA [C0028.002]                                             \nfunction @ 0x402A76\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x402E25\n          or:\n            number: 0xFF @ 0x402E46\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x402CD7, 0x402D72, 0x402E46\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x402D72\n            or:\n              number: 0xFF @ 0x402D72\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x402E46\n            or:\n              number: 0xFF @ 0x402E46\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x402CD7\n            or:\n              number: 0xFF @ 0x402CD7\n      or: = modulo key length\n        mnemonic: idiv @ 0x402BA4, 0x402C08, 0x402C6B, 0x402C75, and 2 more...\nfunction @ 0x40350F\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x4036F2\n          or:\n            number: 0xFF @ 0x403772\n        and: = initialize S\n          characteristic: tight loop @ 0x40361F\n          or:\n            number: 0xFF @ 0x40364A\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x40364A, 0x403772\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x40364A\n            or:\n              number: 0xFF @ 0x40364A\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x403772\n            or:\n              number: 0xFF @ 0x403772\n      or: = modulo key length\n        mnemonic: idiv @ 0x40355D, 0x403628, 0x40363E, 0x403661, and 3 more...\nfunction @ 0x403797\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x403980\n          or:\n            number: 0xFF @ 0x403A03\n        and: = initialize S\n          characteristic: tight loop @ 0x4038AD\n          or:\n            number: 0xFF @ 0x4038D8\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x4038D8, 0x403A03\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x4038D8\n            or:\n              number: 0xFF @ 0x4038D8\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x403A03\n            or:\n              number: 0xFF @ 0x403A03\n      or: = modulo key length\n        mnemonic: idiv @ 0x4037E5, 0x4038B6, 0x4038CC, 0x4038EF, and 3 more...\n\ngenerate random numbers using the Delphi LCG\nnamespace   data-manipulation/prng/lcg                                          \nauthor      william.ballenthin@mandiant.com                                     \nscope       basic block                                                         \nmbc         Cryptography::Generate Pseudo-random Sequence [C0021]               \nreferences  https://en.wikipedia.org/wiki/Linear_congruential_generator,        \n            https://community.osr.com/discussion/130410/generating-random-numbe…\nbasic block @ 0x405535 in function 0x405535\n  and:\n    instruction:\n      and:\n        mnemonic: imul @ 0x405567\n        number: 0x8088405 = multiplier a @ 0x405567\n    mnemonic: inc = increment c @ 0x40556D\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x401DAB\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x401DD3\n        api: LockResource @ 0x401DDE\n      optional:\n        or:\n          api: FindResource @ 0x401DC3\n        api: SizeofResource @ 0x401DF1\n\nget common file path (3 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x4010FD\n  or:\n    api: GetCurrentDirectory @ 0x40119A\nfunction @ 0x401B5F\n  or:\n    api: GetTempPath @ 0x401C97\n    api: GetWindowsDirectory @ 0x401BDD\nfunction @ 0x406B8E\n  or:\n    api: GetCurrentDirectory @ 0x406BB5\n\nset current directory (3 matches)\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x4010FD\n  or:\n    api: SetCurrentDirectory @ 0x4011FA\nfunction @ 0x401AF6\n  or:\n    api: SetCurrentDirectory @ 0x401B12, 0x401B21\nfunction @ 0x401FE7\n  or:\n    api: SetCurrentDirectory @ 0x4020BB\n\ncopy file\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ 0x401FE7\n  or:\n    api: CopyFile @ 0x40206F\n\ncreate directory (2 matches)\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x401AF6\n  or:\n    api: CreateDirectory @ 0x401B07, 0x401B1E\nfunction @ 0x407070\n  or:\n    api: CreateDirectory @ 0x407091, 0x40712C\n\ncheck if file exists (4 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x401B5F\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x401C10\n        instruction:\n          and:\n            mnemonic: cmp @ 0x401C16\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x401C16\nfunction @ 0x401DAB\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x401E6E\n        instruction:\n          and:\n            mnemonic: cmp @ 0x401E74\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x401E74\nfunction @ 0x401FE7\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x402076\n        instruction:\n          and:\n            mnemonic: cmp @ 0x40207C\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x40207C\nfunction @ 0x407070\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x407083\n        instruction:\n          and:\n            mnemonic: cmp @ 0x407089\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x407089\n      and:\n        api: GetFileAttributes @ 0x407118\n        instruction:\n          and:\n            mnemonic: cmp @ 0x40711E\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x40711E\n\nget file attributes (6 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x401B2B in function 0x401AF6\n  or:\n    api: GetFileAttributes @ 0x401B2C\nbasic block @ 0x401B5F in function 0x401B5F\n  or:\n    api: GetFileAttributes @ 0x401C10\nbasic block @ 0x401E67 in function 0x401DAB\n  or:\n    api: GetFileAttributes @ 0x401E6E\nbasic block @ 0x402061 in function 0x401FE7\n  or:\n    api: GetFileAttributes @ 0x402076\nbasic block @ 0x407082 in function 0x407070\n  or:\n    api: GetFileAttributes @ 0x407083\nbasic block @ 0x407102 in function 0x407070\n  or:\n    api: GetFileAttributes @ 0x407118\n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x4014A6\n  or:\n    api: GetFileSizeEx @ 0x401529\nfunction @ 0x4018F9\n  or:\n    api: GetFileSize @ 0x40194A\n\nset file attributes\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ 0x401B2B in function 0x401AF6\n  or:\n    api: SetFileAttributes @ 0x401B36\n\nread file on Windows (3 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x401000\n  or:\n    and:\n      os: windows\n      or:\n        api: fread @ 0x40103F\nfunction @ 0x4018F9\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x401932\n          match: create or open file @ 0x40193A\n            or:\n              api: CreateFile @ 0x40193A\n      or:\n        api: ReadFile @ 0x40197D\nfunction @ 0x405D8A\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x405DAB\n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x401000\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            match: create or open file @ 0x40101B\n              or:\n                api: fopen @ 0x40101B\n      or:\n        api: fwrite @ 0x401047\nfunction @ 0x407136\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x407325\n            number: 0x2 = FILE_WRITE_DATA @ 0x40731B\n            match: create or open file @ 0x40732B\n              or:\n                api: CreateFile @ 0x40732B\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x40714C\n      or:\n        api: WriteFile @ 0x40740B\n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex                                               \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           mehunhoff@google.com                                                 \nscope      instruction                                                          \nmbc        Process::Create Mutex [C0042]                                        \ninstruction @ 0x401F31\n  or:\n    api: OpenMutex @ 0x401F31\n\nget hostname\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ 0x401225\n  or:\n    api: GetComputerName @ 0x40125F\n\ncreate process on Windows\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x401064 in function 0x401064\n  or:\n    api: CreateProcess @ 0x4010A8\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x401064\n  or:\n    and:\n      or:\n        api: TerminateProcess @ 0x4010CC\n\nquery or enumerate registry value\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x4010FD\n  and:\n    optional:\n      match: create or open registry key @ 0x40116E, 0x40117A\n        or:\n          api: RegCreateKey @ 0x40117A\n        or:\n          api: RegCreateKey @ 0x401173\n    or:\n      api: RegQueryValueEx @ 0x4011E4\n\nset registry value\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x4010FD\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x40116E, 0x40117A\n          or:\n            api: RegCreateKey @ 0x40117A\n          or:\n            api: RegCreateKey @ 0x401173\n      or:\n        api: RegSetValueEx @ 0x4011BD\n\ncreate service\nnamespace  host-interaction/service/create                                      \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003], Execution::System Services::Service Execution           \n           [T1569.002]                                                          \nfunction @ 0x401CE8\n  and:\n    api: CreateService @ 0x401D75\n    optional:\n      api: OpenSCManager @ 0x401CFE\n\nstart service\nnamespace  host-interaction/service/start                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003]                                                          \nfunction @ 0x401CE8\n  and:\n    api: StartService @ 0x401D31, 0x401D84\n    optional:\n      match: get service handle @ 0x401CE8\n        or:\n          api: CreateService @ 0x401D75\n          api: OpenService @ 0x401D21\n\nlink function at runtime on Windows (13 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x401749\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401749\ninstruction @ 0x401756\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401756\ninstruction @ 0x401763\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401763\ninstruction @ 0x401770\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401770\ninstruction @ 0x40177D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40177D\ninstruction @ 0x40178A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40178A\ninstruction @ 0x401797\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401797\ninstruction @ 0x401A77\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401A77\ninstruction @ 0x401A84\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401A84\ninstruction @ 0x401A91\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401A91\ninstruction @ 0x401A9E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401A9E\ninstruction @ 0x401AAB\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401AAB\ninstruction @ 0x401AB8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401AB8\n\nlink many functions at runtime (2 matches)\nnamespace  linking/runtime-linking                      \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com\nscope      function                                     \natt&ck     Execution::Shared Modules [T1129]            \nfunction @ 0x40170A\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x401749, 0x401756, 0x401763, 0x401770, and 3 more...\nfunction @ 0x401A45\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x401A77, 0x401A84, 0x401A91, 0x401A9E, and 2 more...\n\nlinked against ZLIB\nnamespace  linking/static/zlib              \nauthor     william.ballenthin@mandiant.com  \nscope      file                             \nmbc        Data::Compression Library [C0060]\nor:\n  regex: /inflate .* Copyright/\n    - \" inflate 1.1.3 Copyright 1995-1998 Mark Adler \" @ file+0xCE3C\n\nenumerate PE sections (2 matches)\nnamespace   load-code/pe                                                        \nauthor      @Ana06, @mr-tz                                                      \nscope       function                                                            \nmbc         Discovery::Code Discovery::Enumerate PE Sections [B0046.001]        \nreferences  https://0x00sec.org/t/reflective-dll-injection/3080,                \n            https://www.ired.team/offensive-security/code-injection-process-inj…\nfunction @ 0x4021E9\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x402260\n        or:\n          mnemonic: movzx @ 0x402260\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x40225C\n              or:\n                mnemonic: movzx @ 0x40225C\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x402266\n    count(basic block): 3 or more @ 0x4021E9, 0x40220A, 0x402214, 0x402219, and 39 more...\n    optional:\n      offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x402224, 0x40223F, 0x4023B4\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x40226C\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x40225C\nfunction @ 0x402470\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x402532\n        or:\n          mnemonic: movzx @ 0x402532\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x402486\n              or:\n                mnemonic: movzx @ 0x402486\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x40248F\n    count(basic block): 3 or more @ 0x402470, 0x402499, 0x40249C, 0x4024A2, and 9 more...\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x402486\n      operand[1].offset: 0x10 = IMAGE_SECTION_HEADER.SizeOfRawData @ 0x402499\n\nparse PE header\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x4021E9\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x40220D, 0x402244, 0x40224C, 0x40227E, and 3 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x402244\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x40220D\n      optional:\n        and:\n          operand[1].offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x402224, 0x40223F, 0x4023B4\n          or:\n            and:\n              arch: i386\n              operand[1].offset: 0x50 = IMAGE_NT_HEADERS.OptionalHeader.SizeOfImage @ 0x4022BE\n              operand[1].offset: 0x34 = IMAGE_NT_HEADERS.OptionalHeader.ImageBase @ 0x4023D0, 0x4023D3\n\npersist via Windows service\nnamespace  persistence/service                                                  \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003], Execution::System Services::Service Execution           \n           [T1569.002]                                                          \nfunction @ 0x401CE8\n  or:\n    and:\n      or:\n        basic block:\n          and:\n            number: 0x2 = SERVICE_AUTO_START @ 0x401D6B\n            api: CreateService @ 0x401D75\n      optional:\n        or:\n          api: OpenService @ 0x401D21\n          api: StartService @ 0x401D31, 0x401D84\n\n\n\n"},"hashes":{"md5":"84c82835a5d21bbcf75a61706d8ab549","sha1":"5ff465afaabcbf0150d1a3ab2c2e74f3a4426467","sha256":"ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 130</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 50772</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Ransomw\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"84c82835a5d21bbcf75a61706d8ab549\",\n        \"sha256\": \"ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_library_rule_\",\n      \"label\": \"library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Modulo [C0058]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_loop__33_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (33 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x4010FD\",\n      \"label\": \"Function 0x4010FD\",\n      \"type\": \"function\",\n      \"address\": \"0x4010FD\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__5_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (5 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_fopen\",\n      \"label\": \"fopen\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40116E\",\n      \"label\": \"Block 0x40116E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40116E\"\n    },\n    {\n      \"id\": \"api_RegCreateKey\",\n      \"label\": \"RegCreateKey\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4010B7\",\n      \"label\": \"Block 0x4010B7\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4010B7\"\n    },\n    {\n      \"id\": \"api_WaitForSingleObject\",\n      \"label\": \"WaitForSingleObject\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_hash_data_with_crc32__2_matches_\",\n      \"label\": \"hash data with CRC32 (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40541F\",\n      \"label\": \"Function 0x40541F\",\n      \"type\": \"function\",\n      \"address\": \"0x40541F\"\n    },\n    {\n      \"id\": \"func_0x405535\",\n      \"label\": \"Function 0x405535\",\n      \"type\": \"function\",\n      \"address\": \"0x405535\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_aes__5_matches_\",\n      \"label\": \"encrypt data using AES (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or\",\n        \"Information::Encryption-Standard Algorithm [E1027.m05]\",\n        \"Cryptography::Encrypt Data::AES [C0027.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x403797\",\n      \"label\": \"Function 0x403797\",\n      \"type\": \"function\",\n      \"address\": \"0x403797\"\n    },\n    {\n      \"id\": \"func_0x402A76\",\n      \"label\": \"Function 0x402A76\",\n      \"type\": \"function\",\n      \"address\": \"0x402A76\"\n    },\n    {\n      \"id\": \"func_0x402E7E\",\n      \"label\": \"Function 0x402E7E\",\n      \"type\": \"function\",\n      \"address\": \"0x402E7E\"\n    },\n    {\n      \"id\": \"func_0x40350F\",\n      \"label\": \"Function 0x40350F\",\n      \"type\": \"function\",\n      \"address\": \"0x40350F\"\n    },\n    {\n      \"id\": \"func_0x4031BC\",\n      \"label\": \"Function 0x4031BC\",\n      \"type\": \"function\",\n      \"address\": \"0x4031BC\"\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com__ivan_kwiatkowski___justicerage_\",\n      \"label\": \"author      william.ballenthin@mandiant.com, Ivan Kwiatkowski (@JusticeRage)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or\",\n        \"Information::Encryption-Standard Algorithm [E1027.m05]\",\n        \"Cryptography::Encrypt Data::AES [C0027.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_aes_constants__5_matches_\",\n      \"label\": \"reference AES constants (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information [T1027]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information [T1027]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_rc4_ksa__3_matches_\",\n      \"label\": \"encrypt data using RC4 KSA (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data::RC4 [C0027.009]\",\n        \"Cryptography::Encryption\",\n        \"Key::RC4 KSA [C0028.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_using_the_delphi_lcg\",\n      \"label\": \"generate random numbers using the Delphi LCG\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence [C0021]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x405535\",\n      \"label\": \"Block 0x405535\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x405535\"\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence [C0021]\"\n      ]\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401DAB\",\n      \"label\": \"Function 0x401DAB\",\n      \"type\": \"function\",\n      \"address\": \"0x401DAB\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__3_matches_\",\n      \"label\": \"get common file path (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x406B8E\",\n      \"label\": \"Function 0x406B8E\",\n      \"type\": \"function\",\n      \"address\": \"0x406B8E\"\n    },\n    {\n      \"id\": \"func_0x401B5F\",\n      \"label\": \"Function 0x401B5F\",\n      \"type\": \"function\",\n      \"address\": \"0x401B5F\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetCurrentDirectory\",\n      \"label\": \"GetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_current_directory__3_matches_\",\n      \"label\": \"set current directory (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401FE7\",\n      \"label\": \"Function 0x401FE7\",\n      \"type\": \"function\",\n      \"address\": \"0x401FE7\"\n    },\n    {\n      \"id\": \"func_0x401AF6\",\n      \"label\": \"Function 0x401AF6\",\n      \"type\": \"function\",\n      \"address\": \"0x401AF6\"\n    },\n    {\n      \"id\": \"api_SetCurrentDirectory\",\n      \"label\": \"SetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_copy_file\",\n      \"label\": \"copy file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"api_CopyFile\",\n      \"label\": \"CopyFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory__2_matches_\",\n      \"label\": \"create directory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407070\",\n      \"label\": \"Function 0x407070\",\n      \"type\": \"function\",\n      \"address\": \"0x407070\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__4_matches_\",\n      \"label\": \"check if file exists (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_get_file_attributes__6_matches_\",\n      \"label\": \"get file attributes (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x407082\",\n      \"label\": \"Block 0x407082\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x407082\"\n    },\n    {\n      \"id\": \"bb_0x401B5F\",\n      \"label\": \"Block 0x401B5F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401B5F\"\n    },\n    {\n      \"id\": \"bb_0x402061\",\n      \"label\": \"Block 0x402061\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x402061\"\n    },\n    {\n      \"id\": \"bb_0x407102\",\n      \"label\": \"Block 0x407102\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x407102\"\n    },\n    {\n      \"id\": \"bb_0x401B2B\",\n      \"label\": \"Block 0x401B2B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401B2B\"\n    },\n    {\n      \"id\": \"bb_0x401E67\",\n      \"label\": \"Block 0x401E67\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401E67\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size__2_matches_\",\n      \"label\": \"get file size (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4014A6\",\n      \"label\": \"Function 0x4014A6\",\n      \"type\": \"function\",\n      \"address\": \"0x4014A6\"\n    },\n    {\n      \"id\": \"func_0x4018F9\",\n      \"label\": \"Function 0x4018F9\",\n      \"type\": \"function\",\n      \"address\": \"0x4018F9\"\n    },\n    {\n      \"id\": \"api_GetFileSizeEx\",\n      \"label\": \"GetFileSizeEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_file_attributes\",\n      \"label\": \"set file attributes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"api_SetFileAttributes\",\n      \"label\": \"SetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__3_matches_\",\n      \"label\": \"read file on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405D8A\",\n      \"label\": \"Function 0x405D8A\",\n      \"type\": \"function\",\n      \"address\": \"0x405D8A\"\n    },\n    {\n      \"id\": \"func_0x401000\",\n      \"label\": \"Function 0x401000\",\n      \"type\": \"function\",\n      \"address\": \"0x401000\"\n    },\n    {\n      \"id\": \"api_fread\",\n      \"label\": \"fread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__2_matches_\",\n      \"label\": \"write file on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407136\",\n      \"label\": \"Function 0x407136\",\n      \"type\": \"function\",\n      \"address\": \"0x407136\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_fwrite\",\n      \"label\": \"fwrite\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_or_open_mutex_on_windows\",\n      \"label\": \"create or open mutex on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"api_OpenMutex\",\n      \"label\": \"OpenMutex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_mehunhoff_google_com\",\n      \"label\": \"mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_hostname\",\n      \"label\": \"get hostname\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401225\",\n      \"label\": \"Function 0x401225\",\n      \"type\": \"function\",\n      \"address\": \"0x401225\"\n    },\n    {\n      \"id\": \"api_GetComputerName\",\n      \"label\": \"GetComputerName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_process_on_windows\",\n      \"label\": \"create process on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401064\",\n      \"label\": \"Block 0x401064\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401064\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401064\",\n      \"label\": \"Function 0x401064\",\n      \"type\": \"function\",\n      \"address\": \"0x401064\"\n    },\n    {\n      \"id\": \"api_TerminateProcess\",\n      \"label\": \"TerminateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value\",\n      \"label\": \"query or enumerate registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value\",\n      \"label\": \"set registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_create_service\",\n      \"label\": \"create service\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\",\n        \"Execution::System Services::Service Execution\",\n        \"[T1569.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401CE8\",\n      \"label\": \"Function 0x401CE8\",\n      \"type\": \"function\",\n      \"address\": \"0x401CE8\"\n    },\n    {\n      \"id\": \"api_OpenSCManager\",\n      \"label\": \"OpenSCManager\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateService\",\n      \"label\": \"CreateService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_start_service\",\n      \"label\": \"start service\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_StartService\",\n      \"label\": \"StartService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_OpenService\",\n      \"label\": \"OpenService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__13_matches_\",\n      \"label\": \"link function at runtime on Windows (13 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_many_functions_at_runtime__2_matches_\",\n      \"label\": \"link many functions at runtime (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40170A\",\n      \"label\": \"Function 0x40170A\",\n      \"type\": \"function\",\n      \"address\": \"0x40170A\"\n    },\n    {\n      \"id\": \"func_0x401A45\",\n      \"label\": \"Function 0x401A45\",\n      \"type\": \"function\",\n      \"address\": \"0x401A45\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_linked_against_zlib\",\n      \"label\": \"linked against ZLIB\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Compression Library [C0060]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_pe_sections__2_matches_\",\n      \"label\": \"enumerate PE sections (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402470\",\n      \"label\": \"Function 0x402470\",\n      \"type\": \"function\",\n      \"address\": \"0x402470\"\n    },\n    {\n      \"id\": \"func_0x4021E9\",\n      \"label\": \"Function 0x4021E9\",\n      \"type\": \"function\",\n      \"address\": \"0x4021E9\"\n    },\n    {\n      \"id\": \"cap_author_______ana06___mr_tz\",\n      \"label\": \"author      @Ana06, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header\",\n      \"label\": \"parse PE header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_persist_via_windows_service\",\n      \"label\": \"persist via Windows service\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\",\n        \"Execution::System Services::Service Execution\",\n        \"[T1569.002]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__33_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__33_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x4010FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__5_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x40116E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x4010B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_crc32__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_with_crc32__2_matches_\",\n      \"target\": \"func_0x40541F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_with_crc32__2_matches_\",\n      \"target\": \"func_0x405535\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x40541F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x405535\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_aes__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_aes__5_matches_\",\n      \"target\": \"func_0x403797\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_aes__5_matches_\",\n      \"target\": \"func_0x402A76\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_aes__5_matches_\",\n      \"target\": \"func_0x402E7E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_aes__5_matches_\",\n      \"target\": \"func_0x40350F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_aes__5_matches_\",\n      \"target\": \"func_0x4031BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com__ivan_kwiatkowski___justicerage_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com__ivan_kwiatkowski___justicerage_\",\n      \"target\": \"func_0x403797\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com__ivan_kwiatkowski___justicerage_\",\n      \"target\": \"func_0x402A76\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com__ivan_kwiatkowski___justicerage_\",\n      \"target\": \"func_0x402E7E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com__ivan_kwiatkowski___justicerage_\",\n      \"target\": \"func_0x40350F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com__ivan_kwiatkowski___justicerage_\",\n      \"target\": \"func_0x4031BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_aes_constants__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_reference_aes_constants__5_matches_\",\n      \"target\": \"func_0x403797\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_reference_aes_constants__5_matches_\",\n      \"target\": \"func_0x402A76\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_reference_aes_constants__5_matches_\",\n      \"target\": \"func_0x402E7E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_reference_aes_constants__5_matches_\",\n      \"target\": \"func_0x40350F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_reference_aes_constants__5_matches_\",\n      \"target\": \"func_0x4031BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x403797\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x402A76\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x402E7E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40350F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x4031BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_rc4_ksa__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__3_matches_\",\n      \"target\": \"func_0x403797\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__3_matches_\",\n      \"target\": \"func_0x402A76\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__3_matches_\",\n      \"target\": \"func_0x40350F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x403797\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x402A76\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x40350F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_using_the_delphi_lcg\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_the_delphi_lcg\",\n      \"target\": \"bb_0x405535\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"bb_0x405535\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x401DAB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401DAB\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401DAB\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401DAB\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401DAB\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x401DAB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401DAB\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401DAB\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401DAB\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401DAB\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x406B8E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x401B5F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x4010FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406B8E\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B5F\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010FD\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406B8E\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B5F\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010FD\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406B8E\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B5F\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010FD\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406B8E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401B5F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4010FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406B8E\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B5F\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010FD\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406B8E\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B5F\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010FD\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406B8E\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B5F\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010FD\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_current_directory__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__3_matches_\",\n      \"target\": \"func_0x401FE7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__3_matches_\",\n      \"target\": \"func_0x401AF6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__3_matches_\",\n      \"target\": \"func_0x4010FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401FE7\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401AF6\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010FD\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401FE7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401AF6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4010FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401FE7\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401AF6\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010FD\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_copy_file\",\n      \"target\": \"func_0x401FE7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401FE7\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401FE7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401FE7\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory__2_matches_\",\n      \"target\": \"func_0x401AF6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__2_matches_\",\n      \"target\": \"func_0x407070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401AF6\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407070\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401AF6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401AF6\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407070\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__4_matches_\",\n      \"target\": \"func_0x401FE7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__4_matches_\",\n      \"target\": \"func_0x401B5F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__4_matches_\",\n      \"target\": \"func_0x407070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__4_matches_\",\n      \"target\": \"func_0x401DAB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401FE7\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B5F\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407070\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401DAB\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401FE7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401B5F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401DAB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401FE7\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B5F\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407070\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401DAB\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x407082\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x401B5F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x402061\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x407102\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x401B2B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x401E67\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x407082\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x401B5F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x402061\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x407102\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x401B2B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x401E67\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x4014A6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x4018F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4014A6\",\n      \"target\": \"api_GetFileSizeEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4018F9\",\n      \"target\": \"api_GetFileSizeEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4014A6\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4018F9\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4014A6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4018F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4014A6\",\n      \"target\": \"api_GetFileSizeEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4018F9\",\n      \"target\": \"api_GetFileSizeEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4014A6\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4018F9\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes\",\n      \"target\": \"bb_0x401B2B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x401B2B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__3_matches_\",\n      \"target\": \"func_0x4018F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__3_matches_\",\n      \"target\": \"func_0x405D8A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__3_matches_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4018F9\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405D8A\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4018F9\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405D8A\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4018F9\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405D8A\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4018F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405D8A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4018F9\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405D8A\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4018F9\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405D8A\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4018F9\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405D8A\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x407136\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407136\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407136\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407136\",\n      \"target\": \"api_fopen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_fopen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407136\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x407136\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407136\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407136\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407136\",\n      \"target\": \"api_fopen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_fopen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407136\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_mutex_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_hostname\",\n      \"target\": \"func_0x401225\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401225\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401225\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401225\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows\",\n      \"target\": \"bb_0x401064\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x401064\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x401064\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401064\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401064\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401064\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value\",\n      \"target\": \"func_0x4010FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4010FD\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010FD\",\n      \"target\": \"api_RegCreateKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4010FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4010FD\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010FD\",\n      \"target\": \"api_RegCreateKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value\",\n      \"target\": \"func_0x4010FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4010FD\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010FD\",\n      \"target\": \"api_RegCreateKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4010FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4010FD\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010FD\",\n      \"target\": \"api_RegCreateKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_service\",\n      \"target\": \"func_0x401CE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401CE8\",\n      \"target\": \"api_OpenSCManager\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401CE8\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x401CE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401CE8\",\n      \"target\": \"api_OpenSCManager\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401CE8\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_start_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_start_service\",\n      \"target\": \"func_0x401CE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401CE8\",\n      \"target\": \"api_StartService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401CE8\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401CE8\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x401CE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401CE8\",\n      \"target\": \"api_StartService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401CE8\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401CE8\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__13_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_many_functions_at_runtime__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__2_matches_\",\n      \"target\": \"func_0x40170A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__2_matches_\",\n      \"target\": \"func_0x401A45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x40170A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x401A45\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_zlib\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_pe_sections__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__2_matches_\",\n      \"target\": \"func_0x402470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__2_matches_\",\n      \"target\": \"func_0x4021E9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______ana06___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x402470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x4021E9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header\",\n      \"target\": \"func_0x4021E9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4021E9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_persist_via_windows_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_persist_via_windows_service\",\n      \"target\": \"func_0x401CE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401CE8\",\n      \"target\": \"api_StartService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401CE8\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401CE8\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x401CE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401CE8\",\n      \"target\": \"api_StartService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401CE8\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401CE8\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-10 12:35:19.814041\",\n    \"total_functions\": \"130\",\n    \"total_features\": \"50772\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-10 12:35:20"}
{"_id":{"$oid":"6a4fa5400108394cb24cdcc9"},"sha256":"55504677f82981962d85495231695d3a92aa0b31ec35a957bd9cbbef618658e3","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_j69l70ix/Win32.Wannacry-019f46be5b007b008f44380f3d6b7c78.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_j69l70ix/Win32.Wannacry-019f46be5b007b008f44380f3d6b7c78.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_j69l70ix/Win32.Wannacry-019f46be5b007b008f44380f3d6b7c78.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 30fe2f9a048d7a734c8d9233f64810ba                                  │\n│ sha1     │ 2027a053de21bd5c783c3f823ed1d36966780ed4                          │\n│ sha256   │ 55504677f82981962d85495231695d3a92aa0b31ec35a957bd9cbbef618658e3  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/Win32.Wannacry-0… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective                ┃ MBC Behavior                                  ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DATA                         │ Compression Library [C0060]                   │\n│ EXECUTION                    │ Install Additional Program [B0023]            │\n│ FILE SYSTEM                  │ Writes File [C0052]                           │\n│ PROCESS                      │ Create Process [C0017]                        │\n└──────────────────────────────┴───────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                              ┃ Namespace                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ extract resource via kernel32 functions │ executable/resource                │\n│ contain an embedded PE file             │ executable/subfile/pe              │\n│ write file on Windows                   │ host-interaction/file-system/write │\n│ create process on Windows               │ host-interaction/process/create    │\n│ linked against ZLIB                     │ linking/static/zlib                │\n└─────────────────────────────────────────┴────────────────────────────────────┘\n\n","verbose":"md5                     30fe2f9a048d7a734c8d9233f64810ba                        \nsha1                    2027a053de21bd5c783c3f823ed1d36966780ed4                \nsha256                  55504677f82981962d85495231695d3a92aa0b31ec35a957bd9cbbe…\npath                    /home/apogean/projects/malware/windows/all_runs/Win32.W…\ntimestamp               2026-07-09 19:12:05.892645                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x10000000                                              \nrules                   /tmp/_MEIDr3hR4/rules                                   \nfunction count          5                                                       \nlibrary function count  2                                                       \ntotal feature count     30028                                                   \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x10001016         \n\ncontain an embedded PE file\nnamespace  executable/subfile/pe\nscope      file                 \n\nwrite file on Windows\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x10001016                        \n\ncreate process on Windows\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x100010AB                     \n\nlinked against ZLIB\nnamespace  linking/static/zlib\nscope      file               \n\n\n\n","very_verbose":"md5                     30fe2f9a048d7a734c8d9233f64810ba                        \nsha1                    2027a053de21bd5c783c3f823ed1d36966780ed4                \nsha256                  55504677f82981962d85495231695d3a92aa0b31ec35a957bd9cbbe…\npath                    /home/apogean/projects/malware/windows/all_runs/Win32.W…\ntimestamp               2026-07-09 19:12:23.726595                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x10000000                                              \nrules                   /tmp/_MEIIn4SOW/rules                                   \nfunction count          5                                                       \nlibrary function count  2                                                       \ntotal feature count     30028                                                   \n\ncreate or open file (library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x1000107C\n  or:\n    api: CreateFile @ 0x1000107C\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x10001016\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x10001039\n        api: LockResource @ 0x10001044\n      optional:\n        or:\n          api: FindResource @ 0x10001026\n        api: SizeofResource @ 0x10001057\n\ncontain an embedded PE file\nnamespace  executable/subfile/pe                        \nauthor     moritz.raabe@mandiant.com                    \nscope      file                                         \nmbc        Execution::Install Additional Program [B0023]\nor:\n  count(characteristic(embedded pe)): 1 or more @ file+0x4064, file+0xF084, file+0x130E4, file+0x36108\n\nwrite file on Windows\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x10001016\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x10001072\n            number: 0x2 = FILE_WRITE_DATA @ 0x1000106C, 0x10001070\n            match: create or open file @ 0x1000107C\n              or:\n                api: CreateFile @ 0x1000107C\n      or:\n        api: WriteFile @ 0x10001096\n\ncreate process on Windows\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x100010AB in function 0x100010AB\n  or:\n    api: CreateProcess @ 0x100010F3\n\nlinked against ZLIB\nnamespace  linking/static/zlib              \nauthor     william.ballenthin@mandiant.com  \nscope      file                             \nmbc        Data::Compression Library [C0060]\nor:\n  regex: /inflate .* Copyright/\n    - \" inflate 1.1.3 Copyright 1995-1998 Mark Adler \" @ file+0x42F44\n\n\n\n"},"hashes":{"md5":"30fe2f9a048d7a734c8d9233f64810ba","sha1":"2027a053de21bd5c783c3f823ed1d36966780ed4","sha256":"55504677f82981962d85495231695d3a92aa0b31ec35a957bd9cbbef618658e3"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 5</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 30028</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Win32.W\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"30fe2f9a048d7a734c8d9233f64810ba\",\n        \"sha256\": \"55504677f82981962d85495231695d3a92aa0b31ec35a957bd9cbbe\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x10001016\",\n      \"label\": \"Function 0x10001016\",\n      \"type\": \"function\",\n      \"address\": \"0x10001016\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_contain_an_embedded_pe_file\",\n      \"label\": \"contain an embedded PE file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows\",\n      \"label\": \"write file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows\",\n      \"label\": \"create process on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x100010AB\",\n      \"label\": \"Block 0x100010AB\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x100010AB\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_linked_against_zlib\",\n      \"label\": \"linked against ZLIB\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Compression Library [C0060]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x10001016\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10001016\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10001016\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10001016\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10001016\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x10001016\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10001016\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10001016\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10001016\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10001016\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_an_embedded_pe_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows\",\n      \"target\": \"func_0x10001016\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10001016\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10001016\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10001016\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10001016\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10001016\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows\",\n      \"target\": \"bb_0x100010AB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x100010AB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_zlib\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 19:12:23.726595\",\n    \"total_functions\": \"5\",\n    \"total_features\": \"30028\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 19:12:24"}
{"_id":{"$oid":"6a4fa9ba0108394cb24cdccc"},"sha256":"ddf2542dc5ac74a98d5ee9e55497572104d6c880aad9137caf884d10ca5953ce","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":true,"path":"/tmp/sdm_capa_n5y882no/Somoto-019f46cb30ff74629c5dbc498a84a55e.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_n5y882no/Somoto-019f46cb30ff74629c5dbc498a84a55e.exe_very_verbose.txt"}},"outputs":{"normal":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"md5                     02e0b78e2876087f678f070ed60e4c30                        \nsha1                    28ab8945612608716ca3959061ce79b92b9c5f41                \nsha256                  ddf2542dc5ac74a98d5ee9e55497572104d6c880aad9137caf884d1…\npath                    /home/apogean/projects/malware/windows/all_runs/Somoto-…\ntimestamp               2026-07-09 22:18:03.232643                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIqeRbou/rules                                   \nfunction count          231                                                     \nlibrary function count  0                                                       \ntotal feature count     8547                                                    \n\ncapture webcam image\nnamespace  collection/webcam\nscope      function         \nmatches    0x40531A         \n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32\nscope      function                        \nmatches    0x406FC4                        \n\nencode data using XOR\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x406FDF                      \n\npackaged as a NSIS installer\nnamespace  executable/installer/nsis\nscope      file                     \n\naccept command line arguments\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x4039AC            \n\nopen clipboard\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x404ABC                  \n\nwrite clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x404ABC                  \n\nquery environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x40158E                             \n\nget common file path (3 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x4039AC                    \n           0x4065B4                    \n           0x406882                    \n\nget file system object information\nnamespace  host-interaction/file-system\nscope      basic block                 \nmatches    0x4039AC                    \n\nset current directory (2 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x40158E                    \n           0x4039AC                    \n\ncopy file (2 matches)\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    0x40158E                         \n           0x4039AC                         \n\ncreate directory (3 matches)\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x40158E                           \n           0x403955                           \n           0x4039AC                           \n\ndelete directory\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x406C7A                           \n\ndelete file (3 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x40158E                           \n           0x4039AC                           \n           0x406C7A                           \n\ncheck if file exists (3 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x405DD6                           \n           0x4069A0                           \n           0x4069D8                           \n\nenumerate files on Windows (2 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x40158E                               \n           0x406C7A                               \n\nenumerate files recursively\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x406C7A                               \n\nget file attributes (5 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x40179D                         \n           0x405F24                         \n           0x406974                         \n           0x4069A0                         \n           0x4069D8                         \n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x40351B                         \n           0x406A6B                         \n\nget file version info\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x40158E                         \n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x401731                         \n           0x4069F0                         \n\nmove file\nnamespace  host-interaction/file-system/move\nscope      function                         \nmatches    0x40158E                         \n\nread .ini file\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x40158E                         \n\nread file on Windows (4 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x40158E                         \n           0x403110                         \n           0x4033D2                         \n           0x406A6B                         \n\nwrite file on Windows (4 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x40158E                          \n           0x40321D                          \n           0x4033D2                          \n           0x406A6B                          \n\nfind graphical window\nnamespace  host-interaction/gui/window/find\nscope      instruction                     \nmatches    0x401FE0                        \n\nhide graphical window (4 matches)\nnamespace  host-interaction/gui/window/hide\nscope      basic block                     \nmatches    0x4031EC                        \n           0x404C29                        \n           0x404D13                        \n           0x404D67                        \n\nget disk size\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x404EF5                         \n\nshutdown system\nnamespace  host-interaction/os\nscope      function           \nmatches    0x4039AC           \n\ncheck OS version\nnamespace  host-interaction/os/version\nscope      function                   \nmatches    0x4065B4                   \n\ncreate process on Windows (3 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x402205                       \n           0x405C2D                       \n           0x406F74                       \n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x4014BE                 \n           0x40158E                 \n\nquery or enumerate registry value (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x40158E                 \n           0x406534                 \n\nset registry value\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x40158E                        \n\ndelete registry key\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x4014BE                        \n\ndelete registry value\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x40158E                        \n\ncreate thread\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x404CCD                      \n\nlink function at runtime on Windows (2 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x40241E               \n           0x4062C9               \n\ncreate shortcut via IShellLink\nnamespace  persistence\nscope      function   \nmatches    0x40158E   \n\n\n\n","very_verbose":"md5                     02e0b78e2876087f678f070ed60e4c30                        \nsha1                    28ab8945612608716ca3959061ce79b92b9c5f41                \nsha256                  ddf2542dc5ac74a98d5ee9e55497572104d6c880aad9137caf884d1…\npath                    /home/apogean/projects/malware/windows/all_runs/Somoto-…\ntimestamp               2026-07-09 22:18:10.628925                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIHzwjm6/rules                                   \nfunction count          231                                                     \nlibrary function count  0                                                       \ntotal feature count     8547                                                    \n\ncalculate modulo 256 via x86 assembly (library rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x4025C3\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x4025C3\n    or:\n      number: 0xFF @ 0x4025C3\n\ncontain loop (39 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401000\n  or:\n    characteristic: loop @ 0x401000\n\ncreate or open file (2 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x403799\n  or:\n    api: CreateFile @ 0x403799\n\ncreate or open registry key (4 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x401496 in function 0x401461\n  or:\n    api: RegOpenKeyEx @ 0x4014A4\n\ndelay execution (2 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x401679 in function 0x40158E\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x40167A\n\nget OS version (library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x4065B4\n  or:\n    api: GetVersion @ 0x406640\n\ncapture webcam image\nnamespace  collection/webcam                \nauthor     johnk3r                          \nscope      function                         \natt&ck     Collection::Video Capture [T1125]\nfunction @ 0x40531A\n  or:\n    basic block:\n      and:\n        api: SendMessage @ 0x4056D4\n        number: 0x419 = WM_CAP_FILE_SAVEDIB @ 0x4056CC\n\nwrite and execute a file\nnamespace              communication/c2/file-transfer               \nmaec/malware-category  launcher                                     \nauthor                 moritz.raabe@mandiant.com                    \nscope                  function                                     \nmbc                    Execution::Install Additional Program [B0023]\nfunction @ 0x40158E\n  and:\n    match: host-interaction/file-system/write @ 0x40158E\n      or:\n        and:\n          os: windows\n          optional:\n            basic block:\n              or:\n                number: 0x40000000 = GENERIC_WRITE @ 0x402D92\n                number: 0x2 = FILE_WRITE_DATA @ 0x402D90\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402B45\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x40288A, 0x4028BA\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x4019D8\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402809\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x4024E8\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x4015E5\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401F4E\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402C51\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401A29\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401A67\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x40285E\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402103, 0x402152\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401DB4\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401F72, 0x401F83\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402030\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x4026BA\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x4029B7\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402CF8\n              or:\n                number: 0x40000000 = GENERIC_WRITE @ 0x401A3E\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401E4B\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401BFE\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x4022BF\n          or:\n            api: WriteFile @ 0x402B36, 0x402E67\n    match: host-interaction/process/create @ 0x402205\n      or:\n        api: ShellExecute @ 0x402216\n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32 \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \nmbc        Data::Checksum::CRC32 [C0032.001]\nfunction @ 0x406FC4\n  or:\n    and:\n      number: 0x1 = bits in a byte @ 0x406FE2, 0x406FEC\n      instruction:\n        and:\n          operand[1].number: 0x1 @ 0x406FE2\n          or:\n            mnemonic: and @ 0x406FE2\n      instruction:\n        and:\n          mnemonic: shr @ 0x406FEC\n          number: 0x1 @ 0x406FEC\n      characteristic: nzxor @ 0x406FEE, 0x407010, 0x407018\n      operand[1].number: 0xEDB88320 @ 0x406FE7\n\nencode data using XOR\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x406FDF in function 0x406FC4\n  and:\n    characteristic: tight loop @ 0x406FDF\n    characteristic: nzxor @ 0x406FEE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\npackaged as a NSIS installer\nnamespace   executable/installer/nsis            \nauthor      moritz.raabe@mandiant.com            \nscope       file                                 \nreferences  https://nsis.sourceforge.io/Main_Page\nor:\n  substring: http://nsis.sf.net\n    - \"http://nsis.sf.net/NSIS_Error\" @ file+0x7A11\n\naccept command line arguments\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x4039AC\n  or:\n    api: GetCommandLine @ 0x403A11\n\nopen clipboard\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ 0x404ABC\n  and:\n    api: OpenClipboard @ 0x404E72\n    optional:\n      api: CloseClipboard @ 0x404ED4\n\nwrite clipboard data\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \nmbc         Impact::Clipboard Modification [E1510]                              \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ 0x404ABC\n  and:\n    optional:\n      match: open clipboard @ 0x404ABC\n        and:\n          api: OpenClipboard @ 0x404E72\n          optional:\n            api: CloseClipboard @ 0x404ED4\n      api: EmptyClipboard @ 0x404E7A\n    or:\n      api: SetClipboardData @ 0x404ECC\n\nquery environment variable\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x40158E\n  or:\n    api: ExpandEnvironmentStrings @ 0x401D21\n\nget common file path (3 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x4039AC\n  or:\n    api: GetTempPath @ 0x403AFC\n    api: GetWindowsDirectory @ 0x403B18\nfunction @ 0x4065B4\n  or:\n    api: GetSystemDirectory @ 0x4066DE\n    api: GetWindowsDirectory @ 0x4066F4\n    api: SHGetSpecialFolderLocation @ 0x406733\nfunction @ 0x406882\n  or:\n    api: GetTempFileName @ 0x4068BC\n\nget file system object information\nnamespace  host-interaction/file-system                   \nauthor     michael.hunhoff@mandiant.com                   \nscope      basic block                                    \natt&ck     Discovery::File and Directory Discovery [T1083]\nbasic block @ 0x4039AC in function 0x4039AC\n  or:\n    api: SHGetFileInfo @ 0x4039F7\n\nset current directory (2 matches)\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x40158E\n  or:\n    api: SetCurrentDirectory @ 0x4017E4\nfunction @ 0x4039AC\n  or:\n    api: SetCurrentDirectory @ 0x403BF9\n\ncopy file (2 matches)\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ 0x40158E\n  or:\n    basic block:\n      and:\n        number: 0x2 = FO_COPY @ 0x4026BA\n        or:\n          api: SHFileOperation @ 0x402710\nfunction @ 0x4039AC\n  or:\n    api: CopyFile @ 0x403C72\n\ncreate directory (3 matches)\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x40158E\n  or:\n    api: CreateDirectory @ 0x401783\nfunction @ 0x403955\n  or:\n    api: CreateDirectory @ 0x40398F\nfunction @ 0x4039AC\n  or:\n    api: CreateDirectory @ 0x403BEE\n\ndelete directory\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ 0x406C7A\n  or:\n    api: RemoveDirectory @ 0x406E9A\n\ndelete file (3 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x40158E\n  or:\n    api: DeleteFile @ 0x402EB9\nfunction @ 0x4039AC\n  or:\n    api: DeleteFile @ 0x403B4B, 0x403C59\nfunction @ 0x406C7A\n  or:\n    api: DeleteFile @ 0x406CAD, 0x406DFD\n\ncheck if file exists (3 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x405DD6\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x405F28\n        instruction:\n          and:\n            mnemonic: cmp @ 0x405F30\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x405F30\nfunction @ 0x4069A0\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x4069AB\n        instruction:\n          and:\n            mnemonic: cmp @ 0x4069B4\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x4069B4\nfunction @ 0x4069D8\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x4069E3\n        instruction:\n          and:\n            mnemonic: cmp @ 0x4069EB\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x4069EB\n\nenumerate files on Windows (2 matches)\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ 0x40158E\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x402D0C\n      or:\n        api: FindNextFile @ 0x402CD8\n      optional:\n        api: FindClose @ 0x402CA6\n        match: contain loop @ 0x40158E\n          or:\n            characteristic: loop @ 0x40158E\nfunction @ 0x406C7A\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x406D69\n      or:\n        api: FindNextFile @ 0x406E43\n      optional:\n        api: FindClose @ 0x406E56\n        match: contain loop @ 0x406C7A\n          or:\n            characteristic: loop @ 0x406C7A\n            characteristic: recursive call @ 0x406C7A\n\nenumerate files recursively\nnamespace  host-interaction/file-system/files/list        \nauthor     @_re_fox, anushka.virgaonkar@mandiant.com      \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nmbc        Discovery::File and Directory Discovery [E1083]\nfunction @ 0x406C7A\n  and:\n    characteristic: recursive call @ 0x406C7A\n    or:\n      match: enumerate files on Windows @ 0x406C7A\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x406D69\n            or:\n              api: FindNextFile @ 0x406E43\n            optional:\n              api: FindClose @ 0x406E56\n              match: contain loop @ 0x406C7A\n                or:\n                  characteristic: loop @ 0x406C7A\n                  characteristic: recursive call @ 0x406C7A\n\nget file attributes (5 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x40179D in function 0x40158E\n  or:\n    api: GetFileAttributes @ 0x4017A1\nbasic block @ 0x405F24 in function 0x405DD6\n  or:\n    api: GetFileAttributes @ 0x405F28\nbasic block @ 0x406974 in function 0x4068DC\n  or:\n    api: GetFileAttributes @ 0x406986\nbasic block @ 0x4069A0 in function 0x4069A0\n  or:\n    api: GetFileAttributes @ 0x4069AB\nbasic block @ 0x4069D8 in function 0x4069D8\n  or:\n    api: GetFileAttributes @ 0x4069E3\n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x40351B\n  or:\n    api: GetFileSize @ 0x40359C\nfunction @ 0x406A6B\n  or:\n    api: GetFileSize @ 0x406B61\n\nget file version info\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x40158E\n  and:\n    or:\n      api: GetFileVersionInfo @ 0x40236A\n    optional: = retrieve specified version information from the version-information resource\n      api: VerQueryValue @ 0x402381\n      or:\n        api: GetFileVersionInfoSize @ 0x40232A\n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ 0x401731 in function 0x40158E\n  or:\n    api: SetFileAttributes @ 0x401741\nbasic block @ 0x4069F0 in function 0x4069D8\n  or:\n    api: SetFileAttributes @ 0x4069F7\n\nmove file\nnamespace  host-interaction/file-system/move                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Move File [C0063]                         \nfunction @ 0x40158E\n  or:\n    api: MoveFile @ 0x401837\n\nread .ini file\nnamespace  host-interaction/file-system/read     \nauthor     @_re_fox, michael.hunhoff@mandiant.com\nscope      function                              \nmbc        File System::Read File [C0051]        \nfunction @ 0x40158E\n  and:\n    optional:\n      api: GetFullPathName @ 0x4018A1\n    or:\n      api: GetPrivateProfileString @ 0x4027E8\n\nread file on Windows (4 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x40158E\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x402BA4\nfunction @ 0x403110\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x40312A\nfunction @ 0x4033D2\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x403429, 0x403485, 0x4034EC\nfunction @ 0x406A6B\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x406B91\n\nwrite file on Windows (4 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x40158E\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x402D92\n            number: 0x2 = FILE_WRITE_DATA @ 0x402D90\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402B45\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x40288A, 0x4028BA\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4019D8\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402809\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4024E8\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4015E5\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401F4E\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402C51\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401A29\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401A67\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x40285E\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402103, 0x402152\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401DB4\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401F72, 0x401F83\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402030\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4026BA\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4029B7\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402CF8\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x401A3E\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401E4B\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401BFE\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4022BF\n      or:\n        api: WriteFile @ 0x402B36, 0x402E67\nfunction @ 0x40321D\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x403352\nfunction @ 0x4033D2\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x4034A5\nfunction @ 0x406A6B\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x406C4E\n\nfind graphical window\nnamespace  host-interaction/gui/window/find               \nauthor     moritz.raabe@mandiant.com                      \nscope      instruction                                    \natt&ck     Discovery::Application Window Discovery [T1010]\ninstruction @ 0x401FE0\n  or:\n    api: FindWindowEx @ 0x401FE0\n\nhide graphical window (4 matches)\nnamespace  host-interaction/gui/window/hide                          \nauthor     michael.hunhoff@mandiant.com                              \nscope      basic block                                               \natt&ck     Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\nbasic block @ 0x4031EC in function 0x403149\n  and:\n    number: 0x0 = SW_HIDE @ 0x4031EF, 0x4031F6\n    api: ShowWindow @ 0x403210\nbasic block @ 0x404C29 in function 0x404ABC\n  and:\n    number: 0x0 = SW_HIDE @ 0x404C2B\n    api: ShowWindow @ 0x404C33\nbasic block @ 0x404D13 in function 0x404ABC\n  and:\n    number: 0x0 = SW_HIDE @ 0x404D15\n    api: ShowWindow @ 0x404D1D, 0x404D27\nbasic block @ 0x404D67 in function 0x404ABC\n  and:\n    number: 0x0 = SW_HIDE @ 0x404D76\n    api: ShowWindow @ 0x404D71\n\nget disk size\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ 0x404EF5\n  or:\n    api: GetDiskFreeSpace @ 0x4051DA\n\nshutdown system\nnamespace  host-interaction/os                   \nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \natt&ck     Impact::System Shutdown/Reboot [T1529]\nfunction @ 0x4039AC\n  or:\n    api: ExitWindowsEx @ 0x403DB2\n\ncheck OS version\nnamespace  host-interaction/os/version                    \nauthor     michael.hunhoff@mandiant.com, johnk3r          \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x4065B4\n  and:\n    match: get OS version @ 0x4065B4\n      or:\n        api: GetVersion @ 0x406640\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x4067D6\n            number: 0x6 = Windows Vista / Windows Server 2008 @ 0x4067D6\n        optional:\n          instruction:\n            and:\n              mnemonic: cmp @ 0x4066B0\n              or:\n                number: 0x0 @ 0x4066B0\n            and:\n              mnemonic: cmp @ 0x406705\n              or:\n                number: 0x0 @ 0x406705\n            and:\n              mnemonic: cmp @ 0x40685E\n              or:\n                number: 0x0 @ 0x40685E\n            and:\n              mnemonic: cmp @ 0x40676C\n              or:\n                number: 0x0 @ 0x40676C\n            and:\n              mnemonic: cmp @ 0x40666E\n              or:\n                number: 0x1 = Windows Server 2008 R2 / Windows 7 @ 0x40666E\n\ncreate process on Windows (3 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x402205 in function 0x40158E\n  or:\n    api: ShellExecute @ 0x402216\nbasic block @ 0x405C2D in function 0x4059F9\n  or:\n    api: ShellExecute @ 0x405C65\nbasic block @ 0x406F74 in function 0x406F74\n  or:\n    api: CreateProcess @ 0x406F9E\n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ 0x4014BE\n  and:\n    optional:\n      match: create or open registry key @ 0x4014BE\n        or:\n          api: RegOpenKeyEx @ 0x4014EB\n    or:\n      api: RegEnumKey @ 0x401535\nfunction @ 0x40158E\n  and:\n    optional:\n      match: create or open registry key @ 0x402887\n        or:\n          api: RegCreateKeyEx @ 0x4028C6\n    or:\n      api: RegEnumKey @ 0x402A43\n\nquery or enumerate registry value (2 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x40158E\n  and:\n    optional:\n      match: create or open registry key @ 0x402887\n        or:\n          api: RegCreateKeyEx @ 0x4028C6\n    or:\n      api: RegEnumValue @ 0x402A5E\n      api: RegQueryValueEx @ 0x40299F\nfunction @ 0x406534\n  and:\n    optional:\n      match: create or open registry key @ 0x406534\n        or:\n          api: RegOpenKeyEx @ 0x40655B\n    or:\n      api: RegQueryValueEx @ 0x406581\n\nset registry value\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x40158E\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x402887\n          or:\n            api: RegCreateKeyEx @ 0x4028C6\n      or:\n        api: RegSetValueEx @ 0x40293F\n\ndelete registry key\nnamespace  host-interaction/registry/delete                                \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\nscope      function                                                        \natt&ck     Defense Evasion::Modify Registry [T1112]                        \nmbc        Operating System::Registry::Delete Registry Key [C0036.002]     \nfunction @ 0x4014BE\n  and:\n    optional:\n      match: create or open registry key @ 0x4014BE\n        or:\n          api: RegOpenKeyEx @ 0x4014EB\n    or:\n      api: RegDeleteKey @ 0x401577\n\ndelete registry value\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ 0x40158E\n  and:\n    optional:\n      match: create or open registry key @ 0x402887\n        or:\n          api: RegCreateKeyEx @ 0x4028C6\n    or:\n      api: RegDeleteValue @ 0x40282B\n\ncreate thread\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x404CCD in function 0x404ABC\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x404CEC\n\n(internal) installer file limitation\nnamespace    internal/limitation/static                                         \nauthor       william.ballenthin@mandiant.com                                    \nscope        file                                                               \ndescription  This sample appears to be an installer.                            \n                                                                                \n             capa cannot handle installers well. This means the results may be  \n             misleading or incomplete.                                          \n             You should try to understand the install mechanism and analyze     \n             created files with capa.                                           \n                                                                                \nor:\n  match: executable/installer @ global\n    or:\n      substring: http://nsis.sf.net\n        - \"http://nsis.sf.net/NSIS_Error\" @ file+0x7A11\n\nlink function at runtime on Windows (2 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x40241E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40241E\ninstruction @ 0x4062C9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4062C9\n\ncreate shortcut via IShellLink\nnamespace   persistence                                                         \nauthor      matthew.williams@mandiant.com                                       \nscope       function                                                            \natt&ck      Persistence::Boot or Logon Autostart Execution::Shortcut            \n            Modification [T1547.009]                                            \nreferences  https://docs.microsoft.com/en-us/windows/win32/shell/links#creating…\nfunction @ 0x40158E\n  and:\n    offset: 0x50 = psl->SetPath @ 0x402576\n    offset: 0x18 = ppf->Save @ 0x4022EB, 0x40262C, 0x402F08, 0x402F4C\n    api: CoCreateInstance @ 0x402540\n    bytes: 0114020000000000c000000000000046 = CLSID_ShellLink @ 0x40253B\n    bytes: 0b01000000000000c000000000000046 = IID_IPersistFile @ 0x40255A\n    or:\n      bytes: ee14020000000000c000000000000046 = IID_IShellLinkA @ 0x402532\n\n\n\n"},"hashes":{"md5":"02e0b78e2876087f678f070ed60e4c30","sha1":"28ab8945612608716ca3959061ce79b92b9c5f41","sha256":"ddf2542dc5ac74a98d5ee9e55497572104d6c880aad9137caf884d10ca5953ce"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 231</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 8547</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Somoto-\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"02e0b78e2876087f678f070ed60e4c30\",\n        \"sha256\": \"ddf2542dc5ac74a98d5ee9e55497572104d6c880aad9137caf884d1\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__39_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (39 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401000\",\n      \"label\": \"Function 0x401000\",\n      \"type\": \"function\",\n      \"address\": \"0x401000\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401496\",\n      \"label\": \"Block 0x401496\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401496\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401679\",\n      \"label\": \"Block 0x401679\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401679\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_capture_webcam_image\",\n      \"label\": \"capture webcam image\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Video Capture [T1125]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40531A\",\n      \"label\": \"Function 0x40531A\",\n      \"type\": \"function\",\n      \"address\": \"0x40531A\"\n    },\n    {\n      \"id\": \"api_SendMessage\",\n      \"label\": \"SendMessage\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____johnk3r\",\n      \"label\": \"author     johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Video Capture [T1125]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_and_execute_a_file\",\n      \"label\": \"write and execute a file\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40158E\",\n      \"label\": \"Function 0x40158E\",\n      \"type\": \"function\",\n      \"address\": \"0x40158E\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_ShellExecute\",\n      \"label\": \"ShellExecute\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_maec_malware_category__launcher\",\n      \"label\": \"maec/malware-category  launcher\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_with_crc32\",\n      \"label\": \"hash data with CRC32\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x406FC4\",\n      \"label\": \"Function 0x406FC4\",\n      \"type\": \"function\",\n      \"address\": \"0x406FC4\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_packaged_as_a_nsis_installer\",\n      \"label\": \"packaged as a NSIS installer\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments\",\n      \"label\": \"accept command line arguments\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4039AC\",\n      \"label\": \"Function 0x4039AC\",\n      \"type\": \"function\",\n      \"address\": \"0x4039AC\"\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_open_clipboard\",\n      \"label\": \"open clipboard\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404ABC\",\n      \"label\": \"Function 0x404ABC\",\n      \"type\": \"function\",\n      \"address\": \"0x404ABC\"\n    },\n    {\n      \"id\": \"api_OpenClipboard\",\n      \"label\": \"OpenClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CloseClipboard\",\n      \"label\": \"CloseClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_clipboard_data\",\n      \"label\": \"write clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"api_SetClipboardData\",\n      \"label\": \"SetClipboardData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_EmptyClipboard\",\n      \"label\": \"EmptyClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable\",\n      \"label\": \"query environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_ExpandEnvironmentStrings\",\n      \"label\": \"ExpandEnvironmentStrings\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path__3_matches_\",\n      \"label\": \"get common file path (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4065B4\",\n      \"label\": \"Function 0x4065B4\",\n      \"type\": \"function\",\n      \"address\": \"0x4065B4\"\n    },\n    {\n      \"id\": \"func_0x406882\",\n      \"label\": \"Function 0x406882\",\n      \"type\": \"function\",\n      \"address\": \"0x406882\"\n    },\n    {\n      \"id\": \"api_GetTempFileName\",\n      \"label\": \"GetTempFileName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHGetSpecialFolderLocation\",\n      \"label\": \"SHGetSpecialFolderLocation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_system_object_information\",\n      \"label\": \"get file system object information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4039AC\",\n      \"label\": \"Block 0x4039AC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4039AC\"\n    },\n    {\n      \"id\": \"api_SHGetFileInfo\",\n      \"label\": \"SHGetFileInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_current_directory__2_matches_\",\n      \"label\": \"set current directory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_SetCurrentDirectory\",\n      \"label\": \"SetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_copy_file__2_matches_\",\n      \"label\": \"copy file (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"api_SHFileOperation\",\n      \"label\": \"SHFileOperation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CopyFile\",\n      \"label\": \"CopyFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory__3_matches_\",\n      \"label\": \"create directory (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x403955\",\n      \"label\": \"Function 0x403955\",\n      \"type\": \"function\",\n      \"address\": \"0x403955\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_delete_directory\",\n      \"label\": \"delete directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x406C7A\",\n      \"label\": \"Function 0x406C7A\",\n      \"type\": \"function\",\n      \"address\": \"0x406C7A\"\n    },\n    {\n      \"id\": \"api_RemoveDirectory\",\n      \"label\": \"RemoveDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_file__3_matches_\",\n      \"label\": \"delete file (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__3_matches_\",\n      \"label\": \"check if file exists (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405DD6\",\n      \"label\": \"Function 0x405DD6\",\n      \"type\": \"function\",\n      \"address\": \"0x405DD6\"\n    },\n    {\n      \"id\": \"func_0x4069A0\",\n      \"label\": \"Function 0x4069A0\",\n      \"type\": \"function\",\n      \"address\": \"0x4069A0\"\n    },\n    {\n      \"id\": \"func_0x4069D8\",\n      \"label\": \"Function 0x4069D8\",\n      \"type\": \"function\",\n      \"address\": \"0x4069D8\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"label\": \"enumerate files on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindNextFile\",\n      \"label\": \"FindNextFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindClose\",\n      \"label\": \"FindClose\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindFirstFile\",\n      \"label\": \"FindFirstFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_recursively\",\n      \"label\": \"enumerate files recursively\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     @_re_fox, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes__5_matches_\",\n      \"label\": \"get file attributes (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x405F24\",\n      \"label\": \"Block 0x405F24\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x405F24\"\n    },\n    {\n      \"id\": \"bb_0x40179D\",\n      \"label\": \"Block 0x40179D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40179D\"\n    },\n    {\n      \"id\": \"bb_0x4069D8\",\n      \"label\": \"Block 0x4069D8\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4069D8\"\n    },\n    {\n      \"id\": \"bb_0x406974\",\n      \"label\": \"Block 0x406974\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x406974\"\n    },\n    {\n      \"id\": \"bb_0x4069A0\",\n      \"label\": \"Block 0x4069A0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4069A0\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size__2_matches_\",\n      \"label\": \"get file size (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x406A6B\",\n      \"label\": \"Function 0x406A6B\",\n      \"type\": \"function\",\n      \"address\": \"0x406A6B\"\n    },\n    {\n      \"id\": \"func_0x40351B\",\n      \"label\": \"Function 0x40351B\",\n      \"type\": \"function\",\n      \"address\": \"0x40351B\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_file_version_info\",\n      \"label\": \"get file version info\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetFileVersionInfo\",\n      \"label\": \"GetFileVersionInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfoSize\",\n      \"label\": \"GetFileVersionInfoSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_VerQueryValue\",\n      \"label\": \"VerQueryValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_file_attributes__2_matches_\",\n      \"label\": \"set file attributes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4069F0\",\n      \"label\": \"Block 0x4069F0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4069F0\"\n    },\n    {\n      \"id\": \"bb_0x401731\",\n      \"label\": \"Block 0x401731\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401731\"\n    },\n    {\n      \"id\": \"api_SetFileAttributes\",\n      \"label\": \"SetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_move_file\",\n      \"label\": \"move file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"api_MoveFile\",\n      \"label\": \"MoveFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read__ini_file\",\n      \"label\": \"read .ini file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetPrivateProfileString\",\n      \"label\": \"GetPrivateProfileString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFullPathName\",\n      \"label\": \"GetFullPathName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__4_matches_\",\n      \"label\": \"read file on Windows (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4033D2\",\n      \"label\": \"Function 0x4033D2\",\n      \"type\": \"function\",\n      \"address\": \"0x4033D2\"\n    },\n    {\n      \"id\": \"func_0x403110\",\n      \"label\": \"Function 0x403110\",\n      \"type\": \"function\",\n      \"address\": \"0x403110\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__4_matches_\",\n      \"label\": \"write file on Windows (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40321D\",\n      \"label\": \"Function 0x40321D\",\n      \"type\": \"function\",\n      \"address\": \"0x40321D\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_graphical_window\",\n      \"label\": \"find graphical window\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindWindowEx\",\n      \"label\": \"FindWindowEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_hide_graphical_window__4_matches_\",\n      \"label\": \"hide graphical window (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x404D67\",\n      \"label\": \"Block 0x404D67\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x404D67\"\n    },\n    {\n      \"id\": \"bb_0x404D13\",\n      \"label\": \"Block 0x404D13\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x404D13\"\n    },\n    {\n      \"id\": \"bb_0x4031EC\",\n      \"label\": \"Block 0x4031EC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4031EC\"\n    },\n    {\n      \"id\": \"bb_0x404C29\",\n      \"label\": \"Block 0x404C29\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x404C29\"\n    },\n    {\n      \"id\": \"api_ShowWindow\",\n      \"label\": \"ShowWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_size\",\n      \"label\": \"get disk size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404EF5\",\n      \"label\": \"Function 0x404EF5\",\n      \"type\": \"function\",\n      \"address\": \"0x404EF5\"\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpace\",\n      \"label\": \"GetDiskFreeSpace\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_shutdown_system\",\n      \"label\": \"shutdown system\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::System Shutdown/Reboot [T1529]\"\n      ]\n    },\n    {\n      \"id\": \"api_ExitWindowsEx\",\n      \"label\": \"ExitWindowsEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_check_os_version\",\n      \"label\": \"check OS version\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetVersion\",\n      \"label\": \"GetVersion\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__3_matches_\",\n      \"label\": \"create process on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x406F74\",\n      \"label\": \"Block 0x406F74\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x406F74\"\n    },\n    {\n      \"id\": \"bb_0x405C2D\",\n      \"label\": \"Block 0x405C2D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x405C2D\"\n    },\n    {\n      \"id\": \"bb_0x402205\",\n      \"label\": \"Block 0x402205\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x402205\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"label\": \"query or enumerate registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4014BE\",\n      \"label\": \"Function 0x4014BE\",\n      \"type\": \"function\",\n      \"address\": \"0x4014BE\"\n    },\n    {\n      \"id\": \"api_RegCreateKeyEx\",\n      \"label\": \"RegCreateKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"api_RegEnumKey\",\n      \"label\": \"RegEnumKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"label\": \"query or enumerate registry value (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x406534\",\n      \"label\": \"Function 0x406534\",\n      \"type\": \"function\",\n      \"address\": \"0x406534\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegEnumValue\",\n      \"label\": \"RegEnumValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value\",\n      \"label\": \"set registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delete_registry_key\",\n      \"label\": \"delete registry key\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegDeleteKey\",\n      \"label\": \"RegDeleteKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_value\",\n      \"label\": \"delete registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegDeleteValue\",\n      \"label\": \"RegDeleteValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_thread\",\n      \"label\": \"create thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x404CCD\",\n      \"label\": \"Block 0x404CCD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x404CCD\"\n    },\n    {\n      \"id\": \"api_CreateThread\",\n      \"label\": \"CreateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal__installer_file_limitation\",\n      \"label\": \"(internal) installer file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__2_matches_\",\n      \"label\": \"link function at runtime on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_shortcut_via_ishelllink\",\n      \"label\": \"create shortcut via IShellLink\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    },\n    {\n      \"id\": \"api_CoCreateInstance\",\n      \"label\": \"CoCreateInstance\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__39_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__39_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x401496\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x401679\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_capture_webcam_image\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_capture_webcam_image\",\n      \"target\": \"func_0x40531A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40531A\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____johnk3r\",\n      \"target\": \"func_0x40531A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40531A\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_and_execute_a_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_and_execute_a_file\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_ShellExecute\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_maec_malware_category__launcher\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_maec_malware_category__launcher\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_ShellExecute\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_crc32\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_with_crc32\",\n      \"target\": \"func_0x406FC4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x406FC4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_packaged_as_a_nsis_installer\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments\",\n      \"target\": \"func_0x4039AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4039AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_clipboard\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_clipboard\",\n      \"target\": \"func_0x404ABC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404ABC\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404ABC\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x404ABC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404ABC\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404ABC\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_clipboard_data\",\n      \"target\": \"func_0x404ABC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404ABC\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404ABC\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404ABC\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404ABC\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404ABC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404ABC\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404ABC\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404ABC\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404ABC\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x4039AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x4065B4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x406882\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4065B4\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406882\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4065B4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406882\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4065B4\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406882\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4065B4\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406882\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4065B4\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406882\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4039AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4065B4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406882\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4065B4\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406882\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4065B4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406882\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4065B4\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406882\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4065B4\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406882\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4065B4\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406882\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_system_object_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_system_object_information\",\n      \"target\": \"bb_0x4039AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4039AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_current_directory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__2_matches_\",\n      \"target\": \"func_0x4039AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__2_matches_\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4039AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_copy_file__2_matches_\",\n      \"target\": \"func_0x4039AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_copy_file__2_matches_\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4039AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory__3_matches_\",\n      \"target\": \"func_0x4039AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__3_matches_\",\n      \"target\": \"func_0x403955\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__3_matches_\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403955\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4039AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403955\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403955\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_directory\",\n      \"target\": \"func_0x406C7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406C7A\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x406C7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406C7A\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x4039AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x406C7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406C7A\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4039AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x406C7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406C7A\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x405DD6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x4069A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x4069D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405DD6\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4069A0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4069D8\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405DD6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4069A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4069D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405DD6\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4069A0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4069D8\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"target\": \"func_0x406C7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406C7A\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406C7A\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406C7A\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406C7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406C7A\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406C7A\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406C7A\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_recursively\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively\",\n      \"target\": \"func_0x406C7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406C7A\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406C7A\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406C7A\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406C7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406C7A\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406C7A\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406C7A\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x405F24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x40179D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x4069D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x406974\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x4069A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x405F24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40179D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4069D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x406974\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4069A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x406A6B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x40351B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406A6B\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40351B\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406A6B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40351B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406A6B\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40351B\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_version_info\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_version_info\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__2_matches_\",\n      \"target\": \"bb_0x4069F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__2_matches_\",\n      \"target\": \"bb_0x401731\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4069F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x401731\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_move_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_move_file\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read__ini_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read__ini_file\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_GetFullPathName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_GetFullPathName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__4_matches_\",\n      \"target\": \"func_0x406A6B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__4_matches_\",\n      \"target\": \"func_0x4033D2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__4_matches_\",\n      \"target\": \"func_0x403110\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__4_matches_\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406A6B\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4033D2\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403110\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406A6B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4033D2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403110\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406A6B\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4033D2\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403110\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__4_matches_\",\n      \"target\": \"func_0x40321D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__4_matches_\",\n      \"target\": \"func_0x406A6B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__4_matches_\",\n      \"target\": \"func_0x4033D2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__4_matches_\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40321D\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406A6B\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4033D2\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40321D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406A6B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4033D2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40321D\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406A6B\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4033D2\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_graphical_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hide_graphical_window__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__4_matches_\",\n      \"target\": \"bb_0x404D67\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__4_matches_\",\n      \"target\": \"bb_0x404D13\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__4_matches_\",\n      \"target\": \"bb_0x4031EC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__4_matches_\",\n      \"target\": \"bb_0x404C29\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x404D67\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x404D13\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4031EC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x404C29\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_size\",\n      \"target\": \"func_0x404EF5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404EF5\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404EF5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404EF5\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_shutdown_system\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_shutdown_system\",\n      \"target\": \"func_0x4039AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4039AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4039AC\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_os_version\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_os_version\",\n      \"target\": \"func_0x4065B4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4065B4\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x4065B4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4065B4\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__3_matches_\",\n      \"target\": \"bb_0x406F74\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__3_matches_\",\n      \"target\": \"bb_0x405C2D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__3_matches_\",\n      \"target\": \"bb_0x402205\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x406F74\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x405C2D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x402205\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"target\": \"func_0x4014BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4014BE\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4014BE\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4014BE\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4014BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4014BE\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4014BE\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4014BE\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"target\": \"func_0x406534\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406534\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406534\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406534\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406534\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406534\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406534\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406534\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406534\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406534\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key\",\n      \"target\": \"func_0x4014BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4014BE\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4014BE\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x4014BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4014BE\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4014BE\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread\",\n      \"target\": \"bb_0x404CCD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x404CCD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal__installer_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_shortcut_via_ishelllink\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_shortcut_via_ishelllink\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______matthew_williams_mandiant_com\",\n      \"target\": \"func_0x40158E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40158E\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 22:18:10.628925\",\n    \"total_functions\": \"231\",\n    \"total_features\": \"8547\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 22:18:11"}
{"_id":{"$oid":"6a4fbb260108394cb24cdcd3"},"sha256":"0d8d45f33c3be34a5523241113bdc5bac128630a9ceb879f67f0aa877787f08f","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"9fbd55e165f109d842a138adb843e9b1","sha1":"3dc54befbd68fd29ec6d588b734aab5f78482110","sha256":"0d8d45f33c3be34a5523241113bdc5bac128630a9ceb879f67f0aa877787f08f"}},"timestamp":"2026-07-09 20:45:50"}
{"_id":{"$oid":"6a4fbbb70108394cb24cdcd5"},"sha256":"527511694daa041f613b9f5fbdae45062bc69dc655f3f584ccba725cd418ea5c","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"ffa35a600ad7c1fb3fca83c304a96731","sha1":"78ba206347203b1f3d16cfc3374998d9abb367a7","sha256":"527511694daa041f613b9f5fbdae45062bc69dc655f3f584ccba725cd418ea5c"}},"timestamp":"2026-07-09 20:48:15"}
{"_id":{"$oid":"6a4fbe9b0108394cb24cdcd8"},"sha256":"6e391ec12f638b91dfee7d7cfc5cd4f47683fc9a2d1fdc88e96956f7f36a60fc","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"783f40ad1359a14f483f4aa56e1db5d2","sha1":"54913fff8603b4ba6b8d47c3424bb9d11cc69646","sha256":"6e391ec12f638b91dfee7d7cfc5cd4f47683fc9a2d1fdc88e96956f7f36a60fc"}},"timestamp":"2026-07-09 21:00:35"}
{"_id":{"$oid":"6a4fc12d0108394cb24cdcdd"},"sha256":"834d1dbfab8330ea5f1844f6e905ed0ac19d1033ee9a9f1122ad2051c56783dc","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":true,"path":"/tmp/sdm_capa_glrbqdq1/InstallBC201401-019f46c5a43678739e5341f28c14821d.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_glrbqdq1/InstallBC201401-019f46c5a43678739e5341f28c14821d.exe_very_verbose.txt"}},"outputs":{"normal":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"md5                     caff801a280d42dbd1ad6b1266d3c43a                        \nsha1                    08b9f5874ad1dc3ee1093c9cd08737645f33f13f                \nsha256                  834d1dbfab8330ea5f1844f6e905ed0ac19d1033ee9a9f1122ad205…\npath                    /home/apogean/projects/malware/windows/all_runs/Install…\ntimestamp               2026-07-09 21:10:35.663908                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIINIKnk/rules                                   \nfunction count          25                                                      \nlibrary function count  0                                                       \ntotal feature count     167202                                                  \n\nreference anti-VM strings targeting Xen\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\npacked with TSULoader\nnamespace  anti-analysis/packer/tsuloader\nscope      file                          \n\ncontains PDB path\nnamespace  executable/pe/pdb\nscope      file             \n\naccept command line arguments\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x401390            \n\nget common file path\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x401495                    \n\ndelete file\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x401495                           \n\ncheck if file exists (2 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x401495                           \n           0x401994                           \n\nget file attributes (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x401741                         \n           0x4019E7                         \n\nget file size\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x4011C3                         \n\nget file version info\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x4010E9                         \n\nset file attributes (3 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x401753                         \n           0x4019F5                         \n           0x401B8F                         \n\nread file on Windows\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x40180A                         \n\nread file via mapping\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x4011C3                         \n\nwrite file on Windows\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x401994                          \n\nprint debug messages\nnamespace  host-interaction/log/debug/write-event\nscope      function                              \nmatches    0x401058                              \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x401495                          \n\nlink function at runtime on Windows\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x401693               \n\nparse PE header\nnamespace  load-code/pe\nscope      function    \nmatches    0x401495    \n\n\n\n","very_verbose":"md5                     caff801a280d42dbd1ad6b1266d3c43a                        \nsha1                    08b9f5874ad1dc3ee1093c9cd08737645f33f13f                \nsha256                  834d1dbfab8330ea5f1844f6e905ed0ac19d1033ee9a9f1122ad205…\npath                    /home/apogean/projects/malware/windows/all_runs/Install…\ntimestamp               2026-07-09 21:11:32.650781                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEI4pMN3M/rules                                   \nfunction count          25                                                      \nlibrary function count  0                                                       \ntotal feature count     167202                                                  \n\ncontain loop (14 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401000\n  or:\n    characteristic: loop @ 0x401000\n\ncreate or open file (3 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x4011DB\n  or:\n    api: CreateFile @ 0x4011DB\n\ndelay execution (library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x401783 in function 0x401495\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x401788\n\nreference anti-VM strings targeting Xen\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /^Xen/i\n    - \"XEni'\" @ file+0x303E8A\n    - \"XeNb@\" @ file+0x72206F\n    - \"xeN;w\" @ file+0xA0615E\n\npacked with TSULoader\nnamespace   anti-analysis/packer/tsuloader                                      \nauthor      william.ballenthin@mandiant.com                                     \nscope       file                                                                \natt&ck      Defense Evasion::Obfuscated Files or Information::Software Packing  \n            [T1027.002]                                                         \nmbc         Anti-Static Analysis::Software Packing [F0001]                      \nreferences  https://www.hexacorn.com/blog/2016/12/15/pe-section-names-re-visite…\nor:\n  section: .tsuarch @ 0x428000\n  section: .tsustub @ 0x409000\n\ncontains PDB path\nnamespace  executable/pe/pdb        \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nregex: /:\\\\.*\\.pdb/\n  - \"D:\\\\Dev\\\\Tin9\\\\InstallDir\\\\vc80-win32u\\\\Loader.pdb\" @ file+0x28D0\n\naccept command line arguments\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x401390\n  or:\n    api: GetCommandLine @ 0x4013D9\n\nget common file path\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x401495\n  or:\n    api: GetTempPath @ 0x4015C7\n\ndelete file\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x401495\n  or:\n    api: DeleteFile @ 0x40176E\n\ncheck if file exists (2 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x401495\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x401748\n        instruction:\n          and:\n            mnemonic: cmp @ 0x40174E\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x40174E\nfunction @ 0x401994\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x4019EA\n        instruction:\n          and:\n            mnemonic: cmp @ 0x4019F0\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x4019F0\n\nget file attributes (2 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x401741 in function 0x401495\n  or:\n    api: GetFileAttributes @ 0x401748\nbasic block @ 0x4019E7 in function 0x401994\n  or:\n    api: GetFileAttributes @ 0x4019EA\n\nget file size\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x4011C3\n  or:\n    api: GetFileSize @ 0x4011F5\n\nget file version info\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x4010E9\n  and:\n    or:\n      api: GetFileVersionInfo @ 0x401121\n    optional: = retrieve specified version information from the version-information resource\n      api: VerQueryValue @ 0x401144, 0x401181\n      or:\n        api: GetFileVersionInfoSize @ 0x4010FC\n\nset file attributes (3 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ 0x401753 in function 0x401495\n  or:\n    api: SetFileAttributes @ 0x40175E\nbasic block @ 0x4019F5 in function 0x401994\n  or:\n    api: SetFileAttributes @ 0x4019FC\nbasic block @ 0x401B8F in function 0x401994\n  or:\n    api: SetFileAttributes @ 0x401B95\n\nread file on Windows\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x40180A\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x401829\n\nread file via mapping\nnamespace  host-interaction/file-system/read\nauthor     michael.hunhoff@mandiant.com     \nscope      function                         \nmbc        File System::Read File [C0051]   \nfunction @ 0x4011C3\n  or:\n    and:\n      basic block:\n        and:\n          api: MapViewOfFile @ 0x40124B\n          or:\n            number: 0x4 = FILE_MAP_READ @ 0x401246\n      optional:\n        api: UnmapViewOfFile @ 0x401381\n        and:\n          match: get file size @ 0x4011C3\n            or:\n              api: GetFileSize @ 0x4011F5\n        basic block:\n          and:\n            api: CreateFileMapping @ 0x401227\n            or:\n              number: 0x2 = PAGE_READONLY @ 0x401217\n\nwrite file on Windows\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x401994\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x401A18\n            number: 0x2 = FILE_WRITE_DATA @ 0x401A14\n            match: create or open file @ 0x401A31\n              or:\n                api: CreateFile @ 0x401A31\n      or:\n        api: WriteFile @ 0x401AD4\n\nprint debug messages\nnamespace  host-interaction/log/debug/write-event\nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \nfunction @ 0x401058\n  or:\n    api: OutputDebugString @ 0x40106F\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x401495\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x40179F\n\n(internal) packer file limitation\nnamespace    internal/limitation/static                                         \nauthor       william.ballenthin@mandiant.com                                    \nscope        file                                                               \ndescription  This sample appears to be packed.                                  \n                                                                                \n             Packed samples have often been obfuscated to hide their logic.     \n             capa cannot handle obfuscation well using static analysis. This    \n             means the results may be misleading or incomplete.                 \n             If possible, you should try to unpack this input file before       \n             analyzing it with capa.                                            \n             Alternatively, run the sample in a supported sandbox and invoke    \n             capa against the report to obtain dynamic analysis results.        \n                                                                                \nor:\n  match: anti-analysis/packer @ global\n    or:\n      section: .tsuarch @ 0x428000\n      section: .tsustub @ 0x409000\n\nlink function at runtime on Windows\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x401693\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401693\n\nparse PE header\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x401495\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x4014FB, 0x401542, 0x40154D, 0x401589, and 12 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x40154D\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x401542\n\n\n\n"},"hashes":{"md5":"caff801a280d42dbd1ad6b1266d3c43a","sha1":"08b9f5874ad1dc3ee1093c9cd08737645f33f13f","sha256":"834d1dbfab8330ea5f1844f6e905ed0ac19d1033ee9a9f1122ad2051c56783dc"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 25</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 167202</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Install\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"caff801a280d42dbd1ad6b1266d3c43a\",\n        \"sha256\": \"834d1dbfab8330ea5f1844f6e905ed0ac19d1033ee9a9f1122ad205\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__14_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (14 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401000\",\n      \"label\": \"Function 0x401000\",\n      \"type\": \"function\",\n      \"address\": \"0x401000\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__3_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (3 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"label\": \"reference anti-VM strings targeting Xen\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_packed_with_tsuloader\",\n      \"label\": \"packed with TSULoader\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Software Packing [F0001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Software Packing [F0001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contains_pdb_path\",\n      \"label\": \"contains PDB path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments\",\n      \"label\": \"accept command line arguments\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401390\",\n      \"label\": \"Function 0x401390\",\n      \"type\": \"function\",\n      \"address\": \"0x401390\"\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path\",\n      \"label\": \"get common file path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401495\",\n      \"label\": \"Function 0x401495\",\n      \"type\": \"function\",\n      \"address\": \"0x401495\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_file\",\n      \"label\": \"delete file\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__2_matches_\",\n      \"label\": \"check if file exists (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401994\",\n      \"label\": \"Function 0x401994\",\n      \"type\": \"function\",\n      \"address\": \"0x401994\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_get_file_attributes__2_matches_\",\n      \"label\": \"get file attributes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4019E7\",\n      \"label\": \"Block 0x4019E7\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4019E7\"\n    },\n    {\n      \"id\": \"bb_0x401741\",\n      \"label\": \"Block 0x401741\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401741\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size\",\n      \"label\": \"get file size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4011C3\",\n      \"label\": \"Function 0x4011C3\",\n      \"type\": \"function\",\n      \"address\": \"0x4011C3\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_file_version_info\",\n      \"label\": \"get file version info\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4010E9\",\n      \"label\": \"Function 0x4010E9\",\n      \"type\": \"function\",\n      \"address\": \"0x4010E9\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfo\",\n      \"label\": \"GetFileVersionInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_VerQueryValue\",\n      \"label\": \"VerQueryValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfoSize\",\n      \"label\": \"GetFileVersionInfoSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_file_attributes__3_matches_\",\n      \"label\": \"set file attributes (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4019F5\",\n      \"label\": \"Block 0x4019F5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4019F5\"\n    },\n    {\n      \"id\": \"bb_0x401B8F\",\n      \"label\": \"Block 0x401B8F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401B8F\"\n    },\n    {\n      \"id\": \"bb_0x401753\",\n      \"label\": \"Block 0x401753\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401753\"\n    },\n    {\n      \"id\": \"api_SetFileAttributes\",\n      \"label\": \"SetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_file_on_windows\",\n      \"label\": \"read file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40180A\",\n      \"label\": \"Function 0x40180A\",\n      \"type\": \"function\",\n      \"address\": \"0x40180A\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_read_file_via_mapping\",\n      \"label\": \"read file via mapping\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFileMapping\",\n      \"label\": \"CreateFileMapping\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_UnmapViewOfFile\",\n      \"label\": \"UnmapViewOfFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_MapViewOfFile\",\n      \"label\": \"MapViewOfFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows\",\n      \"label\": \"write file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_print_debug_messages\",\n      \"label\": \"print debug messages\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401058\",\n      \"label\": \"Function 0x401058\",\n      \"type\": \"function\",\n      \"address\": \"0x401058\"\n    },\n    {\n      \"id\": \"api_OutputDebugString\",\n      \"label\": \"OutputDebugString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"api_ExitProcess\",\n      \"label\": \"ExitProcess\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap__internal__packer_file_limitation\",\n      \"label\": \"(internal) packer file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows\",\n      \"label\": \"link function at runtime on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header\",\n      \"label\": \"parse PE header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__14_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__14_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__3_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_packed_with_tsuloader\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contains_pdb_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments\",\n      \"target\": \"func_0x401390\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401390\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401390\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401390\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path\",\n      \"target\": \"func_0x401495\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401495\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401495\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401495\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file\",\n      \"target\": \"func_0x401495\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401495\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401495\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401495\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__2_matches_\",\n      \"target\": \"func_0x401994\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__2_matches_\",\n      \"target\": \"func_0x401495\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401994\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401495\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401994\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401495\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401994\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401495\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__2_matches_\",\n      \"target\": \"bb_0x4019E7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__2_matches_\",\n      \"target\": \"bb_0x401741\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4019E7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x401741\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size\",\n      \"target\": \"func_0x4011C3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4011C3\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4011C3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4011C3\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_version_info\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_version_info\",\n      \"target\": \"func_0x4010E9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4010E9\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010E9\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010E9\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4010E9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4010E9\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010E9\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010E9\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__3_matches_\",\n      \"target\": \"bb_0x4019F5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__3_matches_\",\n      \"target\": \"bb_0x401B8F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__3_matches_\",\n      \"target\": \"bb_0x401753\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4019F5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x401B8F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x401753\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows\",\n      \"target\": \"func_0x40180A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40180A\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40180A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40180A\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_via_mapping\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_via_mapping\",\n      \"target\": \"func_0x4011C3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4011C3\",\n      \"target\": \"api_CreateFileMapping\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4011C3\",\n      \"target\": \"api_UnmapViewOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4011C3\",\n      \"target\": \"api_MapViewOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4011C3\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4011C3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4011C3\",\n      \"target\": \"api_CreateFileMapping\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4011C3\",\n      \"target\": \"api_UnmapViewOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4011C3\",\n      \"target\": \"api_MapViewOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4011C3\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows\",\n      \"target\": \"func_0x401994\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401994\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401994\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401994\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401994\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401994\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_print_debug_messages\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_print_debug_messages\",\n      \"target\": \"func_0x401058\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401058\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401058\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401058\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x401495\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401495\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401495\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401495\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal__packer_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header\",\n      \"target\": \"func_0x401495\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x401495\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 21:11:32.650781\",\n    \"total_functions\": \"25\",\n    \"total_features\": \"167202\",\n    \"pdb_path\": \"D:\\\\\\\\Dev\\\\\\\\Tin9\\\\\\\\InstallDir\\\\\\\\vc80-win32u\\\\\\\\Loader.pdb\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 21:11:33"}
{"_id":{"$oid":"6a4fc2420108394cb24cdcde"},"sha256":"2b89d0638a967deec3a203472dccbaf331a2a806efe85ec8b6b57da6f55c3552","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"b47e5e32af0e89854d7bcd5b7da93e97","sha1":"5aa09ea9d648aa8058457f0263a2a519f5988e9f","sha256":"2b89d0638a967deec3a203472dccbaf331a2a806efe85ec8b6b57da6f55c3552"}},"timestamp":"2026-07-09 21:16:10"}
{"_id":{"$oid":"6a4fc2ef0108394cb24cdce2"},"sha256":"df7409e284e6a62f07d790e9c4a436b7217a842983c1c1aea93a9cb77fc64f29","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"800ffaff2914cfc7994249d167284192","sha1":"944495124450cee142003573df8b45d0f53cfd49","sha256":"df7409e284e6a62f07d790e9c4a436b7217a842983c1c1aea93a9cb77fc64f29"}},"timestamp":"2026-07-18 16:58:09"}
{"_id":{"$oid":"6a4fc38a0108394cb24cdce6"},"sha256":"b12cd68c5712badcf74719ab5315c9615896539e84e95b88b996abe956e5f8b3","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"38b1eef05500d1575a36a4f9a526dcbe","sha1":"c61602d94d2b87542789cdc5abf85dd97920f0af","sha256":"b12cd68c5712badcf74719ab5315c9615896539e84e95b88b996abe956e5f8b3"}},"timestamp":"2026-07-09 21:21:38"}
{"_id":{"$oid":"6a4fc5d70108394cb24cdce9"},"sha256":"9d88425e266b3a74045186837fbd71de657b47d11efefcf8b3cd185a884b5306","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_m884s1km/TrojanWin32.Duqu.Stuxnet-019f46cab6a272e0abc2b0a2836dd472.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_m884s1km/TrojanWin32.Duqu.Stuxnet-019f46cab6a272e0abc2b0a2836dd472.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_m884s1km/TrojanWin32.Duqu.Stuxnet-019f46cab6a272e0abc2b0a2836dd472.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ c9a31ea148232b201fe7cb7db5c75f5e                                  │\n│ sha1     │ b3074b26b346cb76605171ba19616baf821acf66                          │\n│ sha256   │ 9d88425e266b3a74045186837fbd71de657b47d11efefcf8b3cd185a884b5306  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/TrojanWin32.Duqu… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic             ┃ ATT&CK Technique                                 ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION           │ Obfuscated Files or Information [T1027]          │\n│ DISCOVERY                 │ Process Discovery [T1057]                        │\n│                           │ Query Registry [T1012]                           │\n│                           │ System Information Discovery [T1082]             │\n│ EXECUTION                 │ Shared Modules [T1129]                           │\n└───────────────────────────┴──────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DATA                 │ Encode Data::XOR [C0026.002]                          │\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Encoding-Standard    │\n│                      │ Algorithm [E1027.m02]                                 │\n│ DISCOVERY            │ Code Discovery::Enumerate PE Sections [B0046.001]     │\n│                      │ System Information Discovery [E1082]                  │\n│ FILE SYSTEM          │ Get File Attributes [C0049]                           │\n│                      │ Read File [C0051]                                     │\n│ OPERATING SYSTEM     │ Registry::Query Registry Value [C0036.006]            │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                               ┃ Namespace                         ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ encode data using XOR (2 matches)        │ data-manipulation/encoding/xor    │\n│ complete processing asynchronous IO      │ host-interaction/driver           │\n│ request (2 matches)                      │                                   │\n│ create device object (4 matches)         │ host-interaction/driver           │\n│ get file attributes                      │ host-interaction/file-system/meta │\n│ read file on Windows                     │ host-interaction/file-system/read │\n│ check OS version (4 matches)             │ host-interaction/os/version       │\n│ find process by PID (2 matches)          │ host-interaction/process/list     │\n│ query or enumerate registry value        │ host-interaction/registry         │\n│ link function at runtime on Windows      │ linking/runtime-linking           │\n│ enumerate PE sections                    │ load-code/pe                      │\n│ parse PE header                          │ load-code/pe                      │\n└──────────────────────────────────────────┴───────────────────────────────────┘\n\n","verbose":"md5                     c9a31ea148232b201fe7cb7db5c75f5e                        \nsha1                    b3074b26b346cb76605171ba19616baf821acf66                \nsha256                  9d88425e266b3a74045186837fbd71de657b47d11efefcf8b3cd185…\npath                    /home/apogean/projects/malware/windows/all_runs/TrojanW…\ntimestamp               2026-07-09 21:31:20.104351                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x10000                                                 \nrules                   /tmp/_MEIbC7wKQ/rules                                   \nfunction count          125                                                     \nlibrary function count  8                                                       \ntotal feature count     6272                                                    \n\nencode data using XOR (2 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x11330                       \n           0x12910                       \n\ncomplete processing asynchronous IO request (2 matches)\nnamespace    host-interaction/driver                                            \ndescription  signals that driver has finished all processing for a given IRP    \n             (part of major function)                                           \nscope        basic block                                                        \nmatches      0x10D8C                                                            \n             0x10D8C                                                            \n\ncreate device object (4 matches)\nnamespace  host-interaction/driver\nscope      function               \nmatches    0x10380                \n           0x10450                \n           0x10468                \n           0x10DB0                \n\nget file attributes\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x107EE                          \n\nread file on Windows\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x10750                          \n\ncheck OS version (4 matches)\nnamespace  host-interaction/os/version\nscope      function                   \nmatches    0x122E0                    \n           0x12A10                    \n           0x12CE0                    \n           0x12D30                    \n\nfind process by PID (2 matches)\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    0x12B30                      \n           0x12D80                      \n\nquery or enumerate registry value\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x12810                  \n\nlink function at runtime on Windows\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x12BCC                \n\nenumerate PE sections\nnamespace  load-code/pe\nscope      function    \nmatches    0x11810     \n\nparse PE header\nnamespace  load-code/pe\nscope      function    \nmatches    0x11670     \n\n\n\n","very_verbose":"md5                     c9a31ea148232b201fe7cb7db5c75f5e                        \nsha1                    b3074b26b346cb76605171ba19616baf821acf66                \nsha256                  9d88425e266b3a74045186837fbd71de657b47d11efefcf8b3cd185…\npath                    /home/apogean/projects/malware/windows/all_runs/TrojanW…\ntimestamp               2026-07-09 21:31:26.541341                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x10000                                                 \nrules                   /tmp/_MEILp1JSY/rules                                   \nfunction count          125                                                     \nlibrary function count  8                                                       \ntotal feature count     6272                                                    \n\ncontain loop (38 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x10570\n  or:\n    characteristic: loop @ 0x10570\n\ncreate or open file (2 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x10734\n  or:\n    api: ZwOpenFile @ 0x10734\n\ncreate or open registry key (library rule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x12760 in function 0x12760\n  or:\n    api: ZwOpenKey @ 0x1279E\n\ndelay execution (3 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x10E70 in function 0x10E70\n  or:\n    and:\n      os: windows\n      or:\n        api: KeWaitForSingleObject @ 0x10EAC\n\nget OS version (4 matches, only showing first match of library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x122E0\n  or:\n    api: PsGetVersion @ 0x12314\n\nencode data using XOR (2 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x11330 in function 0x11320\n  and:\n    characteristic: tight loop @ 0x11330\n    characteristic: nzxor @ 0x11330, 0x11361\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x12910 in function 0x12900\n  and:\n    characteristic: tight loop @ 0x12910\n    characteristic: nzxor @ 0x12910, 0x1293E\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\ncomplete processing asynchronous IO request (2 matches)\nnamespace    host-interaction/driver                                            \nauthor       moritz.raabe@mandiant.com                                          \nscope        basic block                                                        \ndescription  signals that driver has finished all processing for a given IRP    \n             (part of major function)                                           \nbasic block @ 0x10D8C in function 0x10D56\n  or:\n    api: IofCompleteRequest @ 0x10D93\nbasic block @ 0x10D8C in function 0x10D56\n  or:\n    api: IofCompleteRequest @ 0x10D93\n\ncreate device object (4 matches)\nnamespace  host-interaction/driver\nauthor     @mr-tz                 \nscope      function               \nfunction @ 0x10380\n  and:\n    api: IoCreateDevice @ 0x10402\nfunction @ 0x10450\n  and:\n    api: IoCreateDevice @ 0x1048D\n    optional: = sets up a symbolic link between a device object name and a user-visible name \nfor the device\n      api: IoCreateSymbolicLink @ 0x104B1\nfunction @ 0x10468\n  and:\n    api: IoCreateDevice @ 0x1048D\n    optional: = sets up a symbolic link between a device object name and a user-visible name \nfor the device\n      api: IoCreateSymbolicLink @ 0x104B1\nfunction @ 0x10DB0\n  and:\n    api: IoCreateDevice @ 0x10DD5\n\nget file attributes\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x107EE in function 0x10790\n  or:\n    api: ZwQueryInformationFile @ 0x10801\n\nread file on Windows\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x10750\n  or:\n    and:\n      os: windows\n      or:\n        api: ZwReadFile @ 0x10778\n\ncheck OS version (4 matches)\nnamespace  host-interaction/os/version                    \nauthor     michael.hunhoff@mandiant.com, johnk3r          \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x122E0\n  and:\n    match: get OS version @ 0x122E0\n      or:\n        api: PsGetVersion @ 0x12314\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1231A\n            number: 0x5 = Windows 2000 @ 0x1231A\n        optional:\n          instruction:\n            and:\n              mnemonic: cmp @ 0x12321\n              or:\n                number: 0x0 @ 0x12321\nfunction @ 0x12A10\n  and:\n    match: get OS version @ 0x12A10\n      or:\n        api: PsGetVersion @ 0x12A65, 0x12A8C\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x12A8E\n            number: 0x5 = Windows 2000 @ 0x12A8E\n          and:\n            mnemonic: cmp @ 0x12A67\n            number: 0x5 = Windows 2000 @ 0x12A67\n        optional:\n          instruction:\n            and:\n              mnemonic: cmp @ 0x12A95\n              or:\n                number: 0x1 = Windows XP @ 0x12A95\nfunction @ 0x12CE0\n  and:\n    match: get OS version @ 0x12CE0\n      or:\n        api: PsGetVersion @ 0x12D01\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x12D07\n            number: 0x5 = Windows 2000 @ 0x12D07\n        optional:\n          instruction:\n            and:\n              mnemonic: cmp @ 0x12D0D\n              or:\n                number: 0x0 @ 0x12D0D\nfunction @ 0x12D30\n  and:\n    match: get OS version @ 0x12D30\n      or:\n        api: PsGetVersion @ 0x12D51\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x12D57\n            number: 0x5 = Windows 2000 @ 0x12D57\n        optional:\n          instruction:\n            and:\n              mnemonic: cmp @ 0x12D5D\n              or:\n                number: 0x2 = Windows XP 64-bit / Windows Server 2003 / Windows Server 2003 R2 @ 0x12D5D\n\nfind process by PID (2 matches)\nnamespace  host-interaction/process/list                                \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::Process Discovery [T1057]                         \nfunction @ 0x12B30\n  and:\n    or:\n      api: PsLookupProcessByProcessId @ 0x12B50\nfunction @ 0x12D80\n  and:\n    optional:\n      api: ObfDereferenceObject @ 0x12DB8, 0x12E23\n    or:\n      api: PsLookupProcessByProcessId @ 0x12D95\n\nquery or enumerate registry value\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x12810\n  and:\n    or:\n      api: ZwQueryValueKey @ 0x1283E, 0x1286C\n\nlink function at runtime on Windows\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x12BCC\n  and:\n    os: windows\n    or:\n      api: MmGetSystemRoutineAddress @ 0x12BCC\n\nenumerate PE sections\nnamespace   load-code/pe                                                        \nauthor      @Ana06, @mr-tz                                                      \nscope       function                                                            \nmbc         Discovery::Code Discovery::Enumerate PE Sections [B0046.001]        \nreferences  https://0x00sec.org/t/reflective-dll-injection/3080,                \n            https://www.ired.team/offensive-security/code-injection-process-inj…\nfunction @ 0x11810\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x1188D\n        or:\n          mnemonic: mov @ 0x1188D\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x11848\n              or:\n                mnemonic: mov @ 0x11848\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x11818\n    count(basic block): 3 or more @ 0x11810, 0x1185A, 0x11860, 0x11868, and 1 more...\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x11860\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x11848\n      operand[1].offset: 0x10 = IMAGE_SECTION_HEADER.SizeOfRawData @ 0x11823, 0x11838\n\nparse PE header\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x11670\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1176B\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x116F1\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x116E6\n\n\n\n"},"hashes":{"md5":"c9a31ea148232b201fe7cb7db5c75f5e","sha1":"b3074b26b346cb76605171ba19616baf821acf66","sha256":"9d88425e266b3a74045186837fbd71de657b47d11efefcf8b3cd185a884b5306"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 125</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 6272</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"TrojanW\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"c9a31ea148232b201fe7cb7db5c75f5e\",\n        \"sha256\": \"9d88425e266b3a74045186837fbd71de657b47d11efefcf8b3cd185\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__38_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (38 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x10570\",\n      \"label\": \"Function 0x10570\",\n      \"type\": \"function\",\n      \"address\": \"0x10570\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_ZwOpenFile\",\n      \"label\": \"ZwOpenFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delay_execution__3_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (3 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x10E70\",\n      \"label\": \"Block 0x10E70\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x10E70\"\n    },\n    {\n      \"id\": \"api_KeWaitForSingleObject\",\n      \"label\": \"KeWaitForSingleObject\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_os_version__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"get OS version (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x122E0\",\n      \"label\": \"Function 0x122E0\",\n      \"type\": \"function\",\n      \"address\": \"0x122E0\"\n    },\n    {\n      \"id\": \"api_PsGetVersion\",\n      \"label\": \"PsGetVersion\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_complete_processing_asynchronous_io_request__2_matches_\",\n      \"label\": \"complete processing asynchronous IO request (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x10D8C\",\n      \"label\": \"Block 0x10D8C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x10D8C\"\n    },\n    {\n      \"id\": \"api_IofCompleteRequest\",\n      \"label\": \"IofCompleteRequest\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______moritz_raabe_mandiant_com\",\n      \"label\": \"author       moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_device_object__4_matches_\",\n      \"label\": \"create device object (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x10380\",\n      \"label\": \"Function 0x10380\",\n      \"type\": \"function\",\n      \"address\": \"0x10380\"\n    },\n    {\n      \"id\": \"func_0x10468\",\n      \"label\": \"Function 0x10468\",\n      \"type\": \"function\",\n      \"address\": \"0x10468\"\n    },\n    {\n      \"id\": \"func_0x10DB0\",\n      \"label\": \"Function 0x10DB0\",\n      \"type\": \"function\",\n      \"address\": \"0x10DB0\"\n    },\n    {\n      \"id\": \"func_0x10450\",\n      \"label\": \"Function 0x10450\",\n      \"type\": \"function\",\n      \"address\": \"0x10450\"\n    },\n    {\n      \"id\": \"api_IoCreateSymbolicLink\",\n      \"label\": \"IoCreateSymbolicLink\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_IoCreateDevice\",\n      \"label\": \"IoCreateDevice\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz\",\n      \"label\": \"author     @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_file_attributes\",\n      \"label\": \"get file attributes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x107EE\",\n      \"label\": \"Block 0x107EE\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x107EE\"\n    },\n    {\n      \"id\": \"api_ZwQueryInformationFile\",\n      \"label\": \"ZwQueryInformationFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows\",\n      \"label\": \"read file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x10750\",\n      \"label\": \"Function 0x10750\",\n      \"type\": \"function\",\n      \"address\": \"0x10750\"\n    },\n    {\n      \"id\": \"api_ZwReadFile\",\n      \"label\": \"ZwReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_os_version__4_matches_\",\n      \"label\": \"check OS version (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x12A10\",\n      \"label\": \"Function 0x12A10\",\n      \"type\": \"function\",\n      \"address\": \"0x12A10\"\n    },\n    {\n      \"id\": \"func_0x12CE0\",\n      \"label\": \"Function 0x12CE0\",\n      \"type\": \"function\",\n      \"address\": \"0x12CE0\"\n    },\n    {\n      \"id\": \"func_0x12D30\",\n      \"label\": \"Function 0x12D30\",\n      \"type\": \"function\",\n      \"address\": \"0x12D30\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_process_by_pid__2_matches_\",\n      \"label\": \"find process by PID (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x12B30\",\n      \"label\": \"Function 0x12B30\",\n      \"type\": \"function\",\n      \"address\": \"0x12B30\"\n    },\n    {\n      \"id\": \"func_0x12D80\",\n      \"label\": \"Function 0x12D80\",\n      \"type\": \"function\",\n      \"address\": \"0x12D80\"\n    },\n    {\n      \"id\": \"api_PsLookupProcessByProcessId\",\n      \"label\": \"PsLookupProcessByProcessId\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_ObfDereferenceObject\",\n      \"label\": \"ObfDereferenceObject\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value\",\n      \"label\": \"query or enumerate registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x12810\",\n      \"label\": \"Function 0x12810\",\n      \"type\": \"function\",\n      \"address\": \"0x12810\"\n    },\n    {\n      \"id\": \"api_ZwQueryValueKey\",\n      \"label\": \"ZwQueryValueKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows\",\n      \"label\": \"link function at runtime on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_MmGetSystemRoutineAddress\",\n      \"label\": \"MmGetSystemRoutineAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_pe_sections\",\n      \"label\": \"enumerate PE sections\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x11810\",\n      \"label\": \"Function 0x11810\",\n      \"type\": \"function\",\n      \"address\": \"0x11810\"\n    },\n    {\n      \"id\": \"cap_author_______ana06___mr_tz\",\n      \"label\": \"author      @Ana06, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header\",\n      \"label\": \"parse PE header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x11670\",\n      \"label\": \"Function 0x11670\",\n      \"type\": \"function\",\n      \"address\": \"0x11670\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__38_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__38_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x10570\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__3_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__3_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x10E70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_os_version__4_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x122E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x122E0\",\n      \"target\": \"api_PsGetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_complete_processing_asynchronous_io_request__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_complete_processing_asynchronous_io_request__2_matches_\",\n      \"target\": \"bb_0x10D8C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x10D8C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_device_object__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_device_object__4_matches_\",\n      \"target\": \"func_0x10380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_device_object__4_matches_\",\n      \"target\": \"func_0x10468\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_device_object__4_matches_\",\n      \"target\": \"func_0x10DB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_device_object__4_matches_\",\n      \"target\": \"func_0x10450\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10380\",\n      \"target\": \"api_IoCreateSymbolicLink\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10468\",\n      \"target\": \"api_IoCreateSymbolicLink\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10DB0\",\n      \"target\": \"api_IoCreateSymbolicLink\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10450\",\n      \"target\": \"api_IoCreateSymbolicLink\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10380\",\n      \"target\": \"api_IoCreateDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10468\",\n      \"target\": \"api_IoCreateDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10DB0\",\n      \"target\": \"api_IoCreateDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10450\",\n      \"target\": \"api_IoCreateDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz\",\n      \"target\": \"func_0x10380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz\",\n      \"target\": \"func_0x10468\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz\",\n      \"target\": \"func_0x10DB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz\",\n      \"target\": \"func_0x10450\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10380\",\n      \"target\": \"api_IoCreateSymbolicLink\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10468\",\n      \"target\": \"api_IoCreateSymbolicLink\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10DB0\",\n      \"target\": \"api_IoCreateSymbolicLink\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10450\",\n      \"target\": \"api_IoCreateSymbolicLink\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10380\",\n      \"target\": \"api_IoCreateDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10468\",\n      \"target\": \"api_IoCreateDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10DB0\",\n      \"target\": \"api_IoCreateDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10450\",\n      \"target\": \"api_IoCreateDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes\",\n      \"target\": \"bb_0x107EE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x107EE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows\",\n      \"target\": \"func_0x10750\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10750\",\n      \"target\": \"api_ZwReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10750\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10750\",\n      \"target\": \"api_ZwReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_os_version__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_os_version__4_matches_\",\n      \"target\": \"func_0x12A10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_os_version__4_matches_\",\n      \"target\": \"func_0x122E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_os_version__4_matches_\",\n      \"target\": \"func_0x12CE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_os_version__4_matches_\",\n      \"target\": \"func_0x12D30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x12A10\",\n      \"target\": \"api_PsGetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x122E0\",\n      \"target\": \"api_PsGetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x12CE0\",\n      \"target\": \"api_PsGetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x12D30\",\n      \"target\": \"api_PsGetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x12A10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x122E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x12CE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x12D30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x12A10\",\n      \"target\": \"api_PsGetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x122E0\",\n      \"target\": \"api_PsGetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x12CE0\",\n      \"target\": \"api_PsGetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x12D30\",\n      \"target\": \"api_PsGetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_process_by_pid__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_find_process_by_pid__2_matches_\",\n      \"target\": \"func_0x12B30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_find_process_by_pid__2_matches_\",\n      \"target\": \"func_0x12D80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x12B30\",\n      \"target\": \"api_PsLookupProcessByProcessId\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x12D80\",\n      \"target\": \"api_PsLookupProcessByProcessId\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x12B30\",\n      \"target\": \"api_ObfDereferenceObject\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x12D80\",\n      \"target\": \"api_ObfDereferenceObject\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x12B30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x12D80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x12B30\",\n      \"target\": \"api_PsLookupProcessByProcessId\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x12D80\",\n      \"target\": \"api_PsLookupProcessByProcessId\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x12B30\",\n      \"target\": \"api_ObfDereferenceObject\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x12D80\",\n      \"target\": \"api_ObfDereferenceObject\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value\",\n      \"target\": \"func_0x12810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x12810\",\n      \"target\": \"api_ZwQueryValueKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x12810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x12810\",\n      \"target\": \"api_ZwQueryValueKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_pe_sections\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections\",\n      \"target\": \"func_0x11810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______ana06___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x11810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header\",\n      \"target\": \"func_0x11670\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x11670\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 21:31:26.541341\",\n    \"total_functions\": \"125\",\n    \"total_features\": \"6272\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 21:31:27"}
{"_id":{"$oid":"6a4fc7140108394cb24cdcec"},"sha256":"8abb47ca7c0c4871c28b89aa0e75493e5eb01e403272888c11fef9e53d633ffe","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_r7irwr9b/001_upx_unpacked.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_r7irwr9b/001_upx_unpacked.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_r7irwr9b/001_upx_unpacked.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 75523ea9b9af74aa0dac145ba9de04e9                                  │\n│ sha1     │ 37c62921ab65cd4ad72d4718d153c8d67a1d9fb0                          │\n│ sha256   │ 6db17d8ddf00e0733ad030d8fe483b8ea504b4dbb25341c6231412bcb95316b5  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /tmp/sdm_unpack_ppm97wz9/Variant.Kazy-019f46cad0df73608500f98144… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION      │ Indicator Removal::Timestomp [T1070.006]              │\n│                      │ Obfuscated Files or Information::Indicator Removal    │\n│                      │ from Tools [T1027.005]                                │\n│ DISCOVERY            │ File and Directory Discovery [T1083]                  │\n│ EXECUTION            │ Shared Modules [T1129]                                │\n│ PRIVILEGE ESCALATION │ Access Token Manipulation [T1134]                     │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-STATIC ANALYSIS │ Executable Code Obfuscation::Argument Obfuscation     │\n│                      │ [B0032.020]                                           │\n│                      │ Executable Code Obfuscation::Stack Strings            │\n│                      │ [B0032.017]                                           │\n│ DISCOVERY            │ File and Directory Discovery [E1083]                  │\n│ EXECUTION            │ Install Additional Program [B0023]                    │\n│ FILE SYSTEM          │ Read File [C0051]                                     │\n│                      │ Writes File [C0052]                                   │\n│ OPERATING SYSTEM     │ Registry::Set Registry Key [C0036.001]                │\n│ PROCESS              │ Create Process [C0017]                                │\n│                      │ Terminate Process [C0018]                             │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ timestomp file                        │ anti-analysis/anti-forensic/timesto… │\n│ contain obfuscated stackstrings (4    │ anti-analysis/obfuscation/string/st… │\n│ matches)                              │                                      │\n│ extract resource via kernel32         │ executable/resource                  │\n│ functions                             │                                      │\n│ contain an embedded PE file           │ executable/subfile/pe                │\n│ get common file path (2 matches)      │ host-interaction/file-system         │\n│ get file size                         │ host-interaction/file-system/meta    │\n│ read file on Windows                  │ host-interaction/file-system/read    │\n│ write file on Windows (2 matches)     │ host-interaction/file-system/write   │\n│ create process on Windows             │ host-interaction/process/create      │\n│ acquire debug privileges              │ host-interaction/process/modify      │\n│ modify access privileges              │ host-interaction/process/modify      │\n│ terminate process                     │ host-interaction/process/terminate   │\n│ set registry value                    │ host-interaction/registry/create     │\n│ link function at runtime on Windows   │ linking/runtime-linking              │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     75523ea9b9af74aa0dac145ba9de04e9                        \nsha1                    37c62921ab65cd4ad72d4718d153c8d67a1d9fb0                \nsha256                  6db17d8ddf00e0733ad030d8fe483b8ea504b4dbb25341c6231412b…\npath                    /tmp/sdm_unpack_ppm97wz9/Variant.Kazy-019f46cad0df73608…\ntimestamp               2026-07-09 21:36:38.184660                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIabtAj6/rules                                   \nfunction count          19                                                      \nlibrary function count  0                                                       \ntotal feature count     1637                                                    \n\ntimestomp file\nnamespace  anti-analysis/anti-forensic/timestomp\nscope      function                             \nmatches    0x40159C                             \n\ncontain obfuscated stackstrings (4 matches)\nnamespace  anti-analysis/obfuscation/string/stackstring\nscope      basic block                                 \nmatches    0x401233                                    \n           0x4014CE                                    \n           0x40159C                                    \n           0x40169F                                    \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x40106E           \n\ncontain an embedded PE file\nnamespace  executable/subfile/pe\nscope      file                 \n\nget common file path (2 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x4011B0                    \n           0x4011FF                    \n\nget file size\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x401355                         \n\nread file on Windows\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x401355                         \n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x40106E                          \n           0x40140D                          \n\ncreate process on Windows\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x4014CE                       \n\nacquire debug privileges\nnamespace  host-interaction/process/modify\nscope      basic block                    \nmatches    0x40101A                       \n\nmodify access privileges\nnamespace  host-interaction/process/modify\nscope      instruction                    \nmatches    0x401053                       \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x40169F                          \n\nset registry value\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x40115F                        \n\nlink function at runtime on Windows\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x401135               \n\n\n\n","very_verbose":"md5                     75523ea9b9af74aa0dac145ba9de04e9                        \nsha1                    37c62921ab65cd4ad72d4718d153c8d67a1d9fb0                \nsha256                  6db17d8ddf00e0733ad030d8fe483b8ea504b4dbb25341c6231412b…\npath                    /tmp/sdm_unpack_ppm97wz9/Variant.Kazy-019f46cad0df73608…\ntimestamp               2026-07-09 21:36:43.773060                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEI7hdJZE/rules                                   \nfunction count          19                                                      \nlibrary function count  0                                                       \ntotal feature count     1637                                                    \n\ncontain loop (2 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x4012EF\n  or:\n    characteristic: loop @ 0x4012EF\n\ncreate or open file (5 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x4010BC\n  or:\n    api: CreateFile @ 0x4010BC\n\ncreate or open registry key (library rule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x40116E in function 0x40115F\n  or:\n    api: RegOpenKeyEx @ 0x401183\n\ntimestomp file\nnamespace  anti-analysis/anti-forensic/timestomp                    \nauthor     moritz.raabe@mandiant.com                                \nscope      function                                                 \natt&ck     Defense Evasion::Indicator Removal::Timestomp [T1070.006]\nfunction @ 0x40159C\n  and:\n    api: SetFileTime @ 0x401686\n    or:\n      api: GetFileTime @ 0x401673\n\ncontain obfuscated stackstrings (4 matches)\nnamespace  anti-analysis/obfuscation/string/stackstring                         \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information::Indicator Removal  \n           from Tools [T1027.005]                                               \nmbc        Anti-Static Analysis::Executable Code Obfuscation::Argument          \n           Obfuscation [B0032.020], Anti-Static Analysis::Executable Code       \n           Obfuscation::Stack Strings [B0032.017]                               \nbasic block @ 0x401233 in function 0x4011FF\n  characteristic: stack string @ 0x401233\nbasic block @ 0x4014CE in function 0x4014CE\n  characteristic: stack string @ 0x4014CE\nbasic block @ 0x40159C in function 0x40159C\n  characteristic: stack string @ 0x40159C\nbasic block @ 0x40169F in function 0x40169F\n  characteristic: stack string @ 0x40169F\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x40106E\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x40109E\n      optional:\n        or:\n          api: FindResource @ 0x40107F\n        api: SizeofResource @ 0x401091\n        api: FreeResource @ 0x4010E4\n\ncontain an embedded PE file\nnamespace  executable/subfile/pe                        \nauthor     moritz.raabe@mandiant.com                    \nscope      file                                         \nmbc        Execution::Install Additional Program [B0023]\nor:\n  count(characteristic(embedded pe)): 1 or more @ file+0x1710, file+0x4310, file+0x5D10\n\nget common file path (2 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x4011B0\n  or:\n    api: GetWindowsDirectory @ 0x4011C5\nfunction @ 0x4011FF\n  or:\n    api: GetWindowsDirectory @ 0x401214\n\nget file size\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x401355\n  or:\n    api: GetFileSize @ 0x4013F0\n\nread file on Windows\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x401355\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x401365\n          match: create or open file @ 0x40136D\n            or:\n              api: CreateFile @ 0x40136D\n      or:\n        api: ReadFile @ 0x4013A5, 0x4013D1\n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x40106E\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x4010B4\n            number: 0x2 = FILE_WRITE_DATA @ 0x4010B0\n            match: create or open file @ 0x4010BC\n              or:\n                api: CreateFile @ 0x4010BC\n      or:\n        api: WriteFile @ 0x4010D3\nfunction @ 0x40140D\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401464\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x401420\n            number: 0x2 = FILE_WRITE_DATA @ 0x40141E\n            match: create or open file @ 0x401428\n              or:\n                api: CreateFile @ 0x401428\n      or:\n        api: WriteFile @ 0x4014A4, 0x4014BB\n\ncreate process on Windows\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x4014CE in function 0x4014CE\n  or:\n    api: CreateProcess @ 0x401593\n\nacquire debug privileges\nnamespace  host-interaction/process/modify                        \nauthor     william.ballenthin@mandiant.com                        \nscope      basic block                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\nbasic block @ 0x40101A in function 0x401000\n  and:\n    string: \"SeDebugPrivilege\" @ 0x40101E\n\nmodify access privileges\nnamespace  host-interaction/process/modify                        \nauthor     moritz.raabe@mandiant.com                              \nscope      instruction                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\ninstruction @ 0x401053\n  and:\n    api: AdjustTokenPrivileges @ 0x401053\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x40169F\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x401966\n\nset registry value\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x40115F\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x40116E\n          or:\n            api: RegOpenKeyEx @ 0x401183\n      or:\n        api: RegSetValueEx @ 0x40119F\n\nlink function at runtime on Windows\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x401135\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401135\n\n\n\n"},"hashes":{"md5":"75523ea9b9af74aa0dac145ba9de04e9","sha1":"37c62921ab65cd4ad72d4718d153c8d67a1d9fb0","sha256":"6db17d8ddf00e0733ad030d8fe483b8ea504b4dbb25341c6231412bcb95316b5"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 19</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 1637</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Variant.Kazy-019f46cad0df73608\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"75523ea9b9af74aa0dac145ba9de04e9\",\n        \"sha256\": \"6db17d8ddf00e0733ad030d8fe483b8ea504b4dbb25341c6231412b\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x4012EF\",\n      \"label\": \"Function 0x4012EF\",\n      \"type\": \"function\",\n      \"address\": \"0x4012EF\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__5_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (5 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_timestomp_file\",\n      \"label\": \"timestomp file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Indicator Removal::Timestomp [T1070.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40159C\",\n      \"label\": \"Function 0x40159C\",\n      \"type\": \"function\",\n      \"address\": \"0x40159C\"\n    },\n    {\n      \"id\": \"api_SetFileTime\",\n      \"label\": \"SetFileTime\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileTime\",\n      \"label\": \"GetFileTime\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Indicator Removal::Timestomp [T1070.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_obfuscated_stackstrings__4_matches_\",\n      \"label\": \"contain obfuscated stackstrings (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40159C\",\n      \"label\": \"Block 0x40159C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40159C\"\n    },\n    {\n      \"id\": \"bb_0x401233\",\n      \"label\": \"Block 0x401233\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401233\"\n    },\n    {\n      \"id\": \"bb_0x4014CE\",\n      \"label\": \"Block 0x4014CE\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4014CE\"\n    },\n    {\n      \"id\": \"bb_0x40169F\",\n      \"label\": \"Block 0x40169F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40169F\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x40106E\",\n      \"label\": \"Function 0x40106E\",\n      \"type\": \"function\",\n      \"address\": \"0x40106E\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FreeResource\",\n      \"label\": \"FreeResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_contain_an_embedded_pe_file\",\n      \"label\": \"contain an embedded PE file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path__2_matches_\",\n      \"label\": \"get common file path (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4011FF\",\n      \"label\": \"Function 0x4011FF\",\n      \"type\": \"function\",\n      \"address\": \"0x4011FF\"\n    },\n    {\n      \"id\": \"func_0x4011B0\",\n      \"label\": \"Function 0x4011B0\",\n      \"type\": \"function\",\n      \"address\": \"0x4011B0\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size\",\n      \"label\": \"get file size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401355\",\n      \"label\": \"Function 0x401355\",\n      \"type\": \"function\",\n      \"address\": \"0x401355\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows\",\n      \"label\": \"read file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__2_matches_\",\n      \"label\": \"write file on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40140D\",\n      \"label\": \"Function 0x40140D\",\n      \"type\": \"function\",\n      \"address\": \"0x40140D\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows\",\n      \"label\": \"create process on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_acquire_debug_privileges\",\n      \"label\": \"acquire debug privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40101A\",\n      \"label\": \"Block 0x40101A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40101A\"\n    },\n    {\n      \"id\": \"cap_modify_access_privileges\",\n      \"label\": \"modify access privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"api_AdjustTokenPrivileges\",\n      \"label\": \"AdjustTokenPrivileges\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40169F\",\n      \"label\": \"Function 0x40169F\",\n      \"type\": \"function\",\n      \"address\": \"0x40169F\"\n    },\n    {\n      \"id\": \"api_ExitProcess\",\n      \"label\": \"ExitProcess\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value\",\n      \"label\": \"set registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40115F\",\n      \"label\": \"Function 0x40115F\",\n      \"type\": \"function\",\n      \"address\": \"0x40115F\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows\",\n      \"label\": \"link function at runtime on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x4012EF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__5_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_timestomp_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_timestomp_file\",\n      \"target\": \"func_0x40159C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40159C\",\n      \"target\": \"api_SetFileTime\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40159C\",\n      \"target\": \"api_GetFileTime\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x40159C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40159C\",\n      \"target\": \"api_SetFileTime\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40159C\",\n      \"target\": \"api_GetFileTime\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_obfuscated_stackstrings__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__4_matches_\",\n      \"target\": \"bb_0x40159C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__4_matches_\",\n      \"target\": \"bb_0x401233\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__4_matches_\",\n      \"target\": \"bb_0x4014CE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__4_matches_\",\n      \"target\": \"bb_0x40169F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x40159C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x401233\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4014CE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x40169F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x40106E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40106E\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40106E\",\n      \"target\": \"api_FreeResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40106E\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40106E\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40106E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40106E\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40106E\",\n      \"target\": \"api_FreeResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40106E\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40106E\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_an_embedded_pe_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__2_matches_\",\n      \"target\": \"func_0x4011FF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__2_matches_\",\n      \"target\": \"func_0x4011B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4011FF\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4011B0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4011FF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4011B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4011FF\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4011B0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size\",\n      \"target\": \"func_0x401355\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401355\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401355\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401355\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows\",\n      \"target\": \"func_0x401355\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401355\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401355\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401355\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401355\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401355\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x40140D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x40106E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40140D\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40106E\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40140D\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40106E\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40140D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40106E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40140D\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40106E\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40140D\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40106E\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows\",\n      \"target\": \"bb_0x4014CE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4014CE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_acquire_debug_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_acquire_debug_privileges\",\n      \"target\": \"bb_0x40101A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"bb_0x40101A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_modify_access_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x40169F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40169F\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40169F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40169F\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value\",\n      \"target\": \"func_0x40115F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40115F\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40115F\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40115F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40115F\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40115F\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 21:36:43.773060\",\n    \"total_functions\": \"19\",\n    \"total_features\": \"1637\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 21:36:44"}
{"_id":{"$oid":"6a4fce4b0108394cb24cdcf1"},"sha256":"036e4f452041f9d573f851d48d92092060107d9ea32e0c532849d61a598b8a71","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_k19_g3t6/001_upx_unpacked.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_k19_g3t6/001_upx_unpacked.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_k19_g3t6/001_upx_unpacked.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ a5b903fc3991cf06221ab3d2f698c827                                  │\n│ sha1     │ b68f05a5e517da43554c279f58a3898a80b64bc8                          │\n│ sha256   │ e40d9c780b0d5adc3b396222d15458f70d577a4fe0e34efa4a20c64a42c57201  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /tmp/sdm_unpack_tbxtr4ov/Win32.Alina.3.4.B-019f46cae688784187692… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic           ┃ ATT&CK Technique                                   ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION         │ Indicator Removal::File Deletion [T1070.004]       │\n│                         │ Modify Registry [T1112]                            │\n│                         │ Obfuscated Files or Information [T1027]            │\n│ DISCOVERY               │ File and Directory Discovery [T1083]               │\n│                         │ Process Discovery [T1057]                          │\n│                         │ Query Registry [T1012]                             │\n│                         │ Software Discovery [T1518]                         │\n│                         │ System Information Discovery [T1082]               │\n│ EXECUTION               │ Command and Scripting Interpreter [T1059]          │\n│                         │ Shared Modules [T1129]                             │\n│ PRIVILEGE ESCALATION    │ Access Token Manipulation [T1134]                  │\n└─────────────────────────┴────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MAEC Category                                    ┃ MAEC Value                ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ malware-category                                 │ launcher                  │\n└──────────────────────────────────────────────────┴───────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Debugger Detection::Timing/Delay Check            │\n│                          │ GetTickCount [B0001.032]                          │\n│ COMMAND AND CONTROL      │ C2 Communication::Receive Data [B0030.002]        │\n│                          │ C2 Communication::Send Data [B0030.001]           │\n│ COMMUNICATION            │ HTTP Communication::Connect to Server [C0002.009] │\n│                          │ HTTP Communication::Create Request [C0002.012]    │\n│                          │ HTTP Communication::Download URL [C0002.006]      │\n│                          │ HTTP Communication::Get Response [C0002.017]      │\n│                          │ HTTP Communication::Send Request [C0002.003]      │\n│ DATA                     │ Check String [C0019]                              │\n│                          │ Checksum::CRC32 [C0032.001]                       │\n│                          │ Encode Data::XOR [C0026.002]                      │\n│ DEFENSE EVASION          │ Obfuscated Files or                               │\n│                          │ Information::Encoding-Standard Algorithm          │\n│                          │ [E1027.m02]                                       │\n│                          │ Self Deletion::COMSPEC Environment Variable       │\n│                          │ [F0007.001]                                       │\n│ DISCOVERY                │ File and Directory Discovery [E1083]              │\n│                          │ System Information Discovery [E1082]              │\n│ EXECUTION                │ Command and Scripting Interpreter [E1059]         │\n│ FILE SYSTEM              │ Copy File [C0045]                                 │\n│                          │ Delete File [C0047]                               │\n│                          │ Read File [C0051]                                 │\n│                          │ Writes File [C0052]                               │\n│ OPERATING SYSTEM         │ Registry::Delete Registry Value [C0036.007]       │\n│                          │ Registry::Query Registry Value [C0036.006]        │\n│                          │ Registry::Set Registry Key [C0036.001]            │\n│ PROCESS                  │ Allocate Thread Local Storage [C0040]             │\n│                          │ Check Mutex [C0043]                               │\n│                          │ Create Mutex [C0042]                              │\n│                          │ Create Process [C0017]                            │\n│                          │ Create Process::Create Suspended Process          │\n│                          │ [C0017.003]                                       │\n│                          │ Create Thread [C0038]                             │\n│                          │ Terminate Process [C0018]                         │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ check for time delay via GetTickCount │ anti-analysis/anti-debugging/debugg… │\n│ (2 matches)                           │                                      │\n│ self delete                           │ anti-analysis/anti-forensic/self-de… │\n│ parse credit card information         │ collection/credit-card               │\n│ receive data (2 matches)              │ communication                        │\n│ send data                             │ communication                        │\n│ hash data with CRC32                  │ data-manipulation/checksum/crc32     │\n│ encode data using XOR (2 matches)     │ data-manipulation/encoding/xor       │\n│ accept command line arguments         │ host-interaction/cli                 │\n│ get common file path (2 matches)      │ host-interaction/file-system         │\n│ copy file                             │ host-interaction/file-system/copy    │\n│ delete file (2 matches)               │ host-interaction/file-system/delete  │\n│ get file size                         │ host-interaction/file-system/meta    │\n│ read file on Windows                  │ host-interaction/file-system/read    │\n│ write file on Windows                 │ host-interaction/file-system/write   │\n│ get disk information                  │ host-interaction/hardware/storage    │\n│ check mutex and terminate process on  │ host-interaction/mutex               │\n│ Windows                               │                                      │\n│ get hostname                          │ host-interaction/os/hostname         │\n│ get process image filename            │ host-interaction/process             │\n│ create process on Windows (2 matches) │ host-interaction/process/create      │\n│ create process suspended              │ host-interaction/process/create      │\n│ enumerate processes (2 matches)       │ host-interaction/process/list        │\n│ acquire debug privileges              │ host-interaction/process/modify      │\n│ query or enumerate registry value     │ host-interaction/registry            │\n│ set registry value                    │ host-interaction/registry/create     │\n│ delete registry value                 │ host-interaction/registry/delete     │\n│ create thread (2 matches)             │ host-interaction/thread/create       │\n│ allocate thread local storage         │ host-interaction/thread/tls          │\n│ link function at runtime on Windows   │ linking/runtime-linking              │\n│ (5 matches)                           │                                      │\n│ link many functions at runtime        │ linking/runtime-linking              │\n│ linked against CPP standard library   │ linking/static                       │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     a5b903fc3991cf06221ab3d2f698c827                        \nsha1                    b68f05a5e517da43554c279f58a3898a80b64bc8                \nsha256                  e40d9c780b0d5adc3b396222d15458f70d577a4fe0e34efa4a20c64…\npath                    /tmp/sdm_unpack_tbxtr4ov/Win32.Alina.3.4.B-019f46cae688…\ntimestamp               2026-07-09 22:07:18.125202                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEInc9bIE/rules                                   \nfunction count          289                                                     \nlibrary function count  316                                                     \ntotal feature count     14231                                                   \n\ncheck for time delay via GetTickCount (2 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    0x404070                                       \n           0x404540                                       \n\nself delete\nnamespace  anti-analysis/anti-forensic/self-deletion\nscope      function                                 \nmatches    0x402260                                 \n\nparse credit card information\nnamespace  collection/credit-card\nscope      function              \nmatches    0x407830              \n\nreceive data (2 matches)\nnamespace    communication                                                     \ndescription  all known techniques for receiving data from a potential C2 server\nscope        function                                                          \nmatches      0x401D90                                                          \n             0x402DA0                                                          \n\nsend data\nnamespace    communication                                                 \ndescription  all known techniques for sending data to a potential C2 server\nscope        function                                                      \nmatches      0x401D90                                                      \n\nconnect to HTTP server\nnamespace  communication/http/client\nscope      function                 \nmatches    0x401D90                 \n\ncreate HTTP request\nnamespace  communication/http/client\nscope      function                 \nmatches    0x401D90                 \n\ndownload URL\nnamespace  communication/http/client\nscope      function                 \nmatches    0x402DA0                 \n\nread data from Internet\nnamespace  communication/http/client\nscope      function                 \nmatches    0x401D90                 \n\nsend HTTP request\nnamespace  communication/http/client\nscope      function                 \nmatches    0x401D90                 \n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32\nscope      function                        \nmatches    0x401040                        \n\nencode data using XOR (2 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x401C10                      \n           0x403DE5                      \n\naccept command line arguments\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x402260            \n\nget common file path (2 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x402260                    \n           0x402DA0                    \n\ncopy file\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    0x402260                         \n\ndelete file (2 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x402260                           \n           0x402DA0                           \n\nget file size\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x402260                         \n\nread file on Windows\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x402260                         \n\nwrite file on Windows\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x402260                          \n\nget disk information\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x4020A0                         \n\ncheck mutex and terminate process on Windows\nnamespace  host-interaction/mutex\nscope      function              \nmatches    0x402260              \n\ncheck mutex on Windows\nnamespace  host-interaction/mutex\nscope      function              \nmatches    0x402260              \n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex\nscope      instruction           \nmatches    0x402297              \n\nget hostname\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    0x4020A0                    \n\nget process image filename\nnamespace  host-interaction/process\nscope      basic block             \nmatches    0x4025B9                \n\ncreate process on Windows (2 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x402B88                       \n           0x402ECB                       \n\ncreate process suspended\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x402B88                       \n\nenumerate processes (2 matches)\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    0x402260                     \n           0x4041F0                     \n\nacquire debug privileges\nnamespace  host-interaction/process/modify\nscope      basic block                    \nmatches    0x401107                       \n\nmodify access privileges\nnamespace  host-interaction/process/modify\nscope      instruction                    \nmatches    0x401136                       \n\nterminate process (2 matches)\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x402260                          \n           0x40B810                          \n\nquery or enumerate registry value\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x401160                 \n\nset registry value\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x401440                        \n\ndelete registry value\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x4015C0                        \n\ncreate thread (2 matches)\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x402FD0                      \n           0x4031BD                      \n\nallocate thread local storage\nnamespace  host-interaction/thread/tls\nscope      function                   \nmatches    0x411A48                   \n\nlink function at runtime on Windows (5 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x41770C               \n           0x41772A               \n           0x41773A               \n           0x41774A               \n           0x41775E               \n\nlink many functions at runtime\nnamespace  linking/runtime-linking\nscope      function               \nmatches    0x4176B5               \n\nlinked against CPP standard library\nnamespace  linking/static\nscope      file          \n\n\n\n","very_verbose":"md5                     a5b903fc3991cf06221ab3d2f698c827                        \nsha1                    b68f05a5e517da43554c279f58a3898a80b64bc8                \nsha256                  e40d9c780b0d5adc3b396222d15458f70d577a4fe0e34efa4a20c64…\npath                    /tmp/sdm_unpack_tbxtr4ov/Win32.Alina.3.4.B-019f46cae688…\ntimestamp               2026-07-09 22:07:29.800479                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIe6vr08/rules                                   \nfunction count          289                                                     \nlibrary function count  316                                                     \ntotal feature count     14231                                                   \n\ncalculate modulo 256 via x86 assembly (library rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x403DEA\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x403DEA\n    or:\n      number: 0xFF @ 0x403DEA\n\ncontain loop (77 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401040\n  or:\n    characteristic: loop @ 0x401040\n\ncreate or open file (4 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x40271C\n  or:\n    api: CreateFile @ 0x40271C\n\ncreate or open registry key (3 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x4011F0 in function 0x401160\n  or:\n    api: RegOpenKeyEx @ 0x401203\n\ndelay execution (10 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x4022F0 in function 0x402260\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x4022F8\n\nopen process (3 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org           \nscope   basic block                  \nmbc     Process::Open Process [C0065]\nbasic block @ 0x402598 in function 0x402260\n  or:\n    api: OpenProcess @ 0x4025A0\n\ncheck for time delay via GetTickCount (2 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection                      \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check     \n           GetTickCount [B0001.032]                                             \nfunction @ 0x404070\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x404073\n        mnemonic: cmp @ 0x404097\n    count(api(GetTickCount)): 2 or more @ 0x4040A0, 0x404165\nfunction @ 0x404540\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x404676\n        mnemonic: cmp @ 0x404692\n    count(api(GetTickCount)): 2 or more @ 0x40454C, 0x404613, 0x404640\n\nself delete\nnamespace  anti-analysis/anti-forensic/self-deletion                            \nauthor     michael.hunhoff@mandiant.com, @mr-tz                                 \nscope      function                                                             \natt&ck     Defense Evasion::Indicator Removal::File Deletion [T1070.004]        \nmbc        Defense Evasion::Self Deletion::COMSPEC Environment Variable         \n           [F0007.001]                                                          \nfunction @ 0x402260\n  and:\n    or:\n      match: host-interaction/process/create @ 0x402B88\n        or:\n          api: CreateProcess @ 0x402BC5\n        or:\n          and:\n            or:\n              number: 0x2 = DEBUG_ONLY_THIS_PROCESS @ 0x402B8A\n            or:\n              api: CreateProcess @ 0x402BC5\n    or:\n      regex: /(^|[\\&;\\|]\\s*)del(\\s.*)?/i\n        - \"Deleted %s from old setup. deleting autostart.\" @ 0x402796\n        - \"Deleted old file %s\" @ 0x40232A\n        - \"Deleted old file from update %s\" @ 0x402394\n\nparse credit card information\nnamespace  collection/credit-card    \nauthor     @_re_fox                  \nscope      function                  \nmbc        Data::Check String [C0019]\nfunction @ 0x407830\n  and:\n    not: = if a function also compares these non-hex characters it's most likely NOT \nparsing CC data\n      and:\n        match: parse credit card information/efff727f6e2f4f8da22050885c920578\n        match: parse credit card information/9d69217cd41f45bda65f68dc58eba594\n        match: parse credit card information/7e601cb3a1fe4ac693b83e4540bae902\n        match: parse credit card information/af277ea9d2704e6a9db43fc05a4d9459\n    3 or more:\n      instruction:\n        and:\n          mnemonic: cmp @ 0x407B91\n          number: 0x5E = '^' (Track 1 separator) @ 0x407B91\n      instruction:\n        and:\n          mnemonic: cmp @ 0x4079C5\n          number: 0x42 = 'B' (Format code) @ 0x4079C5\n      instruction:\n        and:\n          mnemonic: cmp @ 0x407BC7\n          number: 0x3F = '?' (Track 1 & 2 end sentinel) @ 0x407BC7\n\nreceive data (2 matches)\nnamespace    communication                                                     \nauthor       william.ballenthin@mandiant.com                                   \nscope        function                                                          \nmbc          Command and Control::C2 Communication::Receive Data [B0030.002]   \ndescription  all known techniques for receiving data from a potential C2 server\nfunction @ 0x401D90\n  or:\n    match: read data from Internet @ 0x401D90\n      and:\n        optional:\n          or:\n            match: connect to HTTP server @ 0x401D90\n              and:\n                api: InternetConnect @ 0x401E08\n                optional:\n                  match: create HTTP request @ 0x401D90\n                    and:\n                      optional:\n                        api: InternetCloseHandle @ 0x401E8B, 0x401E95, 0x401E9F, 0x401F08, and 8 more...\n                      or:\n                        api: InternetOpen @ 0x401DE1\n        or:\n          api: InternetReadFile @ 0x401F69, 0x401F9C\nfunction @ 0x402DA0\n  or:\n    match: download URL @ 0x402DA0\n      or:\n        api: URLDownloadToFile @ 0x402E3D\n\nsend data\nnamespace    communication                                                 \nauthor       william.ballenthin@mandiant.com, joakim@intezer.com           \nscope        function                                                      \nmbc          Command and Control::C2 Communication::Send Data [B0030.001]  \ndescription  all known techniques for sending data to a potential C2 server\nfunction @ 0x401D90\n  or:\n    and:\n      os: windows\n      or:\n        match: send HTTP request @ 0x401D90\n          or:\n            and:\n              or:\n                api: HttpOpenRequest @ 0x401E39\n                api: InternetConnect @ 0x401E08\n              or:\n                api: HttpSendRequest @ 0x401E64\n\nwrite and execute a file\nnamespace              communication/c2/file-transfer               \nmaec/malware-category  launcher                                     \nauthor                 moritz.raabe@mandiant.com                    \nscope                  function                                     \nmbc                    Execution::Install Additional Program [B0023]\nfunction @ 0x402260\n  and:\n    match: host-interaction/file-system/write @ 0x402260\n      or:\n        and:\n          os: windows\n          optional:\n            basic block:\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402685\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402B8A\n              or:\n                number: 0x40000000 = GENERIC_WRITE @ 0x402874\n                number: 0x2 = FILE_WRITE_DATA @ 0x40286E\n                match: create or open file @ 0x402880\n                  or:\n                    api: CreateFile @ 0x402880\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402339\n              or:\n                match: create or open file @ 0x40271C\n                  or:\n                    api: CreateFile @ 0x40271C\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402BED\n              or:\n                match: create or open file @ 0x4028A7\n                  or:\n                    api: CreateFile @ 0x4028A7\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x4023A3\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x4027A9\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402C6E\n          or:\n            api: WriteFile @ 0x402991\n    match: host-interaction/process/create @ 0x402B88\n      or:\n        api: CreateProcess @ 0x402BC5\n      or:\n        and:\n          or:\n            number: 0x2 = DEBUG_ONLY_THIS_PROCESS @ 0x402B8A\n          or:\n            api: CreateProcess @ 0x402BC5\n\nconnect to HTTP server\nnamespace  communication/http/client                                       \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \nmbc        Communication::HTTP Communication::Connect to Server [C0002.009]\nfunction @ 0x401D90\n  and:\n    api: InternetConnect @ 0x401E08\n    optional:\n      match: create HTTP request @ 0x401D90\n        and:\n          optional:\n            api: InternetCloseHandle @ 0x401E8B, 0x401E95, 0x401E9F, 0x401F08, and 8 more...\n          or:\n            api: InternetOpen @ 0x401DE1\n\ncreate HTTP request\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Create Request [C0002.012]\nfunction @ 0x401D90\n  and:\n    optional:\n      api: InternetCloseHandle @ 0x401E8B, 0x401E95, 0x401E9F, 0x401F08, and 8 more...\n    or:\n      api: InternetOpen @ 0x401DE1\n\ndownload URL\nnamespace  communication/http/client                                            \nauthor     matthew.williams@mandiant.com, michael.hunhoff@mandiant.com,         \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Communication::HTTP Communication::Download URL [C0002.006]          \nfunction @ 0x402DA0\n  or:\n    api: URLDownloadToFile @ 0x402E3D\n\nread data from Internet\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Get Response [C0002.017]  \nfunction @ 0x401D90\n  and:\n    optional:\n      or:\n        match: connect to HTTP server @ 0x401D90\n          and:\n            api: InternetConnect @ 0x401E08\n            optional:\n              match: create HTTP request @ 0x401D90\n                and:\n                  optional:\n                    api: InternetCloseHandle @ 0x401E8B, 0x401E95, 0x401E9F, 0x401F08, and 8 more...\n                  or:\n                    api: InternetOpen @ 0x401DE1\n    or:\n      api: InternetReadFile @ 0x401F69, 0x401F9C\n\nsend HTTP request\nnamespace  communication/http/client                                  \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com    \nscope      function                                                   \nmbc        Communication::HTTP Communication::Send Request [C0002.003]\nfunction @ 0x401D90\n  or:\n    and:\n      or:\n        api: HttpOpenRequest @ 0x401E39\n        api: InternetConnect @ 0x401E08\n      or:\n        api: HttpSendRequest @ 0x401E64\n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32 \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \nmbc        Data::Checksum::CRC32 [C0032.001]\nfunction @ 0x401040\n  or:\n    and:\n      number: 0x1 = bits in a byte @ 0x401044, 0x401046, 0x401050, 0x401054, and 19 more...\n      instruction:\n        and:\n          operand[1].number: 0x1 @ 0x401046\n          or:\n            mnemonic: test @ 0x401046\n        and:\n          operand[1].number: 0x1 @ 0x4010AA\n          or:\n            mnemonic: test @ 0x4010AA\n        and:\n          operand[1].number: 0x1 @ 0x40108C\n          or:\n            mnemonic: test @ 0x40108C\n        and:\n          operand[1].number: 0x1 @ 0x40106E\n          or:\n            mnemonic: test @ 0x40106E\n        and:\n          operand[1].number: 0x1 @ 0x401050\n          or:\n            mnemonic: test @ 0x401050\n        and:\n          operand[1].number: 0x1 @ 0x40109B\n          or:\n            mnemonic: test @ 0x40109B\n        and:\n          operand[1].number: 0x1 @ 0x40107D\n          or:\n            mnemonic: test @ 0x40107D\n        and:\n          operand[1].number: 0x1 @ 0x40105F\n          or:\n            mnemonic: test @ 0x40105F\n      instruction:\n        and:\n          mnemonic: shr @ 0x401081\n          number: 0x1 @ 0x401081\n        and:\n          mnemonic: shr @ 0x401063\n          number: 0x1 @ 0x401063\n        and:\n          mnemonic: shr @ 0x401044\n          number: 0x1 @ 0x401044\n        and:\n          mnemonic: shr @ 0x4010A8\n          number: 0x1 @ 0x4010A8\n        and:\n          mnemonic: shr @ 0x40108A\n          number: 0x1 @ 0x40108A\n        and:\n          mnemonic: shr @ 0x40106C\n          number: 0x1 @ 0x40106C\n        and:\n          mnemonic: shr @ 0x4010AE\n          number: 0x1 @ 0x4010AE\n        and:\n          mnemonic: shr @ 0x401090\n          number: 0x1 @ 0x401090\n        and:\n          mnemonic: shr @ 0x401072\n          number: 0x1 @ 0x401072\n        and:\n          mnemonic: shr @ 0x401054\n          number: 0x1 @ 0x401054\n        and:\n          mnemonic: shr @ 0x4010B7\n          number: 0x1 @ 0x4010B7\n        and:\n          mnemonic: shr @ 0x401099\n          number: 0x1 @ 0x401099\n        and:\n          mnemonic: shr @ 0x40107B\n          number: 0x1 @ 0x40107B\n        and:\n          mnemonic: shr @ 0x40105D\n          number: 0x1 @ 0x40105D\n        and:\n          mnemonic: shr @ 0x40109F\n          number: 0x1 @ 0x40109F\n      characteristic: nzxor @ 0x40104B, 0x401056, 0x401065, 0x401074, and 4 more...\n      operand[1].number: 0xEDB88320 @ 0x40104B, 0x401056, 0x401065, 0x401074, and 4 more...\n\nencode data using XOR (2 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x401C10 in function 0x401C00\n  and:\n    characteristic: tight loop @ 0x401C10\n    characteristic: nzxor @ 0x401C17\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403DE5 in function 0x403AE0\n  and:\n    characteristic: tight loop @ 0x403DE5\n    characteristic: nzxor @ 0x403DE8, 0x403DF3\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\naccept command line arguments\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x402260\n  or:\n    api: GetCommandLine @ 0x4022C7\n\nget common file path (2 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x402260\n  or:\n    api: SHGetSpecialFolderPath @ 0x4023FC\nfunction @ 0x402DA0\n  or:\n    api: GetTempPath @ 0x402DC1\n\ncopy file\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ 0x402260\n  or:\n    api: CopyFile @ 0x402A27\n\ndelete file (2 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x402260\n  or:\n    api: DeleteFile @ 0x4022FF, 0x402376, 0x402743\nfunction @ 0x402DA0\n  or:\n    api: DeleteFile @ 0x402F66\n\nget file size\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x402260\n  or:\n    api: GetFileSize @ 0x4028C3\n\nread file on Windows\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x402260\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x402716, 0x40289B\n          match: create or open file @ 0x40271C, 0x402880, 0x4028A7\n            or:\n              api: CreateFile @ 0x402880\n            or:\n              api: CreateFile @ 0x40271C\n            or:\n              api: CreateFile @ 0x4028A7\n      or:\n        api: ReadFile @ 0x40296D\n\nwrite file on Windows\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x402260\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402685\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402B8A\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x402874\n            number: 0x2 = FILE_WRITE_DATA @ 0x40286E\n            match: create or open file @ 0x402880\n              or:\n                api: CreateFile @ 0x402880\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402339\n          or:\n            match: create or open file @ 0x40271C\n              or:\n                api: CreateFile @ 0x40271C\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402BED\n          or:\n            match: create or open file @ 0x4028A7\n              or:\n                api: CreateFile @ 0x4028A7\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4023A3\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4027A9\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402C6E\n      or:\n        api: WriteFile @ 0x402991\n\nget disk information\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ 0x4020A0\n  or:\n    api: GetVolumeInformation @ 0x4020B8\n\ncheck mutex and terminate process on Windows\nnamespace  host-interaction/mutex                                          \nauthor     @_re_fox, moritz.raabe@mandiant.com, mehunhoff@google.com       \nscope      function                                                        \nmbc        Process::Check Mutex [C0043], Process::Terminate Process [C0018]\nfunction @ 0x402260\n  and:\n    match: check mutex on Windows @ 0x402260\n      or:\n        and:\n          match: create or open mutex on Windows @ 0x402297\n            or:\n              api: CreateMutex @ 0x402297\n          or:\n            basic block:\n              and:\n                api: GetLastError @ 0x402BDC\n                or:\n                  number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x402BED\n              and:\n                api: GetLastError @ 0x402677\n                or:\n                  number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x402685\n              and:\n                api: GetLastError @ 0x402399\n                or:\n                  number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x4023A3\n              and:\n                api: GetLastError @ 0x4022BA\n                or:\n                  number: 0xB7 = ERROR_ALREADY_EXISTS @ 0x4022BC\n              and:\n                api: GetLastError @ 0x40279B\n                or:\n                  number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x4027A9\n              and:\n                api: GetLastError @ 0x40232F\n                or:\n                  number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x402339\n              and:\n                api: GetLastError @ 0x402C64\n                or:\n                  number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x402C6E\n    match: terminate process @ 0x402260\n      or:\n        and:\n          optional:\n            match: open process @ 0x402598\n              or:\n                api: OpenProcess @ 0x4025A0\n          or:\n            api: TerminateProcess @ 0x402635\n\ncheck mutex on Windows\nnamespace  host-interaction/mutex                         \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      function                                       \nmbc        Process::Check Mutex [C0043]                   \nfunction @ 0x402260\n  or:\n    and:\n      match: create or open mutex on Windows @ 0x402297\n        or:\n          api: CreateMutex @ 0x402297\n      or:\n        basic block:\n          and:\n            api: GetLastError @ 0x402BDC\n            or:\n              number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x402BED\n          and:\n            api: GetLastError @ 0x402677\n            or:\n              number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x402685\n          and:\n            api: GetLastError @ 0x402399\n            or:\n              number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x4023A3\n          and:\n            api: GetLastError @ 0x4022BA\n            or:\n              number: 0xB7 = ERROR_ALREADY_EXISTS @ 0x4022BC\n          and:\n            api: GetLastError @ 0x40279B\n            or:\n              number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x4027A9\n          and:\n            api: GetLastError @ 0x40232F\n            or:\n              number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x402339\n          and:\n            api: GetLastError @ 0x402C64\n            or:\n              number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x402C6E\n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex                                               \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           mehunhoff@google.com                                                 \nscope      instruction                                                          \nmbc        Process::Create Mutex [C0042]                                        \ninstruction @ 0x402297\n  or:\n    api: CreateMutex @ 0x402297\n\nget hostname\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ 0x4020A0\n  or:\n    api: GetComputerName @ 0x4020E4\n\nget process image filename\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ 0x4025B9 in function 0x402260\n  or:\n    and:\n      os: windows\n      or:\n        api: GetProcessImageFileName @ 0x4025C6\n\ncreate process on Windows (2 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x402B88 in function 0x402260\n  or:\n    api: CreateProcess @ 0x402BC5\nbasic block @ 0x402ECB in function 0x402DA0\n  or:\n    api: CreateProcess @ 0x402F0F\n\ncreate process suspended\nnamespace   host-interaction/process/create                                     \nauthor      william.ballenthin@mandiant.com, mehunhoff@google.com               \nscope       basic block                                                         \nmbc         Process::Create Process::Create Suspended Process [C0017.003]       \nreferences  https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/an-…\n            https://learn.microsoft.com/en-us/windows/win32/procthread/process-…\nbasic block @ 0x402B88 in function 0x402260\n  or:\n    and:\n      or:\n        number: 0x2 = DEBUG_ONLY_THIS_PROCESS @ 0x402B8A\n      or:\n        api: CreateProcess @ 0x402BC5\n\nenumerate processes (2 matches)\nnamespace  host-interaction/process/list                                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      function                                                             \natt&ck     Discovery::Process Discovery [T1057], Discovery::Software Discovery  \n           [T1518]                                                              \nfunction @ 0x402260\n  or:\n    and:\n      api: Process32First @ 0x402563\n      api: Process32Next @ 0x4026D1\n      optional:\n        basic block:\n          and:\n            api: CreateToolhelp32Snapshot @ 0x40253C\n            or:\n              number: 0xF = TH32CS_SNAPALL @ 0x402530\nfunction @ 0x4041F0\n  or:\n    and:\n      api: Process32First @ 0x40427E\n      api: Process32Next @ 0x404421\n      optional:\n        basic block:\n          and:\n            api: CreateToolhelp32Snapshot @ 0x404212\n            or:\n              number: 0xF = TH32CS_SNAPALL @ 0x40420A\n\nacquire debug privileges\nnamespace  host-interaction/process/modify                        \nauthor     william.ballenthin@mandiant.com                        \nscope      basic block                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\nbasic block @ 0x401107 in function 0x4010D0\n  and:\n    string: \"SeDebugPrivilege\" @ 0x40110B\n    optional:\n      match: modify access privileges @ 0x401136\n        and:\n          api: AdjustTokenPrivileges @ 0x401136\n\nmodify access privileges\nnamespace  host-interaction/process/modify                        \nauthor     moritz.raabe@mandiant.com                              \nscope      instruction                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\ninstruction @ 0x401136\n  and:\n    api: AdjustTokenPrivileges @ 0x401136\n\nterminate process (2 matches)\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x402260\n  or:\n    and:\n      optional:\n        match: open process @ 0x402598\n          or:\n            api: OpenProcess @ 0x4025A0\n      or:\n        api: TerminateProcess @ 0x402635\nfunction @ 0x40B810\n  or:\n    and:\n      or:\n        api: TerminateProcess @ 0x41012D\n\nquery or enumerate registry value\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x401160\n  and:\n    optional:\n      match: create or open registry key @ 0x4011F0\n        or:\n          api: RegOpenKeyEx @ 0x401203\n    or:\n      api: RegQueryValueEx @ 0x4012C8\n\nset registry value\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x401440\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x401457\n          or:\n            api: RegOpenKeyEx @ 0x401469\n      or:\n        api: RegSetValueEx @ 0x4014F3\n\ndelete registry value\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ 0x4015C0\n  and:\n    optional:\n      match: create or open registry key @ 0x4015D6\n        or:\n          api: RegOpenKeyEx @ 0x4015E8\n    or:\n      api: RegDeleteValue @ 0x401643\n\ncreate thread (2 matches)\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x402FD0 in function 0x402FD0\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x402FE5\nbasic block @ 0x4031BD in function 0x4031B0\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x4031CE\n\nallocate thread local storage\nnamespace  host-interaction/thread/tls                   \nauthor     michael.hunhoff@mandiant.com                  \nscope      function                                      \nmbc        Process::Allocate Thread Local Storage [C0040]\nfunction @ 0x411A48\n  or:\n    api: TlsAlloc @ 0x411A48\n\nlink function at runtime on Windows (5 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x41770C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41770C\ninstruction @ 0x41772A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41772A\ninstruction @ 0x41773A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41773A\ninstruction @ 0x41774A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41774A\ninstruction @ 0x41775E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41775E\n\nlink many functions at runtime\nnamespace  linking/runtime-linking                      \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com\nscope      function                                     \natt&ck     Execution::Shared Modules [T1129]            \nfunction @ 0x4176B5\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x41770C, 0x41772A, 0x41773A, 0x41774A, and 1 more...\n\nlinked against CPP standard library\nnamespace   linking/static                                                      \nauthor      @mr-tz                                                              \nscope       file                                                                \nreferences  https://en.wikipedia.org/wiki/P._J._Plauger,                        \n            https://www.dinkumware.com/                                         \nor:\n  string: \"Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL \nRIGHTS RESERVED.\" @ file+0x1E698\n\n\n\n"},"hashes":{"md5":"a5b903fc3991cf06221ab3d2f698c827","sha1":"b68f05a5e517da43554c279f58a3898a80b64bc8","sha256":"e40d9c780b0d5adc3b396222d15458f70d577a4fe0e34efa4a20c64a42c57201"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 289</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 14231</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Win32.Alina.3.4.B-019f46cae688\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"a5b903fc3991cf06221ab3d2f698c827\",\n        \"sha256\": \"e40d9c780b0d5adc3b396222d15458f70d577a4fe0e34efa4a20c64\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__77_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (77 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401040\",\n      \"label\": \"Function 0x401040\",\n      \"type\": \"function\",\n      \"address\": \"0x401040\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4011F0\",\n      \"label\": \"Block 0x4011F0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4011F0\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__10_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (10 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4022F0\",\n      \"label\": \"Block 0x4022F0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4022F0\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_open_process__3_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"open process (3 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Open Process [C0065]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x402598\",\n      \"label\": \"Block 0x402598\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x402598\"\n    },\n    {\n      \"id\": \"api_OpenProcess\",\n      \"label\": \"OpenProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_check_for_time_delay_via_gettickcount__2_matches_\",\n      \"label\": \"check for time delay via GetTickCount (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"GetTickCount [B0001.032]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404070\",\n      \"label\": \"Function 0x404070\",\n      \"type\": \"function\",\n      \"address\": \"0x404070\"\n    },\n    {\n      \"id\": \"func_0x404540\",\n      \"label\": \"Function 0x404540\",\n      \"type\": \"function\",\n      \"address\": \"0x404540\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"GetTickCount [B0001.032]\"\n      ]\n    },\n    {\n      \"id\": \"cap_self_delete\",\n      \"label\": \"self delete\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402260\",\n      \"label\": \"Function 0x402260\",\n      \"type\": \"function\",\n      \"address\": \"0x402260\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_credit_card_information\",\n      \"label\": \"parse credit card information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Check String [C0019]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407830\",\n      \"label\": \"Function 0x407830\",\n      \"type\": \"function\",\n      \"address\": \"0x407830\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox\",\n      \"label\": \"author     @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Check String [C0019]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_data__2_matches_\",\n      \"label\": \"receive data (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401D90\",\n      \"label\": \"Function 0x401D90\",\n      \"type\": \"function\",\n      \"address\": \"0x401D90\"\n    },\n    {\n      \"id\": \"func_0x402DA0\",\n      \"label\": \"Function 0x402DA0\",\n      \"type\": \"function\",\n      \"address\": \"0x402DA0\"\n    },\n    {\n      \"id\": \"api_InternetOpen\",\n      \"label\": \"InternetOpen\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"api_InternetConnect\",\n      \"label\": \"InternetConnect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_InternetReadFile\",\n      \"label\": \"InternetReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_InternetCloseHandle\",\n      \"label\": \"InternetCloseHandle\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_URLDownloadToFile\",\n      \"label\": \"URLDownloadToFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data\",\n      \"label\": \"send data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_HttpOpenRequest\",\n      \"label\": \"HttpOpenRequest\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_HttpSendRequest\",\n      \"label\": \"HttpSendRequest\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_and_execute_a_file\",\n      \"label\": \"write and execute a file\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_maec_malware_category__launcher\",\n      \"label\": \"maec/malware-category  launcher\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_to_http_server\",\n      \"label\": \"connect to HTTP server\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Connect to Server [C0002.009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_http_request\",\n      \"label\": \"create HTTP request\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_download_url\",\n      \"label\": \"download URL\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Download URL [C0002.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Download URL [C0002.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_data_from_internet\",\n      \"label\": \"read data from Internet\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_http_request\",\n      \"label\": \"send HTTP request\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Send Request [C0002.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Send Request [C0002.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_with_crc32\",\n      \"label\": \"hash data with CRC32\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments\",\n      \"label\": \"accept command line arguments\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path__2_matches_\",\n      \"label\": \"get common file path (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_SHGetSpecialFolderPath\",\n      \"label\": \"SHGetSpecialFolderPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_copy_file\",\n      \"label\": \"copy file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"api_CopyFile\",\n      \"label\": \"CopyFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_file__2_matches_\",\n      \"label\": \"delete file (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_get_file_size\",\n      \"label\": \"get file size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_file_on_windows\",\n      \"label\": \"read file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_write_file_on_windows\",\n      \"label\": \"write file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_disk_information\",\n      \"label\": \"get disk information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4020A0\",\n      \"label\": \"Function 0x4020A0\",\n      \"type\": \"function\",\n      \"address\": \"0x4020A0\"\n    },\n    {\n      \"id\": \"api_GetVolumeInformation\",\n      \"label\": \"GetVolumeInformation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_check_mutex_and_terminate_process_on_windows\",\n      \"label\": \"check mutex and terminate process on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Check Mutex [C0043]\",\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"api_TerminateProcess\",\n      \"label\": \"TerminateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_GetLastError\",\n      \"label\": \"GetLastError\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateMutex\",\n      \"label\": \"CreateMutex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox__moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     @_re_fox, moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Check Mutex [C0043]\",\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_mutex_on_windows\",\n      \"label\": \"check mutex on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Check Mutex [C0043]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Check Mutex [C0043]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_or_open_mutex_on_windows\",\n      \"label\": \"create or open mutex on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_mehunhoff_google_com\",\n      \"label\": \"mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_hostname\",\n      \"label\": \"get hostname\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetComputerName\",\n      \"label\": \"GetComputerName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_process_image_filename\",\n      \"label\": \"get process image filename\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x4025B9\",\n      \"label\": \"Block 0x4025B9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4025B9\"\n    },\n    {\n      \"id\": \"api_GetProcessImageFileName\",\n      \"label\": \"GetProcessImageFileName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__2_matches_\",\n      \"label\": \"create process on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x402ECB\",\n      \"label\": \"Block 0x402ECB\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x402ECB\"\n    },\n    {\n      \"id\": \"bb_0x402B88\",\n      \"label\": \"Block 0x402B88\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x402B88\"\n    },\n    {\n      \"id\": \"cap_create_process_suspended\",\n      \"label\": \"create process suspended\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process::Create Suspended Process [C0017.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process::Create Suspended Process [C0017.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_processes__2_matches_\",\n      \"label\": \"enumerate processes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\",\n        \"Discovery::Software Discovery\",\n        \"[T1518]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4041F0\",\n      \"label\": \"Function 0x4041F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4041F0\"\n    },\n    {\n      \"id\": \"api_Process32Next\",\n      \"label\": \"Process32Next\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateToolhelp32Snapshot\",\n      \"label\": \"CreateToolhelp32Snapshot\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_Process32First\",\n      \"label\": \"Process32First\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_acquire_debug_privileges\",\n      \"label\": \"acquire debug privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401107\",\n      \"label\": \"Block 0x401107\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401107\"\n    },\n    {\n      \"id\": \"api_AdjustTokenPrivileges\",\n      \"label\": \"AdjustTokenPrivileges\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"cap_modify_access_privileges\",\n      \"label\": \"modify access privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process__2_matches_\",\n      \"label\": \"terminate process (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40B810\",\n      \"label\": \"Function 0x40B810\",\n      \"type\": \"function\",\n      \"address\": \"0x40B810\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value\",\n      \"label\": \"query or enumerate registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401160\",\n      \"label\": \"Function 0x401160\",\n      \"type\": \"function\",\n      \"address\": \"0x401160\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value\",\n      \"label\": \"set registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401440\",\n      \"label\": \"Function 0x401440\",\n      \"type\": \"function\",\n      \"address\": \"0x401440\"\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delete_registry_value\",\n      \"label\": \"delete registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4015C0\",\n      \"label\": \"Function 0x4015C0\",\n      \"type\": \"function\",\n      \"address\": \"0x4015C0\"\n    },\n    {\n      \"id\": \"api_RegDeleteValue\",\n      \"label\": \"RegDeleteValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_thread__2_matches_\",\n      \"label\": \"create thread (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4031BD\",\n      \"label\": \"Block 0x4031BD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4031BD\"\n    },\n    {\n      \"id\": \"bb_0x402FD0\",\n      \"label\": \"Block 0x402FD0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x402FD0\"\n    },\n    {\n      \"id\": \"api_CreateThread\",\n      \"label\": \"CreateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_allocate_thread_local_storage\",\n      \"label\": \"allocate thread local storage\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Allocate Thread Local Storage [C0040]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x411A48\",\n      \"label\": \"Function 0x411A48\",\n      \"type\": \"function\",\n      \"address\": \"0x411A48\"\n    },\n    {\n      \"id\": \"api_TlsAlloc\",\n      \"label\": \"TlsAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__5_matches_\",\n      \"label\": \"link function at runtime on Windows (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_link_many_functions_at_runtime\",\n      \"label\": \"link many functions at runtime\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4176B5\",\n      \"label\": \"Function 0x4176B5\",\n      \"type\": \"function\",\n      \"address\": \"0x4176B5\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_linked_against_cpp_standard_library\",\n      \"label\": \"linked against CPP standard library\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______mr_tz\",\n      \"label\": \"author      @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__77_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__77_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401040\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x4011F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__10_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__10_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x4022F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_process__3_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_process__3_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x402598\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_time_delay_via_gettickcount__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount__2_matches_\",\n      \"target\": \"func_0x404070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount__2_matches_\",\n      \"target\": \"func_0x404540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x404070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x404540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_self_delete\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_self_delete\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CreateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CreateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_credit_card_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_credit_card_information\",\n      \"target\": \"func_0x407830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox\",\n      \"target\": \"func_0x407830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data__2_matches_\",\n      \"target\": \"func_0x401D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__2_matches_\",\n      \"target\": \"func_0x402DA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_InternetCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_URLDownloadToFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_URLDownloadToFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x401D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x402DA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_InternetCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_URLDownloadToFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_URLDownloadToFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data\",\n      \"target\": \"func_0x401D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x401D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_and_execute_a_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_and_execute_a_file\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CreateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_maec_malware_category__launcher\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_maec_malware_category__launcher\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CreateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_to_http_server\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_to_http_server\",\n      \"target\": \"func_0x401D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_http_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_http_request\",\n      \"target\": \"func_0x401D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_download_url\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_download_url\",\n      \"target\": \"func_0x402DA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_URLDownloadToFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402DA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_URLDownloadToFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_data_from_internet\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet\",\n      \"target\": \"func_0x401D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_http_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_http_request\",\n      \"target\": \"func_0x401D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D90\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_crc32\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_with_crc32\",\n      \"target\": \"func_0x401040\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x401040\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__2_matches_\",\n      \"target\": \"func_0x402DA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__2_matches_\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_SHGetSpecialFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_SHGetSpecialFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402DA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_SHGetSpecialFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_SHGetSpecialFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_copy_file\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__2_matches_\",\n      \"target\": \"func_0x402DA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__2_matches_\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x402DA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402DA0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information\",\n      \"target\": \"func_0x4020A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4020A0\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4020A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4020A0\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_mutex_and_terminate_process_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_mutex_and_terminate_process_on_windows\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CreateMutex\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CreateMutex\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_mutex_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_mutex_on_windows\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CreateMutex\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CreateMutex\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_mutex_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_hostname\",\n      \"target\": \"func_0x4020A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4020A0\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4020A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4020A0\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_process_image_filename\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_process_image_filename\",\n      \"target\": \"bb_0x4025B9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4025B9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__2_matches_\",\n      \"target\": \"bb_0x402ECB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__2_matches_\",\n      \"target\": \"bb_0x402B88\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x402ECB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x402B88\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_suspended\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_suspended\",\n      \"target\": \"bb_0x402B88\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"bb_0x402B88\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_processes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_processes__2_matches_\",\n      \"target\": \"func_0x4041F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_processes__2_matches_\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4041F0\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4041F0\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4041F0\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4041F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4041F0\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4041F0\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4041F0\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_acquire_debug_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_acquire_debug_privileges\",\n      \"target\": \"bb_0x401107\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"bb_0x401107\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_modify_access_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process__2_matches_\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__2_matches_\",\n      \"target\": \"func_0x40B810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B810\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B810\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B810\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402260\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B810\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value\",\n      \"target\": \"func_0x401160\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401160\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401160\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401160\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401160\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401160\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value\",\n      \"target\": \"func_0x401440\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401440\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401440\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401440\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401440\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401440\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value\",\n      \"target\": \"func_0x4015C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4015C0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4015C0\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4015C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4015C0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4015C0\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread__2_matches_\",\n      \"target\": \"bb_0x4031BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__2_matches_\",\n      \"target\": \"bb_0x402FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4031BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x402FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_thread_local_storage\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_thread_local_storage\",\n      \"target\": \"func_0x411A48\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x411A48\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x411A48\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x411A48\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_many_functions_at_runtime\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime\",\n      \"target\": \"func_0x4176B5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x4176B5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_cpp_standard_library\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______mr_tz\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 22:07:29.800479\",\n    \"total_functions\": \"289\",\n    \"total_features\": \"14231\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 22:07:31"}
{"_id":{"$oid":"6a4fcf040108394cb24cdcf3"},"sha256":"4c2efe2f1253b94f16a1cab032f36c7883e4f6c8d9fc17d0ee553b5afb16330c","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_9trpdpe9/Trojan.Destover-SonySigned-019f46cb019971e1850571f878e6fbb0.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_9trpdpe9/Trojan.Destover-SonySigned-019f46cb019971e1850571f878e6fbb0.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_9trpdpe9/Trojan.Destover-SonySigned-019f46cb019971e1850571f878e6fbb0.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ e904bf93403c0fb08b9683a9e858c73e                                  │\n│ sha1     │ 8397c1e1f0b9d53a114850f6b3ae8c1f2b2d1590                          │\n│ sha256   │ 4c2efe2f1253b94f16a1cab032f36c7883e4f6c8d9fc17d0ee553b5afb16330c  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/Trojan.Destover-… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION      │ Obfuscated Files or Information [T1027]               │\n│                      │ Obfuscated Files or Information::Indicator Removal    │\n│                      │ from Tools [T1027.005]                                │\n│ DISCOVERY            │ File and Directory Discovery [T1083]                  │\n│                      │ System Information Discovery [T1082]                  │\n│                      │ System Network Configuration Discovery [T1016]        │\n│ EXECUTION            │ Shared Modules [T1129]                                │\n│ PERSISTENCE          │ Boot or Logon Autostart Execution::Registry Run Keys  │\n│                      │ / Startup Folder [T1547.001]                          │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-STATIC ANALYSIS │ Executable Code Obfuscation::Argument Obfuscation     │\n│                      │ [B0032.020]                                           │\n│                      │ Executable Code Obfuscation::Stack Strings            │\n│                      │ [B0032.017]                                           │\n│ COMMAND AND CONTROL  │ C2 Communication::Receive Data [B0030.002]            │\n│                      │ C2 Communication::Send Data [B0030.001]               │\n│ COMMUNICATION        │ Socket Communication::Connect Socket [C0001.004]      │\n│                      │ Socket Communication::Create TCP Socket [C0001.011]   │\n│                      │ Socket Communication::Create UDP Socket [C0001.010]   │\n│                      │ Socket Communication::Get Socket Status [C0001.012]   │\n│                      │ Socket Communication::Receive Data [C0001.006]        │\n│                      │ Socket Communication::Send Data [C0001.007]           │\n│                      │ Socket Communication::Set Socket Config [C0001.001]   │\n│                      │ Socket Communication::TCP Client [C0001.008]          │\n│                      │ Socket Communication::UDP Client [C0001.013]          │\n│ DATA                 │ Encode Data::XOR [C0026.002]                          │\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Encoding-Standard    │\n│                      │ Algorithm [E1027.m02]                                 │\n│ DISCOVERY            │ File and Directory Discovery [E1083]                  │\n│                      │ System Information Discovery [E1082]                  │\n│ FILE SYSTEM          │ Get File Attributes [C0049]                           │\n│                      │ Move File [C0063]                                     │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                           ┃ Namespace                             ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ contain obfuscated stackstrings      │ anti-analysis/obfuscation/string/sta… │\n│ receive data                         │ communication                         │\n│ send data (2 matches)                │ communication                         │\n│ get socket status (2 matches)        │ communication/socket                  │\n│ set socket configuration (3 matches) │ communication/socket                  │\n│ connect UDP socket                   │ communication/socket/udp              │\n│ act as TCP client                    │ communication/tcp/client              │\n│ encode data using XOR (3 matches)    │ data-manipulation/encoding/xor        │\n│ get common file path                 │ host-interaction/file-system          │\n│ check if file exists                 │ host-interaction/file-system/exists   │\n│ get file attributes                  │ host-interaction/file-system/meta     │\n│ get disk information                 │ host-interaction/hardware/storage     │\n│ get hostname                         │ host-interaction/os/hostname          │\n│ link function at runtime on Windows  │ linking/runtime-linking               │\n│ resolve function by parsing PE       │ load-code/pe                          │\n│ exports                              │                                       │\n│ write file to startup folder         │ persistence/startup-folder            │\n└──────────────────────────────────────┴───────────────────────────────────────┘\n\n","verbose":"md5                     e904bf93403c0fb08b9683a9e858c73e                        \nsha1                    8397c1e1f0b9d53a114850f6b3ae8c1f2b2d1590                \nsha256                  4c2efe2f1253b94f16a1cab032f36c7883e4f6c8d9fc17d0ee553b5…\npath                    /home/apogean/projects/malware/windows/all_runs/Trojan.…\ntimestamp               2026-07-09 22:10:27.235652                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIr8xI7R/rules                                   \nfunction count          99                                                      \nlibrary function count  183                                                     \ntotal feature count     7466                                                    \n\ncontain obfuscated stackstrings\nnamespace  anti-analysis/obfuscation/string/stackstring\nscope      basic block                                 \nmatches    0x405EE3                                    \n\nreceive data\nnamespace    communication                                                     \ndescription  all known techniques for receiving data from a potential C2 server\nscope        function                                                          \nmatches      0x405600                                                          \n\nsend data (2 matches)\nnamespace    communication                                                 \ndescription  all known techniques for sending data to a potential C2 server\nscope        function                                                      \nmatches      0x405470                                                      \n             0x405560                                                      \n\nconnect socket\nnamespace    communication/socket                                               \ndescription  Detects socket connection attempts using common APIs or ConnectEx  \n             setup.                                                             \nscope        basic block                                                        \nmatches      0x40539F                                                           \n\nget socket status (2 matches)\nnamespace  communication/socket\nscope      function            \nmatches    0x405310            \n           0x4054E0            \n\nset socket configuration (3 matches)\nnamespace  communication/socket\nscope      function            \nmatches    0x405310            \n           0x405470            \n           0x4054E0            \n\nreceive data on socket\nnamespace  communication/socket/receive\nscope      function                    \nmatches    0x405600                    \n\nsend data on socket (2 matches)\nnamespace  communication/socket/send\nscope      function                 \nmatches    0x405470                 \n           0x405560                 \n\nconnect TCP socket\nnamespace  communication/socket/tcp\nscope      function                \nmatches    0x405310                \n\ncreate TCP socket\nnamespace  communication/socket/tcp\nscope      basic block             \nmatches    0x405359                \n\nconnect UDP socket\nnamespace    communication/socket/udp                                           \ndescription  Detects UDP socket connections by combining UDP socket creation    \n             with connection attempts.                                          \nscope        function                                                           \nmatches      0x405310                                                           \n\ncreate UDP socket\nnamespace  communication/socket/udp/send\nscope      basic block                  \nmatches    0x405359                     \n\nact as TCP client\nnamespace  communication/tcp/client\nscope      function                \nmatches    0x405310                \n\nencode data using XOR (3 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x4011F5                      \n           0x4012C6                      \n           0x405060                      \n\nget common file path\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x403FF0                    \n\ncheck if file exists\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x407314                           \n\nget file attributes\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x407314                         \n\nmove file\nnamespace  host-interaction/file-system/move\nscope      function                         \nmatches    0x403FF0                         \n\nget disk information\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x402870                         \n\nget hostname\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    0x402370                    \n\nlink function at runtime on Windows\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x4041AE               \n\nresolve function by parsing PE exports\nnamespace  load-code/pe\nscope      function    \nmatches    0x403640    \n\nget startup folder (2 matches)\nnamespace  persistence/startup-folder\nscope      basic block               \nmatches    0x403FF0                  \n           0x404059                  \n\nwrite file to startup folder\nnamespace  persistence/startup-folder\nscope      function                  \nmatches    0x403FF0                  \n\n\n\n","very_verbose":"md5                     e904bf93403c0fb08b9683a9e858c73e                        \nsha1                    8397c1e1f0b9d53a114850f6b3ae8c1f2b2d1590                \nsha256                  4c2efe2f1253b94f16a1cab032f36c7883e4f6c8d9fc17d0ee553b5…\npath                    /home/apogean/projects/malware/windows/all_runs/Trojan.…\ntimestamp               2026-07-09 22:10:35.308148                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIvqpOEp/rules                                   \nfunction count          99                                                      \nlibrary function count  183                                                     \ntotal feature count     7466                                                    \n\ncalculate modulo 256 via x86 assembly (7 matches, only showing first match of \nlibrary rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x40123B\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x40123B\n    or:\n      number: 0xFF @ 0x40123B\n\ncontain loop (32 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401040\n  or:\n    characteristic: tight loop @ 0x401047\n\ndelay execution (library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x403FE0 in function 0x403FD0\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x403FE5\n\ncontain obfuscated stackstrings\nnamespace  anti-analysis/obfuscation/string/stackstring                         \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information::Indicator Removal  \n           from Tools [T1027.005]                                               \nmbc        Anti-Static Analysis::Executable Code Obfuscation::Argument          \n           Obfuscation [B0032.020], Anti-Static Analysis::Executable Code       \n           Obfuscation::Stack Strings [B0032.017]                               \nbasic block @ 0x405EE3 in function 0x405E70\n  characteristic: stack string @ 0x405EE3\n\nreceive data\nnamespace    communication                                                     \nauthor       william.ballenthin@mandiant.com                                   \nscope        function                                                          \nmbc          Command and Control::C2 Communication::Receive Data [B0030.002]   \ndescription  all known techniques for receiving data from a potential C2 server\nfunction @ 0x405600\n  or:\n    match: receive data on socket @ 0x405600\n      or:\n        api: recv @ 0x405662\n\nsend data (2 matches)\nnamespace    communication                                                 \nauthor       william.ballenthin@mandiant.com, joakim@intezer.com           \nscope        function                                                      \nmbc          Command and Control::C2 Communication::Send Data [B0030.001]  \ndescription  all known techniques for sending data to a potential C2 server\nfunction @ 0x405470\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x405470\n          or:\n            api: send @ 0x4054B3\nfunction @ 0x405560\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x405560\n          or:\n            api: send @ 0x4055BC\n\nconnect socket\nnamespace    communication/socket                                               \nauthor       moritz.raabe@mandiant.com, joakim@intezer.com,                     \n             mrhafizfarhad@gmail.com                                            \nscope        basic block                                                        \ndescription  Detects socket connection attempts using common APIs or ConnectEx  \n             setup.                                                             \nbasic block @ 0x40539F in function 0x405310\n  or:\n    api: connect @ 0x4053A7\n\nget socket status (2 matches)\nnamespace  communication/socket                                              \nauthor     michael.hunhoff@mandiant.com                                      \nscope      function                                                          \natt&ck     Discovery::System Network Configuration Discovery [T1016]         \nmbc        Communication::Socket Communication::Get Socket Status [C0001.012]\nfunction @ 0x405310\n  or:\n    api: select @ 0x4053D5\nfunction @ 0x4054E0\n  or:\n    api: select @ 0x40551C\n\nset socket configuration (3 matches)\nnamespace  communication/socket                                              \nauthor     michael.hunhoff@mandiant.com                                      \nscope      function                                                          \nmbc        Communication::Socket Communication::Set Socket Config [C0001.001]\nfunction @ 0x405310\n  or:\n    api: ioctlsocket @ 0x405398, 0x4053F2\nfunction @ 0x405470\n  or:\n    api: setsockopt @ 0x4054A3\nfunction @ 0x4054E0\n  or:\n    api: ioctlsocket @ 0x405536\n\nreceive data on socket\nnamespace  communication/socket/receive                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Receive Data [C0001.006]        \nfunction @ 0x405600\n  or:\n    api: recv @ 0x405662\n\nsend data on socket (2 matches)\nnamespace  communication/socket/send                                            \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Communication::Socket Communication::Send Data [C0001.007]           \nfunction @ 0x405470\n  or:\n    api: send @ 0x4054B3\nfunction @ 0x405560\n  or:\n    api: send @ 0x4055BC\n\nconnect TCP socket\nnamespace  communication/socket/tcp                                             \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           mrhafizfarhad@gmail.com                                              \nscope      function                                                             \nmbc        Communication::Socket Communication::Connect Socket [C0001.004]      \nfunction @ 0x405310\n  and:\n    match: create TCP socket @ 0x405359\n      or:\n        and:\n          or:\n            number: 0x0 = protocol (default) @ 0x40536B\n          number: 0x1 = SOCK_STREAM @ 0x40536D\n          number: 0x2 = AF_INET @ 0x40535A, 0x40536F\n          or:\n            api: socket @ 0x405376\n    match: connect socket @ 0x40539F\n      or:\n        api: connect @ 0x4053A7\n\ncreate TCP socket\nnamespace   communication/socket/tcp                                            \nauthor      william.ballenthin@mandiant.com, joakim@intezer.com,                \n            anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com       \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create TCP Socket [C0001.011]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ 0x405359 in function 0x405310\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ 0x40536B\n      number: 0x1 = SOCK_STREAM @ 0x40536D\n      number: 0x2 = AF_INET @ 0x40535A, 0x40536F\n      or:\n        api: socket @ 0x405376\n\nconnect UDP socket\nnamespace    communication/socket/udp                                           \nauthor       mrhafizfarhad@gmail.com                                            \nscope        function                                                           \nmbc          Communication::Socket Communication::UDP Client [C0001.013]        \ndescription  Detects UDP socket connections by combining UDP socket creation    \n             with connection attempts.                                          \nfunction @ 0x405310\n  and:\n    match: create UDP socket @ 0x405359\n      or:\n        and:\n          number: 0x2 = AF_INET @ 0x40535A, 0x40536F\n          or:\n            number: 0x0 = protocol (default) @ 0x40536B\n          or:\n            api: socket @ 0x405376\n    match: connect socket @ 0x40539F\n      or:\n        api: connect @ 0x4053A7\n\ncreate UDP socket\nnamespace   communication/socket/udp/send                                       \nauthor      moritz.raabe@mandiant.com, joakim@intezer.com,                      \n            michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create UDP Socket [C0001.010]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ 0x405359 in function 0x405310\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x40535A, 0x40536F\n      or:\n        number: 0x0 = protocol (default) @ 0x40536B\n      or:\n        api: socket @ 0x405376\n\nact as TCP client\nnamespace  communication/tcp/client                                     \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                                     \nmbc        Communication::Socket Communication::TCP Client [C0001.008]  \nfunction @ 0x405310\n  or:\n    match: connect TCP socket @ 0x405310\n      and:\n        match: create TCP socket @ 0x405359\n          or:\n            and:\n              or:\n                number: 0x0 = protocol (default) @ 0x40536B\n              number: 0x1 = SOCK_STREAM @ 0x40536D\n              number: 0x2 = AF_INET @ 0x40535A, 0x40536F\n              or:\n                api: socket @ 0x405376\n        match: connect socket @ 0x40539F\n          or:\n            api: connect @ 0x4053A7\n\nencode data using XOR (3 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x4011F5 in function 0x401130\n  and:\n    characteristic: tight loop @ 0x4011F5\n    characteristic: nzxor @ 0x4011FC\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4012C6 in function 0x401130\n  and:\n    characteristic: tight loop @ 0x4012C6\n    characteristic: nzxor @ 0x4012CD\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405060 in function 0x404F00\n  and:\n    characteristic: tight loop @ 0x405060\n    characteristic: nzxor @ 0x40506C\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nget common file path\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x403FF0\n  or:\n    api: SHGetSpecialFolderPath @ 0x404053, 0x404065\n\ncheck if file exists\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x407314\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x407318\n        instruction:\n          and:\n            mnemonic: cmp @ 0x40731E\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x40731E\n\nget file attributes\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x407314 in function 0x407314\n  or:\n    api: GetFileAttributes @ 0x407318\n\nmove file\nnamespace  host-interaction/file-system/move                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Move File [C0063]                         \nfunction @ 0x403FF0\n  or:\n    api: MoveFile @ 0x4040AC\n\nget disk information\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ 0x402870\n  or:\n    api: GetDriveType @ 0x4028D6\n\nget hostname\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ 0x402370\n  or:\n    api: GetComputerName @ 0x402427\n\nlink function at runtime on Windows\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x4041AE\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4041AE\n\nresolve function by parsing PE exports\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x403640\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x403640\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x40373D\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x4036F1\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x4036C2, 0x403A29, 0x403A4A\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x403721, 0x40389A\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x4036A9, 0x4038AA\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x4036A3, 0x403A42, 0x403A55\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x40382D, 0x403895\n\nget startup folder (2 matches)\nnamespace  persistence/startup-folder                                           \nauthor     matthew.williams@mandiant.com                                        \nscope      basic block                                                          \natt&ck     Persistence::Boot or Logon Autostart Execution::Registry Run Keys /  \n           Startup Folder [T1547.001]                                           \nbasic block @ 0x403FF0 in function 0x403FF0\n  and:\n    or:\n      number: 0x7 = CSIDL_STARTUP @ 0x40403C\n    or:\n      api: SHGetSpecialFolderPath @ 0x404053\nbasic block @ 0x404059 in function 0x403FF0\n  and:\n    or:\n      number: 0x18 = CSIDL_COMMON_STARTUP @ 0x404061\n    or:\n      api: SHGetSpecialFolderPath @ 0x404065\n\nwrite file to startup folder\nnamespace  persistence/startup-folder                                           \nauthor     matthew.williams@mandiant.com, j.j.vannielen@utwente.nl              \nscope      function                                                             \natt&ck     Persistence::Boot or Logon Autostart Execution::Registry Run Keys /  \n           Startup Folder [T1547.001]                                           \nfunction @ 0x403FF0\n  or:\n    and:\n      match: get startup folder @ 0x403FF0, 0x404059\n        and:\n          or:\n            number: 0x7 = CSIDL_STARTUP @ 0x40403C\n          or:\n            api: SHGetSpecialFolderPath @ 0x404053\n        and:\n          or:\n            number: 0x18 = CSIDL_COMMON_STARTUP @ 0x404061\n          or:\n            api: SHGetSpecialFolderPath @ 0x404065\n      or:\n        match: move file @ 0x403FF0\n          or:\n            api: MoveFile @ 0x4040AC\n\n\n\n"},"hashes":{"md5":"e904bf93403c0fb08b9683a9e858c73e","sha1":"8397c1e1f0b9d53a114850f6b3ae8c1f2b2d1590","sha256":"4c2efe2f1253b94f16a1cab032f36c7883e4f6c8d9fc17d0ee553b5afb16330c"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 99</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 7466</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Trojan.\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"e904bf93403c0fb08b9683a9e858c73e\",\n        \"sha256\": \"4c2efe2f1253b94f16a1cab032f36c7883e4f6c8d9fc17d0ee553b5\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_library_rule_\",\n      \"label\": \"library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Modulo [C0058]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_loop__32_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (32 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401040\",\n      \"label\": \"Function 0x401040\",\n      \"type\": \"function\",\n      \"address\": \"0x401040\"\n    },\n    {\n      \"id\": \"cap_contain_obfuscated_stackstrings\",\n      \"label\": \"contain obfuscated stackstrings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x405EE3\",\n      \"label\": \"Block 0x405EE3\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x405EE3\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_data\",\n      \"label\": \"receive data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405600\",\n      \"label\": \"Function 0x405600\",\n      \"type\": \"function\",\n      \"address\": \"0x405600\"\n    },\n    {\n      \"id\": \"api_recv\",\n      \"label\": \"recv\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data__2_matches_\",\n      \"label\": \"send data (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405470\",\n      \"label\": \"Function 0x405470\",\n      \"type\": \"function\",\n      \"address\": \"0x405470\"\n    },\n    {\n      \"id\": \"func_0x405560\",\n      \"label\": \"Function 0x405560\",\n      \"type\": \"function\",\n      \"address\": \"0x405560\"\n    },\n    {\n      \"id\": \"api_send\",\n      \"label\": \"send\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_socket\",\n      \"label\": \"connect socket\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x40539F\",\n      \"label\": \"Block 0x40539F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40539F\"\n    },\n    {\n      \"id\": \"api_connect\",\n      \"label\": \"connect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_mrhafizfarhad_gmail_com\",\n      \"label\": \"mrhafizfarhad@gmail.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_socket_status__2_matches_\",\n      \"label\": \"get socket status (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Get Socket Status [C0001.012]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405310\",\n      \"label\": \"Function 0x405310\",\n      \"type\": \"function\",\n      \"address\": \"0x405310\"\n    },\n    {\n      \"id\": \"func_0x4054E0\",\n      \"label\": \"Function 0x4054E0\",\n      \"type\": \"function\",\n      \"address\": \"0x4054E0\"\n    },\n    {\n      \"id\": \"api_select\",\n      \"label\": \"select\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Get Socket Status [C0001.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_socket_configuration__3_matches_\",\n      \"label\": \"set socket configuration (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Set Socket Config [C0001.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_setsockopt\",\n      \"label\": \"setsockopt\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_ioctlsocket\",\n      \"label\": \"ioctlsocket\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_receive_data_on_socket\",\n      \"label\": \"receive data on socket\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Receive Data [C0001.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Receive Data [C0001.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data_on_socket__2_matches_\",\n      \"label\": \"send data on socket (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_tcp_socket\",\n      \"label\": \"connect TCP socket\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Connect Socket [C0001.004]\"\n      ]\n    },\n    {\n      \"id\": \"api_socket\",\n      \"label\": \"socket\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_tcp_socket\",\n      \"label\": \"create TCP socket\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x405359\",\n      \"label\": \"Block 0x405359\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x405359\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_udp_socket\",\n      \"label\": \"connect UDP socket\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::UDP Client [C0001.013]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______mrhafizfarhad_gmail_com\",\n      \"label\": \"author       mrhafizfarhad@gmail.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::UDP Client [C0001.013]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_udp_socket\",\n      \"label\": \"create UDP socket\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create UDP Socket [C0001.010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_act_as_tcp_client\",\n      \"label\": \"act as TCP client\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path\",\n      \"label\": \"get common file path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x403FF0\",\n      \"label\": \"Function 0x403FF0\",\n      \"type\": \"function\",\n      \"address\": \"0x403FF0\"\n    },\n    {\n      \"id\": \"api_SHGetSpecialFolderPath\",\n      \"label\": \"SHGetSpecialFolderPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists\",\n      \"label\": \"check if file exists\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407314\",\n      \"label\": \"Function 0x407314\",\n      \"type\": \"function\",\n      \"address\": \"0x407314\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes\",\n      \"label\": \"get file attributes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x407314\",\n      \"label\": \"Block 0x407314\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x407314\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_move_file\",\n      \"label\": \"move file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"api_MoveFile\",\n      \"label\": \"MoveFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_information\",\n      \"label\": \"get disk information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402870\",\n      \"label\": \"Function 0x402870\",\n      \"type\": \"function\",\n      \"address\": \"0x402870\"\n    },\n    {\n      \"id\": \"api_GetDriveType\",\n      \"label\": \"GetDriveType\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_hostname\",\n      \"label\": \"get hostname\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402370\",\n      \"label\": \"Function 0x402370\",\n      \"type\": \"function\",\n      \"address\": \"0x402370\"\n    },\n    {\n      \"id\": \"api_GetComputerName\",\n      \"label\": \"GetComputerName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows\",\n      \"label\": \"link function at runtime on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"label\": \"resolve function by parsing PE exports\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x403640\",\n      \"label\": \"Function 0x403640\",\n      \"type\": \"function\",\n      \"address\": \"0x403640\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_startup_folder__2_matches_\",\n      \"label\": \"get startup folder (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Registry Run Keys /\",\n        \"Startup Folder [T1547.001]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x404059\",\n      \"label\": \"Block 0x404059\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x404059\"\n    },\n    {\n      \"id\": \"bb_0x403FF0\",\n      \"label\": \"Block 0x403FF0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x403FF0\"\n    },\n    {\n      \"id\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"label\": \"author     matthew.williams@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Registry Run Keys /\",\n        \"Startup Folder [T1547.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_to_startup_folder\",\n      \"label\": \"write file to startup folder\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Registry Run Keys /\",\n        \"Startup Folder [T1547.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____matthew_williams_mandiant_com__j_j_vannielen_utwente_nl\",\n      \"label\": \"author     matthew.williams@mandiant.com, j.j.vannielen@utwente.nl\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Registry Run Keys /\",\n        \"Startup Folder [T1547.001]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__32_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__32_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401040\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_obfuscated_stackstrings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings\",\n      \"target\": \"bb_0x405EE3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x405EE3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data\",\n      \"target\": \"func_0x405600\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405600\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x405600\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405600\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data__2_matches_\",\n      \"target\": \"func_0x405470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__2_matches_\",\n      \"target\": \"func_0x405560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405470\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405560\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x405470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x405560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405470\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405560\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_socket\",\n      \"target\": \"bb_0x40539F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mrhafizfarhad_gmail_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x40539F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_socket_status__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_socket_status__2_matches_\",\n      \"target\": \"func_0x405310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_socket_status__2_matches_\",\n      \"target\": \"func_0x4054E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_select\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4054E0\",\n      \"target\": \"api_select\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4054E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_select\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4054E0\",\n      \"target\": \"api_select\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_socket_configuration__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__3_matches_\",\n      \"target\": \"func_0x405310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__3_matches_\",\n      \"target\": \"func_0x4054E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__3_matches_\",\n      \"target\": \"func_0x405470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4054E0\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405470\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4054E0\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405470\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4054E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4054E0\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405470\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4054E0\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405470\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data_on_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket\",\n      \"target\": \"func_0x405600\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405600\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405600\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405600\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data_on_socket__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__2_matches_\",\n      \"target\": \"func_0x405470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__2_matches_\",\n      \"target\": \"func_0x405560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405470\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405560\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405470\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405560\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_tcp_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_tcp_socket\",\n      \"target\": \"func_0x405310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x405310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_tcp_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket\",\n      \"target\": \"bb_0x405359\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x405359\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_udp_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_udp_socket\",\n      \"target\": \"func_0x405310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______mrhafizfarhad_gmail_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x405310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_udp_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket\",\n      \"target\": \"bb_0x405359\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x405359\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_act_as_tcp_client\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_act_as_tcp_client\",\n      \"target\": \"func_0x405310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405310\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path\",\n      \"target\": \"func_0x403FF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403FF0\",\n      \"target\": \"api_SHGetSpecialFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403FF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403FF0\",\n      \"target\": \"api_SHGetSpecialFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists\",\n      \"target\": \"func_0x407314\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407314\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407314\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407314\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes\",\n      \"target\": \"bb_0x407314\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x407314\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_move_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_move_file\",\n      \"target\": \"func_0x403FF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403FF0\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403FF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403FF0\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information\",\n      \"target\": \"func_0x402870\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402870\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402870\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402870\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_hostname\",\n      \"target\": \"func_0x402370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402370\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402370\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"target\": \"func_0x403640\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x403640\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_startup_folder__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_startup_folder__2_matches_\",\n      \"target\": \"bb_0x404059\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_startup_folder__2_matches_\",\n      \"target\": \"bb_0x403FF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"target\": \"bb_0x404059\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"target\": \"bb_0x403FF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_to_startup_folder\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_to_startup_folder\",\n      \"target\": \"func_0x403FF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403FF0\",\n      \"target\": \"api_SHGetSpecialFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403FF0\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____matthew_williams_mandiant_com__j_j_vannielen_utwente_nl\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____matthew_williams_mandiant_com__j_j_vannielen_utwente_nl\",\n      \"target\": \"func_0x403FF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403FF0\",\n      \"target\": \"api_SHGetSpecialFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403FF0\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 22:10:35.308148\",\n    \"total_functions\": \"99\",\n    \"total_features\": \"7466\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 22:10:36"}
{"_id":{"$oid":"6a4fd06c0108394cb24cdcf6"},"sha256":"6f201afc797370ac6e33fafec41a794a2eb44c1bfd7d9079e3633ebe7bbb41e1","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_hz7xl_bz/001_binwalk_15CB4.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_hz7xl_bz/001_binwalk_15CB4.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_hz7xl_bz/001_binwalk_15CB4.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ c11324b04408d615e59d129f8a6be3ba                                  │\n│ sha1     │ 9b25415c7a87f0238fc9fe7294028c0c9eee763c                          │\n│ sha256   │ f8e4ad3492797ba03edb9529e28e51063d726efa5816fa2f539a7fe2033d4ae3  │\n│ analysis │ static                                                            │\n│ os       │ any                                                               │\n│ format   │ dotnet                                                            │\n│ arch     │ i386                                                              │\n│ path     │ /tmp/sdm_unpack_b40dyd59/Trojan.Bladabindi-019f46cb18407410b79f3… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Archive Collected Data::Archive via Library           │\n│                      │ [T1560.002]                                           │\n│                      │ Input Capture::Keylogging [T1056.001]                 │\n│                      │ Screen Capture [T1113]                                │\n│ DEFENSE EVASION      │ Deobfuscate/Decode Files or Information [T1140]       │\n│                      │ Indicator Removal::File Deletion [T1070.004]          │\n│                      │ Modify Registry [T1112]                               │\n│                      │ Obfuscated Files or Information [T1027]               │\n│                      │ Reflective Code Loading [T1620]                       │\n│ DISCOVERY            │ Account Discovery [T1087]                             │\n│                      │ File and Directory Discovery [T1083]                  │\n│                      │ Process Discovery [T1057]                             │\n│                      │ Query Registry [T1012]                                │\n│                      │ Software Discovery [T1518]                            │\n│                      │ System Information Discovery [T1082]                  │\n│                      │ System Location Discovery::System Language Discovery  │\n│                      │ [T1614.001]                                           │\n│                      │ System Owner/User Discovery [T1033]                   │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MAEC Category                                    ┃ MAEC Value                ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ malware-category                                 │ downloader                │\n│                                                  │ launcher                  │\n└──────────────────────────────────────────────────┴───────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Keylogging::Polling [F0002.002]                       │\n│                      │ Screen Capture::WinAPI [E1113.m01]                    │\n│ COMMAND AND CONTROL  │ C2 Communication::Receive Data [B0030.002]            │\n│                      │ C2 Communication::Send Data [B0030.001]               │\n│ COMMUNICATION        │ HTTP Communication::Get Response [C0002.017]          │\n│                      │ Socket Communication::Create TCP Socket [C0001.011]   │\n│                      │ Socket Communication::Receive Data [C0001.006]        │\n│                      │ Socket Communication::Send Data [C0001.007]           │\n│                      │ Socket Communication::TCP Client [C0001.008]          │\n│ CRYPTOGRAPHY         │ Cryptographic Hash::MD5 [C0029.001]                   │\n│                      │ Generate Pseudo-random Sequence::Use API [C0021.003]  │\n│ DATA                 │ Compress Data [C0024]                                 │\n│                      │ Decode Data::Base64 [C0053.001]                       │\n│                      │ Encode Data::Base64 [C0026.001]                       │\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Encoding-Standard    │\n│                      │ Algorithm [E1027.m02]                                 │\n│                      │ Self Deletion::COMSPEC Environment Variable           │\n│                      │ [F0007.001]                                           │\n│ DISCOVERY            │ Application Window Discovery [E1010]                  │\n│                      │ File and Directory Discovery [E1083]                  │\n│                      │ System Information Discovery [E1082]                  │\n│ FILE SYSTEM          │ Copy File [C0045]                                     │\n│                      │ Delete File [C0047]                                   │\n│                      │ Read File [C0051]                                     │\n│                      │ Writes File [C0052]                                   │\n│ OPERATING SYSTEM     │ Environment Variable::Set Variable [C0034.001]        │\n│                      │ Registry::Delete Registry Key [C0036.002]             │\n│                      │ Registry::Delete Registry Value [C0036.007]           │\n│                      │ Registry::Query Registry Key [C0036.005]              │\n│                      │ Registry::Query Registry Value [C0036.006]            │\n│                      │ Registry::Set Registry Key [C0036.001]                │\n│ PROCESS              │ Create Mutex [C0042]                                  │\n│                      │ Create Process [C0017]                                │\n│                      │ Create Thread [C0038]                                 │\n│                      │ Suspend Thread [C0055]                                │\n│                      │ Terminate Process [C0018]                             │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ self delete (2 matches)               │ anti-analysis/anti-forensic/self-de… │\n│ save image in .NET                    │ collection                           │\n│ log keystrokes                        │ collection/keylog                    │\n│ log keystrokes via polling (2         │ collection/keylog                    │\n│ matches)                              │                                      │\n│ capture screenshot                    │ collection/screenshot                │\n│ send data                             │ communication                        │\n│ receive and write data from server to │ communication/c2/file-transfer       │\n│ client                                │                                      │\n│ act as TCP client                     │ communication/tcp/client             │\n│ compress data using GZip in .NET      │ data-manipulation/compression        │\n│ decode data using Base64 in .NET (2   │ data-manipulation/encoding/base64    │\n│ matches)                              │                                      │\n│ encode data using Base64 (2 matches)  │ data-manipulation/encoding/base64    │\n│ hash data with MD5                    │ data-manipulation/hashing/md5        │\n│ generate random numbers in .NET       │ data-manipulation/prng               │\n│ set environment variable              │ host-interaction/environment-variab… │\n│ get common file path (3 matches)      │ host-interaction/file-system         │\n│ copy file                             │ host-interaction/file-system/copy    │\n│ delete file (3 matches)               │ host-interaction/file-system/delete  │\n│ check if file exists (2 matches)      │ host-interaction/file-system/exists  │\n│ get file version info                 │ host-interaction/file-system/meta    │\n│ read file on Windows                  │ host-interaction/file-system/read    │\n│ write file on Windows (2 matches)     │ host-interaction/file-system/write   │\n│ get graphical window text             │ host-interaction/gui/window/get-text │\n│ get keyboard layout                   │ host-interaction/hardware/keyboard   │\n│ get disk information                  │ host-interaction/hardware/storage    │\n│ create or open mutex on Windows (2    │ host-interaction/mutex               │\n│ matches)                              │                                      │\n│ get hostname                          │ host-interaction/os/hostname         │\n│ get OS version in .NET                │ host-interaction/os/version          │\n│ get process image filename            │ host-interaction/process             │\n│ create a process with modified I/O    │ host-interaction/process/create      │\n│ handles and window                    │                                      │\n│ create process on Windows (2 matches) │ host-interaction/process/create      │\n│ enumerate processes                   │ host-interaction/process/list        │\n│ find process by PID (4 matches)       │ host-interaction/process/list        │\n│ terminate process (3 matches)         │ host-interaction/process/terminate   │\n│ query or enumerate registry key (7    │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ query or enumerate registry value (4  │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ set registry value (5 matches)        │ host-interaction/registry/create     │\n│ delete registry key (2 matches)       │ host-interaction/registry/delete     │\n│ delete registry value (3 matches)     │ host-interaction/registry/delete     │\n│ get session user name                 │ host-interaction/session             │\n│ create thread (3 matches)             │ host-interaction/thread/create       │\n│ suspend thread (6 matches)            │ host-interaction/thread/suspend      │\n│ load .NET assembly                    │ load-code/dotnet                     │\n│ unmanaged call (8 matches)            │ runtime                              │\n│ compiled to the .NET platform         │ runtime/dotnet                       │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     c11324b04408d615e59d129f8a6be3ba                        \nsha1                    9b25415c7a87f0238fc9fe7294028c0c9eee763c                \nsha256                  f8e4ad3492797ba03edb9529e28e51063d726efa5816fa2f539a7fe…\npath                    /tmp/sdm_unpack_b40dyd59/Trojan.Bladabindi-019f46cb1840…\ntimestamp               2026-07-09 22:16:34.914928                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEI2n3Cqz/rules                                   \nfunction count          43                                                      \nlibrary function count  0                                                       \ntotal feature count     2703                                                    \n\nself delete (2 matches)\nnamespace  anti-analysis/anti-forensic/self-deletion\nscope      function                                 \nmatches    token(0x6000005)                         \n           token(0x6000005)                         \n\nsave image in .NET\nnamespace  collection      \nscope      function        \nmatches    token(0x6000005)\n\nlog keystrokes\nnamespace  collection/keylog\nscope      function         \nmatches    token(0x6000032) \n\nlog keystrokes via polling (2 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    token(0x6000032) \n           token(0x6000036) \n\ncapture screenshot\nnamespace  collection/screenshot\nscope      function             \nmatches    token(0x6000005)     \n\nreceive data (2 matches)\nnamespace    communication                                                     \ndescription  all known techniques for receiving data from a potential C2 server\nscope        function                                                          \nmatches      token(0x6000005)                                                  \n             token(0x6000011)                                                  \n\nsend data\nnamespace    communication                                                 \ndescription  all known techniques for sending data to a potential C2 server\nscope        function                                                      \nmatches      token(0x6000001)                                              \n\nreceive and write data from server to client\nnamespace  communication/c2/file-transfer\nscope      function                      \nmatches    token(0x6000005)              \n\nread data from Internet\nnamespace  communication/http/client\nscope      function                 \nmatches    token(0x6000005)         \n\nreceive data on socket\nnamespace  communication/socket/receive\nscope      function                    \nmatches    token(0x6000011)            \n\nsend data on socket\nnamespace  communication/socket/send\nscope      function                 \nmatches    token(0x6000001)         \n\ncreate TCP socket (3 matches)\nnamespace  communication/socket/tcp\nscope      basic block             \nmatches    token(0x6000001)        \n           token(0x600000B)        \n           token(0x6000011)        \n\nact as TCP client\nnamespace  communication/tcp/client\nscope      function                \nmatches    token(0x600000B)        \n\ncompress data using GZip in .NET\nnamespace  data-manipulation/compression\nscope      function                     \nmatches    token(0x6000012)             \n\ndecode data using Base64 in .NET (2 matches)\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    token(0x6000005)                 \n           token(0x6000018)                 \n\nencode data using Base64 (2 matches)\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    token(0x6000005)                 \n           token(0x6000019)                 \n\nhash data with MD5\nnamespace  data-manipulation/hashing/md5\nscope      function                     \nmatches    token(0x6000004)             \n\ngenerate random numbers in .NET\nnamespace  data-manipulation/prng\nscope      function              \nmatches    token(0x6000017)      \n\nset environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    token(0x6000009)                     \n\nget common file path (3 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x6000009)            \n           token(0x6000016)            \n           token(0x600001C)            \n\ncopy file\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    token(0x6000009)                 \n\ndelete file (3 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    token(0x6000005)                   \n           token(0x6000009)                   \n           token(0x6000016)                   \n\ncheck if file exists (2 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x6000005)                   \n           token(0x6000009)                   \n\nget file version info\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    token(0x6000005)                 \n\nread file on Windows\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    token(0x6000036)                 \n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    token(0x6000005)                  \n           token(0x6000036)                  \n\nget graphical window text\nnamespace  host-interaction/gui/window/get-text\nscope      function                            \nmatches    token(0x600000F)                    \n\nget keyboard layout\nnamespace  host-interaction/hardware/keyboard\nscope      function                          \nmatches    token(0x6000032)                  \n\nget disk information\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    token(0x600000E)                 \n\ncreate or open mutex on Windows (2 matches)\nnamespace  host-interaction/mutex\nscope      instruction           \nmatches    token(0x6000039)+0xDC \n           token(0x6000039)+0xFC \n\nget hostname\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    token(0x600001C)            \n\nget OS version in .NET\nnamespace  host-interaction/os/version\nscope      basic block                \nmatches    token(0x600001C)           \n\nget process image filename\nnamespace  host-interaction/process\nscope      basic block             \nmatches    token(0x6000005)        \n\ncreate a process with modified I/O handles and window\nnamespace  host-interaction/process/create\nscope      function                       \nmatches    token(0x6000005)               \n\ncreate process on Windows (2 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    token(0x6000005)               \n           token(0x6000009)               \n\nenumerate processes\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    token(0x6000005)             \n\nfind process by PID (4 matches)\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    token(0x6000005)             \n           token(0x600000F)             \n           token(0x600002E)             \n           token(0x6000039)             \n\nterminate process (3 matches)\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    token(0x6000005)                  \n           token(0x600000B)                  \n           token(0x6000039)                  \n\nquery or enumerate registry key (7 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    token(0x6000003)         \n           token(0x6000005)         \n           token(0x6000009)         \n           token(0x6000016)         \n           token(0x600001E)         \n           token(0x600001F)         \n           token(0x6000039)         \n\nquery or enumerate registry value (4 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    token(0x6000005)         \n           token(0x600001C)         \n           token(0x600001E)         \n           token(0x6000039)         \n\nset registry value (5 matches)\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    token(0x6000005)                \n           token(0x6000005)                \n           token(0x6000009)                \n           token(0x600001D)                \n           token(0x6000039)                \n\ndelete registry key (2 matches)\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    token(0x6000005)                \n           token(0x6000016)                \n\ndelete registry value (3 matches)\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    token(0x6000005)                \n           token(0x6000016)                \n           token(0x600001F)                \n\nget session user name\nnamespace  host-interaction/session\nscope      function                \nmatches    token(0x600001C)        \n\ncreate thread (3 matches)\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    token(0x6000005)              \n           token(0x6000011)              \n           token(0x6000039)              \n\nsuspend thread (6 matches)\nnamespace  host-interaction/thread/suspend\nscope      basic block                    \nmatches    token(0x6000005)               \n           token(0x6000009)               \n           token(0x600000B)               \n           token(0x6000011)               \n           token(0x6000036)               \n           token(0x6000039)               \n\nload .NET assembly\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x600000D)\n\nunmanaged call (8 matches)\nnamespace    runtime                                                       \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nscope        function                                                      \nmatches      token(0x6000002)                                              \n             token(0x600000E)                                              \n             token(0x600000F)                                              \n             token(0x6000010)                                              \n             token(0x600002E)                                              \n             token(0x6000032)                                              \n             token(0x6000036)                                              \n             token(0x6000039)                                              \n\ncompiled to the .NET platform\nnamespace  runtime/dotnet\nscope      file          \n\n\n\n","very_verbose":"md5                     c11324b04408d615e59d129f8a6be3ba                        \nsha1                    9b25415c7a87f0238fc9fe7294028c0c9eee763c                \nsha256                  f8e4ad3492797ba03edb9529e28e51063d726efa5816fa2f539a7fe…\npath                    /tmp/sdm_unpack_b40dyd59/Trojan.Bladabindi-019f46cb1840…\ntimestamp               2026-07-09 22:16:36.132667                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIyL1bAf/rules                                   \nfunction count          43                                                      \nlibrary function count  0                                                       \ntotal feature count     2703                                                    \n\ncreate or open registry key (9 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ token(0x6000003) in function token(0x6000003)\n  or:\n    api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000003)+0x57, token(0x6000003)+0xB4, token(0x6000003)+0x111, \ntoken(0x6000003)+0x16E\n\nself delete (2 matches)\nnamespace  anti-analysis/anti-forensic/self-deletion                            \nauthor     michael.hunhoff@mandiant.com, @mr-tz                                 \nscope      function                                                             \natt&ck     Defense Evasion::Indicator Removal::File Deletion [T1070.004]        \nmbc        Defense Evasion::Self Deletion::COMSPEC Environment Variable         \n           [F0007.001]                                                          \nfunction @ token(0x6000005)\n  and:\n    or:\n      string: \"cmd.exe\" @ token(0x6000005)+0x857\n      match: host-interaction/process/create @ token(0x6000005)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x6000005)+0x72E, token(0x6000005)+0x8EE, token(0x6000005)+0xCB0, \ntoken(0x6000005)+0x12D2, and 1 more...\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x6000005)+0x72E, token(0x6000005)+0x8EE, token(0x6000005)+0xCB0, \ntoken(0x6000005)+0x12D2, and 1 more...\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000005)+0x8AE\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000005)+0x8CE\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000005)+0x85C\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000005)+0x8BE\n              property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x6000005)+0x828\n              property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardInput @ token(0x6000005)+0x838\n              property/read: System.Diagnostics.Process::StandardInput @ token(0x6000005)+0x922\n    or:\n      regex: /(^|[\\&;\\|]\\s*)del(\\s.*)?/i\n        - \"Deleted \" @ token(0x6000005)+0x5C1\nfunction @ token(0x6000005)\n  and:\n    or:\n      string: \"cmd.exe\" @ token(0x6000005)+0x857\n      match: host-interaction/process/create @ token(0x6000005)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x6000005)+0x72E, token(0x6000005)+0x8EE, token(0x6000005)+0xCB0, \ntoken(0x6000005)+0x12D2, and 1 more...\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x6000005)+0x72E, token(0x6000005)+0x8EE, token(0x6000005)+0xCB0, \ntoken(0x6000005)+0x12D2, and 1 more...\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000005)+0x8AE\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000005)+0x8CE\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000005)+0x85C\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000005)+0x8BE\n              property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x6000005)+0x828\n              property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardInput @ token(0x6000005)+0x838\n              property/read: System.Diagnostics.Process::StandardInput @ token(0x6000005)+0x922\n    or:\n      regex: /(^|[\\&;\\|]\\s*)del(\\s.*)?/i\n        - \"Deleted \" @ token(0x6000005)+0x5C1\n\nsave image in .NET\nnamespace  collection                  \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x6000005)\n  and:\n    api: System.Drawing.Image::Save @ token(0x6000005)+0x11CE\n    optional:\n      class: System.Drawing.Imaging.ImageFormat @ token(0x6000005)+0x11C9\n\nlog keystrokes\nnamespace  collection/keylog                                \nauthor     moritz.raabe@mandiant.com                        \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nfunction @ token(0x6000032)\n  or:\n    api: MapVirtualKey @ token(0x6000032)+0x26\n\nlog keystrokes via polling (2 matches)\nnamespace  collection/keylog                                \nauthor     michael.hunhoff@mandiant.com                     \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nmbc        Collection::Keylogging::Polling [F0002.002]      \nfunction @ token(0x6000032)\n  or:\n    api: GetKeyboardState @ token(0x6000032)+0x13\nfunction @ token(0x6000036)\n  or:\n    api: GetAsyncKeyState @ token(0x6000036)+0x2A\n\ncapture screenshot\nnamespace  collection/screenshot                                            \nauthor     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\nscope      function                                                         \natt&ck     Collection::Screen Capture [T1113]                               \nmbc        Collection::Screen Capture::WinAPI [E1113.m01]                   \nfunction @ token(0x6000005)\n  or:\n    api: System.Drawing.Graphics::CopyFromScreen @ token(0x6000005)+0x1135\n\nreceive data (2 matches)\nnamespace    communication                                                     \nauthor       william.ballenthin@mandiant.com                                   \nscope        function                                                          \nmbc          Command and Control::C2 Communication::Receive Data [B0030.002]   \ndescription  all known techniques for receiving data from a potential C2 server\nfunction @ token(0x6000005)\n  or:\n    match: read data from Internet @ token(0x6000005)\n      and:\n        or:\n          api: System.Net.WebClient::DownloadData @ token(0x6000005)+0xC17, token(0x6000005)+0x1368\nfunction @ token(0x6000011)\n  or:\n    match: receive data on socket @ token(0x6000011)\n      or:\n        api: System.Net.Sockets.Socket::Receive @ token(0x6000011)+0x5F\n\nsend data\nnamespace    communication                                                 \nauthor       william.ballenthin@mandiant.com, joakim@intezer.com           \nscope        function                                                      \nmbc          Command and Control::C2 Communication::Send Data [B0030.001]  \ndescription  all known techniques for sending data to a potential C2 server\nfunction @ token(0x6000001)\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ token(0x6000001)\n          or:\n            api: System.Net.Sockets.Socket::Send @ token(0x6000001)+0x6A\n    and:\n      os: linux\n      or:\n        match: create TCP socket @ token(0x6000001)\n          or:\n            property/read: System.Net.Sockets.TcpClient::Client @ token(0x6000001)+0x56\n      or:\n        match: send data on socket @ token(0x6000001)\n          or:\n            api: System.Net.Sockets.Socket::Send @ token(0x6000001)+0x6A\n\ndownload and write a file\nnamespace              communication/c2/file-transfer                           \nmaec/malware-category  downloader                                               \nauthor                 moritz.raabe@mandiant.com                                \nscope                  function                                                 \natt&ck                 Command and Control::Ingress Tool Transfer [T1105]       \nmbc                    Command and Control::C2 Communication::Server to Client  \n                       File Transfer [B0030.003]                                \nfunction @ token(0x6000005)\n  and:\n    match: receive data @ token(0x6000005)\n      or:\n        match: read data from Internet @ token(0x6000005)\n          and:\n            or:\n              api: System.Net.WebClient::DownloadData @ token(0x6000005)+0xC17, token(0x6000005)+0x1368\n    match: host-interaction/file-system/write @ token(0x6000005)\n      or:\n        api: System.IO.File::WriteAllBytes @ token(0x6000005)+0xCA9, token(0x6000005)+0x13F7\n\nreceive and write data from server to client\nnamespace  communication/c2/file-transfer \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ token(0x6000005)\n  and:\n    match: receive data @ token(0x6000005)\n      or:\n        match: read data from Internet @ token(0x6000005)\n          and:\n            or:\n              api: System.Net.WebClient::DownloadData @ token(0x6000005)+0xC17, token(0x6000005)+0x1368\n    match: host-interaction/file-system/write @ token(0x6000005)\n      or:\n        api: System.IO.File::WriteAllBytes @ token(0x6000005)+0xCA9, token(0x6000005)+0x13F7\n\nwrite and execute a file\nnamespace              communication/c2/file-transfer               \nmaec/malware-category  launcher                                     \nauthor                 moritz.raabe@mandiant.com                    \nscope                  function                                     \nmbc                    Execution::Install Additional Program [B0023]\nfunction @ token(0x6000005)\n  and:\n    match: host-interaction/file-system/write @ token(0x6000005)\n      or:\n        api: System.IO.File::WriteAllBytes @ token(0x6000005)+0xCA9, token(0x6000005)+0x13F7\n    match: host-interaction/process/create @ token(0x6000005)\n      or:\n        api: System.Diagnostics.Process::Start @ token(0x6000005)+0x72E, token(0x6000005)+0x8EE, token(0x6000005)+0xCB0, \ntoken(0x6000005)+0x12D2, and 1 more...\n      or:\n        and:\n          api: System.Diagnostics.Process::Start @ token(0x6000005)+0x72E, token(0x6000005)+0x8EE, token(0x6000005)+0xCB0, \ntoken(0x6000005)+0x12D2, and 1 more...\n          or:\n            property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000005)+0x8AE\n            property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000005)+0x8CE\n            property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000005)+0x85C\n            property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000005)+0x8BE\n            property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x6000005)+0x828\n            property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardInput @ token(0x6000005)+0x838\n            property/read: System.Diagnostics.Process::StandardInput @ token(0x6000005)+0x922\n\nread data from Internet\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Get Response [C0002.017]  \nfunction @ token(0x6000005)\n  and:\n    or:\n      api: System.Net.WebClient::DownloadData @ token(0x6000005)+0xC17, token(0x6000005)+0x1368\n\nreceive data on socket\nnamespace  communication/socket/receive                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Receive Data [C0001.006]        \nfunction @ token(0x6000011)\n  or:\n    api: System.Net.Sockets.Socket::Receive @ token(0x6000011)+0x5F\n\nsend data on socket\nnamespace  communication/socket/send                                            \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Communication::Socket Communication::Send Data [C0001.007]           \nfunction @ token(0x6000001)\n  or:\n    api: System.Net.Sockets.Socket::Send @ token(0x6000001)+0x6A\n\ncreate TCP socket (3 matches)\nnamespace   communication/socket/tcp                                            \nauthor      william.ballenthin@mandiant.com, joakim@intezer.com,                \n            anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com       \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create TCP Socket [C0001.011]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ token(0x6000001) in function token(0x6000001)\n  or:\n    property/read: System.Net.Sockets.TcpClient::Client @ token(0x6000001)+0x56\nbasic block @ token(0x600000B) in function token(0x600000B)\n  or:\n    property/read: System.Net.Sockets.TcpClient::Client @ token(0x600000B)+0x1A\nbasic block @ token(0x6000011) in function token(0x6000011)\n  or:\n    property/read: System.Net.Sockets.TcpClient::Client @ token(0x6000011)+0x2F, token(0x6000011)+0x4C\n\nact as TCP client\nnamespace  communication/tcp/client                                     \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                                     \nmbc        Communication::Socket Communication::TCP Client [C0001.008]  \nfunction @ token(0x600000B)\n  or:\n    api: System.Net.Sockets.TcpClient::ctor @ token(0x600000B)+0xB0\n\ncompress data using GZip in .NET\nnamespace  data-manipulation/compression                                      \nauthor     michael.hunhoff@mandiant.com                                       \nscope      function                                                           \natt&ck     Collection::Archive Collected Data::Archive via Library [T1560.002]\nmbc        Data::Compress Data [C0024]                                        \nfunction @ token(0x6000012)\n  or:\n    api: System.IO.Compression.GZipStream::ctor @ token(0x6000012)+0xD, token(0x6000012)+0x5A\n\ndecode data using Base64 in .NET (2 matches)\nnamespace  data-manipulation/encoding/base64                               \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \natt&ck     Defense Evasion::Deobfuscate/Decode Files or Information [T1140]\nmbc        Data::Decode Data::Base64 [C0053.001]                           \nfunction @ token(0x6000005)\n  or:\n    api: System.Convert::FromBase64String @ token(0x6000005)+0xBBE, token(0x6000005)+0xD15, token(0x6000005)+0xDB5, \ntoken(0x6000005)+0xF4B, and 2 more...\nfunction @ token(0x6000018)\n  or:\n    api: System.Convert::FromBase64String @ token(0x6000018)+0x2\n\nencode data using Base64 (2 matches)\nnamespace  data-manipulation/encoding/base64                                    \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::Base64 [C0026.001]         \nfunction @ token(0x6000005)\n  or:\n    api: System.Convert::ToBase64String @ token(0x6000005)+0xDCB, token(0x6000005)+0x1001\nfunction @ token(0x6000019)\n  or:\n    api: System.Convert::ToBase64String @ token(0x6000019)+0xE\n\nhash data with MD5\nnamespace   data-manipulation/hashing/md5                                       \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,         \n            michael.hunhoff@mandiant.com                                        \nscope       function                                                            \nmbc         Cryptography::Cryptographic Hash::MD5 [C0029.001]                   \nreferences  https://github.com/rwfpl/rewolf-x86-virtualizer/blob/master/src/tes…\nfunction @ token(0x6000004)\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Security.Cryptography.MD5CryptoServiceProvider::ctor @ token(0x6000004)+0x0\n      optional:\n        api: System.Security.Cryptography.HashAlgorithm::ComputeHash @ token(0x6000004)+0x8\n\ngenerate random numbers in .NET\nnamespace  data-manipulation/prng                                            \nauthor     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com     \nscope      function                                                          \nmbc        Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\nfunction @ token(0x6000017)\n  or:\n    api: System.Random::Next @ token(0x6000017)+0x29\n\nset environment variable\nnamespace  host-interaction/environment-variable                           \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \nmbc        Operating System::Environment Variable::Set Variable [C0034.001]\nfunction @ token(0x6000009)\n  or:\n    api: System.Environment::SetEnvironmentVariable @ token(0x6000009)+0xEE\n\nget common file path (3 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ token(0x6000009)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x6000009)+0x219, token(0x6000009)+0x239\nfunction @ token(0x6000016)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x6000016)+0xB4\nfunction @ token(0x600001C)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x600001C)+0x234\n\ncopy file\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ token(0x6000009)\n  or:\n    api: System.IO.File::Copy @ token(0x6000009)+0xA5, token(0x6000009)+0x233\n\ndelete file (3 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ token(0x6000005)\n  or:\n    api: System.IO.File::Delete @ token(0x6000005)+0x58D\nfunction @ token(0x6000009)\n  or:\n    api: System.IO.File::Delete @ token(0x6000009)+0x7C\nfunction @ token(0x6000016)\n  or:\n    api: System.IO.File::Delete @ token(0x6000016)+0xCD\n\ncheck if file exists (2 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ token(0x6000005)\n  or:\n    api: System.IO.File::Exists @ token(0x6000005)+0x282\nfunction @ token(0x6000009)\n  or:\n    api: System.IO.File::Exists @ token(0x6000009)+0x5C\n\nget file version info\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ token(0x6000005)\n  and:\n    or:\n      api: System.Diagnostics.FileVersionInfo::GetVersionInfo @ token(0x6000005)+0x23C\n\nread file on Windows\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ token(0x6000036)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x6000036)+0x7\n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ token(0x6000005)\n  or:\n    api: System.IO.File::WriteAllBytes @ token(0x6000005)+0xCA9, token(0x6000005)+0x13F7\nfunction @ token(0x6000036)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x6000036)+0xD4\n\nget graphical window text\nnamespace  host-interaction/gui/window/get-text           \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \nmbc        Discovery::Application Window Discovery [E1010]\nfunction @ token(0x600000F)\n  or:\n    and:\n      optional:\n        api: GetForegroundWindow @ token(0x600000F)+0x0\n      api: GetWindowText @ token(0x600000F)+0x48\n\nget keyboard layout\nnamespace  host-interaction/hardware/keyboard                                   \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Discovery::System Location Discovery::System Language Discovery      \n           [T1614.001]                                                          \nfunction @ token(0x6000032)\n  and:\n    or:\n      api: GetKeyboardLayout @ token(0x6000032)+0x42\n\nget disk information\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ token(0x600000E)\n  or:\n    api: GetVolumeInformation @ token(0x600000E)+0x2F\n\ncreate or open mutex on Windows (2 matches)\nnamespace  host-interaction/mutex                                               \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           mehunhoff@google.com                                                 \nscope      instruction                                                          \nmbc        Process::Create Mutex [C0042]                                        \ninstruction @ token(0x6000039)+0xDC\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Threading.Mutex::OpenExisting @ token(0x6000039)+0xDC\ninstruction @ token(0x6000039)+0xFC\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Threading.Mutex::ctor @ token(0x6000039)+0xFC\n\nget hostname\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ token(0x600001C)\n  or:\n    property/read: System.Environment::MachineName @ token(0x600001C)+0xBA\n\nget OS version in .NET\nnamespace  host-interaction/os/version                    \nauthor     michael.hunhoff@mandiant.com                   \nscope      basic block                                    \natt&ck     Discovery::System Information Discovery [T1082]\nbasic block @ token(0x600001C) in function token(0x600001C)\n  or:\n    property/read: System.Environment::OSVersion @ token(0x600001C)+0x1DA\n    property/read: Microsoft.VisualBasic.Devices.ComputerInfo::OSFullName @ token(0x600001C)+0x14C\n\nget process image filename\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ token(0x6000005) in function token(0x6000005)\n  or:\n    and:\n      api: System.Diagnostics.Process::GetCurrentProcess @ token(0x6000005)+0x73, token(0x6000005)+0xAB6, token(0x6000005)+0x1429\n      property/read: System.Diagnostics.Process::MainModule @ token(0x6000005)+0x102, token(0x6000005)+0x161, token(0x6000005)+0x1C4, \ntoken(0x6000005)+0x1E2, and 4 more...\n      property/read: System.Diagnostics.ProcessModule::FileName @ token(0x6000005)+0x166, token(0x6000005)+0x517, token(0x6000005)+0x6A0\n\ncreate a process with modified I/O handles and window\nnamespace   host-interaction/process/create                                     \nauthor      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com      \nscope       function                                                            \nmbc         Process::Create Process [C0017]                                     \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/processthreadsap…\nfunction @ token(0x6000005)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000005)+0x72E, token(0x6000005)+0x8EE, token(0x6000005)+0xCB0, \ntoken(0x6000005)+0x12D2, and 1 more...\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000005)+0x8AE\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000005)+0x8CE\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000005)+0x85C\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000005)+0x8BE\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x6000005)+0x828\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardInput @ token(0x6000005)+0x838\n        property/read: System.Diagnostics.Process::StandardInput @ token(0x6000005)+0x922\n\ncreate process on Windows (2 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ token(0x6000005) in function token(0x6000005)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000005)+0x72E, token(0x6000005)+0x8EE, token(0x6000005)+0xCB0, \ntoken(0x6000005)+0x12D2, and 1 more...\nbasic block @ token(0x6000009) in function token(0x6000009)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000009)+0xC3\n\nenumerate processes\nnamespace  host-interaction/process/list                                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      function                                                             \natt&ck     Discovery::Process Discovery [T1057], Discovery::Software Discovery  \n           [T1518]                                                              \nfunction @ token(0x6000005)\n  or:\n    api: System.Diagnostics.Process::GetProcesses @ token(0x6000005)+0x90\n\nfind process by PID (4 matches)\nnamespace  host-interaction/process/list                                \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::Process Discovery [T1057]                         \nfunction @ token(0x6000005)\n  and:\n    or:\n      api: System.Diagnostics.Process::GetProcessById @ token(0x6000005)+0x406, token(0x6000005)+0x4EC, token(0x6000005)+0x675\nfunction @ token(0x600000F)\n  and:\n    or:\n      api: System.Diagnostics.Process::GetProcessById @ token(0x600000F)+0x66\nfunction @ token(0x600002E)\n  and:\n    or:\n      api: System.Diagnostics.Process::GetProcessById @ token(0x600002E)+0x10\nfunction @ token(0x6000039)\n  and:\n    or:\n      api: System.Diagnostics.Process::GetProcessById @ token(0x6000039)+0x78\n\nterminate process (3 matches)\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ token(0x6000005)\n  or:\n    api: System.Diagnostics.Process::Kill @ token(0x6000005)+0x40B, token(0x6000005)+0x538, token(0x6000005)+0x6E3, \ntoken(0x6000005)+0x7FD, and 1 more...\nfunction @ token(0x600000B)\n  or:\n    api: System.Diagnostics.Process::Kill @ token(0x600000B)+0x85\nfunction @ token(0x6000039)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x6000039)+0x86\n\nquery or enumerate registry key (7 matches)\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ token(0x6000003)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000003)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000003)+0x57, token(0x6000003)+0xB4, token(0x6000003)+0x111, \ntoken(0x6000003)+0x16E\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000003)+0x57, token(0x6000003)+0xB4, token(0x6000003)+0x111, \ntoken(0x6000003)+0x16E\nfunction @ token(0x6000005)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000005)\n        or:\n          api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x6000005)+0x1646\n    or:\n      api: Microsoft.Win32.RegistryKey::GetSubKeyNames @ token(0x6000005)+0x1514\nfunction @ token(0x6000009)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000009)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000009)+0x181, token(0x6000009)+0x1CE\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000009)+0x181, token(0x6000009)+0x1CE\nfunction @ token(0x6000016)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000016)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000016)+0x1B, token(0x6000016)+0x50, token(0x6000016)+0xF7\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000016)+0x1B, token(0x6000016)+0x50, token(0x6000016)+0xF7\nfunction @ token(0x600001E)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600001E)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600001E)+0x1E\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600001E)+0x1E\nfunction @ token(0x600001F)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600001F)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600001F)+0x1F\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600001F)+0x1F\nfunction @ token(0x6000039)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000039)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000039)+0x281, token(0x6000039)+0x31D\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000039)+0x281, token(0x6000039)+0x31D\n\nquery or enumerate registry value (4 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ token(0x6000005)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000005)\n        or:\n          api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x6000005)+0x1646\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x6000005)+0x1466, token(0x6000005)+0x15B1\n      api: Microsoft.Win32.RegistryKey::GetValueKind @ token(0x6000005)+0x158C\n      api: Microsoft.Win32.RegistryKey::GetValueNames @ token(0x6000005)+0x1555\nfunction @ token(0x600001C)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600001C)\n        or:\n          api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x600001C)+0x309\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValueNames @ token(0x600001C)+0x30E\nfunction @ token(0x600001E)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600001E)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600001E)+0x1E\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x600001E)+0x29\nfunction @ token(0x6000039)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000039)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000039)+0x281, token(0x6000039)+0x31D\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x6000039)+0x246, token(0x6000039)+0x2E2\n\nset registry value (5 matches)\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ token(0x6000005)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x6000005)\n          or:\n            api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x6000005)+0x1646\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000005)+0x13CC, token(0x6000005)+0x160D\nfunction @ token(0x6000005)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x6000005)\n          or:\n            api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x6000005)+0x1646\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000005)+0x13CC, token(0x6000005)+0x160D\nfunction @ token(0x6000009)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x6000009)\n          or:\n            api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000009)+0x181, token(0x6000009)+0x1CE\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000009)+0x1A4, token(0x6000009)+0x1F1\nfunction @ token(0x600001D)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x600001D)\n          or:\n            api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x600001D)+0x1E\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x600001D)+0x25\nfunction @ token(0x6000039)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x6000039)\n          or:\n            api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000039)+0x281, token(0x6000039)+0x31D\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000039)+0x5A, token(0x6000039)+0x2A4, token(0x6000039)+0x340\n\ndelete registry key (2 matches)\nnamespace  host-interaction/registry/delete                                \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\nscope      function                                                        \natt&ck     Defense Evasion::Modify Registry [T1112]                        \nmbc        Operating System::Registry::Delete Registry Key [C0036.002]     \nfunction @ token(0x6000005)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000005)\n        or:\n          api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x6000005)+0x1646\n    or:\n      api: Microsoft.Win32.RegistryKey::DeleteSubKeyTree @ token(0x6000005)+0x1663\nfunction @ token(0x6000016)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000016)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000016)+0x1B, token(0x6000016)+0x50, token(0x6000016)+0xF7\n    or:\n      api: Microsoft.Win32.RegistryKey::DeleteSubKey @ token(0x6000016)+0x102\n\ndelete registry value (3 matches)\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ token(0x6000005)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000005)\n        or:\n          api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x6000005)+0x1646\n    or:\n      api: Microsoft.Win32.RegistryKey::DeleteValue @ token(0x6000005)+0x162A\nfunction @ token(0x6000016)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000016)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000016)+0x1B, token(0x6000016)+0x50, token(0x6000016)+0xF7\n    or:\n      api: Microsoft.Win32.RegistryKey::DeleteValue @ token(0x6000016)+0x26, token(0x6000016)+0x5B\nfunction @ token(0x600001F)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600001F)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600001F)+0x1F\n    or:\n      api: Microsoft.Win32.RegistryKey::DeleteValue @ token(0x600001F)+0x25\n\nget session user name\nnamespace  host-interaction/session                                             \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope      function                                                             \natt&ck     Discovery::System Owner/User Discovery [T1033], Discovery::Account   \n           Discovery [T1087]                                                    \nfunction @ token(0x600001C)\n  or:\n    property/read: System.Environment::UserName @ token(0x600001C)+0xED\n\ncreate thread (3 matches)\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ token(0x6000005) in function token(0x6000005)\n  or:\n    and:\n      api: System.Threading.Thread::Start @ token(0x6000005)+0x38D\n      optional:\n        api: System.Threading.Thread::ctor @ token(0x6000005)+0x36F\nbasic block @ token(0x6000011) in function token(0x6000011)\n  or:\n    and:\n      api: System.Threading.Thread::Start @ token(0x6000011)+0xE7\n      optional:\n        api: System.Threading.Thread::ctor @ token(0x6000011)+0xC0\nbasic block @ token(0x6000039) in function token(0x6000039)\n  or:\n    and:\n      api: System.Threading.Thread::Start @ token(0x6000039)+0x12F, token(0x6000039)+0x157\n      optional:\n        api: System.Threading.Thread::ctor @ token(0x6000039)+0x128, token(0x6000039)+0x150\n\nsuspend thread (6 matches)\nnamespace  host-interaction/thread/suspend                    \nauthor     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\nscope      basic block                                        \nmbc        Process::Suspend Thread [C0055]                    \nbasic block @ token(0x6000005) in function token(0x6000005)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000005)+0x586, token(0x6000005)+0xEAF, token(0x6000005)+0x1448\nbasic block @ token(0x6000009) in function token(0x6000009)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000009)+0x273\nbasic block @ token(0x600000B) in function token(0x600000B)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x600000B)+0xBF\nbasic block @ token(0x6000011) in function token(0x6000011)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000011)+0x19E, token(0x6000011)+0x1C4\nbasic block @ token(0x6000036) in function token(0x6000036)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000036)+0xDA\nbasic block @ token(0x6000039) in function token(0x6000039)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000039)+0xB1, token(0x6000039)+0xD2, token(0x6000039)+0x1A9\n\n(internal) .NET file limitation\nnamespace    internal/limitation/dynamic                        \nauthor       @v1bh475u                                          \nscope        file                                               \ndescription  This dynamic analysis trace describes a .NET file. \n                                                                \n             capa rules are not yet tuned for the .NET runtime, \n             so its analysis may be incomplete or misleading.   \n                                                                \nor:\n  format: dotnet\n\nload .NET assembly\nnamespace  load-code/dotnet                                \nauthor     anushka.virgaonkar@mandiant.com                 \nscope      function                                        \natt&ck     Defense Evasion::Reflective Code Loading [T1620]\nfunction @ token(0x600000D)\n  or:\n    api: System.Reflection.Assembly::Load @ token(0x600000D)+0x1\n\nunmanaged call (8 matches)\nnamespace    runtime                                                       \nauthor       michael.hunhoff@mandiant.com                                  \nscope        function                                                      \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nfunction @ token(0x6000002)\n  or:\n    characteristic: unmanaged call @ token(0x6000002)+0xF\nfunction @ token(0x600000E)\n  or:\n    characteristic: unmanaged call @ token(0x600000E)+0x2F\nfunction @ token(0x600000F)\n  or:\n    characteristic: unmanaged call @ token(0x600000F)+0x0, token(0x600000F)+0x2D, token(0x600000F)+0x48, \ntoken(0x600000F)+0x51\nfunction @ token(0x6000010)\n  or:\n    characteristic: unmanaged call @ token(0x6000010)+0x17\nfunction @ token(0x600002E)\n  or:\n    characteristic: unmanaged call @ token(0x600002E)+0x0, token(0x600002E)+0x9\nfunction @ token(0x6000032)\n  or:\n    characteristic: unmanaged call @ token(0x6000032)+0x13, token(0x6000032)+0x26, token(0x6000032)+0x2D, \ntoken(0x6000032)+0x3B, and 2 more...\nfunction @ token(0x6000036)\n  or:\n    characteristic: unmanaged call @ token(0x6000036)+0x2A\nfunction @ token(0x6000039)\n  or:\n    characteristic: unmanaged call @ token(0x6000039)+0x1CA\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  format: dotnet\n\n\n\n"},"hashes":{"md5":"c11324b04408d615e59d129f8a6be3ba","sha1":"9b25415c7a87f0238fc9fe7294028c0c9eee763c","sha256":"f8e4ad3492797ba03edb9529e28e51063d726efa5816fa2f539a7fe2033d4ae3"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 43</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 2703</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Trojan.Bladabindi-019f46cb1840\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"c11324b04408d615e59d129f8a6be3ba\",\n        \"sha256\": \"f8e4ad3492797ba03edb9529e28e51063d726efa5816fa2f539a7fe\",\n        \"arch\": \"i386\",\n        \"os\": \"any\",\n        \"format\": \"dotnet\"\n      }\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_Microsoft\",\n      \"label\": \"Microsoft\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_self_delete__2_matches_\",\n      \"label\": \"self delete (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_System\",\n      \"label\": \"System\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_save_image_in__net\",\n      \"label\": \"save image in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_log_keystrokes\",\n      \"label\": \"log keystrokes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_MapVirtualKey\",\n      \"label\": \"MapVirtualKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"label\": \"log keystrokes via polling (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetAsyncKeyState\",\n      \"label\": \"GetAsyncKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetKeyboardState\",\n      \"label\": \"GetKeyboardState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_capture_screenshot\",\n      \"label\": \"capture screenshot\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_data__2_matches_\",\n      \"label\": \"receive data (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data\",\n      \"label\": \"send data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_download_and_write_a_file\",\n      \"label\": \"download and write a file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"downloader\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Server to Client\",\n        \"File Transfer [B0030.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_maec_malware_category__downloader\",\n      \"label\": \"maec/malware-category  downloader\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"downloader\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Server to Client\",\n        \"File Transfer [B0030.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_and_write_data_from_server_to_client\",\n      \"label\": \"receive and write data from server to client\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_write_and_execute_a_file\",\n      \"label\": \"write and execute a file\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_maec_malware_category__launcher\",\n      \"label\": \"maec/malware-category  launcher\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_data_from_internet\",\n      \"label\": \"read data from Internet\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_data_on_socket\",\n      \"label\": \"receive data on socket\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Receive Data [C0001.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Receive Data [C0001.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data_on_socket\",\n      \"label\": \"send data on socket\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_tcp_socket__3_matches_\",\n      \"label\": \"create TCP socket (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_act_as_tcp_client\",\n      \"label\": \"act as TCP client\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_compress_data_using_gzip_in__net\",\n      \"label\": \"compress data using GZip in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Compress Data [C0024]\"\n      ]\n    },\n    {\n      \"id\": \"cap_decode_data_using_base64_in__net__2_matches_\",\n      \"label\": \"decode data using Base64 in .NET (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decode Data::Base64 [C0053.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encode_data_using_base64__2_matches_\",\n      \"label\": \"encode data using Base64 (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_with_md5\",\n      \"label\": \"hash data with MD5\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash::MD5 [C0029.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_in__net\",\n      \"label\": \"generate random numbers in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_environment_variable\",\n      \"label\": \"set environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable::Set Variable [C0034.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path__3_matches_\",\n      \"label\": \"get common file path (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_copy_file\",\n      \"label\": \"copy file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_file__3_matches_\",\n      \"label\": \"delete file (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__2_matches_\",\n      \"label\": \"check if file exists (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_version_info\",\n      \"label\": \"get file version info\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows\",\n      \"label\": \"read file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__2_matches_\",\n      \"label\": \"write file on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_graphical_window_text\",\n      \"label\": \"get graphical window text\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetWindowText\",\n      \"label\": \"GetWindowText\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetForegroundWindow\",\n      \"label\": \"GetForegroundWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_keyboard_layout\",\n      \"label\": \"get keyboard layout\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery::System Language Discovery\",\n        \"[T1614.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetKeyboardLayout\",\n      \"label\": \"GetKeyboardLayout\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_information\",\n      \"label\": \"get disk information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetVolumeInformation\",\n      \"label\": \"GetVolumeInformation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_or_open_mutex_on_windows__2_matches_\",\n      \"label\": \"create or open mutex on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_mehunhoff_google_com\",\n      \"label\": \"mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_hostname\",\n      \"label\": \"get hostname\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_os_version_in__net\",\n      \"label\": \"get OS version in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_process_image_filename\",\n      \"label\": \"get process image filename\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_a_process_with_modified_i_o_handles_and_window\",\n      \"label\": \"create a process with modified I/O handles and window\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__2_matches_\",\n      \"label\": \"create process on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_processes\",\n      \"label\": \"enumerate processes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\",\n        \"Discovery::Software Discovery\",\n        \"[T1518]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_process_by_pid__4_matches_\",\n      \"label\": \"find process by PID (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process__3_matches_\",\n      \"label\": \"terminate process (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key__7_matches_\",\n      \"label\": \"query or enumerate registry key (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"label\": \"query or enumerate registry value (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_registry_value__5_matches_\",\n      \"label\": \"set registry value (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_key__2_matches_\",\n      \"label\": \"delete registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_value__3_matches_\",\n      \"label\": \"delete registry value (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_session_user_name\",\n      \"label\": \"get session user name\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\",\n        \"Discovery::Account\",\n        \"Discovery [T1087]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_thread__3_matches_\",\n      \"label\": \"create thread (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_suspend_thread__6_matches_\",\n      \"label\": \"suspend thread (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Suspend Thread [C0055]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Suspend Thread [C0055]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal___net_file_limitation\",\n      \"label\": \"(internal) .NET file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author________v1bh475u\",\n      \"label\": \"author       @v1bh475u\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_load__net_assembly\",\n      \"label\": \"load .NET assembly\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_unmanaged_call__8_matches_\",\n      \"label\": \"unmanaged call (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"label\": \"author       michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compiled_to_the__net_platform\",\n      \"label\": \"compiled to the .NET platform\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_self_delete__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_save_image_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_capture_screenshot\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_download_and_write_a_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_maec_malware_category__downloader\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_and_write_data_from_server_to_client\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_and_execute_a_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_maec_malware_category__launcher\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_data_from_internet\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data_on_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data_on_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_tcp_socket__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_act_as_tcp_client\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compress_data_using_gzip_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decode_data_using_base64_in__net__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encode_data_using_base64__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_md5\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_version_info\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_graphical_window_text\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_keyboard_layout\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_mutex_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_process_image_filename\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_a_process_with_modified_i_o_handles_and_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_processes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_process_by_pid__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_user_name\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_suspend_thread__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal___net_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________v1bh475u\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_load__net_assembly\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_unmanaged_call__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_to_the__net_platform\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 22:16:36.132667\",\n    \"total_functions\": \"43\",\n    \"total_features\": \"2703\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 22:16:36"}
{"_id":{"$oid":"6a4fd38e0108394cb24cdcf9"},"sha256":"2c7b1c5c51f6952e7b8d0ac8137bc890f0edb43f878d0e356a4bdbe1ab325127","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_z6u2wf61/Trojan.Win32.Bechiro.BCD-019f46cb5c4f7bc3a7e837813cf184c8.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_z6u2wf61/Trojan.Win32.Bechiro.BCD-019f46cb5c4f7bc3a7e837813cf184c8.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_z6u2wf61/Trojan.Win32.Bechiro.BCD-019f46cb5c4f7bc3a7e837813cf184c8.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 0d06681f63f3026260aa1e15d86520a0                                  │\n│ sha1     │ 12c42b7fefdefb752a8118fb928b913c0ef7562d                          │\n│ sha256   │ 2c7b1c5c51f6952e7b8d0ac8137bc890f0edb43f878d0e356a4bdbe1ab325127  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/Trojan.Win32.Bec… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\nno capabilities found\n\n","verbose":"md5                     0d06681f63f3026260aa1e15d86520a0                        \nsha1                    12c42b7fefdefb752a8118fb928b913c0ef7562d                \nsha256                  2c7b1c5c51f6952e7b8d0ac8137bc890f0edb43f878d0e356a4bdbe…\npath                    /home/apogean/projects/malware/windows/all_runs/Trojan.…\ntimestamp               2026-07-09 22:29:53.139008                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEImNjLB2/rules                                   \nfunction count          2                                                       \nlibrary function count  0                                                       \ntotal feature count     2091                                                    \n\nno capabilities found\n\n\n","very_verbose":"md5                     0d06681f63f3026260aa1e15d86520a0                        \nsha1                    12c42b7fefdefb752a8118fb928b913c0ef7562d                \nsha256                  2c7b1c5c51f6952e7b8d0ac8137bc890f0edb43f878d0e356a4bdbe…\npath                    /home/apogean/projects/malware/windows/all_runs/Trojan.…\ntimestamp               2026-07-09 22:29:58.375438                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIkCdMZb/rules                                   \nfunction count          2                                                       \nlibrary function count  0                                                       \ntotal feature count     2091                                                    \n\nno capabilities found\n\n\n"},"hashes":{"md5":"0d06681f63f3026260aa1e15d86520a0","sha1":"12c42b7fefdefb752a8118fb928b913c0ef7562d","sha256":"2c7b1c5c51f6952e7b8d0ac8137bc890f0edb43f878d0e356a4bdbe1ab325127"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 2</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 2091</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Trojan.\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"0d06681f63f3026260aa1e15d86520a0\",\n        \"sha256\": \"2c7b1c5c51f6952e7b8d0ac8137bc890f0edb43f878d0e356a4bdbe\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    }\n  ],\n  \"edges\": [],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 22:29:58.375438\",\n    \"total_functions\": \"2\",\n    \"total_features\": \"2091\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 22:29:58"}
{"_id":{"$oid":"6a4fd71e0108394cb24cdcfc"},"sha256":"3a93d0b4345900c5eddfaa574b721546312468a418f34b39bcefbbda9118b0cb","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_ot26lp0o/Trojan.Loadmoney-019f46cc34147fd084091fe8c22bfcb2.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_ot26lp0o/Trojan.Loadmoney-019f46cc34147fd084091fe8c22bfcb2.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_ot26lp0o/Trojan.Loadmoney-019f46cc34147fd084091fe8c22bfcb2.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 6c42954257ef80cc72266400236ea63c                                  │\n│ sha1     │ f217d5ce69e0cb6c29889cc36ed707d2ed18e287                          │\n│ sha256   │ 3a93d0b4345900c5eddfaa574b721546312468a418f34b39bcefbbda9118b0cb  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/Trojan.Loadmoney… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic             ┃ ATT&CK Technique                                 ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ EXECUTION                 │ Command and Scripting Interpreter [T1059]        │\n│                           │ Shared Modules [T1129]                           │\n└───────────────────────────┴──────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective          ┃ MBC Behavior                                        ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DISCOVERY              │ Code Discovery::Enumerate PE Sections [B0046.001]   │\n│ EXECUTION              │ Command and Scripting Interpreter [E1059]           │\n│ FILE SYSTEM            │ Writes File [C0052]                                 │\n│ MEMORY                 │ Allocate Memory [C0007]                             │\n└────────────────────────┴─────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                              ┃ Namespace                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ compiled with MinGW for Windows         │ compiler/mingw                     │\n│ contain a thread local storage (.tls)   │ executable/pe/section/tls          │\n│ section                                 │                                    │\n│ accept command line arguments           │ host-interaction/cli               │\n│ write file on Windows                   │ host-interaction/file-system/write │\n│ get thread local storage value          │ host-interaction/process           │\n│ allocate or change RWX memory           │ host-interaction/process/inject    │\n│ link function at runtime on Windows (5  │ linking/runtime-linking            │\n│ matches)                                │                                    │\n│ enumerate PE sections                   │ load-code/pe                       │\n│ parse PE header                         │ load-code/pe                       │\n└─────────────────────────────────────────┴────────────────────────────────────┘\n\n","verbose":"md5                     6c42954257ef80cc72266400236ea63c                        \nsha1                    f217d5ce69e0cb6c29889cc36ed707d2ed18e287                \nsha256                  3a93d0b4345900c5eddfaa574b721546312468a418f34b39bcefbbd…\npath                    /home/apogean/projects/malware/windows/all_runs/Trojan.…\ntimestamp               2026-07-09 22:45:02.958162                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEISrGOFx/rules                                   \nfunction count          72                                                      \nlibrary function count  0                                                       \ntotal feature count     3144                                                    \n\ncompiled with MinGW for Windows\nnamespace  compiler/mingw\nscope      file          \n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls\nscope      file                     \n\naccept command line arguments\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x402D50            \n\nwrite file on Windows\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x4029C0                          \n\nget thread local storage value\nnamespace  host-interaction/process\nscope      function                \nmatches    0x402E60                \n\nallocate or change RWX memory\nnamespace  host-interaction/process/inject\nscope      basic block                    \nmatches    0x402AB5                       \n\nlink function at runtime on Windows (5 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x401314               \n           0x401B04               \n           0x4025CB               \n           0x4027D7               \n           0x4027F4               \n\nenumerate PE sections\nnamespace  load-code/pe\nscope      function    \nmatches    0x402098    \n\nparse PE header\nnamespace  load-code/pe\nscope      function    \nmatches    0x401DEB    \n\n\n\n","very_verbose":"md5                     6c42954257ef80cc72266400236ea63c                        \nsha1                    f217d5ce69e0cb6c29889cc36ed707d2ed18e287                \nsha256                  3a93d0b4345900c5eddfaa574b721546312468a418f34b39bcefbbd…\npath                    /home/apogean/projects/malware/windows/all_runs/Trojan.…\ntimestamp               2026-07-09 22:45:09.495465                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIKqk9Ck/rules                                   \nfunction count          72                                                      \nlibrary function count  0                                                       \ntotal feature count     3144                                                    \n\nallocate memory (7 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x401883 in function 0x40228A\n  or:\n    api: VirtualAlloc @ 0x40188A\n\nallocate or change RW memory (4 matches, only showing first match of library \nrule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x401E27 in function 0x401DEB\n  and:\n    or:\n      match: allocate memory @ 0x401E27\n        or:\n          api: VirtualAlloc @ 0x401E45\n    or:\n      number: 0x4 = PAGE_READWRITE @ 0x401E2A\n\nchange memory protection (3 matches, only showing first match of library rule)\nauthor  @mr-tz                                  \nscope   basic block                             \nmbc     Memory::Change Memory Protection [C0008]\nbasic block @ 0x401A75 in function 0x402098\n  or:\n    api: VirtualProtect @ 0x401A7F\n\ncontain loop (15 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401340\n  or:\n    characteristic: loop @ 0x401340\n\ncompiled with MinGW for Windows\nnamespace  compiler/mingw                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nand:\n  string: \"Mingw runtime failure:\" @ file+0xD8F4\n  string: \"_Jv_RegisterClasses\" = from GCC @ file+0xD889\n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls   \nauthor     michael.hunhoff@mandiant.com\nscope      file                        \nsection: .tls @ 0x413000\n\naccept command line arguments\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x402D50\n  or:\n    api: GetCommandLine @ 0x402D68\n\nwrite file on Windows\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x4029C0\n  or:\n    and:\n      os: windows\n      or:\n        api: fwrite @ 0x4029F3\n\nget thread local storage value\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x402E60\n  and:\n    api: TlsGetValue @ 0x402E96\n\nallocate or change RWX memory\nnamespace  host-interaction/process/inject\nauthor     @mr-tz, mehunhoff@google.com   \nscope      basic block                    \nmbc        Memory::Allocate Memory [C0007]\nbasic block @ 0x402AB5 in function 0x402A10\n  or:\n    basic block:\n      and:\n        or:\n          match: change memory protection @ 0x402AB5\n            or:\n              api: VirtualProtect @ 0x402AD1\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x402ABF\n\nlink function at runtime on Windows (5 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x401314\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401314\ninstruction @ 0x401B04\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401B04\ninstruction @ 0x4025CB\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4025CB\ninstruction @ 0x4027D7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4027D7\ninstruction @ 0x4027F4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4027F4\n\nenumerate PE sections\nnamespace   load-code/pe                                                        \nauthor      @Ana06, @mr-tz                                                      \nscope       function                                                            \nmbc         Discovery::Code Discovery::Enumerate PE Sections [B0046.001]        \nreferences  https://0x00sec.org/t/reflective-dll-injection/3080,                \n            https://www.ired.team/offensive-security/code-injection-process-inj…\nfunction @ 0x402098\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x401D95\n        or:\n          mnemonic: movzx @ 0x401D95\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x4025EF\n              or:\n                mnemonic: movzx @ 0x4025EF\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x4025FD\n    count(basic block): 3 or more @ 0x4019EE, 0x4019F3, 0x4019FB, 0x401A70, and 40 more...\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x4025EF\n      operand[1].offset: 0x10 = IMAGE_SECTION_HEADER.SizeOfRawData @ 0x401B9B, 0x401C33\n\nparse PE header\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x401DEB\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x401CBB, 0x402138, 0x40217D, 0x4022A0, and 3 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x40217D\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x4026AF\n      optional:\n        and:\n          operand[1].offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x401F80, 0x40216F, 0x402432\n          or:\n            and:\n              arch: i386\n              operand[1].offset: 0x50 = IMAGE_NT_HEADERS.OptionalHeader.SizeOfImage @ 0x40196A, 0x401E27, 0x402113\n              operand[1].offset: 0x34 = IMAGE_NT_HEADERS.OptionalHeader.ImageBase @ 0x4021B6, 0x402620\n\n\n\n"},"hashes":{"md5":"6c42954257ef80cc72266400236ea63c","sha1":"f217d5ce69e0cb6c29889cc36ed707d2ed18e287","sha256":"3a93d0b4345900c5eddfaa574b721546312468a418f34b39bcefbbda9118b0cb"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 72</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 3144</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Trojan.\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"6c42954257ef80cc72266400236ea63c\",\n        \"sha256\": \"3a93d0b4345900c5eddfaa574b721546312468a418f34b39bcefbbd\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_allocate_memory__7_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"allocate memory (7 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401883\",\n      \"label\": \"Block 0x401883\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401883\"\n    },\n    {\n      \"id\": \"api_VirtualAlloc\",\n      \"label\": \"VirtualAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401E27\",\n      \"label\": \"Block 0x401E27\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401E27\"\n    },\n    {\n      \"id\": \"cap_change_memory_protection__3_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"change memory protection (3 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Change Memory Protection [C0008]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401A75\",\n      \"label\": \"Block 0x401A75\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401A75\"\n    },\n    {\n      \"id\": \"api_VirtualProtect\",\n      \"label\": \"VirtualProtect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_contain_loop__15_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (15 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401340\",\n      \"label\": \"Function 0x401340\",\n      \"type\": \"function\",\n      \"address\": \"0x401340\"\n    },\n    {\n      \"id\": \"cap_compiled_with_mingw_for_windows\",\n      \"label\": \"compiled with MinGW for Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"label\": \"contain a thread local storage (.tls) section\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments\",\n      \"label\": \"accept command line arguments\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402D50\",\n      \"label\": \"Function 0x402D50\",\n      \"type\": \"function\",\n      \"address\": \"0x402D50\"\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows\",\n      \"label\": \"write file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4029C0\",\n      \"label\": \"Function 0x4029C0\",\n      \"type\": \"function\",\n      \"address\": \"0x4029C0\"\n    },\n    {\n      \"id\": \"api_fwrite\",\n      \"label\": \"fwrite\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_thread_local_storage_value\",\n      \"label\": \"get thread local storage value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x402E60\",\n      \"label\": \"Function 0x402E60\",\n      \"type\": \"function\",\n      \"address\": \"0x402E60\"\n    },\n    {\n      \"id\": \"api_TlsGetValue\",\n      \"label\": \"TlsGetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_allocate_or_change_rwx_memory\",\n      \"label\": \"allocate or change RWX memory\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x402AB5\",\n      \"label\": \"Block 0x402AB5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x402AB5\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"label\": \"author     @mr-tz, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__5_matches_\",\n      \"label\": \"link function at runtime on Windows (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_pe_sections\",\n      \"label\": \"enumerate PE sections\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402098\",\n      \"label\": \"Function 0x402098\",\n      \"type\": \"function\",\n      \"address\": \"0x402098\"\n    },\n    {\n      \"id\": \"cap_author_______ana06___mr_tz\",\n      \"label\": \"author      @Ana06, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header\",\n      \"label\": \"parse PE header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401DEB\",\n      \"label\": \"Function 0x401DEB\",\n      \"type\": \"function\",\n      \"address\": \"0x401DEB\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_memory__7_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_memory__7_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x401883\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x401E27\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_change_memory_protection__3_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_change_memory_protection__3_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x401A75\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__15_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__15_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_with_mingw_for_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments\",\n      \"target\": \"func_0x402D50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402D50\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402D50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402D50\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows\",\n      \"target\": \"func_0x4029C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4029C0\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4029C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4029C0\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_thread_local_storage_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value\",\n      \"target\": \"func_0x402E60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402E60\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x402E60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402E60\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_or_change_rwx_memory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory\",\n      \"target\": \"bb_0x402AB5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x402AB5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_pe_sections\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections\",\n      \"target\": \"func_0x402098\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______ana06___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x402098\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header\",\n      \"target\": \"func_0x401DEB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x401DEB\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 22:45:09.495465\",\n    \"total_functions\": \"72\",\n    \"total_features\": \"3144\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 22:45:10"}
{"_id":{"$oid":"6a4fdbfa0108394cb24cdcfe"},"sha256":"69e966e730557fde8fd84317cdef1ece00a8bb3470c0b58f3231e170168af169","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_p9yq_o98/ZeusBankingVersion_26Nov2013-019f46cc6d177a639e90556ad66a7265.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_p9yq_o98/ZeusBankingVersion_26Nov2013-019f46cc6d177a639e90556ad66a7265.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_p9yq_o98/ZeusBankingVersion_26Nov2013-019f46cc6d177a639e90556ad66a7265.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ ea039a854d20d7734c5add48f1a51c34                                  │\n│ sha1     │ 9615dca4c0e46b8a39de5428af7db060399230b2                          │\n│ sha256   │ 69e966e730557fde8fd84317cdef1ece00a8bb3470c0b58f3231e170168af169  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/ZeusBankingVersi… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION      │ Obfuscated Files or Information [T1027]               │\n│                      │ Virtualization/Sandbox Evasion::System Checks         │\n│                      │ [T1497.001]                                           │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Virtual Machine Detection [B0009]                 │\n│ DEFENSE EVASION          │ Obfuscated Files or                               │\n│                          │ Information::Encryption-Standard Algorithm        │\n│                          │ [E1027.m05]                                       │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ reference anti-VM strings targeting   │ anti-analysis/anti-vm/vm-detection   │\n│ VMWare                                │                                      │\n│ encrypt data using chaskey            │ data-manipulation/encryption/chaskey │\n│ resolve function by parsing PE        │ load-code/pe                         │\n│ exports (2 matches)                   │                                      │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     ea039a854d20d7734c5add48f1a51c34                        \nsha1                    9615dca4c0e46b8a39de5428af7db060399230b2                \nsha256                  69e966e730557fde8fd84317cdef1ece00a8bb3470c0b58f3231e17…\npath                    /home/apogean/projects/malware/windows/all_runs/ZeusBan…\ntimestamp               2026-07-09 23:05:45.041907                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIAs2nAo/rules                                   \nfunction count          80                                                      \nlibrary function count  1                                                       \ntotal feature count     10073                                                   \n\nreference anti-VM strings targeting VMWare\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nencrypt data using chaskey\nnamespace  data-manipulation/encryption/chaskey\nscope      function                            \nmatches    0x402AAF                            \n\nresolve function by parsing PE exports (2 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x4094B1    \n           0x40A3B6    \n\n\n\n","very_verbose":"md5                     ea039a854d20d7734c5add48f1a51c34                        \nsha1                    9615dca4c0e46b8a39de5428af7db060399230b2                \nsha256                  69e966e730557fde8fd84317cdef1ece00a8bb3470c0b58f3231e17…\npath                    /home/apogean/projects/malware/windows/all_runs/ZeusBan…\ntimestamp               2026-07-09 23:05:53.456198                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEICXpXYc/rules                                   \nfunction count          80                                                      \nlibrary function count  1                                                       \ntotal feature count     10073                                                   \n\ncontain loop (11 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x40113B\n  or:\n    characteristic: loop @ 0x40113B\n\nreference anti-VM strings targeting VMWare\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com, @johnk3r                              \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /vmci/i\n    - \"e_9g+cYbmY2Wr5yL/W+9f6jiMh1[Igj2xvY{r9skJVl25LJbjQVBmtPC8uV9SSX83Udh8JmEkUBZ0[a\nJkoBiPTLNbioJvDire:Mri9cGMxKhGKaClrYJwvQnJvfbojX5+lIjPTdNJBrQ7P+jvDwHMeTGJGQih:q\n3bMCJm7tdjq42H7TmA{l{HQp2Ti0TzDbjPb9KodEmWg7rhsc7nc18QUprYbDrvbsWRnZTqjFW1w0LFQJ\nIGXnUvPd67SP:kjtvVXBfyz2uVlk[IdfnSO1uE[RbKUzsfRRWRqn[Q6rwl:0dgIvXMtmGEQTcdSJHKrp\nMy0S5iYgL3F97nDnlwNC5A:SiNYOmxCQux61r0wJfS3PP1GH8D9nEu9bzaxB9ddeWYP18Cw5V2E0RPdu\ntPw3bQhevmrO9xSv{81r4NS4WnoMhquv2hBRMUmWGG0s6uPdD8RrRzR300nK4Du5Mdv/5rg2OI1m,tUc\n8THKBD4c3J5GX6NCQ6dehl0IJC7w7KwzVwFs7L8jECkuIdMm1fv8:rxrp/,hMiT5Rb:vR0Z3k5Ve8X9n\nkJypSX[Csl7ExgMc3+DvhgEMSCR+ni6u60sHQSs6{dtHhO8Brj3yu2nhP71TEJtodiXIjxglbX2yWV9E\nZQ1GBhuUsfD/UgqHtQYI3nx1HEzZl1fJgT:utnHRQKSWO+lf[PGorHWK,GZgGEqP[zqNJ5m/TgeLN7m3\n8v1oXL:xfqQg55[I2ijkK5Gd{ljsgk8o2MQj2DouGJ,wogMU,SoDfIDefQyw5DRZKB42XtEiU/YC47g9\nJGeEUAbcd+UW0+Vtt29mb2dsJ0RNPp[cGrFz8o:zL6q/eluvl2RjMi9+7dTv5W[a6X:TKIhuVocfVfrC\nW2P68OBoIIJj7n6VdihVvvvUwqJ4oWZBcFetcGu1n5bfHZ5kd2xj9SPE5r{DTFsYO2DGLc4a5ppLjH67\n,mrditJrwHi9[17A3wZ1uFex6kdOTJgboAUO5xiS7m[U8sREjAgwluk+5Hsht+9y{hK+nc5IVi7RfQZb\neu03iGz7MVhY,pZxi23nxlY4lt3ZqTxVL/uAvEObfn8GZxYPsxVYh5o1R2KrE39rIo0dpawt:j{sVx[C\nstJQy+wGK+4+psomjGsaM8N6,lUFhE5iBHYPD4UTroV3s3DaO5fyOvHGvRjwssSVZJqssXtc[5Ocu9vv\nvgHlquiLF23Jf6UEHUV1duqN3+,vclXjzbdNKNY4TL8OlZL/vlJJrJ2H{H0/1gu78B4Vqi0sk85/k5Qc\nswnNir5gMRIFIOn86Z7n,WNrvEj1lgiH{U5aCf68powYRqpqRscMBk0j{cvdzsOVWdQ3SImrIR{X8Y:F\nyqPowuhI3yX5egwTvadWKCRDM7CAY709M10sLjGCInbTb5Kf:cKVFnf/cL6qiyPtoazMIh{2woU4Ubxw\nV0KxWktxbO64l8bMunzp6rSMcg263FjxodQHsmH4Spowv5Pg2bJaoJ6JReYrV7cXcheoyNpk1YWqewOj\ngpVYJnfihbnDH9HZwCTRICWgy1B4iUxw6NZM3s[lZg4mnBut[27sGYViK2RRtwrAOJYHLW2c8LJee+U8\nLl{/yqjZpZRIM3Mj9HG3kibv[w{77SbQLU4DvMPQRgXs33QrcmQIrmInJf3e5uU/:60oMFF0p0tpE44q\nKTqNzHQoYIj+g77TlyS7pDd5L0j6gQHjvQsun2zk[2HLW9kePNsF:/r/VoGUrCET,icBtQFWt94VVzVM\ncIzLXk:Wgj[hNeNMojI75Tpwl+PNg8pqxc{rehkt[gJOiYyvg+VVQQqCBNd9mmuwBNqEtEmg2TxKYWgv\ni/[1c26BnGsvhcd0D1IR7BBJEX51hqGk4cI9ldkmOVSNZeTbP2MmTeo8baBzGD{kh2WDou,S7Z9QCnlJ\nwlkbLRn/pK3OYZq4st{zzsrrTLU0j0u+{hF8FH[VpEgK0JU99q1mUtXqldW9VHyKxY182bnxr/2S22Pz\nyW:qpL3DSIleq7npIgn4hgfu3cc1jgKyY+ewdAsnuz,RRIQkSpiv5EWxPRCNBGtVRLiKo061MznDp38r\np3OWtKLG5oY5oLq14yTkv7n2XIULUe[JT3RC[idYiTvSeoXA6/ZxIvHtCvsSnkDQsKZb[BMhdzukFORd\nK1vMdNWqV0BdBE2o81oRsiYJpE[I7iKlpsnqlT30DC0huMvz3nJAVoPeSjH1tPdFpS[jjjN60VM1YN:B\nC0Ypy2na6nxn8wsCOhejrh2UMb:x{pmztf86kVBLBp4ItywTiHloicj1KxBH[UMCjeuPF7t1Quxp1b0s\nBcEG9AD+OcfhXu,AhEDXSIU6e0Ln7PZZGRyGTJfPf2tfSVWQJR{ZWMTeTjTPgBSyqI3gcQoltEb/qMFf\nkdj2C3jfiQQd2j:fpFktmRN0QZ1onvQme7lZlRnR,IjNMxp69zhT9511hg,fhv8gI+cwIu85t4b17PW2\niVDNuZOb9RV4m3tJVcKll72oDI8KnV4h[r0K1upGzccXUvYPDoGYrG2Iy3zv7wRMDRgUGnj89Qhi7iME\n3wOGurgvWXDVT9wlTTRctfzu1bxrF82/RfUoYIzqOYcUFbfzrbZi9nsQHoXyjB9RdyHqwpON8n6bsiFN\nemN1YyZAKFrbujfQ0rsWrcmD6u,+IQzhDOTbuNglsVWqmS0VFQtM5G6Owb0WfLEomUBiEYlDij,Bws61\nI2YiYfJnPlHsGfnaqvyK21MYkJwJUW91bjeBMElDM0o8SOc1QV[c7XHF98iyJ7Ey:YvXjgUYKLrA{wnC\npzYSpfzFETWY5hv6iLoPcSqlqxnDp1YKHgJgXhNv8bE32ZmO0ciOdgcAnHEQIS1OeZQvoK7qPVec2ZQZ\n:3Q7q1sIXZ4/tKe1S0ST{2li6zUUqRHioOCIFTdSlztosanX8ogl7wkBly{4VrTKWIwbNXrtyT42LyzG\n3jhz{JtEHYCIgBRuzO[32ag14bDZWQRJkUiosjk0zp7xeaFBWI3nfLP+e7,H5ve/jbSPBA:7ZuruStrE\nu5CgF362DPGXTWOfdfPaypxsRLJrBp5TY+8UO66OhachMwzXWuwiIB5dXurDpedDC9NVVd3YPHBtPsLs\nv9GNM0lFXac4h3uD7ITzrOffnXKHD89ZRY7v1lRmy0PyOkIReo6Flu58mcbt66,5XYeRzLGBza7LUZts\nGcRRs6kuDb3d5PfeK+6p0yr2U+ohiUnpB66EX3:ry9sgYUsWhMmKIT7tBYO9JIgVoinOhiCQ9y[3Ge52\n8Vr4DNMs8c1u{gH/oZMo9mb6XE1tsJiw7Ekk0HC/xn8y9rjque[1dQglPm68SXYvB2OpeB0HTLyrQ+fp\n1sESG5[HmgBtMFmncEVkq7qhk2J9Wwn4mPTUFE7ZJZM74Nb1o0Gact7xlInFb7sM9DmdG/YbmLGM818z\nwF4cIBRhN5VI2Y9UBsXiR+uC3mjF7M:6NaPEyjr30eKM3E04CBCys7c3iyFb6Xmt2mmd4RYwZJ{H{yHN\njwuJbsHTPgR5ebxu4qt/eDQ5xSz97MXi,51GCQHZXLMiqYNDCjIctG9J4ApgEi{81KfBjFSO2qlMsAkV\nX3VqZc[56Wg3NzEtFIZXkYUp97:ryAd2SCF+MwXSkicisNYOyL4jov6/Epd+h4mEyjiDg8gmnHNabYba\nln8SJ0[FDukUXcfh0w3yHzKMRrw7H3PRnNcTMSGuv5inKVTp5cjO:3CwbtEwnhTb2D97D7I+nv2srZGI\njYf5[OCyqtgPPSb+wMVJGH2juW11F5G3iI0fSfMyv6Qcb1eDHLcfCl34{BgKuc2yz1GYsb5III{llWnk\nsnRgUaGEHjsP:LzXrUJ8uEnnsDzPFTPZF8cd3re6lzGhTlU4Qts13+QreDOI,4UlkOR19PJSYNF3ISdc\nY8gmjVU5CoBFvuPeMtmhTt:3,JPulPQS1sM+3K2jliV69ZHowUhk4kOqTR9R5/9I5Veizc5+dKmBfBVw\nOUxNJT3BiCMbpW0aBMicm7MMCcQXXU4WIp[RrlbICSof6siAVP{eqJXsSg{wyuBbptM630reTRekcxXJ\nTrzber8q,YlfS552iQYc{HL6IskSJvBNCBdmTMDKfYJwFHvu0WC0:NyfQw1D:MsxY0gxtn4spZ9AjT1B\nMs,k{LPqZyeag8cJ{QdwlrcCZB5w05VjRwvey0fCH8E/LSJO2x7WMVbIz7fzQt2tpCZshX4ps/rnr7RZ\nZtQ1pbfwuLRDURXw,EFXpnxodQIHPEwQxOI8{4rlMDOkH361,YE/U2hi6t59qWvy423tIYrH5cXLcOB8\nrJGu0yzGFfvNQZHmXeCeJDliPBjfpgT0jPx1WGYJf1ckt4WGrjw67pctMF2MHcGVXk27HbTeGrB9lh0Y\ngbJ6lGUWelS/VP32t0lqlgUTqpWfKFNVLsWxU/w73RDkHRDOFrjkLjzVJ1HNPHvmqlsi8mVmWjr97Ggs\nOcXx7xRPxdXw,0PRSJbPoeYgRFEQeX[5HX7ApMBG3Zv1PTf6X1EbTP897fTS65haPjdKRTrsPa5e0Rxe\nu4vbjnVHwZi7g3HnWH:/bGUggM4hZrkak2KTpXV4bqWFMBiAbYkZEYE3GKY0eHdM6G9M9A4FgTYxw9J9\nQKPUcBFMRYKWpdvvxblW:jSKzasP08FBMgwC9e2NOtuoLPZLsNWmjr,Ss0UsXaNmBYgG[VHB8DwmWdmB\nF3viGqV4yLqWnxMozQ7nKESCTW:fGnYUVW{RzJXxkudKjEcz,26+5kudHlSHkSiGx7i1Gu0f0kfFz/u3\n61WySweagY1Q:6MOZY3yBd2oe/HvpJQzY2WBbbfDg2OXS6fT8J,p04t8TLPv6xFxD+oImkYDRSFXNGqx\nX+TW:cYXybm0UldJ,ZF58kdhcuXAqyuWj6zmljewbs8q{pp5PeybHpKPK0sxpMno1bbwI/5+{tRac0eg\nUc35k/jokzhXdKDMpS9Q[JixM1e/culkCr0MmFoEN5lz[xrBo3esRZPpQyVvvM1HUnz0lzYy3443db[n\nGbsCdkmHN+jijWW9nmgHul0A5H0P0FswrW7oySntYqjUXu9KVYQbHEHxlh[Z2tT7w9QeXpyw5ORnlCqz\n[+zexzxCcjq7L9[BjIS6hRuZ928Ke410nMnffMZimFDDwzmsceRW86{1EqT/7iPh[2h6FTE59uLiM3Hh\nj/9bRBKfJe[20YR1c/LflfqEyXB4eC1i8sWlb/Q2EQf6e7TsiEvuE9QrpwO8nnLeSc5LVO1znf3wedh6\nhSSqJqnfTv:tTOv7rhuZByDnRjhGejVZBtNqPBwmIC1YEpJW4U271J9+HEIaQnn5fmsndAlafJLB[PIL\nZe{kRtM8e5oIKIWV,4zY5Scgi1vtTkSuG1YXsZ{c{2P42sXzzj2OMbC+3OIGgrOmCaHGgUeE6oH9EtGG\nMzN0Cm7mZ19wF0cOJrNK0A6jompbEMGJbI,eIyuhL69z7NtP[8h/BOXlDC70YpVs8s8LlgQU43retgGl\nJqHVrG[WWP[O2p15Z/eD[qDk6ae6is9oj1087ZdQZd6ptL5NexKH1OWrjxq1HreDl+oK9FOZ1pQbP1gj\nTPH4gm287z28LwmH:gz/qcPf9jLZqzgKqbeMCM[Xg55gxiGKn7{2QHBQbWtOySJXjXQ55Qgm10rAJNKG\nLFDygiuc8zRdFqSYYNg9VOrOJzqP{d4ho6eE8Y6Z3XC/{6p/u18VslQYzOvZxqsUXCxgtcPFS/qndseU\nbnNN[imCBSwX:+0RC591F4c6Gbp05TFPSxqrtoUYsWin5cbn8yGBTvvmCieVNlBR0SwwnmvxOxuyJ6dO\nCMvaKnlWHjTpy/MmS4bvM0grGOXvQVHE[nkjJdwqGb6YVd25V0KmKcZDKESupciN6G8uYpzne1ZB,PUV\nbdW8x+x4kzF+FVoTqk1xfXxgCkx148frrDG5,3qi4JFUrXl59Nc26Pe1,m,8XX977gWejE8UFd9qFyEK\ncEsSlRinU9o5Hw:luMGI6FZ9Zan3qKp5hTGookMOTQjGWnMERtwqUjb/cFEYTF6mt1HQpAo+J18L09pV\ndEks11SIYDb0Ol,6rLxK,2BNvCTD7quXSm2AxNd3:MwBVsz4oWtaoPXVledphBk0dEBUKX6qmGGFdlfz\niith[7WD[xhFdHOSoQ,dhrZVHIiYNKOBm7O6WjTmUvKCCR0KS6:sqVPCYUp27kFEEpus5aeF{/uajLPh\n89[fYZxGXRltpdqQ[jzs9ZtNH/BhxP,jbfsRs/cgCP,yMzEN6nwIGVJ+xwnSit[3liQhjQUe0r3Zw2V7\nQiLvknr4V1mYEoSuzsXqC8d47sIjr4xtHeGFEwbV{5cAC6hoSK{tWsKUGwrSjwYzoswmgBwyHJmYrVGr\nu8S0rCC2X20sqoOE6KZA8XOTLeYm8lmCF1IE7Mh2[aIDRqtf8MreKoVID6E8z7zqRKzY0dwDIv5XpChh\ngxQhwbCXsI61P+PlRRQrxS:j2IOzzShaOTvMeszurA69{3Hew3DevX9Wc0{6FlzSVHDcMcTQXwgEkCKm\nDWOg,bLqM/QDUGlKg2sPwnUuUirBmKCmNs0wWfsFf24FNUeZl0eLRMyYIX1V1TPI4m:JBAiuQHYfqY{6\nFTqUmKYumeREy/8C5hc330naTafxo/PYSAWwE1y1k/G0jE[7twZgUFI6X6m7OHM+6Q:cJJ\" @ file+0x193D4\n\nencrypt data using chaskey\nnamespace   data-manipulation/encryption/chaskey                                \nauthor      still@teamt5.org                                                    \nscope       function                                                            \natt&ck      Defense Evasion::Obfuscated Files or Information [T1027]            \nmbc         Defense Evasion::Obfuscated Files or                                \n            Information::Encryption-Standard Algorithm [E1027.m05]              \nreferences  https://mouha.be/chaskey/,                                          \n            https://github.com/TheWover/donut/blob/47758d787209dd1744f58c140102…\nfunction @ 0x402AAF\n  and:\n    match: contain loop @ 0x402AAF\n      or:\n        characteristic: loop @ 0x402AAF\n        characteristic: recursive call @ 0x402AAF\n    instruction:\n      and:\n        number: 0xD @ 0x4032A0\n        or:\n          mnemonic: shl @ 0x4032A0\n    instruction:\n      and:\n        number: 0x8 @ 0x402B4B\n        or:\n          mnemonic: shl @ 0x402B4B\n    instruction:\n      and:\n        number: 0x7 @ 0x402CA9\n        or:\n          mnemonic: shl @ 0x402CA9\n    instruction:\n      and:\n        number: 0x5 @ 0x403528\n        or:\n          mnemonic: shl @ 0x403528\n      and:\n        number: 0x5 @ 0x40535B\n        or:\n          mnemonic: shl @ 0x40535B\n    count(characteristic(nzxor)): 6 or more @ 0x402ADC, 0x402AFB, 0x402B0A, 0x402B4E, and 174 more...\n\nresolve function by parsing PE exports (2 matches)\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x4094B1\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x4094B1\n      mnemonic: movzx @ 0x4097DA, 0x4097E1, 0x4099B1, 0x4099B5, and 54 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x40A5AF, 0x40A7A7, 0x40AAB5, 0x40AFAE\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x40B067, 0x40B097\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x40A44E, 0x40A4A2, 0x40A539, 0x40A5DF, and 12 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x40A635, 0x40A8FC, 0x40AFDA\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x40A676, 0x40A71E, 0x40A9D8, 0x40AAC3, and 5 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x40A4B8, 0x40A5A3, 0x40A623, 0x40A7C4, and 8 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x40A558, 0x40A560, 0x40A564, 0x40A5B7, and 8 more...\nfunction @ 0x40A3B6\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x40A3B6\n      mnemonic: movzx @ 0x40A7E6, 0x40A883, 0x40AAFD, 0x40AB09, and 19 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x40A5AF, 0x40A7A7, 0x40AAB5, 0x40ACA7, and 2 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x40AC70, 0x40B067, 0x40B097\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x40A44E, 0x40A4A2, 0x40A539, 0x40A5DF, and 21 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x40A635, 0x40A8FC, 0x40AFDA, 0x40B766, and 1 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x40A676, 0x40A71E, 0x40A9D8, 0x40AAC3, and 12 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x40A4B8, 0x40A5A3, 0x40A623, 0x40A7C4, and 21 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x40A558, 0x40A560, 0x40A564, 0x40A5B7, and 19 more...\n\n\n\n"},"hashes":{"md5":"ea039a854d20d7734c5add48f1a51c34","sha1":"9615dca4c0e46b8a39de5428af7db060399230b2","sha256":"69e966e730557fde8fd84317cdef1ece00a8bb3470c0b58f3231e170168af169"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 80</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 10073</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"ZeusBan\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"ea039a854d20d7734c5add48f1a51c34\",\n        \"sha256\": \"69e966e730557fde8fd84317cdef1ece00a8bb3470c0b58f3231e17\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__11_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (11 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x40113B\",\n      \"label\": \"Function 0x40113B\",\n      \"type\": \"function\",\n      \"address\": \"0x40113B\"\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_vmware\",\n      \"label\": \"reference anti-VM strings targeting VMWare\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com___johnk3r\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, @johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_chaskey\",\n      \"label\": \"encrypt data using chaskey\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or\",\n        \"Information::Encryption-Standard Algorithm [E1027.m05]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402AAF\",\n      \"label\": \"Function 0x402AAF\",\n      \"type\": \"function\",\n      \"address\": \"0x402AAF\"\n    },\n    {\n      \"id\": \"cap_author______still_teamt5_org\",\n      \"label\": \"author      still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or\",\n        \"Information::Encryption-Standard Algorithm [E1027.m05]\"\n      ]\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports__2_matches_\",\n      \"label\": \"resolve function by parsing PE exports (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x4094B1\",\n      \"label\": \"Function 0x4094B1\",\n      \"type\": \"function\",\n      \"address\": \"0x4094B1\"\n    },\n    {\n      \"id\": \"func_0x40A3B6\",\n      \"label\": \"Function 0x40A3B6\",\n      \"type\": \"function\",\n      \"address\": \"0x40A3B6\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__11_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__11_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x40113B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_vmware\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com___johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_chaskey\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_chaskey\",\n      \"target\": \"func_0x402AAF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______still_teamt5_org\",\n      \"target\": \"func_0x402AAF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__2_matches_\",\n      \"target\": \"func_0x4094B1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__2_matches_\",\n      \"target\": \"func_0x40A3B6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x4094B1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x40A3B6\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 23:05:53.456198\",\n    \"total_functions\": \"80\",\n    \"total_features\": \"10073\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 23:05:54"}
{"_id":{"$oid":"6a4fe3c00108394cb24cdd00"},"sha256":"d765e722e295969c0a5c2d90f549db8b89ab617900bf4698db41c7cdad993bb9","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_c9wrn0xf/CryptoLocker_10Sep2013-019f46ccb6b079d0991fddbe54ea2e93.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_c9wrn0xf/CryptoLocker_10Sep2013-019f46ccb6b079d0991fddbe54ea2e93.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_c9wrn0xf/CryptoLocker_10Sep2013-019f46ccb6b079d0991fddbe54ea2e93.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 04fb36199787f2e3e2135611a38321eb                                  │\n│ sha1     │ 65559245709fe98052eb284577f1fd61c01ad20d                          │\n│ sha256   │ d765e722e295969c0a5c2d90f549db8b89ab617900bf4698db41c7cdad993bb9  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/CryptoLocker_10S… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Clipboard Data [T1115]                                │\n│                      │ Input Capture::Keylogging [T1056.001]                 │\n│ DEFENSE EVASION      │ File and Directory Permissions Modification [T1222]   │\n│                      │ Hide Artifacts::Hidden Window [T1564.003]             │\n│                      │ Modify Registry [T1112]                               │\n│                      │ Obfuscated Files or Information [T1027]               │\n│ DISCOVERY            │ File and Directory Discovery [T1083]                  │\n│                      │ Query Registry [T1012]                                │\n│                      │ System Information Discovery [T1082]                  │\n│                      │ System Location Discovery::System Language Discovery  │\n│                      │ [T1614.001]                                           │\n│ EXECUTION            │ Command and Scripting Interpreter [T1059]             │\n│                      │ Shared Modules [T1129]                                │\n│ PERSISTENCE          │ Boot or Logon Autostart Execution::Registry Run Keys  │\n│                      │ / Startup Folder [T1547.001]                          │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Keylogging::Polling [F0002.002]                       │\n│ COMMUNICATION        │ HTTP Communication::Create Request [C0002.012]        │\n│                      │ HTTP Communication::Get Response [C0002.017]          │\n│                      │ HTTP Communication::Read Header [C0002.014]           │\n│                      │ HTTP Communication::Set Header [C0002.013]            │\n│                      │ HTTP Communication::WinHTTP [C0002.008]               │\n│ CRYPTOGRAPHY         │ Cryptographic Hash [C0029]                            │\n│                      │ Cryptographic Hash::SHA1 [C0029.002]                  │\n│                      │ Decrypt Data [C0031]                                  │\n│                      │ Encrypt Data [C0027]                                  │\n│                      │ Encrypt Data::AES [C0027.001]                         │\n│                      │ Encryption Key [C0028]                                │\n│                      │ Encryption Key::Import Public Key [C0028.001]         │\n│                      │ Generate Pseudo-random Sequence [C0021]               │\n│ DATA                 │ Encode Data::XOR [C0026.002]                          │\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Encoding-Standard    │\n│                      │ Algorithm [E1027.m02]                                 │\n│                      │ Obfuscated Files or Information::Encryption-Standard  │\n│                      │ Algorithm [E1027.m05]                                 │\n│ DISCOVERY            │ Application Window Discovery [E1010]                  │\n│                      │ File and Directory Discovery [E1083]                  │\n│                      │ System Information Discovery [E1082]                  │\n│ EXECUTION            │ Command and Scripting Interpreter [E1059]             │\n│ FILE SYSTEM          │ Copy File [C0045]                                     │\n│                      │ Delete File [C0047]                                   │\n│                      │ Get File Attributes [C0049]                           │\n│                      │ Move File [C0063]                                     │\n│                      │ Read File [C0051]                                     │\n│                      │ Set File Attributes [C0050]                           │\n│                      │ Writes File [C0052]                                   │\n│ IMPACT               │ Clipboard Modification [E1510]                        │\n│ OPERATING SYSTEM     │ Registry::Delete Registry Key [C0036.002]             │\n│                      │ Registry::Delete Registry Value [C0036.007]           │\n│                      │ Registry::Query Registry Key [C0036.005]              │\n│                      │ Registry::Query Registry Value [C0036.006]            │\n│                      │ Registry::Set Registry Key [C0036.001]                │\n│ PERSISTENCE          │ Registry Run Keys / Startup Folder [F0012]            │\n│ PROCESS              │ Check Mutex [C0043]                                   │\n│                      │ Create Mutex [C0042]                                  │\n│                      │ Create Process [C0017]                                │\n│                      │ Create Thread [C0038]                                 │\n│                      │ Resume Thread [C0054]                                 │\n│                      │ Terminate Process [C0018]                             │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ inspect load icon resource            │ anti-analysis                        │\n│ log keystrokes via polling (2         │ collection/keylog                    │\n│ matches)                              │                                      │\n│ initialize WinHTTP library            │ communication/http                   │\n│ read HTTP header                      │ communication/http                   │\n│ set HTTP header                       │ communication/http                   │\n│ prepare HTTP request                  │ communication/http/client            │\n│ receive HTTP response (2 matches)     │ communication/http/client            │\n│ encode data using XOR (15 matches)    │ data-manipulation/encoding/xor       │\n│ create new key via                    │ data-manipulation/encryption         │\n│ CryptAcquireContext (2 matches)       │                                      │\n│ encrypt or decrypt via WinCrypt (4    │ data-manipulation/encryption         │\n│ matches)                              │                                      │\n│ import public key                     │ data-manipulation/encryption         │\n│ encrypt data using AES via WinAPI (2  │ data-manipulation/encryption/aes     │\n│ matches)                              │                                      │\n│ reference public RSA key              │ data-manipulation/encryption/rsa     │\n│ hash data via WinCrypt                │ data-manipulation/hashing            │\n│ hash data using SHA1                  │ data-manipulation/hashing/sha1       │\n│ hash data using SHA1 via WinCrypt     │ data-manipulation/hashing/sha1       │\n│ generate random numbers using a       │ data-manipulation/prng/mersenne      │\n│ Mersenne Twister (3 matches)          │                                      │\n│ extract resource via kernel32         │ executable/resource                  │\n│ functions (2 matches)                 │                                      │\n│ accept command line arguments (2      │ host-interaction/cli                 │\n│ matches)                              │                                      │\n│ write clipboard data                  │ host-interaction/clipboard           │\n│ query environment variable (2         │ host-interaction/environment-variab… │\n│ matches)                              │                                      │\n│ get common file path (3 matches)      │ host-interaction/file-system         │\n│ get file system object information    │ host-interaction/file-system         │\n│ copy file                             │ host-interaction/file-system/copy    │\n│ delete file (4 matches)               │ host-interaction/file-system/delete  │\n│ enumerate files recursively           │ host-interaction/file-system/files/… │\n│ get file attributes                   │ host-interaction/file-system/meta    │\n│ get file size (2 matches)             │ host-interaction/file-system/meta    │\n│ set file attributes (7 matches)       │ host-interaction/file-system/meta    │\n│ move file                             │ host-interaction/file-system/move    │\n│ read file on Windows (2 matches)      │ host-interaction/file-system/read    │\n│ write file on Windows (4 matches)     │ host-interaction/file-system/write   │\n│ get graphical window text (2 matches) │ host-interaction/gui/window/get-text │\n│ hide graphical window (5 matches)     │ host-interaction/gui/window/hide     │\n│ get disk information (2 matches)      │ host-interaction/hardware/storage    │\n│ get disk size (2 matches)             │ host-interaction/hardware/storage    │\n│ check mutex on Windows                │ host-interaction/mutex               │\n│ get hostname                          │ host-interaction/os/hostname         │\n│ create process on Windows (5 matches) │ host-interaction/process/create      │\n│ terminate process                     │ host-interaction/process/terminate   │\n│ query or enumerate registry key       │ host-interaction/registry            │\n│ query or enumerate registry value (8  │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ delete registry key                   │ host-interaction/registry/delete     │\n│ delete registry value (2 matches)     │ host-interaction/registry/delete     │\n│ create thread                         │ host-interaction/thread/create       │\n│ resume thread                         │ host-interaction/thread/resume       │\n│ link function at runtime on Windows   │ linking/runtime-linking              │\n│ (6 matches)                           │                                      │\n│ resolve function by parsing PE        │ load-code/pe                         │\n│ exports (3 matches)                   │                                      │\n│ persist via Run registry key (4       │ persistence/registry/run             │\n│ matches)                              │                                      │\n│ identify system language via API      │ targeting/language                   │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     04fb36199787f2e3e2135611a38321eb                        \nsha1                    65559245709fe98052eb284577f1fd61c01ad20d                \nsha256                  d765e722e295969c0a5c2d90f549db8b89ab617900bf4698db41c7c…\npath                    /home/apogean/projects/malware/windows/all_runs/CryptoL…\ntimestamp               2026-07-09 23:38:51.279962                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIFlqYZ6/rules                                   \nfunction count          322                                                     \nlibrary function count  6                                                       \ntotal feature count     23090                                                   \n\ninspect load icon resource\nnamespace  anti-analysis\nscope      basic block  \nmatches    0x40DD10     \n\nlog keystrokes via polling (2 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    0x4067F0         \n           0x407140         \n\ninitialize WinHTTP library\nnamespace  communication/http\nscope      function          \nmatches    0x408250          \n\nread HTTP header\nnamespace  communication/http\nscope      function          \nmatches    0x408640          \n\nset HTTP header\nnamespace  communication/http\nscope      function          \nmatches    0x408340          \n\nprepare HTTP request\nnamespace  communication/http/client\nscope      function                 \nmatches    0x408340                 \n\nreceive HTTP response (2 matches)\nnamespace  communication/http/client\nscope      function                 \nmatches    0x407470                 \n           0x408410                 \n\nencode data using XOR (15 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x4019E0                      \n           0x403170                      \n           0x404F71                      \n           0x404FC0                      \n           0x405010                      \n           0x407AE0                      \n           0x407B12                      \n           0x40A160                      \n           0x40AA00                      \n           0x40E9D1                      \n           0x40F0A0                      \n           0x40FE96                      \n           0x4102E1                      \n           0x410440                      \n           0x410521                      \n\ncreate new key via CryptAcquireContext (2 matches)\nnamespace  data-manipulation/encryption\nscope      basic block                 \nmatches    0x404642                    \n           0x404748                    \n\nencrypt or decrypt via WinCrypt (4 matches)\nnamespace  data-manipulation/encryption\nscope      function                    \nmatches    0x4048F0                    \n           0x404960                    \n           0x404A50                    \n           0x404AC0                    \n\nimport public key\nnamespace  data-manipulation/encryption\nscope      function                    \nmatches    0x404720                    \n\nencrypt data using AES via WinAPI (2 matches)\nnamespace  data-manipulation/encryption/aes\nscope      function                        \nmatches    0x404040                        \n           0x407730                        \n\nreference public RSA key\nnamespace  data-manipulation/encryption/rsa\nscope      function                        \nmatches    0x40F280                        \n\nhash data via WinCrypt\nnamespace  data-manipulation/hashing\nscope      function                 \nmatches    0x404D60                 \n\ninitialize hashing via WinCrypt\nnamespace  data-manipulation/hashing\nscope      function                 \nmatches    0x404D60                 \n\nhash data using SHA1\nnamespace  data-manipulation/hashing/sha1\nscope      function                      \nmatches    0x404D60                      \n\nhash data using SHA1 via WinCrypt\nnamespace  data-manipulation/hashing/sha1\nscope      function                      \nmatches    0x404D60                      \n\ngenerate random numbers using a Mersenne Twister (3 matches)\nnamespace  data-manipulation/prng/mersenne\nscope      function                       \nmatches    0x404F60                       \n           0x404FA0                       \n           0x4079E0                       \n\nextract resource via kernel32 functions (2 matches)\nnamespace  executable/resource\nscope      function           \nmatches    0x40A760           \n           0x40BB20           \n\naccept command line arguments (2 matches)\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x4010C0            \n           0x401D60            \n\nopen clipboard\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x408D30                  \n\nwrite clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x408D30                  \n\nquery environment variable (2 matches)\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x402380                             \n           0x40E720                             \n\nget common file path (3 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x402380                    \n           0x4050C0                    \n           0x405880                    \n\nget file system object information\nnamespace  host-interaction/file-system\nscope      basic block                 \nmatches    0x40DF83                    \n\ncopy file\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    0x40E990                         \n\ndelete file (4 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x401000                           \n           0x405550                           \n           0x40E720                           \n           0x40E990                           \n\nenumerate files on Windows\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x405570                               \n\nenumerate files recursively\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x405570                               \n\nget file attributes\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x40458A                         \n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x403EB0                         \n           0x404040                         \n\nset file attributes (7 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x401010                         \n           0x4045DC                         \n           0x405550                         \n           0x40E8CD                         \n           0x40EA50                         \n           0x40EA97                         \n           0x40EB87                         \n\nmove file\nnamespace  host-interaction/file-system/move\nscope      function                         \nmatches    0x404420                         \n\nread file on Windows (2 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x403C80                         \n           0x405250                         \n\nwrite file on Windows (4 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x403D70                          \n           0x403EB0                          \n           0x404040                          \n           0x40E720                          \n\nget graphical window text (2 matches)\nnamespace  host-interaction/gui/window/get-text\nscope      function                            \nmatches    0x40CFD0                            \n           0x40DD10                            \n\nhide graphical window (5 matches)\nnamespace  host-interaction/gui/window/hide\nscope      basic block                     \nmatches    0x40A7EF                        \n           0x40A843                        \n           0x40B911                        \n           0x40D476                        \n           0x40D7B0                        \n\nget disk information (2 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x402F90                         \n           0x403070                         \n\nget disk size (2 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x402F90                         \n           0x403070                         \n\ncheck mutex on Windows\nnamespace  host-interaction/mutex\nscope      function              \nmatches    0x401990              \n\ncreate or open mutex on Windows (2 matches)\nnamespace  host-interaction/mutex\nscope      instruction           \nmatches    0x401A39              \n           0x410333              \n\nget hostname\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    0x4013E0                    \n\ncreate process on Windows (5 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x401910                       \n           0x401966                       \n           0x408F4D                       \n           0x40EAF2                       \n           0x41014D                       \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x401E00                          \n\nquery or enumerate registry key\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x4093A0                 \n\nquery or enumerate registry value (8 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x403070                 \n           0x409140                 \n           0x4092A0                 \n           0x40A070                 \n           0x40A760                 \n           0x40EFD0                 \n           0x410370                 \n           0x410770                 \n\nset registry value (5 matches)\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x409010                        \n           0x4090C0                        \n           0x40F3D0                        \n           0x40F790                        \n           0x4104F0                        \n\ndelete registry key\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x409340                        \n\ndelete registry value (2 matches)\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x40EBC0                        \n           0x410830                        \n\ncreate thread\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x409577                      \n\nresume thread\nnamespace  host-interaction/thread/resume\nscope      basic block                   \nmatches    0x409593                      \n\nlink function at runtime on Windows (6 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x4052B4               \n           0x405334               \n           0x405965               \n           0x408185               \n           0x409363               \n           0x40EC7A               \n\nresolve function by parsing PE exports (3 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x4033B0    \n           0x403403    \n           0x40CFD0    \n\npersist via Run registry key (4 matches)\nnamespace  persistence/registry/run\nscope      function                \nmatches    0x4021F0                \n           0x409010                \n           0x409010                \n           0x40EBC0                \n\nidentify system language via API\nnamespace  targeting/language\nscope      function          \nmatches    0x40EC60          \n\n\n\n","very_verbose":"md5                     04fb36199787f2e3e2135611a38321eb                        \nsha1                    65559245709fe98052eb284577f1fd61c01ad20d                \nsha256                  d765e722e295969c0a5c2d90f549db8b89ab617900bf4698db41c7c…\npath                    /home/apogean/projects/malware/windows/all_runs/CryptoL…\ntimestamp               2026-07-09 23:39:02.862203                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEI3AWib8/rules                                   \nfunction count          322                                                     \nlibrary function count  6                                                       \ntotal feature count     23090                                                   \n\ncontain loop (91 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401000\n  or:\n    characteristic: loop @ 0x401000\n\ncreate or open file (4 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x4026EA\n  or:\n    api: CreateFile @ 0x4026EA\n\ncreate or open registry key (18 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x40226D in function 0x4021F0\n  or:\n    api: RegOpenKeyEx @ 0x4022A2\n\ndelay execution (57 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x401036 in function 0x401000\n  or:\n    and:\n      os: windows\n      or:\n        api: WaitForSingleObject @ 0x401043\n\ninspect load icon resource\nnamespace  anti-analysis               \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ 0x40DD10 in function 0x40DD10\n  and:\n    api: LoadIcon @ 0x40DD42\n    number: 0x0 @ 0x40DD50, 0x40DDB5\n    mnemonic: test @ 0x40DDC4\n    not:\n      or: = predefined icon identifiers\n        number: 0x7F05 = IDI_WINLOGO\n        number: 0x7F06 = IDI_SHIELD\n        number: 0x7F02 = IDI_QUESTION\n        number: 0x7F00 = IDI_APPLICATION\n        number: 0x7F04 = (IDI_ASTERISK | IDI_INFORMATION)\n        number: 0x7F01 = (IDI_ERROR | IDI_HAND)\n        number: 0x7F03 = (IDI_EXCLAMATION | IDI_WARNING)\n\nlog keystrokes via polling (2 matches)\nnamespace  collection/keylog                                \nauthor     michael.hunhoff@mandiant.com                     \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nmbc        Collection::Keylogging::Polling [F0002.002]      \nfunction @ 0x4067F0\n  or:\n    api: GetKeyState @ 0x406994, 0x4069A6\nfunction @ 0x407140\n  or:\n    api: GetKeyState @ 0x4071E4, 0x4071F2, 0x407200\n\ninitialize WinHTTP library\nnamespace  communication/http                                    \nauthor     michael.hunhoff@mandiant.com                          \nscope      function                                              \nmbc        Communication::HTTP Communication::WinHTTP [C0002.008]\nfunction @ 0x408250\n  and:\n    api: WinHttpOpen @ 0x408293\n\nread HTTP header\nnamespace  communication/http                                           \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Read Header [C0002.014]   \nfunction @ 0x408640\n  or:\n    api: WinHttpQueryHeaders @ 0x408667\n\nset HTTP header\nnamespace  communication/http                                           \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Set Header [C0002.013]    \nfunction @ 0x408340\n  or:\n    api: WinHttpAddRequestHeaders @ 0x4083AF\n\nprepare HTTP request\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com                                 \nscope      function                                                     \nmbc        Communication::HTTP Communication::Create Request [C0002.012]\nfunction @ 0x408340\n  or:\n    api: WinHttpOpenRequest @ 0x408391\n\nreceive HTTP response (2 matches)\nnamespace  communication/http/client                                  \nauthor     michael.hunhoff@mandiant.com                               \nscope      function                                                   \nmbc        Communication::HTTP Communication::Get Response [C0002.017]\nfunction @ 0x407470\n  or:\n    api: WinHttpReceiveResponse @ 0x4075C8\nfunction @ 0x408410\n  or:\n    and:\n      api: WinHttpReadData @ 0x4084DE\n\nencode data using XOR (15 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x4019E0 in function 0x401990\n  and:\n    characteristic: tight loop @ 0x4019E0\n    characteristic: nzxor @ 0x4019F4, 0x4019FE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403170 in function 0x403070\n  and:\n    characteristic: tight loop @ 0x403170\n    characteristic: nzxor @ 0x403170\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404F71 in function 0x404F60\n  and:\n    characteristic: tight loop @ 0x404F71\n    characteristic: nzxor @ 0x404F76\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404FC0 in function 0x404FA0\n  and:\n    characteristic: tight loop @ 0x404FC0\n    characteristic: nzxor @ 0x404FC7, 0x404FD5, 0x404FE3, 0x404FEA\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405010 in function 0x404FA0\n  and:\n    characteristic: tight loop @ 0x405010\n    characteristic: nzxor @ 0x405012, 0x40501E, 0x40502F, 0x405035\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407AE0 in function 0x4079E0\n  and:\n    characteristic: tight loop @ 0x407AE0\n    characteristic: nzxor @ 0x407AE5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407B12 in function 0x4079E0\n  and:\n    characteristic: tight loop @ 0x407B12\n    characteristic: nzxor @ 0x407B17\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x40A160 in function 0x40A070\n  and:\n    characteristic: tight loop @ 0x40A160\n    characteristic: nzxor @ 0x40A160\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x40AA00 in function 0x40A760\n  and:\n    characteristic: tight loop @ 0x40AA00\n    characteristic: nzxor @ 0x40AA00\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x40E9D1 in function 0x40E990\n  and:\n    characteristic: tight loop @ 0x40E9D1\n    characteristic: nzxor @ 0x40E9E5, 0x40E9EC\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x40F0A0 in function 0x40EFD0\n  and:\n    characteristic: tight loop @ 0x40F0A0\n    characteristic: nzxor @ 0x40F0A0\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x40FE96 in function 0x40FDD0\n  and:\n    characteristic: tight loop @ 0x40FE96\n    characteristic: nzxor @ 0x40FE9F, 0x40FEAD, 0x40FEB5, 0x40FEC1, and 5 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4102E1 in function 0x4102A0\n  and:\n    characteristic: tight loop @ 0x4102E1\n    characteristic: nzxor @ 0x4102F5, 0x4102FC\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x410440 in function 0x410370\n  and:\n    characteristic: tight loop @ 0x410440\n    characteristic: nzxor @ 0x410440\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x410521 in function 0x4104F0\n  and:\n    characteristic: tight loop @ 0x410521\n    characteristic: nzxor @ 0x410521\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\ncreate new key via CryptAcquireContext (2 matches)\nnamespace   data-manipulation/encryption                                        \nauthor      chuong.dong@mandiant.com                                            \nscope       basic block                                                         \natt&ck      Defense Evasion::Obfuscated Files or Information [T1027]            \nmbc         Cryptography::Encryption Key [C0028]                                \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/wincrypt/nf-winc…\nbasic block @ 0x404642 in function 0x404620\n  and:\n    api: CryptAcquireContext @ 0x404651\n    or:\n      number: 0x18 = CRYPT_NEWKEYSET | CRYPT_DELETEKEYSET @ 0x404647\nbasic block @ 0x404748 in function 0x404720\n  and:\n    api: CryptAcquireContext @ 0x404757\n    or:\n      number: 0x18 = CRYPT_NEWKEYSET | CRYPT_DELETEKEYSET @ 0x40474D\n\nencrypt or decrypt via WinCrypt (4 matches)\nnamespace  data-manipulation/encryption                                         \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Decrypt Data [C0031], Cryptography::Encrypt Data       \n           [C0027]                                                              \nfunction @ 0x4048F0\n  and:\n    or:\n      api: CryptEncrypt @ 0x404931\nfunction @ 0x404960\n  and:\n    or:\n      api: CryptEncrypt @ 0x404987\nfunction @ 0x404A50\n  and:\n    or:\n      api: CryptDecrypt @ 0x404A97\nfunction @ 0x404AC0\n  and:\n    or:\n      api: CryptDecrypt @ 0x404B54\n\nimport public key\nnamespace  data-manipulation/encryption                               \nauthor     william.ballenthin@mandiant.com                            \nscope      function                                                   \nmbc        Cryptography::Encryption Key::Import Public Key [C0028.001]\nfunction @ 0x404720\n  and:\n    api: CryptAcquireContext @ 0x404757, 0x404770\n    api: CryptImportPublicKeyInfo @ 0x4047A4\n\nencrypt data using AES via WinAPI (2 matches)\nnamespace  data-manipulation/encryption/aes                                     \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encryption-Standard\n           Algorithm [E1027.m05], Cryptography::Encrypt Data::AES [C0027.001]   \nfunction @ 0x404040\n  and:\n    or:\n      api: CryptGenKey @ 0x4040E1\n    or:\n      number: 0x6610 = CALG_AES_256 @ 0x4040A7\n    optional:\n      or:\n        number: 0x1 = PROV_RSA_FULL @ 0x4040D7, 0x404129, 0x40419E, 0x404227, and 1 more...\nfunction @ 0x407730\n  and:\n    or:\n      api: CryptGenKey @ 0x4077C2\n    or:\n      number: 0x660E = CALG_AES_128 @ 0x407791\n    optional:\n      or:\n        number: 0x1 = PROV_RSA_FULL @ 0x407757, 0x4077BA, 0x407865, 0x407893, and 1 more...\n\nreference public RSA key\nnamespace   data-manipulation/encryption/rsa                                    \nauthor      moritz.raabe@mandiant.com                                           \nscope       function                                                            \nmbc         Cryptography::Encryption Key [C0028]                                \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/wincrypt/ns-win…\n            https://learn.microsoft.com/en-us/windows/win32/api/wincrypt/ns-win…\nfunction @ 0x40F280\n  or:\n    bytes: 0602000000a4000052534131 @ 0x40F2BA\n\nhash data via WinCrypt\nnamespace  data-manipulation/hashing               \nauthor     michael.hunhoff@mandiant.com            \nscope      function                                \nmbc        Cryptography::Cryptographic Hash [C0029]\nfunction @ 0x404D60\n  and:\n    api: CryptHashData @ 0x404DDF\n\ninitialize hashing via WinCrypt\nnamespace  data-manipulation/hashing   \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x404D60\n  and:\n    api: CryptCreateHash @ 0x404DB4\n\nhash data using SHA1\nnamespace  data-manipulation/hashing/sha1                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           william.ballenthin@mandiant.com                                      \nscope      function                                                             \nmbc        Cryptography::Cryptographic Hash::SHA1 [C0029.002]                   \nfunction @ 0x404D60\n  or:\n    basic block:\n      and:\n        number: 0x8004 = CALG_SHA1 @ 0x404DAD\n        api: CryptCreateHash @ 0x404DB4\n\nhash data using SHA1 via WinCrypt\nnamespace  data-manipulation/hashing/sha1\nauthor     michael.hunhoff@mandiant.com  \nscope      function                      \nfunction @ 0x404D60\n  or:\n    and:\n      match: initialize hashing via WinCrypt @ 0x404D60\n        and:\n          api: CryptCreateHash @ 0x404DB4\n      number: 0x8004 = CALG_SHA1 @ 0x404DAD\n      api: CryptHashData @ 0x404DDF\n\ngenerate random numbers using a Mersenne Twister (3 matches)\nnamespace  data-manipulation/prng/mersenne                      \nauthor     moritz.raabe@mandiant.com                            \nscope      function                                             \nmbc        Cryptography::Generate Pseudo-random Sequence [C0021]\nfunction @ 0x404F60\n  or:\n    number: 0x6C078965 @ 0x404F7B\nfunction @ 0x404FA0\n  or:\n    number: 0xFF3A58AD @ 0x40508D\nfunction @ 0x4079E0\n  or:\n    number: 0x6C078965 @ 0x407AEA, 0x407B1C\n\nextract resource via kernel32 functions (2 matches)\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x40A760\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x40A8A3\n        api: LockResource @ 0x40A8B2\n      optional:\n        or:\n          api: FindResourceEx @ 0x40A872\n        api: SizeofResource @ 0x40A888\nfunction @ 0x40BB20\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x40BB60\n        api: LockResource @ 0x40BB6B\n      optional:\n        or:\n          api: FindResourceEx @ 0x40BB38\n        api: SizeofResource @ 0x40BB4C\n\naccept command line arguments (2 matches)\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x4010C0\n  or:\n    api: CommandLineToArgv @ 0x4010D8\nfunction @ 0x401D60\n  or:\n    api: GetCommandLine @ 0x401D97\n\nopen clipboard\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ 0x408D30\n  and:\n    api: OpenClipboard @ 0x408D94\n    optional:\n      api: CloseClipboard @ 0x408DB2\n\nwrite clipboard data\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \nmbc         Impact::Clipboard Modification [E1510]                              \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ 0x408D30\n  and:\n    optional:\n      match: open clipboard @ 0x408D30\n        and:\n          api: OpenClipboard @ 0x408D94\n          optional:\n            api: CloseClipboard @ 0x408DB2\n      api: EmptyClipboard @ 0x408D9E\n    or:\n      api: SetClipboardData @ 0x408DA7\n\nquery environment variable (2 matches)\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x402380\n  or:\n    api: ExpandEnvironmentStrings @ 0x40241F\nfunction @ 0x40E720\n  or:\n    api: GetEnvironmentVariable @ 0x40E73D\n\nget common file path (3 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x402380\n  or:\n    api: GetTempPath @ 0x4023A2\nfunction @ 0x4050C0\n  or:\n    api: GetTempPath @ 0x4050DC\nfunction @ 0x405880\n  or:\n    api: SHGetFolderPath @ 0x4059A0\n\nget file system object information\nnamespace  host-interaction/file-system                   \nauthor     michael.hunhoff@mandiant.com                   \nscope      basic block                                    \natt&ck     Discovery::File and Directory Discovery [T1083]\nbasic block @ 0x40DF83 in function 0x40DF60\n  or:\n    api: SHGetFileInfo @ 0x40DFBC\n\ncopy file\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ 0x40E990\n  or:\n    api: CopyFileEx @ 0x40EA89\n\ndelete file (4 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x401000\n  or:\n    api: DeleteFile @ 0x401020\nfunction @ 0x405550\n  or:\n    api: DeleteFile @ 0x405560\nfunction @ 0x40E720\n  or:\n    api: DeleteFile @ 0x40E8E6\nfunction @ 0x40E990\n  or:\n    api: DeleteFile @ 0x40EA6B, 0x40EB9C\n\nenumerate files on Windows\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ 0x405570\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x4055B6\n      or:\n        api: FindNextFile @ 0x405703\n      optional:\n        api: FindClose @ 0x405736\n        match: contain loop @ 0x405570\n          or:\n            characteristic: loop @ 0x405570\n            characteristic: recursive call @ 0x405570\n\nenumerate files recursively\nnamespace  host-interaction/file-system/files/list        \nauthor     @_re_fox, anushka.virgaonkar@mandiant.com      \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nmbc        Discovery::File and Directory Discovery [E1083]\nfunction @ 0x405570\n  and:\n    characteristic: recursive call @ 0x405570\n    or:\n      match: enumerate files on Windows @ 0x405570\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x4055B6\n            or:\n              api: FindNextFile @ 0x405703\n            optional:\n              api: FindClose @ 0x405736\n              match: contain loop @ 0x405570\n                or:\n                  characteristic: loop @ 0x405570\n                  characteristic: recursive call @ 0x405570\n\nget file attributes\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x40458A in function 0x404420\n  or:\n    api: GetFileAttributes @ 0x4045B7\n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x403EB0\n  or:\n    api: GetFileSizeEx @ 0x403F0C\nfunction @ 0x404040\n  or:\n    api: GetFileSizeEx @ 0x404064\n\nset file attributes (7 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ 0x401010 in function 0x401000\n  or:\n    api: SetFileAttributes @ 0x401019\nbasic block @ 0x4045DC in function 0x404420\n  or:\n    api: SetFileAttributes @ 0x4045E0\nbasic block @ 0x405550 in function 0x405550\n  or:\n    api: SetFileAttributes @ 0x405559\nbasic block @ 0x40E8CD in function 0x40E720\n  or:\n    api: SetFileAttributes @ 0x40E8D9\nbasic block @ 0x40EA50 in function 0x40E990\n  or:\n    api: SetFileAttributes @ 0x40EA62\nbasic block @ 0x40EA97 in function 0x40E990\n  or:\n    api: SetFileAttributes @ 0x40EAA0\nbasic block @ 0x40EB87 in function 0x40E990\n  or:\n    api: SetFileAttributes @ 0x40EB93\n\nmove file\nnamespace  host-interaction/file-system/move                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Move File [C0063]                         \nfunction @ 0x404420\n  or:\n    api: MoveFileEx @ 0x4045CE\n\nread file on Windows (2 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x403C80\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x403CB9\nfunction @ 0x405250\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x405275\n\nwrite file on Windows (4 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x403D70\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x403E34, 0x403E4E\nfunction @ 0x403EB0\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x403F30\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x403FF5\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x40401A\n      or:\n        api: WriteFile @ 0x403FC5\nfunction @ 0x404040\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x4042AA\nfunction @ 0x40E720\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x40E810\n\nget graphical window text (2 matches)\nnamespace  host-interaction/gui/window/get-text           \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \nmbc        Discovery::Application Window Discovery [E1010]\nfunction @ 0x40CFD0\n  or:\n    and:\n      api: GetWindowText @ 0x40CFEE\nfunction @ 0x40DD10\n  or:\n    and:\n      or:\n        basic block:\n          and:\n            number: 0xD = WM_GETTEXT @ 0x40DE0F\n            api: SendMessage @ 0x40DE3E, 0x40DE65\n\nhide graphical window (5 matches)\nnamespace  host-interaction/gui/window/hide                          \nauthor     michael.hunhoff@mandiant.com                              \nscope      basic block                                               \natt&ck     Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\nbasic block @ 0x40A7EF in function 0x40A760\n  and:\n    number: 0x0 = SW_HIDE @ 0x40A7EF, 0x40A816, 0x40A827\n    api: ShowWindow @ 0x40A7F5\nbasic block @ 0x40A843 in function 0x40A760\n  and:\n    number: 0x0 = SW_HIDE @ 0x40A843\n    api: ShowWindow @ 0x40A846\nbasic block @ 0x40B911 in function 0x40B670\n  and:\n    number: 0x0 = SW_HIDE @ 0x40B924, 0x40B926\n    api: ShowWindow @ 0x40B968\nbasic block @ 0x40D476 in function 0x40D430\n  and:\n    number: 0x0 = SW_HIDE @ 0x40D4A1\n    api: ShowWindow @ 0x40D4B7\nbasic block @ 0x40D7B0 in function 0x40D7B0\n  and:\n    number: 0x0 = SW_HIDE @ 0x40D7BB, 0x40D7CF, 0x40D7D1\n    api: ShowWindow @ 0x40D7C3\n\nget disk information (2 matches)\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ 0x402F90\n  or:\n    api: GetDriveType @ 0x402F9B\n    api: GetVolumeInformation @ 0x402FBC\nfunction @ 0x403070\n  or:\n    api: GetDriveType @ 0x40328C\n    api: GetLogicalDrives @ 0x403085\n    api: GetVolumeInformation @ 0x4032B6\n\nget disk size (2 matches)\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ 0x402F90\n  or:\n    api: GetDiskFreeSpaceEx @ 0x402FD8\nfunction @ 0x403070\n  or:\n    api: GetDiskFreeSpaceEx @ 0x4032D8\n\ncheck mutex on Windows\nnamespace  host-interaction/mutex                         \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      function                                       \nmbc        Process::Check Mutex [C0043]                   \nfunction @ 0x401990\n  or:\n    and:\n      match: create or open mutex on Windows @ 0x401A39\n        or:\n          api: CreateMutex @ 0x401A39\n      or:\n        basic block:\n          and:\n            api: GetLastError @ 0x401A4D\n            or:\n              number: 0xB7 = ERROR_ALREADY_EXISTS @ 0x401A53\n\ncreate or open mutex on Windows (2 matches)\nnamespace  host-interaction/mutex                                               \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           mehunhoff@google.com                                                 \nscope      instruction                                                          \nmbc        Process::Create Mutex [C0042]                                        \ninstruction @ 0x401A39\n  or:\n    api: CreateMutex @ 0x401A39\ninstruction @ 0x410333\n  or:\n    api: CreateMutex @ 0x410333\n\nget hostname\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ 0x4013E0\n  or:\n    api: GetComputerName @ 0x4014DD\n\ncreate process on Windows (5 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x401910 in function 0x401910\n  or:\n    api: ShellExecuteEx @ 0x401951\nbasic block @ 0x401966 in function 0x401910\n  or:\n    api: ShellExecuteEx @ 0x401971\nbasic block @ 0x408F4D in function 0x408F10\n  or:\n    api: CreateProcess @ 0x408F70\nbasic block @ 0x40EAF2 in function 0x40E990\n  or:\n    api: CreateProcess @ 0x40EB3A\nbasic block @ 0x41014D in function 0x4100E0\n  or:\n    api: CreateProcess @ 0x41019E\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x401E00\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x401E09\n\nquery or enumerate registry key\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ 0x4093A0\n  and:\n    optional:\n      match: create or open registry key @ 0x4093DD\n        or:\n          api: RegOpenKeyEx @ 0x4093E9\n    or:\n      api: RegEnumKeyEx @ 0x40946A, 0x40949C\n\nquery or enumerate registry value (8 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x403070\n  and:\n    optional:\n      match: create or open registry key @ 0x4030D0\n        or:\n          api: RegOpenKeyEx @ 0x403102\n    or:\n      api: RegQueryValueEx @ 0x40312C\nfunction @ 0x409140\n  and:\n    or:\n      api: RegQueryValueEx @ 0x409159, 0x4091EF, 0x409222\nfunction @ 0x4092A0\n  and:\n    or:\n      api: RegQueryValueEx @ 0x4092C4\nfunction @ 0x40A070\n  and:\n    optional:\n      match: create or open registry key @ 0x40A0CA\n        or:\n          api: RegOpenKeyEx @ 0x40A0F9\n    or:\n      api: RegQueryValueEx @ 0x40A122\nfunction @ 0x40A760\n  and:\n    optional:\n      match: create or open registry key @ 0x40A959\n        or:\n          api: RegOpenKeyEx @ 0x40A988\n    or:\n      api: RegQueryValueEx @ 0x40A9BA\nfunction @ 0x40EFD0\n  and:\n    optional:\n      match: create or open registry key @ 0x40F007\n        or:\n          api: RegOpenKeyEx @ 0x40F036\n    or:\n      api: RegQueryValueEx @ 0x40F060\nfunction @ 0x410370\n  and:\n    optional:\n      match: create or open registry key @ 0x4103AA\n        or:\n          api: RegOpenKeyEx @ 0x4103DC\n    or:\n      api: RegQueryValueEx @ 0x410400\nfunction @ 0x410770\n  and:\n    or:\n      api: RegEnumValue @ 0x41079A\n\nset registry value (5 matches)\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x409010\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x409010\n          or:\n            api: RegCreateKeyEx @ 0x40903E\n      or:\n        api: RegSetValueEx @ 0x409092\nfunction @ 0x4090C0\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x4090C0\n          or:\n            api: RegCreateKeyEx @ 0x4090F1\n      or:\n        api: RegSetValueEx @ 0x40910C\nfunction @ 0x40F3D0\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x40F586\n          or:\n            api: RegCreateKeyEx @ 0x40F5BB\n      or:\n        api: RegSetValueEx @ 0x40F5D9\nfunction @ 0x40F790\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x40F960\n          or:\n            api: RegCreateKeyEx @ 0x40F988\n      or:\n        api: RegSetValueEx @ 0x40F9A6\nfunction @ 0x4104F0\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x410536\n          or:\n            api: RegCreateKeyEx @ 0x41055E\n      or:\n        api: RegSetValueEx @ 0x410582\n\ndelete registry key\nnamespace  host-interaction/registry/delete                                \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\nscope      function                                                        \natt&ck     Defense Evasion::Modify Registry [T1112]                        \nmbc        Operating System::Registry::Delete Registry Key [C0036.002]     \nfunction @ 0x409340\n  and:\n    or:\n      api: RegDeleteKey @ 0x40937E\n\ndelete registry value (2 matches)\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ 0x40EBC0\n  and:\n    optional:\n      match: create or open registry key @ 0x40EBE5\n        or:\n          api: RegOpenKeyEx @ 0x40EC17\n    or:\n      api: RegDeleteValue @ 0x40EC2A\nfunction @ 0x410830\n  and:\n    optional:\n      match: create or open registry key @ 0x4108A7\n        or:\n          api: RegOpenKeyEx @ 0x4108C5\n    or:\n      api: RegDeleteValue @ 0x4108DC\n\ncreate thread\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x409577 in function 0x409540\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x409589\n\nresume thread\nnamespace  host-interaction/thread/resume                     \nauthor     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\nscope      basic block                                        \nmbc        Process::Resume Thread [C0054]                     \nbasic block @ 0x409593 in function 0x409540\n  or:\n    api: ResumeThread @ 0x40959E\n\nlink function at runtime on Windows (6 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x4052B4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4052B4\ninstruction @ 0x405334\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x405334\ninstruction @ 0x405965\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x405965\ninstruction @ 0x408185\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x408185\ninstruction @ 0x409363\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x409363\ninstruction @ 0x40EC7A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40EC7A\n\nresolve function by parsing PE exports (3 matches)\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x4033B0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x4033B0\n      mnemonic: movzx @ 0x40384A\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x403413, 0x403695, 0x4036C0\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x403591, 0x4037A9\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x403720, 0x40373A\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x40380F\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x403808, 0x403813, 0x403A07, 0x403A0D\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x4039FE\nfunction @ 0x403403\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x403403\n      mnemonic: movzx @ 0x40384A\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x403413, 0x403695, 0x4036C0\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x403591, 0x4037A9\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x403720, 0x40373A\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x40380F\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x403808, 0x403813, 0x403A07, 0x403A0D\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x4039FE\nfunction @ 0x40CFD0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x40CFD0\n      mnemonic: movzx @ 0x40D014, 0x40D067, 0x40D099, 0x40D0A7, and 2 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x40D0D8, 0x40D0EC, 0x40D0F9, 0x40D232\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x40CFFA, 0x40D014, 0x40D389\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x40D1AE, 0x40D1D6, 0x40D2DC, 0x40D2E2, and 3 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x40D186, 0x40D2F4, 0x40D31E, 0x40D383, and 1 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x40D182, 0x40D31A, 0x40D3A9\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x40D2EB, 0x40D2FD, 0x40D37A, 0x40D38C\n\npersist via Run registry key (4 matches)\nnamespace  persistence/registry/run                                             \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com                      \nscope      function                                                             \natt&ck     Persistence::Boot or Logon Autostart Execution::Registry Run Keys /  \n           Startup Folder [T1547.001]                                           \nmbc        Persistence::Registry Run Keys / Startup Folder [F0012]              \nfunction @ 0x4021F0\n  and:\n    or:\n      number: 0x80000001 = HKEY_CURRENT_USER @ 0x402291\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\" @ 0x402289\nfunction @ 0x409010\n  and:\n    or:\n      match: set registry value @ 0x409010\n        or:\n          and:\n            optional:\n              match: create or open registry key @ 0x409010\n                or:\n                  api: RegCreateKeyEx @ 0x40903E\n            or:\n              api: RegSetValueEx @ 0x409092\n      number: 0x80000001 = HKEY_CURRENT_USER @ 0x409036\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\" @ 0x40902E\nfunction @ 0x409010\n  and:\n    or:\n      match: set registry value @ 0x409010\n        or:\n          and:\n            optional:\n              match: create or open registry key @ 0x409010\n                or:\n                  api: RegCreateKeyEx @ 0x40903E\n            or:\n              api: RegSetValueEx @ 0x409092\n      number: 0x80000001 = HKEY_CURRENT_USER @ 0x409036\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\" @ 0x40902E\nfunction @ 0x40EBC0\n  and:\n    or:\n      number: 0x80000001 = HKEY_CURRENT_USER @ 0x40EBEF, 0x40EC0F\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\" @ 0x40EC07\n\nidentify system language via API\nnamespace  targeting/language                                                   \nauthor     william.ballenthin@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Location Discovery::System Language Discovery      \n           [T1614.001]                                                          \nfunction @ 0x40EC60\n  and:\n    os: windows\n    or:\n      api: GetUserDefaultUILanguage @ 0x40ED7D\n\n\n\n"},"hashes":{"md5":"04fb36199787f2e3e2135611a38321eb","sha1":"65559245709fe98052eb284577f1fd61c01ad20d","sha256":"d765e722e295969c0a5c2d90f549db8b89ab617900bf4698db41c7cdad993bb9"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 322</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 23090</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"CryptoL\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"04fb36199787f2e3e2135611a38321eb\",\n        \"sha256\": \"d765e722e295969c0a5c2d90f549db8b89ab617900bf4698db41c7c\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__91_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (91 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401000\",\n      \"label\": \"Function 0x401000\",\n      \"type\": \"function\",\n      \"address\": \"0x401000\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40226D\",\n      \"label\": \"Block 0x40226D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40226D\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__57_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (57 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401036\",\n      \"label\": \"Block 0x401036\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401036\"\n    },\n    {\n      \"id\": \"api_WaitForSingleObject\",\n      \"label\": \"WaitForSingleObject\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_inspect_load_icon_resource\",\n      \"label\": \"inspect load icon resource\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x40DD10\",\n      \"label\": \"Block 0x40DD10\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40DD10\"\n    },\n    {\n      \"id\": \"api_LoadIcon\",\n      \"label\": \"LoadIcon\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"label\": \"log keystrokes via polling (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4067F0\",\n      \"label\": \"Function 0x4067F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4067F0\"\n    },\n    {\n      \"id\": \"func_0x407140\",\n      \"label\": \"Function 0x407140\",\n      \"type\": \"function\",\n      \"address\": \"0x407140\"\n    },\n    {\n      \"id\": \"api_GetKeyState\",\n      \"label\": \"GetKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_initialize_winhttp_library\",\n      \"label\": \"initialize WinHTTP library\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::WinHTTP [C0002.008]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408250\",\n      \"label\": \"Function 0x408250\",\n      \"type\": \"function\",\n      \"address\": \"0x408250\"\n    },\n    {\n      \"id\": \"api_WinHttpOpen\",\n      \"label\": \"WinHttpOpen\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_http_header\",\n      \"label\": \"read HTTP header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Read Header [C0002.014]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408640\",\n      \"label\": \"Function 0x408640\",\n      \"type\": \"function\",\n      \"address\": \"0x408640\"\n    },\n    {\n      \"id\": \"api_WinHttpQueryHeaders\",\n      \"label\": \"WinHttpQueryHeaders\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Read Header [C0002.014]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_http_header\",\n      \"label\": \"set HTTP header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Set Header [C0002.013]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408340\",\n      \"label\": \"Function 0x408340\",\n      \"type\": \"function\",\n      \"address\": \"0x408340\"\n    },\n    {\n      \"id\": \"api_WinHttpAddRequestHeaders\",\n      \"label\": \"WinHttpAddRequestHeaders\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_prepare_http_request\",\n      \"label\": \"prepare HTTP request\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"api_WinHttpOpenRequest\",\n      \"label\": \"WinHttpOpenRequest\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_receive_http_response__2_matches_\",\n      \"label\": \"receive HTTP response (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408410\",\n      \"label\": \"Function 0x408410\",\n      \"type\": \"function\",\n      \"address\": \"0x408410\"\n    },\n    {\n      \"id\": \"func_0x407470\",\n      \"label\": \"Function 0x407470\",\n      \"type\": \"function\",\n      \"address\": \"0x407470\"\n    },\n    {\n      \"id\": \"api_WinHttpReadData\",\n      \"label\": \"WinHttpReadData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_WinHttpReceiveResponse\",\n      \"label\": \"WinHttpReceiveResponse\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_new_key_via_cryptacquirecontext__2_matches_\",\n      \"label\": \"create new key via CryptAcquireContext (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encryption Key [C0028]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x404748\",\n      \"label\": \"Block 0x404748\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x404748\"\n    },\n    {\n      \"id\": \"bb_0x404642\",\n      \"label\": \"Block 0x404642\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x404642\"\n    },\n    {\n      \"id\": \"api_CryptAcquireContext\",\n      \"label\": \"CryptAcquireContext\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______chuong_dong_mandiant_com\",\n      \"label\": \"author      chuong.dong@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encryption Key [C0028]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_or_decrypt_via_wincrypt__4_matches_\",\n      \"label\": \"encrypt or decrypt via WinCrypt (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Decrypt Data [C0031]\",\n        \"Cryptography::Encrypt Data\",\n        \"[C0027]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404960\",\n      \"label\": \"Function 0x404960\",\n      \"type\": \"function\",\n      \"address\": \"0x404960\"\n    },\n    {\n      \"id\": \"func_0x404A50\",\n      \"label\": \"Function 0x404A50\",\n      \"type\": \"function\",\n      \"address\": \"0x404A50\"\n    },\n    {\n      \"id\": \"func_0x4048F0\",\n      \"label\": \"Function 0x4048F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4048F0\"\n    },\n    {\n      \"id\": \"func_0x404AC0\",\n      \"label\": \"Function 0x404AC0\",\n      \"type\": \"function\",\n      \"address\": \"0x404AC0\"\n    },\n    {\n      \"id\": \"api_CryptEncrypt\",\n      \"label\": \"CryptEncrypt\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CryptDecrypt\",\n      \"label\": \"CryptDecrypt\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Decrypt Data [C0031]\",\n        \"Cryptography::Encrypt Data\",\n        \"[C0027]\"\n      ]\n    },\n    {\n      \"id\": \"cap_import_public_key\",\n      \"label\": \"import public key\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encryption Key::Import Public Key [C0028.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404720\",\n      \"label\": \"Function 0x404720\",\n      \"type\": \"function\",\n      \"address\": \"0x404720\"\n    },\n    {\n      \"id\": \"api_CryptImportPublicKeyInfo\",\n      \"label\": \"CryptImportPublicKeyInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encryption Key::Import Public Key [C0028.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_aes_via_winapi__2_matches_\",\n      \"label\": \"encrypt data using AES via WinAPI (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encryption-Standard\",\n        \"Algorithm [E1027.m05]\",\n        \"Cryptography::Encrypt Data::AES [C0027.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407730\",\n      \"label\": \"Function 0x407730\",\n      \"type\": \"function\",\n      \"address\": \"0x407730\"\n    },\n    {\n      \"id\": \"func_0x404040\",\n      \"label\": \"Function 0x404040\",\n      \"type\": \"function\",\n      \"address\": \"0x404040\"\n    },\n    {\n      \"id\": \"api_CryptGenKey\",\n      \"label\": \"CryptGenKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_reference_public_rsa_key\",\n      \"label\": \"reference public RSA key\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encryption Key [C0028]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40F280\",\n      \"label\": \"Function 0x40F280\",\n      \"type\": \"function\",\n      \"address\": \"0x40F280\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encryption Key [C0028]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_via_wincrypt\",\n      \"label\": \"hash data via WinCrypt\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash [C0029]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404D60\",\n      \"label\": \"Function 0x404D60\",\n      \"type\": \"function\",\n      \"address\": \"0x404D60\"\n    },\n    {\n      \"id\": \"api_CryptHashData\",\n      \"label\": \"CryptHashData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_initialize_hashing_via_wincrypt\",\n      \"label\": \"initialize hashing via WinCrypt\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_CryptCreateHash\",\n      \"label\": \"CryptCreateHash\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_hash_data_using_sha1\",\n      \"label\": \"hash data using SHA1\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash::SHA1 [C0029.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_william_ballenthin_mandiant_com\",\n      \"label\": \"william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash::SHA1 [C0029.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_using_sha1_via_wincrypt\",\n      \"label\": \"hash data using SHA1 via WinCrypt\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_using_a_mersenne_twister__3_matches_\",\n      \"label\": \"generate random numbers using a Mersenne Twister (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence [C0021]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404FA0\",\n      \"label\": \"Function 0x404FA0\",\n      \"type\": \"function\",\n      \"address\": \"0x404FA0\"\n    },\n    {\n      \"id\": \"func_0x4079E0\",\n      \"label\": \"Function 0x4079E0\",\n      \"type\": \"function\",\n      \"address\": \"0x4079E0\"\n    },\n    {\n      \"id\": \"func_0x404F60\",\n      \"label\": \"Function 0x404F60\",\n      \"type\": \"function\",\n      \"address\": \"0x404F60\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions__2_matches_\",\n      \"label\": \"extract resource via kernel32 functions (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x40A760\",\n      \"label\": \"Function 0x40A760\",\n      \"type\": \"function\",\n      \"address\": \"0x40A760\"\n    },\n    {\n      \"id\": \"func_0x40BB20\",\n      \"label\": \"Function 0x40BB20\",\n      \"type\": \"function\",\n      \"address\": \"0x40BB20\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResourceEx\",\n      \"label\": \"FindResourceEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments__2_matches_\",\n      \"label\": \"accept command line arguments (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4010C0\",\n      \"label\": \"Function 0x4010C0\",\n      \"type\": \"function\",\n      \"address\": \"0x4010C0\"\n    },\n    {\n      \"id\": \"func_0x401D60\",\n      \"label\": \"Function 0x401D60\",\n      \"type\": \"function\",\n      \"address\": \"0x401D60\"\n    },\n    {\n      \"id\": \"api_CommandLineToArgv\",\n      \"label\": \"CommandLineToArgv\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_open_clipboard\",\n      \"label\": \"open clipboard\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408D30\",\n      \"label\": \"Function 0x408D30\",\n      \"type\": \"function\",\n      \"address\": \"0x408D30\"\n    },\n    {\n      \"id\": \"api_OpenClipboard\",\n      \"label\": \"OpenClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CloseClipboard\",\n      \"label\": \"CloseClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_write_clipboard_data\",\n      \"label\": \"write clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"api_EmptyClipboard\",\n      \"label\": \"EmptyClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SetClipboardData\",\n      \"label\": \"SetClipboardData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable__2_matches_\",\n      \"label\": \"query environment variable (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40E720\",\n      \"label\": \"Function 0x40E720\",\n      \"type\": \"function\",\n      \"address\": \"0x40E720\"\n    },\n    {\n      \"id\": \"func_0x402380\",\n      \"label\": \"Function 0x402380\",\n      \"type\": \"function\",\n      \"address\": \"0x402380\"\n    },\n    {\n      \"id\": \"api_ExpandEnvironmentStrings\",\n      \"label\": \"ExpandEnvironmentStrings\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetEnvironmentVariable\",\n      \"label\": \"GetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path__3_matches_\",\n      \"label\": \"get common file path (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4050C0\",\n      \"label\": \"Function 0x4050C0\",\n      \"type\": \"function\",\n      \"address\": \"0x4050C0\"\n    },\n    {\n      \"id\": \"func_0x405880\",\n      \"label\": \"Function 0x405880\",\n      \"type\": \"function\",\n      \"address\": \"0x405880\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHGetFolderPath\",\n      \"label\": \"SHGetFolderPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_system_object_information\",\n      \"label\": \"get file system object information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40DF83\",\n      \"label\": \"Block 0x40DF83\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40DF83\"\n    },\n    {\n      \"id\": \"api_SHGetFileInfo\",\n      \"label\": \"SHGetFileInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_copy_file\",\n      \"label\": \"copy file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40E990\",\n      \"label\": \"Function 0x40E990\",\n      \"type\": \"function\",\n      \"address\": \"0x40E990\"\n    },\n    {\n      \"id\": \"api_CopyFileEx\",\n      \"label\": \"CopyFileEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_file__4_matches_\",\n      \"label\": \"delete file (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405550\",\n      \"label\": \"Function 0x405550\",\n      \"type\": \"function\",\n      \"address\": \"0x405550\"\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_enumerate_files_on_windows\",\n      \"label\": \"enumerate files on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405570\",\n      \"label\": \"Function 0x405570\",\n      \"type\": \"function\",\n      \"address\": \"0x405570\"\n    },\n    {\n      \"id\": \"api_FindFirstFile\",\n      \"label\": \"FindFirstFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindNextFile\",\n      \"label\": \"FindNextFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindClose\",\n      \"label\": \"FindClose\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_recursively\",\n      \"label\": \"enumerate files recursively\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     @_re_fox, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes\",\n      \"label\": \"get file attributes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40458A\",\n      \"label\": \"Block 0x40458A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40458A\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_get_file_size__2_matches_\",\n      \"label\": \"get file size (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x403EB0\",\n      \"label\": \"Function 0x403EB0\",\n      \"type\": \"function\",\n      \"address\": \"0x403EB0\"\n    },\n    {\n      \"id\": \"api_GetFileSizeEx\",\n      \"label\": \"GetFileSizeEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_file_attributes__7_matches_\",\n      \"label\": \"set file attributes (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40EA97\",\n      \"label\": \"Block 0x40EA97\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40EA97\"\n    },\n    {\n      \"id\": \"bb_0x401010\",\n      \"label\": \"Block 0x401010\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401010\"\n    },\n    {\n      \"id\": \"bb_0x40EA50\",\n      \"label\": \"Block 0x40EA50\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40EA50\"\n    },\n    {\n      \"id\": \"bb_0x40EB87\",\n      \"label\": \"Block 0x40EB87\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40EB87\"\n    },\n    {\n      \"id\": \"bb_0x405550\",\n      \"label\": \"Block 0x405550\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x405550\"\n    },\n    {\n      \"id\": \"bb_0x4045DC\",\n      \"label\": \"Block 0x4045DC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4045DC\"\n    },\n    {\n      \"id\": \"bb_0x40E8CD\",\n      \"label\": \"Block 0x40E8CD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40E8CD\"\n    },\n    {\n      \"id\": \"api_SetFileAttributes\",\n      \"label\": \"SetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_move_file\",\n      \"label\": \"move file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404420\",\n      \"label\": \"Function 0x404420\",\n      \"type\": \"function\",\n      \"address\": \"0x404420\"\n    },\n    {\n      \"id\": \"api_MoveFileEx\",\n      \"label\": \"MoveFileEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__2_matches_\",\n      \"label\": \"read file on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x403C80\",\n      \"label\": \"Function 0x403C80\",\n      \"type\": \"function\",\n      \"address\": \"0x403C80\"\n    },\n    {\n      \"id\": \"func_0x405250\",\n      \"label\": \"Function 0x405250\",\n      \"type\": \"function\",\n      \"address\": \"0x405250\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__4_matches_\",\n      \"label\": \"write file on Windows (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x403D70\",\n      \"label\": \"Function 0x403D70\",\n      \"type\": \"function\",\n      \"address\": \"0x403D70\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_graphical_window_text__2_matches_\",\n      \"label\": \"get graphical window text (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40DD10\",\n      \"label\": \"Function 0x40DD10\",\n      \"type\": \"function\",\n      \"address\": \"0x40DD10\"\n    },\n    {\n      \"id\": \"func_0x40CFD0\",\n      \"label\": \"Function 0x40CFD0\",\n      \"type\": \"function\",\n      \"address\": \"0x40CFD0\"\n    },\n    {\n      \"id\": \"api_GetWindowText\",\n      \"label\": \"GetWindowText\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SendMessage\",\n      \"label\": \"SendMessage\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_hide_graphical_window__5_matches_\",\n      \"label\": \"hide graphical window (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40D476\",\n      \"label\": \"Block 0x40D476\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40D476\"\n    },\n    {\n      \"id\": \"bb_0x40A843\",\n      \"label\": \"Block 0x40A843\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40A843\"\n    },\n    {\n      \"id\": \"bb_0x40B911\",\n      \"label\": \"Block 0x40B911\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40B911\"\n    },\n    {\n      \"id\": \"bb_0x40A7EF\",\n      \"label\": \"Block 0x40A7EF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40A7EF\"\n    },\n    {\n      \"id\": \"bb_0x40D7B0\",\n      \"label\": \"Block 0x40D7B0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40D7B0\"\n    },\n    {\n      \"id\": \"api_ShowWindow\",\n      \"label\": \"ShowWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_information__2_matches_\",\n      \"label\": \"get disk information (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402F90\",\n      \"label\": \"Function 0x402F90\",\n      \"type\": \"function\",\n      \"address\": \"0x402F90\"\n    },\n    {\n      \"id\": \"func_0x403070\",\n      \"label\": \"Function 0x403070\",\n      \"type\": \"function\",\n      \"address\": \"0x403070\"\n    },\n    {\n      \"id\": \"api_GetLogicalDrives\",\n      \"label\": \"GetLogicalDrives\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetDriveType\",\n      \"label\": \"GetDriveType\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetVolumeInformation\",\n      \"label\": \"GetVolumeInformation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_size__2_matches_\",\n      \"label\": \"get disk size (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpaceEx\",\n      \"label\": \"GetDiskFreeSpaceEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_check_mutex_on_windows\",\n      \"label\": \"check mutex on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Check Mutex [C0043]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401990\",\n      \"label\": \"Function 0x401990\",\n      \"type\": \"function\",\n      \"address\": \"0x401990\"\n    },\n    {\n      \"id\": \"api_CreateMutex\",\n      \"label\": \"CreateMutex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetLastError\",\n      \"label\": \"GetLastError\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Check Mutex [C0043]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_or_open_mutex_on_windows__2_matches_\",\n      \"label\": \"create or open mutex on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_mehunhoff_google_com\",\n      \"label\": \"mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_hostname\",\n      \"label\": \"get hostname\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4013E0\",\n      \"label\": \"Function 0x4013E0\",\n      \"type\": \"function\",\n      \"address\": \"0x4013E0\"\n    },\n    {\n      \"id\": \"api_GetComputerName\",\n      \"label\": \"GetComputerName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__5_matches_\",\n      \"label\": \"create process on Windows (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40EAF2\",\n      \"label\": \"Block 0x40EAF2\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40EAF2\"\n    },\n    {\n      \"id\": \"bb_0x401910\",\n      \"label\": \"Block 0x401910\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401910\"\n    },\n    {\n      \"id\": \"bb_0x41014D\",\n      \"label\": \"Block 0x41014D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x41014D\"\n    },\n    {\n      \"id\": \"bb_0x408F4D\",\n      \"label\": \"Block 0x408F4D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x408F4D\"\n    },\n    {\n      \"id\": \"bb_0x401966\",\n      \"label\": \"Block 0x401966\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401966\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_ShellExecuteEx\",\n      \"label\": \"ShellExecuteEx\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401E00\",\n      \"label\": \"Function 0x401E00\",\n      \"type\": \"function\",\n      \"address\": \"0x401E00\"\n    },\n    {\n      \"id\": \"api_ExitProcess\",\n      \"label\": \"ExitProcess\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key\",\n      \"label\": \"query or enumerate registry key\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4093A0\",\n      \"label\": \"Function 0x4093A0\",\n      \"type\": \"function\",\n      \"address\": \"0x4093A0\"\n    },\n    {\n      \"id\": \"api_RegEnumKeyEx\",\n      \"label\": \"RegEnumKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__8_matches_\",\n      \"label\": \"query or enumerate registry value (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40A070\",\n      \"label\": \"Function 0x40A070\",\n      \"type\": \"function\",\n      \"address\": \"0x40A070\"\n    },\n    {\n      \"id\": \"func_0x409140\",\n      \"label\": \"Function 0x409140\",\n      \"type\": \"function\",\n      \"address\": \"0x409140\"\n    },\n    {\n      \"id\": \"func_0x410770\",\n      \"label\": \"Function 0x410770\",\n      \"type\": \"function\",\n      \"address\": \"0x410770\"\n    },\n    {\n      \"id\": \"func_0x40EFD0\",\n      \"label\": \"Function 0x40EFD0\",\n      \"type\": \"function\",\n      \"address\": \"0x40EFD0\"\n    },\n    {\n      \"id\": \"func_0x410370\",\n      \"label\": \"Function 0x410370\",\n      \"type\": \"function\",\n      \"address\": \"0x410370\"\n    },\n    {\n      \"id\": \"func_0x4092A0\",\n      \"label\": \"Function 0x4092A0\",\n      \"type\": \"function\",\n      \"address\": \"0x4092A0\"\n    },\n    {\n      \"id\": \"api_RegEnumValue\",\n      \"label\": \"RegEnumValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value__5_matches_\",\n      \"label\": \"set registry value (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40F3D0\",\n      \"label\": \"Function 0x40F3D0\",\n      \"type\": \"function\",\n      \"address\": \"0x40F3D0\"\n    },\n    {\n      \"id\": \"func_0x4090C0\",\n      \"label\": \"Function 0x4090C0\",\n      \"type\": \"function\",\n      \"address\": \"0x4090C0\"\n    },\n    {\n      \"id\": \"func_0x4104F0\",\n      \"label\": \"Function 0x4104F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4104F0\"\n    },\n    {\n      \"id\": \"func_0x40F790\",\n      \"label\": \"Function 0x40F790\",\n      \"type\": \"function\",\n      \"address\": \"0x40F790\"\n    },\n    {\n      \"id\": \"func_0x409010\",\n      \"label\": \"Function 0x409010\",\n      \"type\": \"function\",\n      \"address\": \"0x409010\"\n    },\n    {\n      \"id\": \"api_RegCreateKeyEx\",\n      \"label\": \"RegCreateKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delete_registry_key\",\n      \"label\": \"delete registry key\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x409340\",\n      \"label\": \"Function 0x409340\",\n      \"type\": \"function\",\n      \"address\": \"0x409340\"\n    },\n    {\n      \"id\": \"api_RegDeleteKey\",\n      \"label\": \"RegDeleteKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_value__2_matches_\",\n      \"label\": \"delete registry value (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40EBC0\",\n      \"label\": \"Function 0x40EBC0\",\n      \"type\": \"function\",\n      \"address\": \"0x40EBC0\"\n    },\n    {\n      \"id\": \"func_0x410830\",\n      \"label\": \"Function 0x410830\",\n      \"type\": \"function\",\n      \"address\": \"0x410830\"\n    },\n    {\n      \"id\": \"api_RegDeleteValue\",\n      \"label\": \"RegDeleteValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_thread\",\n      \"label\": \"create thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x409577\",\n      \"label\": \"Block 0x409577\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x409577\"\n    },\n    {\n      \"id\": \"api_CreateThread\",\n      \"label\": \"CreateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_resume_thread\",\n      \"label\": \"resume thread\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Resume Thread [C0054]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x409593\",\n      \"label\": \"Block 0x409593\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x409593\"\n    },\n    {\n      \"id\": \"api_ResumeThread\",\n      \"label\": \"ResumeThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Resume Thread [C0054]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__6_matches_\",\n      \"label\": \"link function at runtime on Windows (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports__3_matches_\",\n      \"label\": \"resolve function by parsing PE exports (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x403403\",\n      \"label\": \"Function 0x403403\",\n      \"type\": \"function\",\n      \"address\": \"0x403403\"\n    },\n    {\n      \"id\": \"func_0x4033B0\",\n      \"label\": \"Function 0x4033B0\",\n      \"type\": \"function\",\n      \"address\": \"0x4033B0\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_persist_via_run_registry_key__4_matches_\",\n      \"label\": \"persist via Run registry key (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Registry Run Keys / Startup Folder [F0012]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4021F0\",\n      \"label\": \"Function 0x4021F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4021F0\"\n    },\n    {\n      \"id\": \"cap_identify_system_language_via_api\",\n      \"label\": \"identify system language via API\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery::System Language Discovery\",\n        \"[T1614.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40EC60\",\n      \"label\": \"Function 0x40EC60\",\n      \"type\": \"function\",\n      \"address\": \"0x40EC60\"\n    },\n    {\n      \"id\": \"api_GetUserDefaultUILanguage\",\n      \"label\": \"GetUserDefaultUILanguage\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__91_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__91_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x40226D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__57_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__57_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x401036\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_inspect_load_icon_resource\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_inspect_load_icon_resource\",\n      \"target\": \"bb_0x40DD10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x40DD10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"target\": \"func_0x4067F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"target\": \"func_0x407140\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4067F0\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407140\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4067F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407140\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4067F0\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407140\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_initialize_winhttp_library\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_initialize_winhttp_library\",\n      \"target\": \"func_0x408250\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408250\",\n      \"target\": \"api_WinHttpOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408250\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408250\",\n      \"target\": \"api_WinHttpOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_http_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_http_header\",\n      \"target\": \"func_0x408640\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408640\",\n      \"target\": \"api_WinHttpQueryHeaders\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x408640\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408640\",\n      \"target\": \"api_WinHttpQueryHeaders\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_http_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_http_header\",\n      \"target\": \"func_0x408340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408340\",\n      \"target\": \"api_WinHttpAddRequestHeaders\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x408340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408340\",\n      \"target\": \"api_WinHttpAddRequestHeaders\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_prepare_http_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_prepare_http_request\",\n      \"target\": \"func_0x408340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408340\",\n      \"target\": \"api_WinHttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408340\",\n      \"target\": \"api_WinHttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_http_response__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_http_response__2_matches_\",\n      \"target\": \"func_0x408410\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_http_response__2_matches_\",\n      \"target\": \"func_0x407470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408410\",\n      \"target\": \"api_WinHttpReadData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407470\",\n      \"target\": \"api_WinHttpReadData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408410\",\n      \"target\": \"api_WinHttpReceiveResponse\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407470\",\n      \"target\": \"api_WinHttpReceiveResponse\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408410\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408410\",\n      \"target\": \"api_WinHttpReadData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407470\",\n      \"target\": \"api_WinHttpReadData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408410\",\n      \"target\": \"api_WinHttpReceiveResponse\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407470\",\n      \"target\": \"api_WinHttpReceiveResponse\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_new_key_via_cryptacquirecontext__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_new_key_via_cryptacquirecontext__2_matches_\",\n      \"target\": \"bb_0x404748\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_new_key_via_cryptacquirecontext__2_matches_\",\n      \"target\": \"bb_0x404642\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______chuong_dong_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______chuong_dong_mandiant_com\",\n      \"target\": \"bb_0x404748\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______chuong_dong_mandiant_com\",\n      \"target\": \"bb_0x404642\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_or_decrypt_via_wincrypt__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_or_decrypt_via_wincrypt__4_matches_\",\n      \"target\": \"func_0x404960\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_or_decrypt_via_wincrypt__4_matches_\",\n      \"target\": \"func_0x404A50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_or_decrypt_via_wincrypt__4_matches_\",\n      \"target\": \"func_0x4048F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_or_decrypt_via_wincrypt__4_matches_\",\n      \"target\": \"func_0x404AC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404960\",\n      \"target\": \"api_CryptEncrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404A50\",\n      \"target\": \"api_CryptEncrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4048F0\",\n      \"target\": \"api_CryptEncrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404AC0\",\n      \"target\": \"api_CryptEncrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404960\",\n      \"target\": \"api_CryptDecrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404A50\",\n      \"target\": \"api_CryptDecrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4048F0\",\n      \"target\": \"api_CryptDecrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404AC0\",\n      \"target\": \"api_CryptDecrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x404960\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x404A50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4048F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x404AC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404960\",\n      \"target\": \"api_CryptEncrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404A50\",\n      \"target\": \"api_CryptEncrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4048F0\",\n      \"target\": \"api_CryptEncrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404AC0\",\n      \"target\": \"api_CryptEncrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404960\",\n      \"target\": \"api_CryptDecrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404A50\",\n      \"target\": \"api_CryptDecrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4048F0\",\n      \"target\": \"api_CryptDecrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404AC0\",\n      \"target\": \"api_CryptDecrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_import_public_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_import_public_key\",\n      \"target\": \"func_0x404720\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404720\",\n      \"target\": \"api_CryptAcquireContext\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404720\",\n      \"target\": \"api_CryptImportPublicKeyInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x404720\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404720\",\n      \"target\": \"api_CryptAcquireContext\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404720\",\n      \"target\": \"api_CryptImportPublicKeyInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_aes_via_winapi__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_aes_via_winapi__2_matches_\",\n      \"target\": \"func_0x407730\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_aes_via_winapi__2_matches_\",\n      \"target\": \"func_0x404040\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407730\",\n      \"target\": \"api_CryptGenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404040\",\n      \"target\": \"api_CryptGenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x407730\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x404040\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407730\",\n      \"target\": \"api_CryptGenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404040\",\n      \"target\": \"api_CryptGenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_public_rsa_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_reference_public_rsa_key\",\n      \"target\": \"func_0x40F280\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x40F280\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_via_wincrypt\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt\",\n      \"target\": \"func_0x404D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404D60\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x404D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404D60\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_initialize_hashing_via_wincrypt\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_initialize_hashing_via_wincrypt\",\n      \"target\": \"func_0x404D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404D60\",\n      \"target\": \"api_CryptCreateHash\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x404D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404D60\",\n      \"target\": \"api_CryptCreateHash\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_sha1\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_sha1\",\n      \"target\": \"func_0x404D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404D60\",\n      \"target\": \"api_CryptCreateHash\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x404D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404D60\",\n      \"target\": \"api_CryptCreateHash\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_sha1_via_wincrypt\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_sha1_via_wincrypt\",\n      \"target\": \"func_0x404D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404D60\",\n      \"target\": \"api_CryptCreateHash\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404D60\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x404D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404D60\",\n      \"target\": \"api_CryptCreateHash\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404D60\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_using_a_mersenne_twister__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_a_mersenne_twister__3_matches_\",\n      \"target\": \"func_0x404FA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_a_mersenne_twister__3_matches_\",\n      \"target\": \"func_0x4079E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_a_mersenne_twister__3_matches_\",\n      \"target\": \"func_0x404F60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x404FA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4079E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x404F60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__2_matches_\",\n      \"target\": \"func_0x40A760\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__2_matches_\",\n      \"target\": \"func_0x40BB20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A760\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BB20\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A760\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BB20\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A760\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BB20\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A760\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BB20\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40A760\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40BB20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A760\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BB20\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A760\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BB20\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A760\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BB20\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A760\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BB20\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__2_matches_\",\n      \"target\": \"func_0x4010C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__2_matches_\",\n      \"target\": \"func_0x401D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4010C0\",\n      \"target\": \"api_CommandLineToArgv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D60\",\n      \"target\": \"api_CommandLineToArgv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010C0\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D60\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4010C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4010C0\",\n      \"target\": \"api_CommandLineToArgv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D60\",\n      \"target\": \"api_CommandLineToArgv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4010C0\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401D60\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_clipboard\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_clipboard\",\n      \"target\": \"func_0x408D30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408D30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_clipboard_data\",\n      \"target\": \"func_0x408D30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x408D30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__2_matches_\",\n      \"target\": \"func_0x40E720\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__2_matches_\",\n      \"target\": \"func_0x402380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E720\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402380\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E720\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402380\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x40E720\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x402380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E720\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402380\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E720\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402380\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x4050C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x405880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x402380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4050C0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405880\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402380\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4050C0\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405880\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402380\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4050C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4050C0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405880\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402380\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4050C0\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405880\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402380\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_system_object_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_system_object_information\",\n      \"target\": \"bb_0x40DF83\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x40DF83\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_copy_file\",\n      \"target\": \"func_0x40E990\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E990\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40E990\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E990\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__4_matches_\",\n      \"target\": \"func_0x40E990\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__4_matches_\",\n      \"target\": \"func_0x405550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__4_matches_\",\n      \"target\": \"func_0x40E720\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__4_matches_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E990\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405550\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E720\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40E990\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40E720\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E990\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405550\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E720\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows\",\n      \"target\": \"func_0x405570\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405570\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405570\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405570\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405570\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405570\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405570\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405570\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_recursively\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively\",\n      \"target\": \"func_0x405570\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405570\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405570\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405570\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405570\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405570\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405570\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405570\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes\",\n      \"target\": \"bb_0x40458A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40458A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x403EB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x404040\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403EB0\",\n      \"target\": \"api_GetFileSizeEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404040\",\n      \"target\": \"api_GetFileSizeEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403EB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404040\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403EB0\",\n      \"target\": \"api_GetFileSizeEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404040\",\n      \"target\": \"api_GetFileSizeEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__7_matches_\",\n      \"target\": \"bb_0x40EA97\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__7_matches_\",\n      \"target\": \"bb_0x401010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__7_matches_\",\n      \"target\": \"bb_0x40EA50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__7_matches_\",\n      \"target\": \"bb_0x40EB87\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__7_matches_\",\n      \"target\": \"bb_0x405550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__7_matches_\",\n      \"target\": \"bb_0x4045DC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__7_matches_\",\n      \"target\": \"bb_0x40E8CD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40EA97\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x401010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40EA50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40EB87\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x405550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4045DC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40E8CD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_move_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_move_file\",\n      \"target\": \"func_0x404420\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404420\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x404420\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404420\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__2_matches_\",\n      \"target\": \"func_0x403C80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__2_matches_\",\n      \"target\": \"func_0x405250\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403C80\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405250\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403C80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405250\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403C80\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405250\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__4_matches_\",\n      \"target\": \"func_0x403D70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__4_matches_\",\n      \"target\": \"func_0x403EB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__4_matches_\",\n      \"target\": \"func_0x40E720\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__4_matches_\",\n      \"target\": \"func_0x404040\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403D70\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403EB0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E720\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404040\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403D70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403EB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40E720\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404040\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403D70\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403EB0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E720\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404040\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_graphical_window_text__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__2_matches_\",\n      \"target\": \"func_0x40DD10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__2_matches_\",\n      \"target\": \"func_0x40CFD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40DD10\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40CFD0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DD10\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40CFD0\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x40DD10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x40CFD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40DD10\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40CFD0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DD10\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40CFD0\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hide_graphical_window__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__5_matches_\",\n      \"target\": \"bb_0x40D476\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__5_matches_\",\n      \"target\": \"bb_0x40A843\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__5_matches_\",\n      \"target\": \"bb_0x40B911\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__5_matches_\",\n      \"target\": \"bb_0x40A7EF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__5_matches_\",\n      \"target\": \"bb_0x40D7B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x40D476\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x40A843\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x40B911\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x40A7EF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x40D7B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__2_matches_\",\n      \"target\": \"func_0x402F90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__2_matches_\",\n      \"target\": \"func_0x403070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402F90\",\n      \"target\": \"api_GetLogicalDrives\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403070\",\n      \"target\": \"api_GetLogicalDrives\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402F90\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403070\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402F90\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403070\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402F90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402F90\",\n      \"target\": \"api_GetLogicalDrives\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403070\",\n      \"target\": \"api_GetLogicalDrives\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402F90\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403070\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402F90\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403070\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_size__2_matches_\",\n      \"target\": \"func_0x402F90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_size__2_matches_\",\n      \"target\": \"func_0x403070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402F90\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403070\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402F90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402F90\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403070\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_mutex_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_mutex_on_windows\",\n      \"target\": \"func_0x401990\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401990\",\n      \"target\": \"api_CreateMutex\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401990\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x401990\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401990\",\n      \"target\": \"api_CreateMutex\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401990\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_mutex_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_hostname\",\n      \"target\": \"func_0x4013E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4013E0\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4013E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4013E0\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__5_matches_\",\n      \"target\": \"bb_0x40EAF2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__5_matches_\",\n      \"target\": \"bb_0x401910\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__5_matches_\",\n      \"target\": \"bb_0x41014D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__5_matches_\",\n      \"target\": \"bb_0x408F4D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__5_matches_\",\n      \"target\": \"bb_0x401966\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x40EAF2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x401910\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x41014D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x408F4D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x401966\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x401E00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401E00\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401E00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401E00\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key\",\n      \"target\": \"func_0x4093A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4093A0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4093A0\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4093A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4093A0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4093A0\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__8_matches_\",\n      \"target\": \"func_0x40A760\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__8_matches_\",\n      \"target\": \"func_0x40A070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__8_matches_\",\n      \"target\": \"func_0x409140\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__8_matches_\",\n      \"target\": \"func_0x410770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__8_matches_\",\n      \"target\": \"func_0x40EFD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__8_matches_\",\n      \"target\": \"func_0x410370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__8_matches_\",\n      \"target\": \"func_0x4092A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__8_matches_\",\n      \"target\": \"func_0x403070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A760\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A070\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409140\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410770\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EFD0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410370\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4092A0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403070\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A760\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A070\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409140\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410770\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EFD0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410370\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4092A0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403070\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A760\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A070\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409140\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410770\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EFD0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410370\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4092A0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403070\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40A760\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40A070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x409140\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x410770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40EFD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x410370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4092A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A760\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A070\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409140\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410770\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EFD0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410370\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4092A0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403070\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A760\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A070\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409140\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410770\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EFD0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410370\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4092A0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403070\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A760\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A070\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409140\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410770\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EFD0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410370\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4092A0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403070\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__5_matches_\",\n      \"target\": \"func_0x40F3D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__5_matches_\",\n      \"target\": \"func_0x4090C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__5_matches_\",\n      \"target\": \"func_0x4104F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__5_matches_\",\n      \"target\": \"func_0x40F790\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__5_matches_\",\n      \"target\": \"func_0x409010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40F3D0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4090C0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4104F0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F790\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409010\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F3D0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4090C0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4104F0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F790\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409010\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40F3D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4090C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4104F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40F790\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x409010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40F3D0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4090C0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4104F0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F790\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409010\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F3D0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4090C0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4104F0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F790\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409010\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key\",\n      \"target\": \"func_0x409340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x409340\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x409340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x409340\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value__2_matches_\",\n      \"target\": \"func_0x40EBC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value__2_matches_\",\n      \"target\": \"func_0x410830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40EBC0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410830\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EBC0\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410830\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40EBC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x410830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40EBC0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410830\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EBC0\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410830\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread\",\n      \"target\": \"bb_0x409577\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x409577\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resume_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resume_thread\",\n      \"target\": \"bb_0x409593\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x409593\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__3_matches_\",\n      \"target\": \"func_0x40CFD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__3_matches_\",\n      \"target\": \"func_0x403403\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__3_matches_\",\n      \"target\": \"func_0x4033B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x40CFD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x403403\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x4033B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_persist_via_run_registry_key__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_persist_via_run_registry_key__4_matches_\",\n      \"target\": \"func_0x409010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_persist_via_run_registry_key__4_matches_\",\n      \"target\": \"func_0x4021F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_persist_via_run_registry_key__4_matches_\",\n      \"target\": \"func_0x40EBC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x409010\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4021F0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EBC0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409010\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4021F0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EBC0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x409010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x4021F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x40EBC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x409010\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4021F0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EBC0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409010\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4021F0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EBC0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_identify_system_language_via_api\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_identify_system_language_via_api\",\n      \"target\": \"func_0x40EC60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40EC60\",\n      \"target\": \"api_GetUserDefaultUILanguage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40EC60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40EC60\",\n      \"target\": \"api_GetUserDefaultUILanguage\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 23:39:02.862203\",\n    \"total_functions\": \"322\",\n    \"total_features\": \"23090\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 23:39:04"}
{"_id":{"$oid":"6a4fe4ff0108394cb24cdd04"},"sha256":"e9cfb6eb3a77cd6ea162cf4cb131b5f6ad2a679c0ba9757d718c2f9265a9668f","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_5eu1aib8/Win32.Unclassified-019f46cce97272f2a25235fe9f51e257.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_5eu1aib8/Win32.Unclassified-019f46cce97272f2a25235fe9f51e257.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_5eu1aib8/Win32.Unclassified-019f46cce97272f2a25235fe9f51e257.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 1c234a8879840da21f197b2608a164c9                                  │\n│ sha1     │ ed7f6d70968fed5cf59ed2a141fca928e1b0522f                          │\n│ sha256   │ e9cfb6eb3a77cd6ea162cf4cb131b5f6ad2a679c0ba9757d718c2f9265a9668f  │\n│ analysis │ static                                                            │\n│ os       │ any                                                               │\n│ format   │ dotnet                                                            │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/Win32.Unclassifi… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DISCOVERY            │ Analysis Tool Discovery::Process detection            │\n│                      │ [B0013.001]                                           │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                                          ┃ Namespace              ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ reference analysis tools strings                    │ anti-analysis          │\n│ compiled to the .NET platform                       │ runtime/dotnet         │\n└─────────────────────────────────────────────────────┴────────────────────────┘\n\n","verbose":"md5                     1c234a8879840da21f197b2608a164c9                        \nsha1                    ed7f6d70968fed5cf59ed2a141fca928e1b0522f                \nsha256                  e9cfb6eb3a77cd6ea162cf4cb131b5f6ad2a679c0ba9757d718c2f9…\npath                    /home/apogean/projects/malware/windows/all_runs/Win32.U…\ntimestamp               2026-07-09 23:44:19.824221                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIzYlJSC/rules                                   \nfunction count          0                                                       \nlibrary function count  0                                                       \ntotal feature count     4945                                                    \n\nreference analysis tools strings\nnamespace  anti-analysis\nscope      file         \n\ncompiled to the .NET platform\nnamespace  runtime/dotnet\nscope      file          \n\n\n\n","very_verbose":"md5                     1c234a8879840da21f197b2608a164c9                        \nsha1                    ed7f6d70968fed5cf59ed2a141fca928e1b0522f                \nsha256                  e9cfb6eb3a77cd6ea162cf4cb131b5f6ad2a679c0ba9757d718c2f9…\npath                    /home/apogean/projects/malware/windows/all_runs/Win32.U…\ntimestamp               2026-07-09 23:44:23.035327                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIxmLTqD/rules                                   \nfunction count          0                                                       \nlibrary function count  0                                                       \ntotal feature count     4945                                                    \n\nreference analysis tools strings\nnamespace   anti-analysis                                                       \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \nmbc         Discovery::Analysis Tool Discovery::Process detection [B0013.001]   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /(?<!\\w)ida?(\\.exe)?$/i\n    - \"%IdA\" @ file+0x39BDC\n\n(internal) .NET file limitation\nnamespace    internal/limitation/dynamic                        \nauthor       @v1bh475u                                          \nscope        file                                               \ndescription  This dynamic analysis trace describes a .NET file. \n                                                                \n             capa rules are not yet tuned for the .NET runtime, \n             so its analysis may be incomplete or misleading.   \n                                                                \nor:\n  format: dotnet\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  format: dotnet\n\n\n\n"},"hashes":{"md5":"1c234a8879840da21f197b2608a164c9","sha1":"ed7f6d70968fed5cf59ed2a141fca928e1b0522f","sha256":"e9cfb6eb3a77cd6ea162cf4cb131b5f6ad2a679c0ba9757d718c2f9265a9668f"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 0</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 4945</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Win32.U\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"1c234a8879840da21f197b2608a164c9\",\n        \"sha256\": \"e9cfb6eb3a77cd6ea162cf4cb131b5f6ad2a679c0ba9757d718c2f9\",\n        \"arch\": \"i386\",\n        \"os\": \"any\",\n        \"format\": \"dotnet\"\n      }\n    },\n    {\n      \"id\": \"cap_reference_analysis_tools_strings\",\n      \"label\": \"reference analysis tools strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal___net_file_limitation\",\n      \"label\": \"(internal) .NET file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author________v1bh475u\",\n      \"label\": \"author       @v1bh475u\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compiled_to_the__net_platform\",\n      \"label\": \"compiled to the .NET platform\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_analysis_tools_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal___net_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________v1bh475u\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_to_the__net_platform\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-09 23:44:23.035327\",\n    \"total_functions\": \"0\",\n    \"total_features\": \"4945\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-09 23:44:23"}
{"_id":{"$oid":"6a4feccb0108394cb24cdd09"},"sha256":"40050153dceec2c8fbb1912f8eeabe449d1e265f0c8198008be8b34e5403e731","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_h9nw9luu/Trojan.Kovter-019f46cd0f817e919789e963b55061ca.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_h9nw9luu/Trojan.Kovter-019f46cd0f817e919789e963b55061ca.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_h9nw9luu/Trojan.Kovter-019f46cd0f817e919789e963b55061ca.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 15af6227d39ca3f9d1dcd8566efb0057                                  │\n│ sha1     │ c8c3bf9ed944b614ae4b3e747e69e84026fb4039                          │\n│ sha256   │ 40050153dceec2c8fbb1912f8eeabe449d1e265f0c8198008be8b34e5403e731  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/Trojan.Kovter-01… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic         ┃ ATT&CK Technique                                     ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION            │ Input Capture::Keylogging [T1056.001]                │\n│                       │ Screen Capture [T1113]                               │\n│ DEFENSE EVASION       │ File and Directory Permissions Modification [T1222]  │\n│                       │ Obfuscated Files or Information [T1027]              │\n│ DISCOVERY             │ Application Window Discovery [T1010]                 │\n│                       │ File and Directory Discovery [T1083]                 │\n│                       │ Query Registry [T1012]                               │\n│                       │ System Information Discovery [T1082]                 │\n│                       │ System Location Discovery [T1614]                    │\n│ EXECUTION             │ Shared Modules [T1129]                               │\n└───────────────────────┴──────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective         ┃ MBC Behavior                                         ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION            │ Keylogging::Polling [F0002.002]                      │\n│                       │ Screen Capture::WinAPI [E1113.m01]                   │\n│ COMMAND AND CONTROL   │ C2 Communication::Receive Data [B0030.002]           │\n│                       │ C2 Communication::Send Data [B0030.001]              │\n│ COMMUNICATION         │ HTTP Communication::Connect to Server [C0002.009]    │\n│                       │ HTTP Communication::Create Request [C0002.012]       │\n│                       │ HTTP Communication::Get Response [C0002.017]         │\n│                       │ HTTP Communication::Send Data [C0002.005]            │\n│ CRYPTOGRAPHY          │ Cryptographic Hash [C0029]                           │\n│                       │ Decrypt Data [C0031]                                 │\n│                       │ Encrypt Data [C0027]                                 │\n│ DISCOVERY             │ Application Window Discovery [E1010]                 │\n│                       │ File and Directory Discovery [E1083]                 │\n│                       │ File and Directory Discovery::Log File [E1083.m01]   │\n│                       │ System Information Discovery [E1082]                 │\n│ FILE SYSTEM           │ Copy File [C0045]                                    │\n│                       │ Create Directory [C0046]                             │\n│                       │ Delete Directory [C0048]                             │\n│                       │ Delete File [C0047]                                  │\n│                       │ Move File [C0063]                                    │\n│                       │ Read File [C0051]                                    │\n│                       │ Set File Attributes [C0050]                          │\n│ OPERATING SYSTEM      │ Environment Variable::Set Variable [C0034.001]       │\n│                       │ Registry::Query Registry Value [C0036.006]           │\n│ PROCESS               │ Allocate Thread Local Storage [C0040]                │\n│                       │ Create Mutex [C0042]                                 │\n│                       │ Create Process [C0017]                               │\n│                       │ Create Process::Create Suspended Process [C0017.003] │\n│                       │ Set Thread Local Storage Value [C0041]               │\n│                       │ Terminate Process [C0018]                            │\n└───────────────────────┴──────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                           ┃ Namespace                             ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ get geographical location            │ collection                            │\n│ log keystrokes via polling           │ collection/keylog                     │\n│ capture screenshot                   │ collection/screenshot                 │\n│ receive data (17 matches)            │ communication                         │\n│ send data                            │ communication                         │\n│ connect to HTTP server (2 matches)   │ communication/http/client             │\n│ create HTTP request (4 matches)      │ communication/http/client             │\n│ encrypt or decrypt via WinCrypt      │ data-manipulation/encryption          │\n│ hash data via WinCrypt (22 matches)  │ data-manipulation/hashing             │\n│ extract resource via kernel32        │ executable/resource                   │\n│ functions                            │                                       │\n│ interact with driver via IOCTL (3    │ host-interaction/driver               │\n│ matches)                             │                                       │\n│ set environment variable (3 matches) │ host-interaction/environment-variable │\n│ get common file path (18 matches)    │ host-interaction/file-system          │\n│ get file system object information   │ host-interaction/file-system          │\n│ (4 matches)                          │                                       │\n│ copy file (5 matches)                │ host-interaction/file-system/copy     │\n│ create directory (14 matches)        │ host-interaction/file-system/create   │\n│ delete directory (4 matches)         │ host-interaction/file-system/delete   │\n│ delete file (2 matches)              │ host-interaction/file-system/delete   │\n│ get file size (7 matches)            │ host-interaction/file-system/meta     │\n│ get file version info (3 matches)    │ host-interaction/file-system/meta     │\n│ set file attributes (3 matches)      │ host-interaction/file-system/meta     │\n│ move file (24 matches)               │ host-interaction/file-system/move     │\n│ read file on Windows (4 matches)     │ host-interaction/file-system/read     │\n│ set application hook (3 matches)     │ host-interaction/gui                  │\n│ find graphical window (11 matches)   │ host-interaction/gui/window/find      │\n│ get graphical window text (2         │ host-interaction/gui/window/get-text  │\n│ matches)                             │                                       │\n│ get disk information                 │ host-interaction/hardware/storage     │\n│ print debug messages (2 matches)     │ host-interaction/log/debug/write-eve… │\n│ access the Windows event log (2      │ host-interaction/log/winevt/access    │\n│ matches)                             │                                       │\n│ create or open mutex on Windows (2   │ host-interaction/mutex                │\n│ matches)                             │                                       │\n│ get system information on Windows (2 │ host-interaction/os/info              │\n│ matches)                             │                                       │\n│ get thread local storage value (3    │ host-interaction/process              │\n│ matches)                             │                                       │\n│ create process on Windows (23        │ host-interaction/process/create       │\n│ matches)                             │                                       │\n│ create process suspended (2 matches) │ host-interaction/process/create       │\n│ terminate process (6 matches)        │ host-interaction/process/terminate    │\n│ query or enumerate registry value (2 │ host-interaction/registry             │\n│ matches)                             │                                       │\n│ allocate thread local storage (3     │ host-interaction/thread/tls           │\n│ matches)                             │                                       │\n│ set thread local storage value (3    │ host-interaction/thread/tls           │\n│ matches)                             │                                       │\n│ get ntdll base address (2 matches)   │ linking/runtime-linking               │\n└──────────────────────────────────────┴───────────────────────────────────────┘\n\n","verbose":"md5                     15af6227d39ca3f9d1dcd8566efb0057                        \nsha1                    c8c3bf9ed944b614ae4b3e747e69e84026fb4039                \nsha256                  40050153dceec2c8fbb1912f8eeabe449d1e265f0c8198008be8b34…\npath                    /home/apogean/projects/malware/windows/all_runs/Trojan.…\ntimestamp               2026-07-10 00:17:19.535576                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEI7utumd/rules                                   \nfunction count          1271                                                    \nlibrary function count  6                                                       \ntotal feature count     62500                                                   \n\nget geographical location\nnamespace  collection\nscope      function  \nmatches    0x407D63  \n\nlog keystrokes via polling\nnamespace  collection/keylog\nscope      function         \nmatches    0x4128E5         \n\ncapture screenshot\nnamespace  collection/screenshot\nscope      function             \nmatches    0x4128E5             \n\nreceive data (17 matches)\nnamespace    communication                                                     \ndescription  all known techniques for receiving data from a potential C2 server\nscope        function                                                          \nmatches      0x405BC0                                                          \n             0x405BD7                                                          \n             0x405C0D                                                          \n             0x405C30                                                          \n             0x405C8A                                                          \n             0x405CAD                                                          \n             0x405D53                                                          \n             0x405D91                                                          \n             0x405DC6                                                          \n             0x40E629                                                          \n             0x40E646                                                          \n             0x40E674                                                          \n             0x410599                                                          \n             0x4105C9                                                          \n             0x4105FD                                                          \n             0x410617                                                          \n             0x412E00                                                          \n\nsend data\nnamespace    communication                                                 \ndescription  all known techniques for sending data to a potential C2 server\nscope        function                                                      \nmatches      0x40B74F                                                      \n\nconnect to HTTP server (2 matches)\nnamespace  communication/http/client\nscope      function                 \nmatches    0x40D7A0                 \n           0x40D7AD                 \n\ncreate HTTP request (4 matches)\nnamespace  communication/http/client\nscope      function                 \nmatches    0x401970                 \n           0x404BF5                 \n           0x40F1C3                 \n           0x40F1E0                 \n\nread data from Internet (17 matches)\nnamespace  communication/http/client\nscope      function                 \nmatches    0x405BC0                 \n           0x405BD7                 \n           0x405C0D                 \n           0x405C30                 \n           0x405C8A                 \n           0x405CAD                 \n           0x405D53                 \n           0x405D91                 \n           0x405DC6                 \n           0x40E629                 \n           0x40E646                 \n           0x40E674                 \n           0x410599                 \n           0x4105C9                 \n           0x4105FD                 \n           0x410617                 \n           0x412E00                 \n\nsend file via HTTP\nnamespace  communication/http/client\nscope      instruction              \nmatches    0x40B756                 \n\nencrypt or decrypt via WinCrypt\nnamespace  data-manipulation/encryption\nscope      function                    \nmatches    0x409247                    \n\nhash data via WinCrypt (22 matches)\nnamespace  data-manipulation/hashing\nscope      function                 \nmatches    0x405BC0                 \n           0x405BD7                 \n           0x405C0D                 \n           0x405C30                 \n           0x405C8A                 \n           0x409D7A                 \n           0x409D9B                 \n           0x40AB57                 \n           0x40AB5D                 \n           0x40AB8C                 \n           0x40ABA5                 \n           0x40C783                 \n           0x40C7E5                 \n           0x40C803                 \n           0x40C817                 \n           0x40C898                 \n           0x40E629                 \n           0x40E646                 \n           0x40E674                 \n           0x40EE6C                 \n           0x4115F3                 \n           0x412E00                 \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x406D08           \n\ninteract with driver via IOCTL (3 matches)\nnamespace  host-interaction/driver\nscope      instruction            \nmatches    0x406234               \n           0x406234               \n           0x4117D3               \n\nset environment variable (3 matches)\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x407E93                             \n           0x407EE4                             \n           0x407F0C                             \n\nget common file path (18 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x403FC0                    \n           0x404005                    \n           0x404029                    \n           0x40434C                    \n           0x404362                    \n           0x40439E                    \n           0x4043D1                    \n           0x408C16                    \n           0x40C898                    \n           0x40E629                    \n           0x40E646                    \n           0x40E674                    \n           0x40EF63                    \n           0x40EF91                    \n           0x40EFBA                    \n           0x40F009                    \n           0x4128E5                    \n           0x412E00                    \n\nget file system object information (4 matches)\nnamespace  host-interaction/file-system\nscope      basic block                 \nmatches    0x407124                    \n           0x407124                    \n           0x407124                    \n           0x407124                    \n\ncopy file (5 matches)\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    0x405792                         \n           0x40950C                         \n           0x40DE7B                         \n           0x40DECF                         \n           0x40DF12                         \n\ncreate directory (14 matches)\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x401AE8                           \n           0x4052E6                           \n           0x407F81                           \n           0x407FB2                           \n           0x407FE5                           \n           0x408012                           \n           0x40BFC0                           \n           0x40BFFB                           \n           0x40F1C3                           \n           0x40F1E0                           \n           0x40F201                           \n           0x40F220                           \n           0x410416                           \n           0x41045E                           \n\ndelete directory (4 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x4045BF                           \n           0x4045CA                           \n           0x4045E3                           \n           0x40A794                           \n\ndelete file (2 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x406F81                           \n           0x406F84                           \n\nget file size (7 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x405BC0                         \n           0x40BDE5                         \n           0x40BE11                         \n           0x40BE2C                         \n           0x40D190                         \n           0x40D1C4                         \n           0x40D1FC                         \n\nget file version info (3 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x407A7A                         \n           0x40AB57                         \n           0x40AB5D                         \n\nset file attributes (3 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x40AB57                         \n           0x40AB5D                         \n           0x412928                         \n\nmove file (24 matches)\nnamespace  host-interaction/file-system/move\nscope      function                         \nmatches    0x4017BF                         \n           0x40188F                         \n           0x4018A8                         \n           0x404469                         \n           0x404488                         \n           0x406713                         \n           0x40808A                         \n           0x4080CF                         \n           0x4080D8                         \n           0x4080FC                         \n           0x40812C                         \n           0x408632                         \n           0x408D30                         \n           0x40AF8E                         \n           0x40AFC4                         \n           0x40B890                         \n           0x40B8B4                         \n           0x40B922                         \n           0x40B954                         \n           0x40B966                         \n           0x40F480                         \n           0x40F4B9                         \n           0x4128E5                         \n           0x412E00                         \n\nread file on Windows (4 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x40FB3E                         \n           0x40FB5D                         \n           0x40FB6A                         \n           0x40FB88                         \n\nset application hook (3 matches)\nnamespace  host-interaction/gui\nscope      instruction         \nmatches    0x40A051            \n           0x40A051            \n           0x40A1A1            \n\nfind graphical window (11 matches)\nnamespace  host-interaction/gui/window/find\nscope      instruction                     \nmatches    0x402C7B                        \n           0x402C7B                        \n           0x40557C                        \n           0x40557C                        \n           0x40557C                        \n           0x40557C                        \n           0x40557C                        \n           0x40557C                        \n           0x40557C                        \n           0x40557C                        \n           0x40557C                        \n\nget graphical window text (2 matches)\nnamespace  host-interaction/gui/window/get-text\nscope      function                            \nmatches    0x401CD2                            \n           0x408C16                            \n\nget disk information\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x40CC49                         \n\nprint debug messages (2 matches)\nnamespace  host-interaction/log/debug/write-event\nscope      function                              \nmatches    0x408C16                              \n           0x408C8B                              \n\naccess the Windows event log (2 matches)\nnamespace  host-interaction/log/winevt/access\nscope      function                          \nmatches    0x408C16                          \n           0x408C8B                          \n\ncreate or open mutex on Windows (2 matches)\nnamespace  host-interaction/mutex\nscope      instruction           \nmatches    0x404CED              \n           0x40DA56              \n\nget system information on Windows (2 matches)\nnamespace  host-interaction/os/info\nscope      function                \nmatches    0x40DE7B                \n           0x40DECF                \n\nget thread local storage value (3 matches)\nnamespace  host-interaction/process\nscope      function                \nmatches    0x404469                \n           0x404488                \n           0x406713                \n\ncreate process on Windows (23 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x4017DD                       \n           0x40EB47                       \n           0x40EB47                       \n           0x404891                       \n           0x404891                       \n           0x407847                       \n           0x40B732                       \n           0x40B708                       \n           0x40B708                       \n           0x40B732                       \n           0x40B708                       \n           0x40B732                       \n           0x40D7C0                       \n           0x40D7C0                       \n           0x40DA7F                       \n           0x40DE13                       \n           0x40DE13                       \n           0x4107E9                       \n           0x4107E9                       \n           0x4108D1                       \n           0x4108D1                       \n           0x4108D1                       \n           0x40F461                       \n\ncreate process suspended (2 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x40DE13                       \n           0x40DE13                       \n\nterminate process (6 matches)\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x40DE0D                          \n           0x40DE57                          \n           0x410C5F                          \n           0x410C76                          \n           0x410CAD                          \n           0x410D24                          \n\nquery or enumerate registry value (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x40635B                 \n           0x406F1C                 \n\nallocate thread local storage (3 matches)\nnamespace  host-interaction/thread/tls\nscope      function                   \nmatches    0x404E01                   \n           0x404E18                   \n           0x409E5D                   \n\nset thread local storage value (3 matches)\nnamespace  host-interaction/thread/tls\nscope      function                   \nmatches    0x40B60F                   \n           0x40B63A                   \n           0x40C933                   \n\naccess PEB ldr_data (2 matches)\nnamespace  linking/runtime-linking\nscope      basic block            \nmatches    0x406AC0               \n           0x406AC0               \n\nget ntdll base address (2 matches)\nnamespace  linking/runtime-linking\nscope      basic block            \nmatches    0x406AC0               \n           0x406AC0               \n\n\n\n","very_verbose":"md5                     15af6227d39ca3f9d1dcd8566efb0057                        \nsha1                    c8c3bf9ed944b614ae4b3e747e69e84026fb4039                \nsha256                  40050153dceec2c8fbb1912f8eeabe449d1e265f0c8198008be8b34…\npath                    /home/apogean/projects/malware/windows/all_runs/Trojan.…\ntimestamp               2026-07-10 00:17:37.329159                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIiiy17p/rules                                   \nfunction count          1271                                                    \nlibrary function count  6                                                       \ntotal feature count     62500                                                   \n\nPEB access (5 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Debugger Detection::Process Environment   \n            Block [B0001.019]                                                   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nbasic block @ 0x406AC0 in function 0x406A6B\n  or:\n    and:\n      arch: i386\n      characteristic: fs access @ 0x406AEE\n      or:\n        offset: 0x30 @ 0x406AEA\n\ncalculate modulo 256 via x86 assembly (12 matches, only showing first match of \nlibrary rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x403DFB\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x403DFB\n    or:\n      number: 0xFF @ 0x403DFB\n\ncontain loop (256 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x4014E0\n  or:\n    characteristic: loop @ 0x4014E0\n\ncreate or open file (2 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x406CFD\n  or:\n    api: CreateFile @ 0x406CFD\n\ncreate or open registry key (14 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x402978 in function 0x402978\n  or:\n    api: RegCreateKeyEx @ 0x402981\n\ndelay execution (6 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x404988 in function 0x404988\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x40498D\n\nget OS version (19 matches, only showing first match of library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x405311\n  or:\n    api: GetVersion @ 0x40E70E\n\nget geographical location\nnamespace  collection                                  \nauthor     moritz.raabe, michael.hunhoff@mandiant.com  \nscope      function                                    \natt&ck     Discovery::System Location Discovery [T1614]\nfunction @ 0x407D63\n  or:\n    api: GetLocaleInfo @ 0x407D86\n\nlog keystrokes via polling\nnamespace  collection/keylog                                \nauthor     michael.hunhoff@mandiant.com                     \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nmbc        Collection::Keylogging::Polling [F0002.002]      \nfunction @ 0x4128E5\n  or:\n    api: GetAsyncKeyState @ 0x41294F\n\ncapture screenshot\nnamespace  collection/screenshot                                            \nauthor     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\nscope      function                                                         \natt&ck     Collection::Screen Capture [T1113]                               \nmbc        Collection::Screen Capture::WinAPI [E1113.m01]                   \nfunction @ 0x4128E5\n  or:\n    basic block:\n      and:\n        api: BitBlt @ 0x412957\n        characteristic: tight loop @ 0x412928\n\nreceive data (17 matches)\nnamespace    communication                                                     \nauthor       william.ballenthin@mandiant.com                                   \nscope        function                                                          \nmbc          Command and Control::C2 Communication::Receive Data [B0030.002]   \ndescription  all known techniques for receiving data from a potential C2 server\nfunction @ 0x405BC0\n  or:\n    match: read data from Internet @ 0x405BC0\n      and:\n        or:\n          api: InternetReadFile @ 0x405DE2\nfunction @ 0x405BD7\n  or:\n    match: read data from Internet @ 0x405BD7\n      and:\n        or:\n          api: InternetReadFile @ 0x405DE2\nfunction @ 0x405C0D\n  or:\n    match: read data from Internet @ 0x405C0D\n      and:\n        or:\n          api: InternetReadFile @ 0x405DE2\nfunction @ 0x405C30\n  or:\n    match: read data from Internet @ 0x405C30\n      and:\n        or:\n          api: InternetReadFile @ 0x405DE2\nfunction @ 0x405C8A\n  or:\n    match: read data from Internet @ 0x405C8A\n      and:\n        or:\n          api: InternetReadFile @ 0x405DE2\nfunction @ 0x405CAD\n  or:\n    match: read data from Internet @ 0x405CAD\n      and:\n        or:\n          api: InternetReadFile @ 0x405DE2\nfunction @ 0x405D53\n  or:\n    match: read data from Internet @ 0x405D53\n      and:\n        or:\n          api: InternetReadFile @ 0x405DE2\nfunction @ 0x405D91\n  or:\n    match: read data from Internet @ 0x405D91\n      and:\n        or:\n          api: InternetReadFile @ 0x405DE2\nfunction @ 0x405DC6\n  or:\n    match: read data from Internet @ 0x405DC6\n      and:\n        or:\n          api: InternetReadFile @ 0x405DE2\nfunction @ 0x40E629\n  or:\n    match: read data from Internet @ 0x40E629\n      and:\n        or:\n          api: InternetReadFile @ 0x405DE2\nfunction @ 0x40E646\n  or:\n    match: read data from Internet @ 0x40E646\n      and:\n        or:\n          api: InternetReadFile @ 0x405DE2\nfunction @ 0x40E674\n  or:\n    match: read data from Internet @ 0x40E674\n      and:\n        or:\n          api: InternetReadFile @ 0x405DE2\nfunction @ 0x410599\n  or:\n    match: read data from Internet @ 0x410599\n      and:\n        or:\n          api: InternetReadFile @ 0x410629\nfunction @ 0x4105C9\n  or:\n    match: read data from Internet @ 0x4105C9\n      and:\n        or:\n          api: InternetReadFile @ 0x410629\nfunction @ 0x4105FD\n  or:\n    match: read data from Internet @ 0x4105FD\n      and:\n        or:\n          api: InternetReadFile @ 0x410629\nfunction @ 0x410617\n  or:\n    match: read data from Internet @ 0x410617\n      and:\n        or:\n          api: InternetReadFile @ 0x410629\nfunction @ 0x412E00\n  or:\n    match: read data from Internet @ 0x412E00\n      and:\n        or:\n          api: InternetReadFile @ 0x405DE2\n\nsend data\nnamespace    communication                                                 \nauthor       william.ballenthin@mandiant.com, joakim@intezer.com           \nscope        function                                                      \nmbc          Command and Control::C2 Communication::Send Data [B0030.001]  \ndescription  all known techniques for sending data to a potential C2 server\nfunction @ 0x40B74F\n  or:\n    and:\n      os: windows\n      or:\n        match: send file via HTTP @ 0x40B756\n          and:\n            api: InternetWriteFile @ 0x40B756\n\nconnect to HTTP server (2 matches)\nnamespace  communication/http/client                                       \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \nmbc        Communication::HTTP Communication::Connect to Server [C0002.009]\nfunction @ 0x40D7A0\n  and:\n    api: InternetConnect @ 0x40D7B6\nfunction @ 0x40D7AD\n  and:\n    api: InternetConnect @ 0x40D7B6\n\ncreate HTTP request (4 matches)\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Create Request [C0002.012]\nfunction @ 0x401970\n  and:\n    or:\n      api: InternetOpen @ 0x401A58\nfunction @ 0x404BF5\n  and:\n    or:\n      api: InternetOpen @ 0x404BF9\nfunction @ 0x40F1C3\n  and:\n    or:\n      api: InternetOpen @ 0x40F1EF\nfunction @ 0x40F1E0\n  and:\n    or:\n      api: InternetOpen @ 0x40F1EF\n\nread data from Internet (17 matches)\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Get Response [C0002.017]  \nfunction @ 0x405BC0\n  and:\n    or:\n      api: InternetReadFile @ 0x405DE2\nfunction @ 0x405BD7\n  and:\n    or:\n      api: InternetReadFile @ 0x405DE2\nfunction @ 0x405C0D\n  and:\n    or:\n      api: InternetReadFile @ 0x405DE2\nfunction @ 0x405C30\n  and:\n    or:\n      api: InternetReadFile @ 0x405DE2\nfunction @ 0x405C8A\n  and:\n    or:\n      api: InternetReadFile @ 0x405DE2\nfunction @ 0x405CAD\n  and:\n    or:\n      api: InternetReadFile @ 0x405DE2\nfunction @ 0x405D53\n  and:\n    or:\n      api: InternetReadFile @ 0x405DE2\nfunction @ 0x405D91\n  and:\n    or:\n      api: InternetReadFile @ 0x405DE2\nfunction @ 0x405DC6\n  and:\n    or:\n      api: InternetReadFile @ 0x405DE2\nfunction @ 0x40E629\n  and:\n    or:\n      api: InternetReadFile @ 0x405DE2\nfunction @ 0x40E646\n  and:\n    or:\n      api: InternetReadFile @ 0x405DE2\nfunction @ 0x40E674\n  and:\n    or:\n      api: InternetReadFile @ 0x405DE2\nfunction @ 0x410599\n  and:\n    or:\n      api: InternetReadFile @ 0x410629\nfunction @ 0x4105C9\n  and:\n    or:\n      api: InternetReadFile @ 0x410629\nfunction @ 0x4105FD\n  and:\n    or:\n      api: InternetReadFile @ 0x410629\nfunction @ 0x410617\n  and:\n    or:\n      api: InternetReadFile @ 0x410629\nfunction @ 0x412E00\n  and:\n    or:\n      api: InternetReadFile @ 0x405DE2\n\nsend file via HTTP\nnamespace  communication/http/client                               \nauthor     matthew.williams@mandiant.com                           \nscope      instruction                                             \nmbc        Communication::HTTP Communication::Send Data [C0002.005]\ninstruction @ 0x40B756\n  and:\n    api: InternetWriteFile @ 0x40B756\n\nencrypt or decrypt via WinCrypt\nnamespace  data-manipulation/encryption                                         \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Decrypt Data [C0031], Cryptography::Encrypt Data       \n           [C0027]                                                              \nfunction @ 0x409247\n  and:\n    or:\n      api: CryptDecrypt @ 0x409258\n\nhash data via WinCrypt (22 matches)\nnamespace  data-manipulation/hashing               \nauthor     michael.hunhoff@mandiant.com            \nscope      function                                \nmbc        Cryptography::Cryptographic Hash [C0029]\nfunction @ 0x405BC0\n  and:\n    api: CryptHashData @ 0x405C60\nfunction @ 0x405BD7\n  and:\n    api: CryptHashData @ 0x405C60\nfunction @ 0x405C0D\n  and:\n    api: CryptHashData @ 0x405C60\nfunction @ 0x405C30\n  and:\n    api: CryptHashData @ 0x405C60\nfunction @ 0x405C8A\n  and:\n    api: CryptHashData @ 0x405C60\nfunction @ 0x409D7A\n  and:\n    api: CryptHashData @ 0x409DD5\nfunction @ 0x409D9B\n  and:\n    api: CryptHashData @ 0x409DD5\nfunction @ 0x40AB57\n  and:\n    api: CryptHashData @ 0x40ABC8\nfunction @ 0x40AB5D\n  and:\n    api: CryptHashData @ 0x40ABC8\nfunction @ 0x40AB8C\n  and:\n    api: CryptHashData @ 0x40ABC8\nfunction @ 0x40ABA5\n  and:\n    api: CryptHashData @ 0x40ABC8\nfunction @ 0x40C783\n  and:\n    api: CryptHashData @ 0x40C833\nfunction @ 0x40C7E5\n  and:\n    api: CryptHashData @ 0x40C833\nfunction @ 0x40C803\n  and:\n    api: CryptHashData @ 0x40C833\nfunction @ 0x40C817\n  and:\n    api: CryptHashData @ 0x40C833\nfunction @ 0x40C898\n  and:\n    api: CryptHashData @ 0x40C833\nfunction @ 0x40E629\n  and:\n    api: CryptHashData @ 0x405C60\nfunction @ 0x40E646\n  and:\n    api: CryptHashData @ 0x405C60\nfunction @ 0x40E674\n  and:\n    api: CryptHashData @ 0x405C60\nfunction @ 0x40EE6C\n  and:\n    api: CryptHashData @ 0x40EE51\nfunction @ 0x4115F3\n  and:\n    api: CryptHashData @ 0x4116E3\nfunction @ 0x412E00\n  and:\n    api: CryptHashData @ 0x405C60\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x406D08\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x406D1C\n\ninteract with driver via IOCTL (3 matches)\nnamespace  host-interaction/driver  \nauthor     moritz.raabe@mandiant.com\nscope      instruction              \ninstruction @ 0x406234\n  or:\n    api: DeviceIoControl @ 0x406234\ninstruction @ 0x406234\n  or:\n    api: DeviceIoControl @ 0x406234\ninstruction @ 0x4117D3\n  or:\n    api: DeviceIoControl @ 0x4117D3\n\nset environment variable (3 matches)\nnamespace  host-interaction/environment-variable                           \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \nmbc        Operating System::Environment Variable::Set Variable [C0034.001]\nfunction @ 0x407E93\n  or:\n    api: SetEnvironmentVariable @ 0x407EC5\nfunction @ 0x407EE4\n  or:\n    api: SetEnvironmentVariable @ 0x407EC5\nfunction @ 0x407F0C\n  or:\n    api: SetEnvironmentVariable @ 0x407EC5\n\nget common file path (18 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x403FC0\n  or:\n    api: GetTempPath @ 0x411FA7\nfunction @ 0x404005\n  or:\n    api: GetTempPath @ 0x411FA7\nfunction @ 0x404029\n  or:\n    api: GetTempPath @ 0x411FA7\nfunction @ 0x40434C\n  or:\n    api: GetTempPath @ 0x404441\nfunction @ 0x404362\n  or:\n    api: GetTempPath @ 0x404441\nfunction @ 0x40439E\n  or:\n    api: GetTempPath @ 0x404441\nfunction @ 0x4043D1\n  or:\n    api: GetTempPath @ 0x404441\nfunction @ 0x408C16\n  or:\n    api: GetSystemDirectory @ 0x408C81\nfunction @ 0x40C898\n  or:\n    api: GetTempPath @ 0x40C8A6\nfunction @ 0x40E629\n  or:\n    api: GetTempPath @ 0x411FA7\nfunction @ 0x40E646\n  or:\n    api: GetTempPath @ 0x411FA7\nfunction @ 0x40E674\n  or:\n    api: GetTempPath @ 0x411FA7\nfunction @ 0x40EF63\n  or:\n    api: GetTempPath @ 0x40F07A\nfunction @ 0x40EF91\n  or:\n    api: GetTempPath @ 0x40F07A\nfunction @ 0x40EFBA\n  or:\n    api: GetTempPath @ 0x40F07A\nfunction @ 0x40F009\n  or:\n    api: GetTempPath @ 0x40F07A\nfunction @ 0x4128E5\n  or:\n    api: GetTempPath @ 0x404441\nfunction @ 0x412E00\n  or:\n    api: GetTempPath @ 0x411FA7\n\nget file system object information (4 matches)\nnamespace  host-interaction/file-system                   \nauthor     michael.hunhoff@mandiant.com                   \nscope      basic block                                    \natt&ck     Discovery::File and Directory Discovery [T1083]\nbasic block @ 0x407124 in function 0x407124\n  or:\n    api: SHGetFileInfo @ 0x407142\nbasic block @ 0x407124 in function 0x407124\n  or:\n    api: SHGetFileInfo @ 0x407142\nbasic block @ 0x407124 in function 0x407124\n  or:\n    api: SHGetFileInfo @ 0x407142\nbasic block @ 0x407124 in function 0x407124\n  or:\n    api: SHGetFileInfo @ 0x407142\n\ncopy file (5 matches)\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ 0x405792\n  or:\n    api: CopyFile @ 0x4057F3\nfunction @ 0x40950C\n  or:\n    api: CopyFile @ 0x40953C\nfunction @ 0x40DE7B\n  or:\n    api: CopyFileEx @ 0x40DFDD\nfunction @ 0x40DECF\n  or:\n    api: CopyFileEx @ 0x40DFDD\nfunction @ 0x40DF12\n  or:\n    api: CopyFileEx @ 0x40DFDD\n\ncreate directory (14 matches)\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x401AE8\n  or:\n    api: CreateDirectoryEx @ 0x408028\nfunction @ 0x4052E6\n  or:\n    api: CreateDirectory @ 0x4104B1\nfunction @ 0x407F81\n  or:\n    api: CreateDirectoryEx @ 0x408028\nfunction @ 0x407FB2\n  or:\n    api: CreateDirectoryEx @ 0x408028\nfunction @ 0x407FE5\n  or:\n    api: CreateDirectoryEx @ 0x408028\nfunction @ 0x408012\n  or:\n    api: CreateDirectoryEx @ 0x408028\nfunction @ 0x40BFC0\n  or:\n    api: CreateDirectoryEx @ 0x40C00F\nfunction @ 0x40BFFB\n  or:\n    api: CreateDirectoryEx @ 0x40C00F\nfunction @ 0x40F1C3\n  or:\n    api: CreateDirectoryEx @ 0x40F23A\nfunction @ 0x40F1E0\n  or:\n    api: CreateDirectoryEx @ 0x40F23A\nfunction @ 0x40F201\n  or:\n    api: CreateDirectoryEx @ 0x40F23A\nfunction @ 0x40F220\n  or:\n    api: CreateDirectoryEx @ 0x40F23A\nfunction @ 0x410416\n  or:\n    api: CreateDirectory @ 0x4104B1\nfunction @ 0x41045E\n  or:\n    api: CreateDirectory @ 0x4104B1\n\ndelete directory (4 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ 0x4045BF\n  or:\n    api: RemoveDirectory @ 0x4045F8\nfunction @ 0x4045CA\n  or:\n    api: RemoveDirectory @ 0x4045F8\nfunction @ 0x4045E3\n  or:\n    api: RemoveDirectory @ 0x4045F8\nfunction @ 0x40A794\n  or:\n    api: RemoveDirectory @ 0x40A7B7\n\ndelete file (2 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x406F81\n  or:\n    api: DeleteFile @ 0x406FBE\nfunction @ 0x406F84\n  or:\n    api: DeleteFile @ 0x406FBE\n\nget file size (7 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x405BC0\n  or:\n    api: GetFileSize @ 0x40BE48\nfunction @ 0x40BDE5\n  or:\n    api: GetFileSize @ 0x40BE48\nfunction @ 0x40BE11\n  or:\n    api: GetFileSize @ 0x40BE48\nfunction @ 0x40BE2C\n  or:\n    api: GetFileSize @ 0x40BE48\nfunction @ 0x40D190\n  or:\n    api: GetFileSize @ 0x40D22C\nfunction @ 0x40D1C4\n  or:\n    api: GetFileSize @ 0x40D22C\nfunction @ 0x40D1FC\n  or:\n    api: GetFileSize @ 0x40D22C\n\nget file version info (3 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x407A7A\n  and:\n    or:\n      api: GetFileVersionInfo @ 0x407A91\nfunction @ 0x40AB57\n  and:\n    or:\n      api: GetFileVersionInfo @ 0x40AB74\nfunction @ 0x40AB5D\n  and:\n    or:\n      api: GetFileVersionInfo @ 0x40AB74\n\nset file attributes (3 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ 0x40AB57 in function 0x40AB57\n  or:\n    api: SetFileAttributes @ 0x40AB83\nbasic block @ 0x40AB5D in function 0x40AB5D\n  or:\n    api: SetFileAttributes @ 0x40AB83\nbasic block @ 0x412928 in function 0x4128E5\n  or:\n    api: SetFileAttributes @ 0x412972\n\nmove file (24 matches)\nnamespace  host-interaction/file-system/move                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Move File [C0063]                         \nfunction @ 0x4017BF\n  or:\n    api: MoveFileEx @ 0x401877\nfunction @ 0x40188F\n  or:\n    api: MoveFileEx @ 0x401877\nfunction @ 0x4018A8\n  or:\n    api: MoveFileEx @ 0x401877\nfunction @ 0x404469\n  or:\n    api: MoveFile @ 0x408643\nfunction @ 0x404488\n  or:\n    api: MoveFile @ 0x408643\nfunction @ 0x406713\n  or:\n    api: MoveFile @ 0x408643\nfunction @ 0x40808A\n  or:\n    api: MoveFileWithProgress @ 0x408156\nfunction @ 0x4080CF\n  or:\n    api: MoveFileWithProgress @ 0x408156\nfunction @ 0x4080D8\n  or:\n    api: MoveFileWithProgress @ 0x408156\nfunction @ 0x4080FC\n  or:\n    api: MoveFileWithProgress @ 0x408156\nfunction @ 0x40812C\n  or:\n    api: MoveFileWithProgress @ 0x408156\nfunction @ 0x408632\n  or:\n    api: MoveFile @ 0x408643\nfunction @ 0x408D30\n  or:\n    api: MoveFileWithProgress @ 0x408D31\nfunction @ 0x40AF8E\n  or:\n    api: MoveFileWithProgress @ 0x40AFEA\nfunction @ 0x40AFC4\n  or:\n    api: MoveFileWithProgress @ 0x40AFEA\nfunction @ 0x40B890\n  or:\n    api: MoveFileEx @ 0x40B97E\nfunction @ 0x40B8B4\n  or:\n    api: MoveFileEx @ 0x40B97E\nfunction @ 0x40B922\n  or:\n    api: MoveFileEx @ 0x40B97E\nfunction @ 0x40B954\n  or:\n    api: MoveFileEx @ 0x40B954\nfunction @ 0x40B966\n  or:\n    api: MoveFileEx @ 0x40B97E\nfunction @ 0x40F480\n  or:\n    api: MoveFileEx @ 0x40F4D5\nfunction @ 0x40F4B9\n  or:\n    api: MoveFileEx @ 0x40F4D5\nfunction @ 0x4128E5\n  or:\n    api: MoveFileWithProgress @ 0x408156\nfunction @ 0x412E00\n  or:\n    api: MoveFileEx @ 0x40F4D5\n\nread file on Windows (4 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x40FB3E\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x40FBA6\nfunction @ 0x40FB5D\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x40FBA6\nfunction @ 0x40FB6A\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x40FBA6\nfunction @ 0x40FB88\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x40FBA6\n\nset application hook (3 matches)\nnamespace  host-interaction/gui        \nauthor     michael.hunhoff@mandiant.com\nscope      instruction                 \ninstruction @ 0x40A051\n  or:\n    api: SetWindowsHookEx @ 0x40A051\ninstruction @ 0x40A051\n  or:\n    api: SetWindowsHookEx @ 0x40A051\ninstruction @ 0x40A1A1\n  or:\n    api: UnhookWindowsHookEx @ 0x40A1A1\n\nfind graphical window (11 matches)\nnamespace  host-interaction/gui/window/find               \nauthor     moritz.raabe@mandiant.com                      \nscope      instruction                                    \natt&ck     Discovery::Application Window Discovery [T1010]\ninstruction @ 0x402C7B\n  or:\n    api: FindWindowEx @ 0x402C7B\ninstruction @ 0x402C7B\n  or:\n    api: FindWindowEx @ 0x402C7B\ninstruction @ 0x40557C\n  or:\n    api: FindWindowEx @ 0x40557C\ninstruction @ 0x40557C\n  or:\n    api: FindWindowEx @ 0x40557C\ninstruction @ 0x40557C\n  or:\n    api: FindWindowEx @ 0x40557C\ninstruction @ 0x40557C\n  or:\n    api: FindWindowEx @ 0x40557C\ninstruction @ 0x40557C\n  or:\n    api: FindWindowEx @ 0x40557C\ninstruction @ 0x40557C\n  or:\n    api: FindWindowEx @ 0x40557C\ninstruction @ 0x40557C\n  or:\n    api: FindWindowEx @ 0x40557C\ninstruction @ 0x40557C\n  or:\n    api: FindWindowEx @ 0x40557C\ninstruction @ 0x40557C\n  or:\n    api: FindWindowEx @ 0x40557C\n\nget graphical window text (2 matches)\nnamespace  host-interaction/gui/window/get-text           \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \nmbc        Discovery::Application Window Discovery [E1010]\nfunction @ 0x401CD2\n  or:\n    and:\n      api: GetWindowText @ 0x401D28\nfunction @ 0x408C16\n  or:\n    and:\n      api: GetWindowText @ 0x408C79\n\nget disk information\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ 0x40CC49\n  or:\n    api: GetDriveType @ 0x40CC59\n\nprint debug messages (2 matches)\nnamespace  host-interaction/log/debug/write-event\nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \nfunction @ 0x408C16\n  or:\n    api: OutputDebugString @ 0x408CB5\nfunction @ 0x408C8B\n  or:\n    api: OutputDebugString @ 0x408CB5\n\naccess the Windows event log (2 matches)\nnamespace  host-interaction/log/winevt/access                           \nauthor     moritz.raabe@mandiant.com                                    \nscope      function                                                     \nmbc        Discovery::File and Directory Discovery::Log File [E1083.m01]\nfunction @ 0x408C16\n  or:\n    api: ReportEvent @ 0x408CAF\nfunction @ 0x408C8B\n  or:\n    api: ReportEvent @ 0x408CAF\n\ncreate or open mutex on Windows (2 matches)\nnamespace  host-interaction/mutex                                               \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           mehunhoff@google.com                                                 \nscope      instruction                                                          \nmbc        Process::Create Mutex [C0042]                                        \ninstruction @ 0x404CED\n  or:\n    api: CreateMutex @ 0x404CED\ninstruction @ 0x40DA56\n  or:\n    api: CreateMutex @ 0x40DA56\n\nget system information on Windows (2 matches)\nnamespace  host-interaction/os/info                       \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com  \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x40DE7B\n  and:\n    os: windows\n    or:\n      api: GetSystemInfo @ 0x40DEDB\nfunction @ 0x40DECF\n  and:\n    os: windows\n    or:\n      api: GetSystemInfo @ 0x40DEDB\n\nget thread local storage value (3 matches)\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x404469\n  and:\n    api: TlsGetValue @ 0x40860B\nfunction @ 0x404488\n  and:\n    api: TlsGetValue @ 0x40860B\nfunction @ 0x406713\n  and:\n    api: TlsGetValue @ 0x40860B\n\ncreate process on Windows (23 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x4017DD in function 0x4017BF\n  or:\n    api: ShellExecute @ 0x4017EB\nbasic block @ 0x404891 in function 0x4048C2\n  or:\n    api: ShellExecuteEx @ 0x4048AC\nbasic block @ 0x404891 in function 0x4048C2\n  or:\n    api: ShellExecuteEx @ 0x4048AC\nbasic block @ 0x407847 in function 0x407847\n  or:\n    api: CreateProcess @ 0x407848\nbasic block @ 0x40B708 in function 0x40B708\n  or:\n    api: ShellExecute @ 0x40B732\nbasic block @ 0x40B708 in function 0x40B708\n  or:\n    api: ShellExecute @ 0x40B732\nbasic block @ 0x40B708 in function 0x40B708\n  or:\n    api: ShellExecute @ 0x40B732\nbasic block @ 0x40B732 in function 0x40B732\n  or:\n    api: ShellExecute @ 0x40B732\nbasic block @ 0x40B732 in function 0x40B732\n  or:\n    api: ShellExecute @ 0x40B732\nbasic block @ 0x40B732 in function 0x40B732\n  or:\n    api: ShellExecute @ 0x40B732\nbasic block @ 0x40D7C0 in function 0x40D7AD\n  or:\n    api: ShellExecute @ 0x40D7C0\nbasic block @ 0x40D7C0 in function 0x40D7AD\n  or:\n    api: ShellExecute @ 0x40D7C0\nbasic block @ 0x40DA7F in function 0x40DA75\n  or:\n    api: CreateProcess @ 0x40DAAE\nbasic block @ 0x40DE13 in function 0x40DE57\n  or:\n    api: CreateProcess @ 0x40DE48\nbasic block @ 0x40DE13 in function 0x40DE57\n  or:\n    api: CreateProcess @ 0x40DE48\nbasic block @ 0x40EB47 in function 0x404488\n  or:\n    api: ShellExecute @ 0x40EB7C\nbasic block @ 0x40EB47 in function 0x404488\n  or:\n    api: ShellExecute @ 0x40EB7C\nbasic block @ 0x40F461 in function 0x412E00\n  or:\n    api: ShellExecute @ 0x40F47A\nbasic block @ 0x4107E9 in function 0x4107E1\n  or:\n    api: ShellExecuteEx @ 0x410823\nbasic block @ 0x4107E9 in function 0x4107E1\n  or:\n    api: ShellExecuteEx @ 0x410823\nbasic block @ 0x4108D1 in function 0x410962\n  or:\n    api: CreateProcess @ 0x4108DE\nbasic block @ 0x4108D1 in function 0x410962\n  or:\n    api: CreateProcess @ 0x4108DE\nbasic block @ 0x4108D1 in function 0x410962\n  or:\n    api: CreateProcess @ 0x4108DE\n\ncreate process suspended (2 matches)\nnamespace   host-interaction/process/create                                     \nauthor      william.ballenthin@mandiant.com, mehunhoff@google.com               \nscope       basic block                                                         \nmbc         Process::Create Process::Create Suspended Process [C0017.003]       \nreferences  https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/an-…\n            https://learn.microsoft.com/en-us/windows/win32/procthread/process-…\nbasic block @ 0x40DE13 in function 0x40DE57\n  or:\n    and:\n      or:\n        number: 0x2 = DEBUG_ONLY_THIS_PROCESS @ 0x40DE20\n      or:\n        api: CreateProcess @ 0x40DE48\nbasic block @ 0x40DE13 in function 0x40DE57\n  or:\n    and:\n      or:\n        number: 0x2 = DEBUG_ONLY_THIS_PROCESS @ 0x40DE20\n      or:\n        api: CreateProcess @ 0x40DE48\n\nterminate process (6 matches)\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x40DE0D\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x40DE37\nfunction @ 0x40DE57\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x40DE37\nfunction @ 0x410C5F\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x410D2B\nfunction @ 0x410C76\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x410D2B\nfunction @ 0x410CAD\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x410D2B\nfunction @ 0x410D24\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x410D2B\n\nquery or enumerate registry value (2 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x40635B\n  and:\n    or:\n      api: RegQueryValueEx @ 0x4063D3\nfunction @ 0x406F1C\n  and:\n    or:\n      api: RegEnumValue @ 0x406F4C\n\nallocate thread local storage (3 matches)\nnamespace  host-interaction/thread/tls                   \nauthor     michael.hunhoff@mandiant.com                  \nscope      function                                      \nmbc        Process::Allocate Thread Local Storage [C0040]\nfunction @ 0x404E01\n  or:\n    api: TlsAlloc @ 0x404E31\nfunction @ 0x404E18\n  or:\n    api: TlsAlloc @ 0x404E31\nfunction @ 0x409E5D\n  or:\n    api: TlsAlloc @ 0x409E99\n\nset thread local storage value (3 matches)\nnamespace  host-interaction/thread/tls                    \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \nmbc        Process::Set Thread Local Storage Value [C0041]\nfunction @ 0x40B60F\n  and:\n    api: TlsSetValue @ 0x4071D4\nfunction @ 0x40B63A\n  and:\n    api: TlsSetValue @ 0x4071D4\nfunction @ 0x40C933\n  and:\n    api: TlsSetValue @ 0x40C93D\n\naccess PEB ldr_data (2 matches)\nnamespace   linking/runtime-linking                                             \nauthor      moritz.raabe@mandiant.com                                           \nscope       basic block                                                         \natt&ck      Execution::Shared Modules [T1129]                                   \nreferences  https://www.geoffchappell.com/studies/windows/km/ntoskrnl/inc/api/n…\n            https://github.com/d35ha/CallObfuscator/blob/5834aff9ff4511f1408ae4…\nbasic block @ 0x406AC0 in function 0x406A6B\n  or:\n    and: = x32\n      arch: i386\n      match: PEB access @ 0x406AC0\n        or:\n          and:\n            arch: i386\n            characteristic: fs access @ 0x406AEE\n            or:\n              offset: 0x30 @ 0x406AEA\n      offset: 0xC = PEB.LDR_DATA @ 0x406AFD, 0x406B01\n      or: = resolve a module list\n        offset: 0xC = PEB.LDR_DATA.InLoadOrderModuleList @ 0x406AFD, 0x406B01\n        offset: 0x14 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x406AF5\nbasic block @ 0x406AC0 in function 0x406A6B\n  or:\n    and: = x32\n      arch: i386\n      match: PEB access @ 0x406AC0\n        or:\n          and:\n            arch: i386\n            characteristic: fs access @ 0x406AEE\n            or:\n              offset: 0x30 @ 0x406AEA\n      offset: 0xC = PEB.LDR_DATA @ 0x406AFD, 0x406B01\n      or: = resolve a module list\n        offset: 0xC = PEB.LDR_DATA.InLoadOrderModuleList @ 0x406AFD, 0x406B01\n        offset: 0x14 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x406AF5\n\nget ntdll base address (2 matches)\nnamespace   linking/runtime-linking                                             \nauthor      moritz.raabe@mandiant.com                                           \nscope       basic block                                                         \natt&ck      Execution::Shared Modules [T1129]                                   \nreferences  https://idafchev.github.io/exploit/2017/09/26/writing_windows_shell…\n            https://www.geoffchappell.com/studies/windows/win32/ntdll/structs/l…\nbasic block @ 0x406AC0 in function 0x406A6B\n  and:\n    match: access PEB ldr_data @ 0x406AC0\n      or:\n        and: = x32\n          arch: i386\n          match: PEB access @ 0x406AC0\n            or:\n              and:\n                arch: i386\n                characteristic: fs access @ 0x406AEE\n                or:\n                  offset: 0x30 @ 0x406AEA\n          offset: 0xC = PEB.LDR_DATA @ 0x406AFD, 0x406B01\n          or: = resolve a module list\n            offset: 0xC = PEB.LDR_DATA.InLoadOrderModuleList @ 0x406AFD, 0x406B01\n            offset: 0x14 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x406AF5\n    count(offset): 1 @ 0x406B04\n    or:\n      and:\n        arch: i386\n        offset: 0x18 = LDR_DATA_TABLE_ENTRY.DllBase @ 0x406AC1, 0x406B1D\nbasic block @ 0x406AC0 in function 0x406A6B\n  and:\n    match: access PEB ldr_data @ 0x406AC0\n      or:\n        and: = x32\n          arch: i386\n          match: PEB access @ 0x406AC0\n            or:\n              and:\n                arch: i386\n                characteristic: fs access @ 0x406AEE\n                or:\n                  offset: 0x30 @ 0x406AEA\n          offset: 0xC = PEB.LDR_DATA @ 0x406AFD, 0x406B01\n          or: = resolve a module list\n            offset: 0xC = PEB.LDR_DATA.InLoadOrderModuleList @ 0x406AFD, 0x406B01\n            offset: 0x14 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x406AF5\n    count(offset): 1 @ 0x406B04\n    or:\n      and:\n        arch: i386\n        offset: 0x18 = LDR_DATA_TABLE_ENTRY.DllBase @ 0x406AC1, 0x406B1D\n\n\n\n"},"hashes":{"md5":"15af6227d39ca3f9d1dcd8566efb0057","sha1":"c8c3bf9ed944b614ae4b3e747e69e84026fb4039","sha256":"40050153dceec2c8fbb1912f8eeabe449d1e265f0c8198008be8b34e5403e731"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 1271</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 62500</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Trojan.\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"15af6227d39ca3f9d1dcd8566efb0057\",\n        \"sha256\": \"40050153dceec2c8fbb1912f8eeabe449d1e265f0c8198008be8b34\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_peb_access__5_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"PEB access (5 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Process Environment\",\n        \"Block [B0001.019]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x406AC0\",\n      \"label\": \"Block 0x406AC0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x406AC0\"\n    },\n    {\n      \"id\": \"cap_library_rule_\",\n      \"label\": \"library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Modulo [C0058]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_loop__256_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (256 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x4014E0\",\n      \"label\": \"Function 0x4014E0\",\n      \"type\": \"function\",\n      \"address\": \"0x4014E0\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x402978\",\n      \"label\": \"Block 0x402978\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x402978\"\n    },\n    {\n      \"id\": \"api_RegCreateKeyEx\",\n      \"label\": \"RegCreateKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__6_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (6 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x404988\",\n      \"label\": \"Block 0x404988\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x404988\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_os_version__19_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"get OS version (19 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x405311\",\n      \"label\": \"Function 0x405311\",\n      \"type\": \"function\",\n      \"address\": \"0x405311\"\n    },\n    {\n      \"id\": \"api_GetVersion\",\n      \"label\": \"GetVersion\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_geographical_location\",\n      \"label\": \"get geographical location\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407D63\",\n      \"label\": \"Function 0x407D63\",\n      \"type\": \"function\",\n      \"address\": \"0x407D63\"\n    },\n    {\n      \"id\": \"api_GetLocaleInfo\",\n      \"label\": \"GetLocaleInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_polling\",\n      \"label\": \"log keystrokes via polling\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4128E5\",\n      \"label\": \"Function 0x4128E5\",\n      \"type\": \"function\",\n      \"address\": \"0x4128E5\"\n    },\n    {\n      \"id\": \"api_GetAsyncKeyState\",\n      \"label\": \"GetAsyncKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_capture_screenshot\",\n      \"label\": \"capture screenshot\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"api_BitBlt\",\n      \"label\": \"BitBlt\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_data__17_matches_\",\n      \"label\": \"receive data (17 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x410599\",\n      \"label\": \"Function 0x410599\",\n      \"type\": \"function\",\n      \"address\": \"0x410599\"\n    },\n    {\n      \"id\": \"func_0x40E629\",\n      \"label\": \"Function 0x40E629\",\n      \"type\": \"function\",\n      \"address\": \"0x40E629\"\n    },\n    {\n      \"id\": \"func_0x410617\",\n      \"label\": \"Function 0x410617\",\n      \"type\": \"function\",\n      \"address\": \"0x410617\"\n    },\n    {\n      \"id\": \"func_0x405DC6\",\n      \"label\": \"Function 0x405DC6\",\n      \"type\": \"function\",\n      \"address\": \"0x405DC6\"\n    },\n    {\n      \"id\": \"func_0x405CAD\",\n      \"label\": \"Function 0x405CAD\",\n      \"type\": \"function\",\n      \"address\": \"0x405CAD\"\n    },\n    {\n      \"id\": \"func_0x405C8A\",\n      \"label\": \"Function 0x405C8A\",\n      \"type\": \"function\",\n      \"address\": \"0x405C8A\"\n    },\n    {\n      \"id\": \"func_0x4105FD\",\n      \"label\": \"Function 0x4105FD\",\n      \"type\": \"function\",\n      \"address\": \"0x4105FD\"\n    },\n    {\n      \"id\": \"func_0x40E646\",\n      \"label\": \"Function 0x40E646\",\n      \"type\": \"function\",\n      \"address\": \"0x40E646\"\n    },\n    {\n      \"id\": \"func_0x412E00\",\n      \"label\": \"Function 0x412E00\",\n      \"type\": \"function\",\n      \"address\": \"0x412E00\"\n    },\n    {\n      \"id\": \"func_0x405BC0\",\n      \"label\": \"Function 0x405BC0\",\n      \"type\": \"function\",\n      \"address\": \"0x405BC0\"\n    },\n    {\n      \"id\": \"func_0x405BD7\",\n      \"label\": \"Function 0x405BD7\",\n      \"type\": \"function\",\n      \"address\": \"0x405BD7\"\n    },\n    {\n      \"id\": \"func_0x4105C9\",\n      \"label\": \"Function 0x4105C9\",\n      \"type\": \"function\",\n      \"address\": \"0x4105C9\"\n    },\n    {\n      \"id\": \"func_0x405D53\",\n      \"label\": \"Function 0x405D53\",\n      \"type\": \"function\",\n      \"address\": \"0x405D53\"\n    },\n    {\n      \"id\": \"func_0x405D91\",\n      \"label\": \"Function 0x405D91\",\n      \"type\": \"function\",\n      \"address\": \"0x405D91\"\n    },\n    {\n      \"id\": \"func_0x405C30\",\n      \"label\": \"Function 0x405C30\",\n      \"type\": \"function\",\n      \"address\": \"0x405C30\"\n    },\n    {\n      \"id\": \"func_0x40E674\",\n      \"label\": \"Function 0x40E674\",\n      \"type\": \"function\",\n      \"address\": \"0x40E674\"\n    },\n    {\n      \"id\": \"func_0x405C0D\",\n      \"label\": \"Function 0x405C0D\",\n      \"type\": \"function\",\n      \"address\": \"0x405C0D\"\n    },\n    {\n      \"id\": \"api_InternetReadFile\",\n      \"label\": \"InternetReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data\",\n      \"label\": \"send data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40B74F\",\n      \"label\": \"Function 0x40B74F\",\n      \"type\": \"function\",\n      \"address\": \"0x40B74F\"\n    },\n    {\n      \"id\": \"api_InternetWriteFile\",\n      \"label\": \"InternetWriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_to_http_server__2_matches_\",\n      \"label\": \"connect to HTTP server (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Connect to Server [C0002.009]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40D7A0\",\n      \"label\": \"Function 0x40D7A0\",\n      \"type\": \"function\",\n      \"address\": \"0x40D7A0\"\n    },\n    {\n      \"id\": \"func_0x40D7AD\",\n      \"label\": \"Function 0x40D7AD\",\n      \"type\": \"function\",\n      \"address\": \"0x40D7AD\"\n    },\n    {\n      \"id\": \"api_InternetConnect\",\n      \"label\": \"InternetConnect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_http_request__4_matches_\",\n      \"label\": \"create HTTP request (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40F1E0\",\n      \"label\": \"Function 0x40F1E0\",\n      \"type\": \"function\",\n      \"address\": \"0x40F1E0\"\n    },\n    {\n      \"id\": \"func_0x401970\",\n      \"label\": \"Function 0x401970\",\n      \"type\": \"function\",\n      \"address\": \"0x401970\"\n    },\n    {\n      \"id\": \"func_0x40F1C3\",\n      \"label\": \"Function 0x40F1C3\",\n      \"type\": \"function\",\n      \"address\": \"0x40F1C3\"\n    },\n    {\n      \"id\": \"func_0x404BF5\",\n      \"label\": \"Function 0x404BF5\",\n      \"type\": \"function\",\n      \"address\": \"0x404BF5\"\n    },\n    {\n      \"id\": \"api_InternetOpen\",\n      \"label\": \"InternetOpen\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_data_from_internet__17_matches_\",\n      \"label\": \"read data from Internet (17 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_file_via_http\",\n      \"label\": \"send file via HTTP\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Send Data [C0002.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"label\": \"author     matthew.williams@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Send Data [C0002.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_or_decrypt_via_wincrypt\",\n      \"label\": \"encrypt or decrypt via WinCrypt\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Decrypt Data [C0031]\",\n        \"Cryptography::Encrypt Data\",\n        \"[C0027]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x409247\",\n      \"label\": \"Function 0x409247\",\n      \"type\": \"function\",\n      \"address\": \"0x409247\"\n    },\n    {\n      \"id\": \"api_CryptDecrypt\",\n      \"label\": \"CryptDecrypt\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Decrypt Data [C0031]\",\n        \"Cryptography::Encrypt Data\",\n        \"[C0027]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"label\": \"hash data via WinCrypt (22 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash [C0029]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40AB57\",\n      \"label\": \"Function 0x40AB57\",\n      \"type\": \"function\",\n      \"address\": \"0x40AB57\"\n    },\n    {\n      \"id\": \"func_0x40C803\",\n      \"label\": \"Function 0x40C803\",\n      \"type\": \"function\",\n      \"address\": \"0x40C803\"\n    },\n    {\n      \"id\": \"func_0x40C817\",\n      \"label\": \"Function 0x40C817\",\n      \"type\": \"function\",\n      \"address\": \"0x40C817\"\n    },\n    {\n      \"id\": \"func_0x4115F3\",\n      \"label\": \"Function 0x4115F3\",\n      \"type\": \"function\",\n      \"address\": \"0x4115F3\"\n    },\n    {\n      \"id\": \"func_0x40AB8C\",\n      \"label\": \"Function 0x40AB8C\",\n      \"type\": \"function\",\n      \"address\": \"0x40AB8C\"\n    },\n    {\n      \"id\": \"func_0x409D7A\",\n      \"label\": \"Function 0x409D7A\",\n      \"type\": \"function\",\n      \"address\": \"0x409D7A\"\n    },\n    {\n      \"id\": \"func_0x40C898\",\n      \"label\": \"Function 0x40C898\",\n      \"type\": \"function\",\n      \"address\": \"0x40C898\"\n    },\n    {\n      \"id\": \"func_0x40C783\",\n      \"label\": \"Function 0x40C783\",\n      \"type\": \"function\",\n      \"address\": \"0x40C783\"\n    },\n    {\n      \"id\": \"func_0x40AB5D\",\n      \"label\": \"Function 0x40AB5D\",\n      \"type\": \"function\",\n      \"address\": \"0x40AB5D\"\n    },\n    {\n      \"id\": \"func_0x40C7E5\",\n      \"label\": \"Function 0x40C7E5\",\n      \"type\": \"function\",\n      \"address\": \"0x40C7E5\"\n    },\n    {\n      \"id\": \"func_0x40EE6C\",\n      \"label\": \"Function 0x40EE6C\",\n      \"type\": \"function\",\n      \"address\": \"0x40EE6C\"\n    },\n    {\n      \"id\": \"func_0x409D9B\",\n      \"label\": \"Function 0x409D9B\",\n      \"type\": \"function\",\n      \"address\": \"0x409D9B\"\n    },\n    {\n      \"id\": \"func_0x40ABA5\",\n      \"label\": \"Function 0x40ABA5\",\n      \"type\": \"function\",\n      \"address\": \"0x40ABA5\"\n    },\n    {\n      \"id\": \"api_CryptHashData\",\n      \"label\": \"CryptHashData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x406D08\",\n      \"label\": \"Function 0x406D08\",\n      \"type\": \"function\",\n      \"address\": \"0x406D08\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_interact_with_driver_via_ioctl__3_matches_\",\n      \"label\": \"interact with driver via IOCTL (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_DeviceIoControl\",\n      \"label\": \"DeviceIoControl\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_environment_variable__3_matches_\",\n      \"label\": \"set environment variable (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable::Set Variable [C0034.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407F0C\",\n      \"label\": \"Function 0x407F0C\",\n      \"type\": \"function\",\n      \"address\": \"0x407F0C\"\n    },\n    {\n      \"id\": \"func_0x407EE4\",\n      \"label\": \"Function 0x407EE4\",\n      \"type\": \"function\",\n      \"address\": \"0x407EE4\"\n    },\n    {\n      \"id\": \"func_0x407E93\",\n      \"label\": \"Function 0x407E93\",\n      \"type\": \"function\",\n      \"address\": \"0x407E93\"\n    },\n    {\n      \"id\": \"api_SetEnvironmentVariable\",\n      \"label\": \"SetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__18_matches_\",\n      \"label\": \"get common file path (18 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40EF91\",\n      \"label\": \"Function 0x40EF91\",\n      \"type\": \"function\",\n      \"address\": \"0x40EF91\"\n    },\n    {\n      \"id\": \"func_0x403FC0\",\n      \"label\": \"Function 0x403FC0\",\n      \"type\": \"function\",\n      \"address\": \"0x403FC0\"\n    },\n    {\n      \"id\": \"func_0x408C16\",\n      \"label\": \"Function 0x408C16\",\n      \"type\": \"function\",\n      \"address\": \"0x408C16\"\n    },\n    {\n      \"id\": \"func_0x40EFBA\",\n      \"label\": \"Function 0x40EFBA\",\n      \"type\": \"function\",\n      \"address\": \"0x40EFBA\"\n    },\n    {\n      \"id\": \"func_0x4043D1\",\n      \"label\": \"Function 0x4043D1\",\n      \"type\": \"function\",\n      \"address\": \"0x4043D1\"\n    },\n    {\n      \"id\": \"func_0x404005\",\n      \"label\": \"Function 0x404005\",\n      \"type\": \"function\",\n      \"address\": \"0x404005\"\n    },\n    {\n      \"id\": \"func_0x404362\",\n      \"label\": \"Function 0x404362\",\n      \"type\": \"function\",\n      \"address\": \"0x404362\"\n    },\n    {\n      \"id\": \"func_0x40439E\",\n      \"label\": \"Function 0x40439E\",\n      \"type\": \"function\",\n      \"address\": \"0x40439E\"\n    },\n    {\n      \"id\": \"func_0x40EF63\",\n      \"label\": \"Function 0x40EF63\",\n      \"type\": \"function\",\n      \"address\": \"0x40EF63\"\n    },\n    {\n      \"id\": \"func_0x40F009\",\n      \"label\": \"Function 0x40F009\",\n      \"type\": \"function\",\n      \"address\": \"0x40F009\"\n    },\n    {\n      \"id\": \"func_0x404029\",\n      \"label\": \"Function 0x404029\",\n      \"type\": \"function\",\n      \"address\": \"0x404029\"\n    },\n    {\n      \"id\": \"func_0x40434C\",\n      \"label\": \"Function 0x40434C\",\n      \"type\": \"function\",\n      \"address\": \"0x40434C\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_system_object_information__4_matches_\",\n      \"label\": \"get file system object information (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x407124\",\n      \"label\": \"Block 0x407124\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x407124\"\n    },\n    {\n      \"id\": \"api_SHGetFileInfo\",\n      \"label\": \"SHGetFileInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_copy_file__5_matches_\",\n      \"label\": \"copy file (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40DE7B\",\n      \"label\": \"Function 0x40DE7B\",\n      \"type\": \"function\",\n      \"address\": \"0x40DE7B\"\n    },\n    {\n      \"id\": \"func_0x405792\",\n      \"label\": \"Function 0x405792\",\n      \"type\": \"function\",\n      \"address\": \"0x405792\"\n    },\n    {\n      \"id\": \"func_0x40950C\",\n      \"label\": \"Function 0x40950C\",\n      \"type\": \"function\",\n      \"address\": \"0x40950C\"\n    },\n    {\n      \"id\": \"func_0x40DECF\",\n      \"label\": \"Function 0x40DECF\",\n      \"type\": \"function\",\n      \"address\": \"0x40DECF\"\n    },\n    {\n      \"id\": \"func_0x40DF12\",\n      \"label\": \"Function 0x40DF12\",\n      \"type\": \"function\",\n      \"address\": \"0x40DF12\"\n    },\n    {\n      \"id\": \"api_CopyFile\",\n      \"label\": \"CopyFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CopyFileEx\",\n      \"label\": \"CopyFileEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory__14_matches_\",\n      \"label\": \"create directory (14 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407FB2\",\n      \"label\": \"Function 0x407FB2\",\n      \"type\": \"function\",\n      \"address\": \"0x407FB2\"\n    },\n    {\n      \"id\": \"func_0x401AE8\",\n      \"label\": \"Function 0x401AE8\",\n      \"type\": \"function\",\n      \"address\": \"0x401AE8\"\n    },\n    {\n      \"id\": \"func_0x40BFFB\",\n      \"label\": \"Function 0x40BFFB\",\n      \"type\": \"function\",\n      \"address\": \"0x40BFFB\"\n    },\n    {\n      \"id\": \"func_0x407F81\",\n      \"label\": \"Function 0x407F81\",\n      \"type\": \"function\",\n      \"address\": \"0x407F81\"\n    },\n    {\n      \"id\": \"func_0x410416\",\n      \"label\": \"Function 0x410416\",\n      \"type\": \"function\",\n      \"address\": \"0x410416\"\n    },\n    {\n      \"id\": \"func_0x408012\",\n      \"label\": \"Function 0x408012\",\n      \"type\": \"function\",\n      \"address\": \"0x408012\"\n    },\n    {\n      \"id\": \"func_0x40BFC0\",\n      \"label\": \"Function 0x40BFC0\",\n      \"type\": \"function\",\n      \"address\": \"0x40BFC0\"\n    },\n    {\n      \"id\": \"func_0x40F220\",\n      \"label\": \"Function 0x40F220\",\n      \"type\": \"function\",\n      \"address\": \"0x40F220\"\n    },\n    {\n      \"id\": \"func_0x4052E6\",\n      \"label\": \"Function 0x4052E6\",\n      \"type\": \"function\",\n      \"address\": \"0x4052E6\"\n    },\n    {\n      \"id\": \"func_0x40F201\",\n      \"label\": \"Function 0x40F201\",\n      \"type\": \"function\",\n      \"address\": \"0x40F201\"\n    },\n    {\n      \"id\": \"func_0x407FE5\",\n      \"label\": \"Function 0x407FE5\",\n      \"type\": \"function\",\n      \"address\": \"0x407FE5\"\n    },\n    {\n      \"id\": \"func_0x41045E\",\n      \"label\": \"Function 0x41045E\",\n      \"type\": \"function\",\n      \"address\": \"0x41045E\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_CreateDirectoryEx\",\n      \"label\": \"CreateDirectoryEx\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_delete_directory__4_matches_\",\n      \"label\": \"delete directory (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4045CA\",\n      \"label\": \"Function 0x4045CA\",\n      \"type\": \"function\",\n      \"address\": \"0x4045CA\"\n    },\n    {\n      \"id\": \"func_0x4045BF\",\n      \"label\": \"Function 0x4045BF\",\n      \"type\": \"function\",\n      \"address\": \"0x4045BF\"\n    },\n    {\n      \"id\": \"func_0x40A794\",\n      \"label\": \"Function 0x40A794\",\n      \"type\": \"function\",\n      \"address\": \"0x40A794\"\n    },\n    {\n      \"id\": \"func_0x4045E3\",\n      \"label\": \"Function 0x4045E3\",\n      \"type\": \"function\",\n      \"address\": \"0x4045E3\"\n    },\n    {\n      \"id\": \"api_RemoveDirectory\",\n      \"label\": \"RemoveDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_file__2_matches_\",\n      \"label\": \"delete file (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x406F84\",\n      \"label\": \"Function 0x406F84\",\n      \"type\": \"function\",\n      \"address\": \"0x406F84\"\n    },\n    {\n      \"id\": \"func_0x406F81\",\n      \"label\": \"Function 0x406F81\",\n      \"type\": \"function\",\n      \"address\": \"0x406F81\"\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_get_file_size__7_matches_\",\n      \"label\": \"get file size (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40D1C4\",\n      \"label\": \"Function 0x40D1C4\",\n      \"type\": \"function\",\n      \"address\": \"0x40D1C4\"\n    },\n    {\n      \"id\": \"func_0x40BE11\",\n      \"label\": \"Function 0x40BE11\",\n      \"type\": \"function\",\n      \"address\": \"0x40BE11\"\n    },\n    {\n      \"id\": \"func_0x40D190\",\n      \"label\": \"Function 0x40D190\",\n      \"type\": \"function\",\n      \"address\": \"0x40D190\"\n    },\n    {\n      \"id\": \"func_0x40D1FC\",\n      \"label\": \"Function 0x40D1FC\",\n      \"type\": \"function\",\n      \"address\": \"0x40D1FC\"\n    },\n    {\n      \"id\": \"func_0x40BDE5\",\n      \"label\": \"Function 0x40BDE5\",\n      \"type\": \"function\",\n      \"address\": \"0x40BDE5\"\n    },\n    {\n      \"id\": \"func_0x40BE2C\",\n      \"label\": \"Function 0x40BE2C\",\n      \"type\": \"function\",\n      \"address\": \"0x40BE2C\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_file_version_info__3_matches_\",\n      \"label\": \"get file version info (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407A7A\",\n      \"label\": \"Function 0x407A7A\",\n      \"type\": \"function\",\n      \"address\": \"0x407A7A\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfo\",\n      \"label\": \"GetFileVersionInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_file_attributes__3_matches_\",\n      \"label\": \"set file attributes (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x412928\",\n      \"label\": \"Block 0x412928\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x412928\"\n    },\n    {\n      \"id\": \"bb_0x40AB57\",\n      \"label\": \"Block 0x40AB57\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40AB57\"\n    },\n    {\n      \"id\": \"bb_0x40AB5D\",\n      \"label\": \"Block 0x40AB5D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40AB5D\"\n    },\n    {\n      \"id\": \"api_SetFileAttributes\",\n      \"label\": \"SetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_move_file__24_matches_\",\n      \"label\": \"move file (24 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408632\",\n      \"label\": \"Function 0x408632\",\n      \"type\": \"function\",\n      \"address\": \"0x408632\"\n    },\n    {\n      \"id\": \"func_0x4080FC\",\n      \"label\": \"Function 0x4080FC\",\n      \"type\": \"function\",\n      \"address\": \"0x4080FC\"\n    },\n    {\n      \"id\": \"func_0x40188F\",\n      \"label\": \"Function 0x40188F\",\n      \"type\": \"function\",\n      \"address\": \"0x40188F\"\n    },\n    {\n      \"id\": \"func_0x408D30\",\n      \"label\": \"Function 0x408D30\",\n      \"type\": \"function\",\n      \"address\": \"0x408D30\"\n    },\n    {\n      \"id\": \"func_0x40B890\",\n      \"label\": \"Function 0x40B890\",\n      \"type\": \"function\",\n      \"address\": \"0x40B890\"\n    },\n    {\n      \"id\": \"func_0x40AFC4\",\n      \"label\": \"Function 0x40AFC4\",\n      \"type\": \"function\",\n      \"address\": \"0x40AFC4\"\n    },\n    {\n      \"id\": \"func_0x404488\",\n      \"label\": \"Function 0x404488\",\n      \"type\": \"function\",\n      \"address\": \"0x404488\"\n    },\n    {\n      \"id\": \"func_0x406713\",\n      \"label\": \"Function 0x406713\",\n      \"type\": \"function\",\n      \"address\": \"0x406713\"\n    },\n    {\n      \"id\": \"func_0x40B922\",\n      \"label\": \"Function 0x40B922\",\n      \"type\": \"function\",\n      \"address\": \"0x40B922\"\n    },\n    {\n      \"id\": \"func_0x40B954\",\n      \"label\": \"Function 0x40B954\",\n      \"type\": \"function\",\n      \"address\": \"0x40B954\"\n    },\n    {\n      \"id\": \"func_0x40B966\",\n      \"label\": \"Function 0x40B966\",\n      \"type\": \"function\",\n      \"address\": \"0x40B966\"\n    },\n    {\n      \"id\": \"func_0x4080D8\",\n      \"label\": \"Function 0x4080D8\",\n      \"type\": \"function\",\n      \"address\": \"0x4080D8\"\n    },\n    {\n      \"id\": \"func_0x4080CF\",\n      \"label\": \"Function 0x4080CF\",\n      \"type\": \"function\",\n      \"address\": \"0x4080CF\"\n    },\n    {\n      \"id\": \"func_0x40AF8E\",\n      \"label\": \"Function 0x40AF8E\",\n      \"type\": \"function\",\n      \"address\": \"0x40AF8E\"\n    },\n    {\n      \"id\": \"func_0x4018A8\",\n      \"label\": \"Function 0x4018A8\",\n      \"type\": \"function\",\n      \"address\": \"0x4018A8\"\n    },\n    {\n      \"id\": \"func_0x404469\",\n      \"label\": \"Function 0x404469\",\n      \"type\": \"function\",\n      \"address\": \"0x404469\"\n    },\n    {\n      \"id\": \"func_0x40812C\",\n      \"label\": \"Function 0x40812C\",\n      \"type\": \"function\",\n      \"address\": \"0x40812C\"\n    },\n    {\n      \"id\": \"func_0x40F480\",\n      \"label\": \"Function 0x40F480\",\n      \"type\": \"function\",\n      \"address\": \"0x40F480\"\n    },\n    {\n      \"id\": \"func_0x40808A\",\n      \"label\": \"Function 0x40808A\",\n      \"type\": \"function\",\n      \"address\": \"0x40808A\"\n    },\n    {\n      \"id\": \"func_0x40F4B9\",\n      \"label\": \"Function 0x40F4B9\",\n      \"type\": \"function\",\n      \"address\": \"0x40F4B9\"\n    },\n    {\n      \"id\": \"func_0x40B8B4\",\n      \"label\": \"Function 0x40B8B4\",\n      \"type\": \"function\",\n      \"address\": \"0x40B8B4\"\n    },\n    {\n      \"id\": \"func_0x4017BF\",\n      \"label\": \"Function 0x4017BF\",\n      \"type\": \"function\",\n      \"address\": \"0x4017BF\"\n    },\n    {\n      \"id\": \"api_MoveFile\",\n      \"label\": \"MoveFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_MoveFileWithProgress\",\n      \"label\": \"MoveFileWithProgress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_MoveFileEx\",\n      \"label\": \"MoveFileEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__4_matches_\",\n      \"label\": \"read file on Windows (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40FB88\",\n      \"label\": \"Function 0x40FB88\",\n      \"type\": \"function\",\n      \"address\": \"0x40FB88\"\n    },\n    {\n      \"id\": \"func_0x40FB3E\",\n      \"label\": \"Function 0x40FB3E\",\n      \"type\": \"function\",\n      \"address\": \"0x40FB3E\"\n    },\n    {\n      \"id\": \"func_0x40FB6A\",\n      \"label\": \"Function 0x40FB6A\",\n      \"type\": \"function\",\n      \"address\": \"0x40FB6A\"\n    },\n    {\n      \"id\": \"func_0x40FB5D\",\n      \"label\": \"Function 0x40FB5D\",\n      \"type\": \"function\",\n      \"address\": \"0x40FB5D\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_application_hook__3_matches_\",\n      \"label\": \"set application hook (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_SetWindowsHookEx\",\n      \"label\": \"SetWindowsHookEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_UnhookWindowsHookEx\",\n      \"label\": \"UnhookWindowsHookEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_find_graphical_window__11_matches_\",\n      \"label\": \"find graphical window (11 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindWindowEx\",\n      \"label\": \"FindWindowEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_graphical_window_text__2_matches_\",\n      \"label\": \"get graphical window text (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401CD2\",\n      \"label\": \"Function 0x401CD2\",\n      \"type\": \"function\",\n      \"address\": \"0x401CD2\"\n    },\n    {\n      \"id\": \"api_GetWindowText\",\n      \"label\": \"GetWindowText\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_information\",\n      \"label\": \"get disk information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40CC49\",\n      \"label\": \"Function 0x40CC49\",\n      \"type\": \"function\",\n      \"address\": \"0x40CC49\"\n    },\n    {\n      \"id\": \"api_GetDriveType\",\n      \"label\": \"GetDriveType\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_print_debug_messages__2_matches_\",\n      \"label\": \"print debug messages (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x408C8B\",\n      \"label\": \"Function 0x408C8B\",\n      \"type\": \"function\",\n      \"address\": \"0x408C8B\"\n    },\n    {\n      \"id\": \"api_OutputDebugString\",\n      \"label\": \"OutputDebugString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_access_the_windows_event_log__2_matches_\",\n      \"label\": \"access the Windows event log (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery::Log File [E1083.m01]\"\n      ]\n    },\n    {\n      \"id\": \"api_ReportEvent\",\n      \"label\": \"ReportEvent\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_or_open_mutex_on_windows__2_matches_\",\n      \"label\": \"create or open mutex on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateMutex\",\n      \"label\": \"CreateMutex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_mehunhoff_google_com\",\n      \"label\": \"mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_system_information_on_windows__2_matches_\",\n      \"label\": \"get system information on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetSystemInfo\",\n      \"label\": \"GetSystemInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_thread_local_storage_value__3_matches_\",\n      \"label\": \"get thread local storage value (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_TlsGetValue\",\n      \"label\": \"TlsGetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__23_matches_\",\n      \"label\": \"create process on Windows (23 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x407847\",\n      \"label\": \"Block 0x407847\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x407847\"\n    },\n    {\n      \"id\": \"bb_0x40DA7F\",\n      \"label\": \"Block 0x40DA7F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40DA7F\"\n    },\n    {\n      \"id\": \"bb_0x40B732\",\n      \"label\": \"Block 0x40B732\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40B732\"\n    },\n    {\n      \"id\": \"bb_0x40D7C0\",\n      \"label\": \"Block 0x40D7C0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40D7C0\"\n    },\n    {\n      \"id\": \"bb_0x4108D1\",\n      \"label\": \"Block 0x4108D1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4108D1\"\n    },\n    {\n      \"id\": \"bb_0x40F461\",\n      \"label\": \"Block 0x40F461\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40F461\"\n    },\n    {\n      \"id\": \"bb_0x404891\",\n      \"label\": \"Block 0x404891\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x404891\"\n    },\n    {\n      \"id\": \"bb_0x40B708\",\n      \"label\": \"Block 0x40B708\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40B708\"\n    },\n    {\n      \"id\": \"bb_0x4017DD\",\n      \"label\": \"Block 0x4017DD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4017DD\"\n    },\n    {\n      \"id\": \"bb_0x40EB47\",\n      \"label\": \"Block 0x40EB47\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40EB47\"\n    },\n    {\n      \"id\": \"bb_0x40DE13\",\n      \"label\": \"Block 0x40DE13\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40DE13\"\n    },\n    {\n      \"id\": \"bb_0x4107E9\",\n      \"label\": \"Block 0x4107E9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4107E9\"\n    },\n    {\n      \"id\": \"api_ShellExecuteEx\",\n      \"label\": \"ShellExecuteEx\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_ShellExecute\",\n      \"label\": \"ShellExecute\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_create_process_suspended__2_matches_\",\n      \"label\": \"create process suspended (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process::Create Suspended Process [C0017.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process::Create Suspended Process [C0017.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process__6_matches_\",\n      \"label\": \"terminate process (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x410C76\",\n      \"label\": \"Function 0x410C76\",\n      \"type\": \"function\",\n      \"address\": \"0x410C76\"\n    },\n    {\n      \"id\": \"func_0x40DE0D\",\n      \"label\": \"Function 0x40DE0D\",\n      \"type\": \"function\",\n      \"address\": \"0x40DE0D\"\n    },\n    {\n      \"id\": \"func_0x40DE57\",\n      \"label\": \"Function 0x40DE57\",\n      \"type\": \"function\",\n      \"address\": \"0x40DE57\"\n    },\n    {\n      \"id\": \"func_0x410D24\",\n      \"label\": \"Function 0x410D24\",\n      \"type\": \"function\",\n      \"address\": \"0x410D24\"\n    },\n    {\n      \"id\": \"func_0x410CAD\",\n      \"label\": \"Function 0x410CAD\",\n      \"type\": \"function\",\n      \"address\": \"0x410CAD\"\n    },\n    {\n      \"id\": \"func_0x410C5F\",\n      \"label\": \"Function 0x410C5F\",\n      \"type\": \"function\",\n      \"address\": \"0x410C5F\"\n    },\n    {\n      \"id\": \"api_ExitProcess\",\n      \"label\": \"ExitProcess\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"label\": \"query or enumerate registry value (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40635B\",\n      \"label\": \"Function 0x40635B\",\n      \"type\": \"function\",\n      \"address\": \"0x40635B\"\n    },\n    {\n      \"id\": \"func_0x406F1C\",\n      \"label\": \"Function 0x406F1C\",\n      \"type\": \"function\",\n      \"address\": \"0x406F1C\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegEnumValue\",\n      \"label\": \"RegEnumValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_allocate_thread_local_storage__3_matches_\",\n      \"label\": \"allocate thread local storage (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Allocate Thread Local Storage [C0040]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404E01\",\n      \"label\": \"Function 0x404E01\",\n      \"type\": \"function\",\n      \"address\": \"0x404E01\"\n    },\n    {\n      \"id\": \"func_0x404E18\",\n      \"label\": \"Function 0x404E18\",\n      \"type\": \"function\",\n      \"address\": \"0x404E18\"\n    },\n    {\n      \"id\": \"func_0x409E5D\",\n      \"label\": \"Function 0x409E5D\",\n      \"type\": \"function\",\n      \"address\": \"0x409E5D\"\n    },\n    {\n      \"id\": \"api_TlsAlloc\",\n      \"label\": \"TlsAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_thread_local_storage_value__3_matches_\",\n      \"label\": \"set thread local storage value (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Set Thread Local Storage Value [C0041]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40C933\",\n      \"label\": \"Function 0x40C933\",\n      \"type\": \"function\",\n      \"address\": \"0x40C933\"\n    },\n    {\n      \"id\": \"func_0x40B60F\",\n      \"label\": \"Function 0x40B60F\",\n      \"type\": \"function\",\n      \"address\": \"0x40B60F\"\n    },\n    {\n      \"id\": \"func_0x40B63A\",\n      \"label\": \"Function 0x40B63A\",\n      \"type\": \"function\",\n      \"address\": \"0x40B63A\"\n    },\n    {\n      \"id\": \"api_TlsSetValue\",\n      \"label\": \"TlsSetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_access_peb_ldr_data__2_matches_\",\n      \"label\": \"access PEB ldr_data (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_ntdll_base_address__2_matches_\",\n      \"label\": \"get ntdll base address (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_peb_access__5_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_peb_access__5_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x406AC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__256_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__256_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x4014E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x402978\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__6_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__6_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x404988\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version__19_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_os_version__19_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x405311\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405311\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_geographical_location\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location\",\n      \"target\": \"func_0x407D63\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407D63\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407D63\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407D63\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_polling\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling\",\n      \"target\": \"func_0x4128E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4128E5\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4128E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4128E5\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_capture_screenshot\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_capture_screenshot\",\n      \"target\": \"func_0x4128E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4128E5\",\n      \"target\": \"api_BitBlt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4128E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4128E5\",\n      \"target\": \"api_BitBlt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data__17_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x410599\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x40E629\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x410617\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x405DC6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x405CAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x405C8A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x4105FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x40E646\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x412E00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x405BC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x405BD7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x4105C9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x405D53\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x405D91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x405C30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x40E674\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__17_matches_\",\n      \"target\": \"func_0x405C0D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x410599\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E629\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410617\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DC6\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405CAD\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C8A\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4105FD\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E646\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x412E00\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405BC0\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405BD7\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4105C9\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405D53\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405D91\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C30\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E674\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C0D\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x410599\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40E629\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x410617\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x405DC6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x405CAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x405C8A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x4105FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40E646\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x412E00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x405BC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x405BD7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x4105C9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x405D53\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x405D91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x405C30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40E674\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x405C0D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x410599\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E629\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410617\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DC6\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405CAD\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C8A\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4105FD\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E646\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x412E00\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405BC0\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405BD7\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4105C9\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405D53\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405D91\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C30\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E674\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C0D\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data\",\n      \"target\": \"func_0x40B74F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40B74F\",\n      \"target\": \"api_InternetWriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x40B74F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40B74F\",\n      \"target\": \"api_InternetWriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_to_http_server__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_to_http_server__2_matches_\",\n      \"target\": \"func_0x40D7A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_to_http_server__2_matches_\",\n      \"target\": \"func_0x40D7AD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40D7A0\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D7AD\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40D7A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40D7AD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40D7A0\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D7AD\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_http_request__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_http_request__4_matches_\",\n      \"target\": \"func_0x40F1E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_http_request__4_matches_\",\n      \"target\": \"func_0x401970\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_http_request__4_matches_\",\n      \"target\": \"func_0x40F1C3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_http_request__4_matches_\",\n      \"target\": \"func_0x404BF5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40F1E0\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401970\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F1C3\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404BF5\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40F1E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401970\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40F1C3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404BF5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40F1E0\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401970\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F1C3\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404BF5\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_data_from_internet__17_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x410599\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x40E629\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x410617\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x405DC6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x405CAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x405C8A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x4105FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x40E646\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x412E00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x405BC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x405BD7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x4105C9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x405D53\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x405D91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x405C30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x40E674\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__17_matches_\",\n      \"target\": \"func_0x405C0D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x410599\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E629\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410617\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DC6\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405CAD\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C8A\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4105FD\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E646\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x412E00\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405BC0\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405BD7\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4105C9\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405D53\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405D91\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C30\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E674\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C0D\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x410599\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40E629\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x410617\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405DC6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405CAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405C8A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4105FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40E646\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x412E00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405BC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405BD7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4105C9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405D53\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405D91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405C30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40E674\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405C0D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x410599\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E629\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410617\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DC6\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405CAD\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C8A\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4105FD\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E646\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x412E00\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405BC0\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405BD7\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4105C9\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405D53\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405D91\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C30\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E674\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C0D\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_file_via_http\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_or_decrypt_via_wincrypt\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_or_decrypt_via_wincrypt\",\n      \"target\": \"func_0x409247\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x409247\",\n      \"target\": \"api_CryptDecrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x409247\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x409247\",\n      \"target\": \"api_CryptDecrypt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x40AB57\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x40C803\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x40C817\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x4115F3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x40AB8C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x409D7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x40E674\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x40E629\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x405C8A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x40C898\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x405BD7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x40C783\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x40AB5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x40C7E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x405BC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x40EE6C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x409D9B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x40ABA5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x40E646\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x412E00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x405C30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_via_wincrypt__22_matches_\",\n      \"target\": \"func_0x405C0D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40AB57\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C803\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C817\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4115F3\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AB8C\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409D7A\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E674\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E629\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C8A\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C898\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405BD7\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C783\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AB5D\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C7E5\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405BC0\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EE6C\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409D9B\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40ABA5\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E646\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x412E00\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C30\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C0D\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40AB57\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40C803\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40C817\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4115F3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40AB8C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x409D7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40E674\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40E629\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405C8A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40C898\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405BD7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40C783\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40AB5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40C7E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405BC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40EE6C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x409D9B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40ABA5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40E646\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x412E00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405C30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405C0D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40AB57\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C803\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C817\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4115F3\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AB8C\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409D7A\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E674\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E629\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C8A\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C898\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405BD7\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C783\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AB5D\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C7E5\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405BC0\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EE6C\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409D9B\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40ABA5\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E646\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x412E00\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C30\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405C0D\",\n      \"target\": \"api_CryptHashData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x406D08\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406D08\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x406D08\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406D08\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_interact_with_driver_via_ioctl__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_environment_variable__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_environment_variable__3_matches_\",\n      \"target\": \"func_0x407F0C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_environment_variable__3_matches_\",\n      \"target\": \"func_0x407EE4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_environment_variable__3_matches_\",\n      \"target\": \"func_0x407E93\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407F0C\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407EE4\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407E93\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407F0C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407EE4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407E93\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407F0C\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407EE4\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407E93\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__18_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x40EF91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x40E629\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x403FC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x408C16\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x40C898\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x40E646\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x40EFBA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x412E00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x4043D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x4128E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x404005\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x404362\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x40439E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x40EF63\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x40F009\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x404029\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x40E674\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__18_matches_\",\n      \"target\": \"func_0x40434C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40EF91\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E629\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403FC0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408C16\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C898\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E646\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EFBA\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x412E00\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4043D1\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4128E5\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404005\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404362\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40439E\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EF63\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F009\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404029\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E674\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40434C\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EF91\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E629\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403FC0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408C16\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C898\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E646\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EFBA\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x412E00\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4043D1\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4128E5\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404005\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404362\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40439E\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EF63\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F009\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404029\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E674\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40434C\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40EF91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40E629\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403FC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x408C16\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40C898\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40E646\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40EFBA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x412E00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4043D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4128E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404005\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404362\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40439E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40EF63\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40F009\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404029\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40E674\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40434C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40EF91\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E629\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403FC0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408C16\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C898\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E646\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EFBA\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x412E00\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4043D1\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4128E5\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404005\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404362\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40439E\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EF63\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F009\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404029\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E674\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40434C\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EF91\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E629\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403FC0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408C16\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C898\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E646\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EFBA\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x412E00\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4043D1\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4128E5\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404005\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404362\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40439E\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EF63\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F009\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404029\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E674\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40434C\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_system_object_information__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_system_object_information__4_matches_\",\n      \"target\": \"bb_0x407124\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x407124\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_copy_file__5_matches_\",\n      \"target\": \"func_0x40DE7B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_copy_file__5_matches_\",\n      \"target\": \"func_0x405792\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_copy_file__5_matches_\",\n      \"target\": \"func_0x40950C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_copy_file__5_matches_\",\n      \"target\": \"func_0x40DECF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_copy_file__5_matches_\",\n      \"target\": \"func_0x40DF12\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40DE7B\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405792\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40950C\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DECF\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DF12\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DE7B\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405792\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40950C\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DECF\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DF12\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40DE7B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405792\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40950C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40DECF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40DF12\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40DE7B\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405792\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40950C\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DECF\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DF12\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DE7B\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405792\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40950C\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DECF\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DF12\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory__14_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory__14_matches_\",\n      \"target\": \"func_0x407FB2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__14_matches_\",\n      \"target\": \"func_0x401AE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__14_matches_\",\n      \"target\": \"func_0x40BFFB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__14_matches_\",\n      \"target\": \"func_0x407F81\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__14_matches_\",\n      \"target\": \"func_0x410416\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__14_matches_\",\n      \"target\": \"func_0x408012\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__14_matches_\",\n      \"target\": \"func_0x40BFC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__14_matches_\",\n      \"target\": \"func_0x40F220\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__14_matches_\",\n      \"target\": \"func_0x4052E6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__14_matches_\",\n      \"target\": \"func_0x40F201\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__14_matches_\",\n      \"target\": \"func_0x40F1E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__14_matches_\",\n      \"target\": \"func_0x407FE5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__14_matches_\",\n      \"target\": \"func_0x41045E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__14_matches_\",\n      \"target\": \"func_0x40F1C3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407FB2\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401AE8\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BFFB\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407F81\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410416\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408012\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BFC0\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F220\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4052E6\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F201\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F1E0\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407FE5\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41045E\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F1C3\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407FB2\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401AE8\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BFFB\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407F81\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410416\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408012\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BFC0\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F220\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4052E6\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F201\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F1E0\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407FE5\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41045E\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F1C3\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407FB2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401AE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40BFFB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407F81\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x410416\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408012\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40BFC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40F220\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4052E6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40F201\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40F1E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407FE5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x41045E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40F1C3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407FB2\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401AE8\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BFFB\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407F81\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410416\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408012\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BFC0\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F220\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4052E6\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F201\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F1E0\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407FE5\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41045E\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F1C3\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407FB2\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401AE8\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BFFB\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407F81\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410416\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408012\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BFC0\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F220\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4052E6\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F201\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F1E0\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407FE5\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41045E\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F1C3\",\n      \"target\": \"api_CreateDirectoryEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_directory__4_matches_\",\n      \"target\": \"func_0x4045CA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_directory__4_matches_\",\n      \"target\": \"func_0x4045BF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_directory__4_matches_\",\n      \"target\": \"func_0x40A794\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_directory__4_matches_\",\n      \"target\": \"func_0x4045E3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4045CA\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4045BF\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A794\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4045E3\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4045CA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4045BF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40A794\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4045E3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4045CA\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4045BF\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40A794\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4045E3\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__2_matches_\",\n      \"target\": \"func_0x406F84\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__2_matches_\",\n      \"target\": \"func_0x406F81\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406F84\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406F81\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x406F84\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x406F81\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406F84\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406F81\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size__7_matches_\",\n      \"target\": \"func_0x40D1C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__7_matches_\",\n      \"target\": \"func_0x40BE11\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__7_matches_\",\n      \"target\": \"func_0x40D190\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__7_matches_\",\n      \"target\": \"func_0x40D1FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__7_matches_\",\n      \"target\": \"func_0x405BC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__7_matches_\",\n      \"target\": \"func_0x40BDE5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__7_matches_\",\n      \"target\": \"func_0x40BE2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40D1C4\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BE11\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D190\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D1FC\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405BC0\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BDE5\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BE2C\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40D1C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40BE11\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40D190\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40D1FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405BC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40BDE5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40BE2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40D1C4\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BE11\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D190\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40D1FC\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405BC0\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BDE5\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BE2C\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_version_info__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_version_info__3_matches_\",\n      \"target\": \"func_0x407A7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_version_info__3_matches_\",\n      \"target\": \"func_0x40AB57\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_version_info__3_matches_\",\n      \"target\": \"func_0x40AB5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407A7A\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AB57\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AB5D\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x407A7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40AB57\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40AB5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407A7A\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AB57\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AB5D\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__3_matches_\",\n      \"target\": \"bb_0x412928\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__3_matches_\",\n      \"target\": \"bb_0x40AB57\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__3_matches_\",\n      \"target\": \"bb_0x40AB5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x412928\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40AB57\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40AB5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_move_file__24_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x408632\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x4080FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x40188F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x408D30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x40B890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x40AFC4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x404488\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x406713\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x40B922\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x40B954\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x40B966\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x4080D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x4080CF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x40AF8E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x4018A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x404469\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x40812C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x4128E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x40F480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x40808A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x40F4B9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x40B8B4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x412E00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__24_matches_\",\n      \"target\": \"func_0x4017BF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408632\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080FC\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40188F\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B890\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AFC4\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404488\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406713\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B922\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B954\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B966\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080D8\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080CF\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AF8E\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4018A8\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404469\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40812C\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4128E5\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F480\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40808A\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F4B9\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B8B4\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x412E00\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4017BF\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408632\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080FC\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40188F\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B890\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AFC4\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404488\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406713\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B922\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B954\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B966\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080D8\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080CF\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AF8E\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4018A8\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404469\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40812C\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4128E5\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F480\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40808A\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F4B9\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B8B4\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x412E00\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4017BF\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408632\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080FC\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40188F\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B890\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AFC4\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404488\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406713\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B922\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B954\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B966\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080D8\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080CF\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AF8E\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4018A8\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404469\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40812C\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4128E5\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F480\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40808A\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F4B9\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B8B4\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x412E00\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4017BF\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408632\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4080FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40188F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408D30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40B890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40AFC4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x404488\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x406713\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40B922\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40B954\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40B966\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4080D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4080CF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40AF8E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4018A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x404469\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40812C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4128E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40F480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40808A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40F4B9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40B8B4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x412E00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4017BF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408632\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080FC\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40188F\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B890\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AFC4\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404488\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406713\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B922\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B954\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B966\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080D8\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080CF\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AF8E\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4018A8\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404469\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40812C\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4128E5\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F480\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40808A\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F4B9\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B8B4\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x412E00\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4017BF\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408632\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080FC\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40188F\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B890\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AFC4\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404488\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406713\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B922\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B954\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B966\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080D8\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080CF\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AF8E\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4018A8\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404469\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40812C\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4128E5\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F480\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40808A\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F4B9\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B8B4\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x412E00\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4017BF\",\n      \"target\": \"api_MoveFileWithProgress\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408632\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080FC\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40188F\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408D30\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B890\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AFC4\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404488\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406713\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B922\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B954\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B966\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080D8\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4080CF\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AF8E\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4018A8\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404469\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40812C\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4128E5\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F480\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40808A\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40F4B9\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B8B4\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x412E00\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4017BF\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__4_matches_\",\n      \"target\": \"func_0x40FB88\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__4_matches_\",\n      \"target\": \"func_0x40FB3E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__4_matches_\",\n      \"target\": \"func_0x40FB6A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__4_matches_\",\n      \"target\": \"func_0x40FB5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40FB88\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40FB3E\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40FB6A\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40FB5D\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40FB88\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40FB3E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40FB6A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40FB5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40FB88\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40FB3E\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40FB6A\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40FB5D\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_application_hook__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_graphical_window__11_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_graphical_window_text__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__2_matches_\",\n      \"target\": \"func_0x401CD2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__2_matches_\",\n      \"target\": \"func_0x408C16\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401CD2\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408C16\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x401CD2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x408C16\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401CD2\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408C16\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information\",\n      \"target\": \"func_0x40CC49\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40CC49\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40CC49\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40CC49\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_print_debug_messages__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_print_debug_messages__2_matches_\",\n      \"target\": \"func_0x408C8B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_print_debug_messages__2_matches_\",\n      \"target\": \"func_0x408C16\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408C8B\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408C16\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408C8B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408C16\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408C8B\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408C16\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_the_windows_event_log__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_access_the_windows_event_log__2_matches_\",\n      \"target\": \"func_0x408C8B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_the_windows_event_log__2_matches_\",\n      \"target\": \"func_0x408C16\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408C8B\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408C16\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x408C8B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x408C16\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408C8B\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408C16\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_mutex_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_system_information_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_system_information_on_windows__2_matches_\",\n      \"target\": \"func_0x40DECF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_system_information_on_windows__2_matches_\",\n      \"target\": \"func_0x40DE7B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40DECF\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DE7B\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x40DECF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x40DE7B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40DECF\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DE7B\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_thread_local_storage_value__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__3_matches_\",\n      \"target\": \"func_0x404488\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__3_matches_\",\n      \"target\": \"func_0x404469\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__3_matches_\",\n      \"target\": \"func_0x406713\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404488\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404469\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406713\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x404488\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x404469\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x406713\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404488\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404469\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406713\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__23_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__23_matches_\",\n      \"target\": \"bb_0x407847\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__23_matches_\",\n      \"target\": \"bb_0x40DA7F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__23_matches_\",\n      \"target\": \"bb_0x40B732\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__23_matches_\",\n      \"target\": \"bb_0x40D7C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__23_matches_\",\n      \"target\": \"bb_0x4108D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__23_matches_\",\n      \"target\": \"bb_0x40F461\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__23_matches_\",\n      \"target\": \"bb_0x404891\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__23_matches_\",\n      \"target\": \"bb_0x40B708\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__23_matches_\",\n      \"target\": \"bb_0x4017DD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__23_matches_\",\n      \"target\": \"bb_0x40EB47\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__23_matches_\",\n      \"target\": \"bb_0x40DE13\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__23_matches_\",\n      \"target\": \"bb_0x4107E9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x407847\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x40DA7F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x40B732\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x40D7C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4108D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x40F461\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x404891\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x40B708\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4017DD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x40EB47\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x40DE13\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4107E9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_suspended__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_suspended__2_matches_\",\n      \"target\": \"bb_0x40DE13\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"bb_0x40DE13\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process__6_matches_\",\n      \"target\": \"func_0x410C76\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__6_matches_\",\n      \"target\": \"func_0x40DE0D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__6_matches_\",\n      \"target\": \"func_0x40DE57\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__6_matches_\",\n      \"target\": \"func_0x410D24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__6_matches_\",\n      \"target\": \"func_0x410CAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__6_matches_\",\n      \"target\": \"func_0x410C5F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x410C76\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DE0D\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DE57\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410D24\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410CAD\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410C5F\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x410C76\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40DE0D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40DE57\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x410D24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x410CAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x410C5F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x410C76\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DE0D\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40DE57\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410D24\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410CAD\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x410C5F\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"target\": \"func_0x40635B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"target\": \"func_0x406F1C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40635B\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406F1C\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40635B\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406F1C\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40635B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406F1C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40635B\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406F1C\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40635B\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406F1C\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_thread_local_storage__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_thread_local_storage__3_matches_\",\n      \"target\": \"func_0x404E01\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_thread_local_storage__3_matches_\",\n      \"target\": \"func_0x404E18\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_thread_local_storage__3_matches_\",\n      \"target\": \"func_0x409E5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404E01\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404E18\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409E5D\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x404E01\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x404E18\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x409E5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404E01\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404E18\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x409E5D\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_thread_local_storage_value__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__3_matches_\",\n      \"target\": \"func_0x40C933\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__3_matches_\",\n      \"target\": \"func_0x40B60F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__3_matches_\",\n      \"target\": \"func_0x40B63A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40C933\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B60F\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B63A\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40C933\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40B60F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40B63A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40C933\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B60F\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B63A\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_peb_ldr_data__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__2_matches_\",\n      \"target\": \"bb_0x406AC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x406AC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_ntdll_base_address__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_ntdll_base_address__2_matches_\",\n      \"target\": \"bb_0x406AC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x406AC0\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-10 00:17:37.329159\",\n    \"total_functions\": \"1271\",\n    \"total_features\": \"62500\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-10 00:17:39"}
{"_id":{"$oid":"6a4fed580108394cb24cdd0a"},"sha256":"699ec052ecc898bdbdafea0027c4ab44c3d01ae011c17745dd2b7fbddaa077f3","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_78qklua4/Win32.AgentTesla-019f46cd4ebf7711a1e74ba40b4703a4.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_78qklua4/Win32.AgentTesla-019f46cd4ebf7711a1e74ba40b4703a4.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_78qklua4/Win32.AgentTesla-019f46cd4ebf7711a1e74ba40b4703a4.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 2b294b3499d1cce794badffc959b7618                                  │\n│ sha1     │ 9aa826795798948e8058e3ff1342d81d5d8ee4fa                          │\n│ sha256   │ 699ec052ecc898bdbdafea0027c4ab44c3d01ae011c17745dd2b7fbddaa077f3  │\n│ analysis │ static                                                            │\n│ os       │ any                                                               │\n│ format   │ dotnet                                                            │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/Win32.AgentTesla… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DISCOVERY            │ Analysis Tool Discovery::Process detection            │\n│                      │ [B0013.001]                                           │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                                          ┃ Namespace              ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ reference analysis tools strings                    │ anti-analysis          │\n│ compiled to the .NET platform                       │ runtime/dotnet         │\n└─────────────────────────────────────────────────────┴────────────────────────┘\n\n","verbose":"md5                     2b294b3499d1cce794badffc959b7618                        \nsha1                    9aa826795798948e8058e3ff1342d81d5d8ee4fa                \nsha256                  699ec052ecc898bdbdafea0027c4ab44c3d01ae011c17745dd2b7fb…\npath                    /home/apogean/projects/malware/windows/all_runs/Win32.A…\ntimestamp               2026-07-10 00:19:58.355169                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIXsIqF1/rules                                   \nfunction count          19                                                      \nlibrary function count  0                                                       \ntotal feature count     4711                                                    \n\nreference analysis tools strings\nnamespace  anti-analysis\nscope      file         \n\ncompiled to the .NET platform\nnamespace  runtime/dotnet\nscope      file          \n\n\n\n","very_verbose":"md5                     2b294b3499d1cce794badffc959b7618                        \nsha1                    9aa826795798948e8058e3ff1342d81d5d8ee4fa                \nsha256                  699ec052ecc898bdbdafea0027c4ab44c3d01ae011c17745dd2b7fb…\npath                    /home/apogean/projects/malware/windows/all_runs/Win32.A…\ntimestamp               2026-07-10 00:20:00.814351                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEI4MEXHk/rules                                   \nfunction count          19                                                      \nlibrary function count  0                                                       \ntotal feature count     4711                                                    \n\nreference analysis tools strings\nnamespace   anti-analysis                                                       \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \nmbc         Discovery::Analysis Tool Discovery::Process detection [B0013.001]   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /(?<!\\w)ida?(\\.exe)?$/i\n    - \"IDAT\" @ file+0x2BA40, file+0x3BA40\n\n(internal) .NET file limitation\nnamespace    internal/limitation/dynamic                        \nauthor       @v1bh475u                                          \nscope        file                                               \ndescription  This dynamic analysis trace describes a .NET file. \n                                                                \n             capa rules are not yet tuned for the .NET runtime, \n             so its analysis may be incomplete or misleading.   \n                                                                \nor:\n  format: dotnet\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  format: dotnet\n\n\n\n"},"hashes":{"md5":"2b294b3499d1cce794badffc959b7618","sha1":"9aa826795798948e8058e3ff1342d81d5d8ee4fa","sha256":"699ec052ecc898bdbdafea0027c4ab44c3d01ae011c17745dd2b7fbddaa077f3"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 19</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 4711</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Win32.A\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"2b294b3499d1cce794badffc959b7618\",\n        \"sha256\": \"699ec052ecc898bdbdafea0027c4ab44c3d01ae011c17745dd2b7fb\",\n        \"arch\": \"i386\",\n        \"os\": \"any\",\n        \"format\": \"dotnet\"\n      }\n    },\n    {\n      \"id\": \"cap_reference_analysis_tools_strings\",\n      \"label\": \"reference analysis tools strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal___net_file_limitation\",\n      \"label\": \"(internal) .NET file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author________v1bh475u\",\n      \"label\": \"author       @v1bh475u\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compiled_to_the__net_platform\",\n      \"label\": \"compiled to the .NET platform\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_analysis_tools_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal___net_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________v1bh475u\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_to_the__net_platform\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-10 00:20:00.814351\",\n    \"total_functions\": \"19\",\n    \"total_features\": \"4711\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-10 00:20:00"}
{"_id":{"$oid":"6a4feeac0108394cb24cdd0e"},"sha256":"e67834d1e8b38ec5864cfa101b140aeaba8f1900a6e269e6a94c90fcbfe56678","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_7cokmg4n/Ransomware.Cerber-019f46cdc4917d52a23cef8be97f1622.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_7cokmg4n/Ransomware.Cerber-019f46cdc4917d52a23cef8be97f1622.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_7cokmg4n/Ransomware.Cerber-019f46cdc4917d52a23cef8be97f1622.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 8b6bc16fd137c09a08b02bbe1bb7d670                                  │\n│ sha1     │ c69a0f6c6f809c01db92ca658fcf1b643391a2b7                          │\n│ sha256   │ e67834d1e8b38ec5864cfa101b140aeaba8f1900a6e269e6a94c90fcbfe56678  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/Ransomware.Cerbe… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\nno capabilities found\n\n","verbose":"md5                     8b6bc16fd137c09a08b02bbe1bb7d670                        \nsha1                    c69a0f6c6f809c01db92ca658fcf1b643391a2b7                \nsha256                  e67834d1e8b38ec5864cfa101b140aeaba8f1900a6e269e6a94c90f…\npath                    /home/apogean/projects/malware/windows/all_runs/Ransomw…\ntimestamp               2026-07-10 00:25:33.107346                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIoRVCce/rules                                   \nfunction count          14                                                      \nlibrary function count  0                                                       \ntotal feature count     4466                                                    \n\nno capabilities found\n\n\n","very_verbose":"md5                     8b6bc16fd137c09a08b02bbe1bb7d670                        \nsha1                    c69a0f6c6f809c01db92ca658fcf1b643391a2b7                \nsha256                  e67834d1e8b38ec5864cfa101b140aeaba8f1900a6e269e6a94c90f…\npath                    /home/apogean/projects/malware/windows/all_runs/Ransomw…\ntimestamp               2026-07-10 00:25:39.886200                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIxLZblY/rules                                   \nfunction count          14                                                      \nlibrary function count  0                                                       \ntotal feature count     4466                                                    \n\ncontain loop (5 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x44F2A0\n  or:\n    characteristic: loop @ 0x44F2A0\n    characteristic: recursive call @ 0x44F2A0\n\n\n\n"},"hashes":{"md5":"8b6bc16fd137c09a08b02bbe1bb7d670","sha1":"c69a0f6c6f809c01db92ca658fcf1b643391a2b7","sha256":"e67834d1e8b38ec5864cfa101b140aeaba8f1900a6e269e6a94c90fcbfe56678"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 14</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 4466</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Ransomw\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"8b6bc16fd137c09a08b02bbe1bb7d670\",\n        \"sha256\": \"e67834d1e8b38ec5864cfa101b140aeaba8f1900a6e269e6a94c90f\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__5_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (5 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x44F2A0\",\n      \"label\": \"Function 0x44F2A0\",\n      \"type\": \"function\",\n      \"address\": \"0x44F2A0\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__5_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__5_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x44F2A0\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-10 00:25:39.886200\",\n    \"total_functions\": \"14\",\n    \"total_features\": \"4466\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-10 00:25:40"}
{"_id":{"$oid":"6a4ff6e00108394cb24cdd11"},"sha256":"1c0ea462f0bbd7acfdf4c6daf3cb8ce09e1375b766fbd3ff89f40c0aa3f4fc96","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_pse2liqg/Win32.GravityRat-019f46cde34c7352bcaeb6bfad5b9c42.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_pse2liqg/Win32.GravityRat-019f46cde34c7352bcaeb6bfad5b9c42.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_pse2liqg/Win32.GravityRat-019f46cde34c7352bcaeb6bfad5b9c42.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ ec629f648434fc3d17e9561532d038c8                                  │\n│ sha1     │ 1a1b5976acb4cd25c1e225473a64a67438222768                          │\n│ sha256   │ 1c0ea462f0bbd7acfdf4c6daf3cb8ce09e1375b766fbd3ff89f40c0aa3f4fc96  │\n│ analysis │ static                                                            │\n│ os       │ any                                                               │\n│ format   │ dotnet                                                            │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/Win32.GravityRat… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Data from Information Repositories [T1213]            │\n│ DEFENSE EVASION      │ Deobfuscate/Decode Files or Information [T1140]       │\n│                      │ File and Directory Permissions Modification [T1222]   │\n│                      │ Obfuscated Files or Information [T1027]               │\n│                      │ Reflective Code Loading [T1620]                       │\n│                      │ Virtualization/Sandbox Evasion::System Checks         │\n│                      │ [T1497.001]                                           │\n│ DISCOVERY            │ Account Discovery [T1087]                             │\n│                      │ Application Window Discovery [T1010]                  │\n│                      │ File and Directory Discovery [T1083]                  │\n│                      │ Process Discovery [T1057]                             │\n│                      │ Query Registry [T1012]                                │\n│                      │ Software Discovery [T1518]                            │\n│                      │ System Information Discovery [T1082]                  │\n│                      │ System Owner/User Discovery [T1033]                   │\n│ EXECUTION            │ Windows Management Instrumentation [T1047]            │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Virtual Machine Detection [B0009]                 │\n│ COMMAND AND CONTROL      │ C2 Communication::Receive Data [B0030.002]        │\n│                          │ C2 Communication::Send Data [B0030.001]           │\n│ COMMUNICATION            │ HTTP Communication::Get Response [C0002.017]      │\n│ CRYPTOGRAPHY             │ Cryptographic Hash::MD5 [C0029.001]               │\n│                          │ Encrypt Data::AES [C0027.001]                     │\n│                          │ Generate Pseudo-random Sequence::Use API          │\n│                          │ [C0021.003]                                       │\n│ DATA                     │ Decode Data::Base64 [C0053.001]                   │\n│                          │ Encode Data::Base64 [C0026.001]                   │\n│ DEFENSE EVASION          │ Obfuscated Files or                               │\n│                          │ Information::Encoding-Standard Algorithm          │\n│                          │ [E1027.m02]                                       │\n│                          │ Obfuscated Files or                               │\n│                          │ Information::Encryption-Standard Algorithm        │\n│                          │ [E1027.m05]                                       │\n│ DISCOVERY                │ File and Directory Discovery [E1083]              │\n│                          │ System Information Discovery [E1082]              │\n│ FILE SYSTEM              │ Copy File [C0045]                                 │\n│                          │ Create Directory [C0046]                          │\n│                          │ Delete File [C0047]                               │\n│                          │ Get File Attributes [C0049]                       │\n│                          │ Move File [C0063]                                 │\n│                          │ Read File [C0051]                                 │\n│                          │ Set File Attributes [C0050]                       │\n│                          │ Writes File [C0052]                               │\n│ OPERATING SYSTEM         │ Registry::Query Registry Key [C0036.005]          │\n│                          │ Registry::Query Registry Value [C0036.006]        │\n│ PROCESS                  │ Create Mutex [C0042]                              │\n│                          │ Create Process [C0017]                            │\n│                          │ Suspend Thread [C0055]                            │\n│                          │ Terminate Process [C0018]                         │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ reference anti-VM strings             │ anti-analysis/anti-vm/vm-detection   │\n│ reference anti-VM strings targeting   │ anti-analysis/anti-vm/vm-detection   │\n│ Parallels                             │                                      │\n│ reference anti-VM strings targeting   │ anti-analysis/anti-vm/vm-detection   │\n│ VMWare                                │                                      │\n│ reference anti-VM strings targeting   │ anti-analysis/anti-vm/vm-detection   │\n│ VirtualBox                            │                                      │\n│ reference anti-VM strings targeting   │ anti-analysis/anti-vm/vm-detection   │\n│ VirtualPC                             │                                      │\n│ reference WMI statements (2 matches)  │ collection/database/wmi              │\n│ get MAC address in .NET               │ collection/network                   │\n│ receive data                          │ communication                        │\n│ send data (3 matches)                 │ communication                        │\n│ decode data using Base64 in .NET      │ data-manipulation/encoding/base64    │\n│ encode data using Base64              │ data-manipulation/encoding/base64    │\n│ encrypt data using AES via .NET       │ data-manipulation/encryption/aes     │\n│ hash data with MD5                    │ data-manipulation/hashing/md5        │\n│ generate random bytes in .NET         │ data-manipulation/prng               │\n│ generate random numbers in .NET (3    │ data-manipulation/prng               │\n│ matches)                              │                                      │\n│ find data using regex in .NET (7      │ data-manipulation/regex              │\n│ matches)                              │                                      │\n│ contains PDB path                     │ executable/pe/pdb                    │\n│ access .NET resource (3 matches)      │ executable/resource                  │\n│ extract resource via kernel32         │ executable/resource                  │\n│ functions (4 matches)                 │                                      │\n│ enumerate drives                      │ host-interaction/file-system         │\n│ generate random filename in .NET (2   │ host-interaction/file-system         │\n│ matches)                              │                                      │\n│ get common file path (2 matches)      │ host-interaction/file-system         │\n│ copy file (2 matches)                 │ host-interaction/file-system/copy    │\n│ create directory (7 matches)          │ host-interaction/file-system/create  │\n│ delete file (3 matches)               │ host-interaction/file-system/delete  │\n│ check if directory exists             │ host-interaction/file-system/exists  │\n│ check if file exists (17 matches)     │ host-interaction/file-system/exists  │\n│ enumerate files in .NET (2 matches)   │ host-interaction/file-system/files/… │\n│ get file attributes (3 matches)       │ host-interaction/file-system/meta    │\n│ get file size (6 matches)             │ host-interaction/file-system/meta    │\n│ set file attributes (2 matches)       │ host-interaction/file-system/meta    │\n│ move file                             │ host-interaction/file-system/move    │\n│ read file on Windows (5 matches)      │ host-interaction/file-system/read    │\n│ write file on Windows (3 matches)     │ host-interaction/file-system/write   │\n│ enumerate gui resources               │ host-interaction/gui                 │\n│ get disk information                  │ host-interaction/hardware/storage    │\n│ allocate unmanaged memory in .NET (2  │ host-interaction/memory              │\n│ matches)                              │                                      │\n│ manipulate unmanaged memory in .NET   │ host-interaction/memory              │\n│ (22 matches)                          │                                      │\n│ create or open mutex on Windows       │ host-interaction/mutex               │\n│ get hostname (3 matches)              │ host-interaction/os/hostname         │\n│ create a process with modified I/O    │ host-interaction/process/create      │\n│ handles and window                    │                                      │\n│ create process on Windows (2 matches) │ host-interaction/process/create      │\n│ enumerate processes                   │ host-interaction/process/list        │\n│ terminate process                     │ host-interaction/process/terminate   │\n│ query or enumerate registry key (2    │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ query or enumerate registry value (2  │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ get session user name (4 matches)     │ host-interaction/session             │\n│ suspend thread (4 matches)            │ host-interaction/thread/suspend      │\n│ execute via asynchronous task in .NET │ host-interaction/thread/task         │\n│ access WMI data in .NET (8 matches)   │ host-interaction/wmi                 │\n│ load .NET assembly                    │ load-code/dotnet                     │\n│ unmanaged call (13 matches)           │ runtime                              │\n│ compiled to the .NET platform         │ runtime/dotnet                       │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     ec629f648434fc3d17e9561532d038c8                        \nsha1                    1a1b5976acb4cd25c1e225473a64a67438222768                \nsha256                  1c0ea462f0bbd7acfdf4c6daf3cb8ce09e1375b766fbd3ff89f40c0…\npath                    /home/apogean/projects/malware/windows/all_runs/Win32.G…\ntimestamp               2026-07-10 01:00:32.129651                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIqLkEls/rules                                   \nfunction count          1219                                                    \nlibrary function count  0                                                       \ntotal feature count     32612                                                   \n\nreference anti-VM strings\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nreference anti-VM strings targeting Parallels\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nreference anti-VM strings targeting VMWare\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nreference anti-VM strings targeting VirtualBox\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nreference anti-VM strings targeting VirtualPC\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nreference WMI statements (2 matches)\nnamespace  collection/database/wmi\nscope      function               \nmatches    token(0x600004B)       \n           token(0x6000062)       \n\nget MAC address in .NET\nnamespace  collection/network\nscope      function          \nmatches    token(0x600005E)  \n\nreceive data\nnamespace    communication                                                     \ndescription  all known techniques for receiving data from a potential C2 server\nscope        function                                                          \nmatches      token(0x6000033)                                                  \n\nsend data (3 matches)\nnamespace    communication                                                 \ndescription  all known techniques for sending data to a potential C2 server\nscope        function                                                      \nmatches      token(0x600002C)                                              \n             token(0x600002D)                                              \n             token(0x600002E)                                              \n\nread data from Internet\nnamespace  communication/http/client\nscope      function                 \nmatches    token(0x6000033)         \n\nsend data to Internet (3 matches)\nnamespace  communication/http/client\nscope      function                 \nmatches    token(0x600002C)         \n           token(0x600002D)         \n           token(0x600002E)         \n\ndecode data using Base64 in .NET\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    token(0x6000071)                 \n\nencode data using Base64\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    token(0x6000070)                 \n\nencrypt data using AES via .NET\nnamespace  data-manipulation/encryption/aes\nscope      file                            \n\nhash data with MD5\nnamespace  data-manipulation/hashing/md5\nscope      function                     \nmatches    token(0x600005F)             \n\ngenerate random bytes in .NET\nnamespace  data-manipulation/prng\nscope      function              \nmatches    token(0x60002C0)      \n\ngenerate random numbers in .NET (3 matches)\nnamespace  data-manipulation/prng\nscope      function              \nmatches    token(0x60001D1)      \n           token(0x600024A)      \n           token(0x600032F)      \n\nfind data using regex in .NET (7 matches)\nnamespace  data-manipulation/regex\nscope      function               \nmatches    token(0x6000059)       \n           token(0x600005A)       \n           token(0x6000379)       \n           token(0x600037A)       \n           token(0x600037D)       \n           token(0x600037E)       \n           token(0x6000380)       \n\ncontains PDB path\nnamespace  executable/pe/pdb\nscope      file             \n\naccess .NET resource (3 matches)\nnamespace  executable/resource\nscope      function           \nmatches    token(0x6000006)   \n           token(0x6000492)   \n           token(0x6000493)   \n\nextract resource via kernel32 functions (4 matches)\nnamespace  executable/resource\nscope      function           \nmatches    token(0x60003FE)   \n           token(0x600041F)   \n           token(0x6000422)   \n           token(0x6000442)   \n\nenumerate drives\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x6000474)            \n\ngenerate random filename in .NET (2 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x60001E7)            \n           token(0x60001EC)            \n\nget common file path (2 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x6000001)            \n           token(0x600006B)            \n\ncopy file (2 matches)\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    token(0x600007A)                 \n           token(0x60001E9)                 \n\ncreate directory (7 matches)\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    token(0x600006B)                   \n           token(0x600006D)                   \n           token(0x6000075)                   \n           token(0x6000077)                   \n           token(0x60000A4)                   \n           token(0x6000469)                   \n           token(0x6000482)                   \n\ndelete file (3 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    token(0x6000079)                   \n           token(0x60001C3)                   \n           token(0x60001E8)                   \n\ncheck if directory exists\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x60000A4)                   \n\ncheck if file exists (17 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x6000001)                   \n           token(0x600002D)                   \n           token(0x600006D)                   \n           token(0x6000076)                   \n           token(0x6000078)                   \n           token(0x6000079)                   \n           token(0x600007A)                   \n           token(0x60000A3)                   \n           token(0x6000112)                   \n           token(0x6000114)                   \n           token(0x60001EC)                   \n           token(0x6000469)                   \n           token(0x6000490)                   \n           token(0x6000491)                   \n           token(0x6000495)                   \n           token(0x6000496)                   \n           token(0x60004A8)                   \n\nenumerate files in .NET (2 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    token(0x600006C)                       \n           token(0x6000374)                       \n\nget file attributes (3 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    token(0x60000A5)                 \n           token(0x6000112)                 \n           token(0x6000114)                 \n\nget file size (6 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    token(0x600006D)                 \n           token(0x6000112)                 \n           token(0x6000386)                 \n           token(0x6000390)                 \n           token(0x60004A8)                 \n           token(0x60004A9)                 \n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    token(0x600006B)                 \n           token(0x60000A3)                 \n\nmove file\nnamespace  host-interaction/file-system/move\nscope      function                         \nmatches    token(0x60001E8)                 \n\nread file on Windows (5 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    token(0x6000001)                 \n           token(0x6000076)                 \n           token(0x6000078)                 \n           token(0x60003E4)                 \n           token(0x6000495)                 \n\nwrite file on Windows (3 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    token(0x6000075)                  \n           token(0x6000077)                  \n           token(0x6000464)                  \n\nenumerate gui resources\nnamespace  host-interaction/gui\nscope      function            \nmatches    token(0x600043E)    \n\nget disk information\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    token(0x6000522)                 \n\nallocate unmanaged memory in .NET (2 matches)\nnamespace  host-interaction/memory\nscope      function               \nmatches    token(0x60003B9)       \n           token(0x60003E4)       \n\nmanipulate unmanaged memory in .NET (22 matches)\nnamespace  host-interaction/memory\nscope      function               \nmatches    token(0x60003B9)       \n           token(0x60003BF)       \n           token(0x60003C2)       \n           token(0x60003C6)       \n           token(0x60003C7)       \n           token(0x60003C8)       \n           token(0x60003CD)       \n           token(0x60003CF)       \n           token(0x60003E4)       \n           token(0x60003E5)       \n           token(0x60003ED)       \n           token(0x60003F6)       \n           token(0x60003FE)       \n           token(0x600041F)       \n           token(0x6000422)       \n           token(0x600042A)       \n           token(0x6000430)       \n           token(0x6000435)       \n           token(0x6000436)       \n           token(0x600043E)       \n           token(0x600043F)       \n           token(0x6000440)       \n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex\nscope      instruction           \nmatches    token(0x6000005)+0x8  \n\nget hostname (3 matches)\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    token(0x6000042)            \n           token(0x6000043)            \n           token(0x600004F)            \n\ncreate a process with modified I/O handles and window\nnamespace  host-interaction/process/create\nscope      function                       \nmatches    token(0x6000469)               \n\ncreate process on Windows (2 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    token(0x6000469)               \n           token(0x6000491)               \n\nenumerate processes\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    token(0x600046E)             \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    token(0x6000469)                  \n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    token(0x600003D)         \n           token(0x600005B)         \n\nquery or enumerate registry value (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    token(0x600003D)         \n           token(0x600005B)         \n\nget session user name (4 matches)\nnamespace  host-interaction/session\nscope      function                \nmatches    token(0x6000042)        \n           token(0x6000043)        \n           token(0x600004E)        \n           token(0x600005C)        \n\nsuspend thread (4 matches)\nnamespace  host-interaction/thread/suspend\nscope      basic block                    \nmatches    token(0x6000003)               \n           token(0x600002D)               \n           token(0x6000031)               \n           token(0x600047A)               \n\nexecute via asynchronous task in .NET\nnamespace  host-interaction/thread/task\nscope      function                    \nmatches    token(0x6000483)            \n\naccess WMI data in .NET (8 matches)\nnamespace  host-interaction/wmi\nscope      function            \nmatches    token(0x600003E)    \n           token(0x600003F)    \n           token(0x6000040)    \n           token(0x6000041)    \n           token(0x6000042)    \n           token(0x600004B)    \n           token(0x600005D)    \n           token(0x6000062)    \n\nload .NET assembly\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x6000006)\n\nunmanaged call (13 matches)\nnamespace    runtime                                                       \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nscope        function                                                      \nmatches      token(0x60003C6)                                              \n             token(0x60003C7)                                              \n             token(0x60003C8)                                              \n             token(0x60003FE)                                              \n             token(0x600041F)                                              \n             token(0x6000421)                                              \n             token(0x6000422)                                              \n             token(0x600042A)                                              \n             token(0x600043D)                                              \n             token(0x600043E)                                              \n             token(0x600043F)                                              \n             token(0x6000440)                                              \n             token(0x6000442)                                              \n\ncompiled to the .NET platform\nnamespace  runtime/dotnet\nscope      file          \n\n\n\n","very_verbose":"md5                     ec629f648434fc3d17e9561532d038c8                        \nsha1                    1a1b5976acb4cd25c1e225473a64a67438222768                \nsha256                  1c0ea462f0bbd7acfdf4c6daf3cb8ce09e1375b766fbd3ff89f40c0…\npath                    /home/apogean/projects/malware/windows/all_runs/Win32.G…\ntimestamp               2026-07-10 01:00:39.228416                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIex6ZxR/rules                                   \nfunction count          1219                                                    \nlibrary function count  0                                                       \ntotal feature count     32612                                                   \n\ncontain loop (library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ token(0x6000374)\n  or:\n    characteristic: recursive call @ token(0x6000374)\n\ncreate or open registry key (2 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ token(0x600003D) in function token(0x600003D)\n  or:\n    api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600003D)+0x13\n\nreference anti-VM strings\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      moritz.raabe@mandiant.com                                           \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/ctxis/CAPE/blob/master/modules/signatures/antivm…\n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /A M I/i\n    - \"A M I\" @ file+0x27160\n\nreference anti-VM strings targeting Parallels\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /Parallels/i\n    - \"00:1C:42 / Parallels, Inc.\" @ file+0x27524\n\nreference anti-VM strings targeting VMWare\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com, @johnk3r                              \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /VMWare/i\n    - \"00:05:69 / VMware, Inc.\" @ file+0x27496\n    - \"00:0C:29 / VMware, Inc.\" @ file+0x27466\n    - \"00:50:56 / VMware, Inc.\" @ file+0x27436\n    - \"VMware\" @ file+0x27132\n    - \"vmware\" @ file+0x27228\n\nreference anti-VM strings targeting VirtualBox\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /VirtualBox/i\n    - \"08:00:27 / PCS Systemtechnik GmbH (VirtualBox)\" @ file+0x274C6\n    - \"VirtualBox\" @ file+0x27236\n\nreference anti-VM strings targeting VirtualPC\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /SOFTWARE\\\\Microsoft\\\\Virtual Machine\\\\Guest\\\\Parameters/i\n    - \"SOFTWARE\\\\Microsoft\\\\Virtual Machine\\\\Guest\\\\Parameters\" @ file+0x26FEA\n\nreference WMI statements (2 matches)\nnamespace  collection/database/wmi                               \nauthor     michael.hunhoff@mandiant.com                          \nscope      function                                              \natt&ck     Collection::Data from Information Repositories [T1213]\nfunction @ token(0x600004B)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_OperatingSystem\" @ token(0x600004B)+0x7\nfunction @ token(0x6000062)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_UserAccount\" @ token(0x6000062)+0x0\n\nget MAC address in .NET\nnamespace  collection/network                                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           echernofsky@google.com                                               \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nfunction @ token(0x600005E)\n  or:\n    api: System.Net.NetworkInformation.NetworkInterface::GetPhysicalAddress @ token(0x600005E)+0x67\n\nreceive data\nnamespace    communication                                                     \nauthor       william.ballenthin@mandiant.com                                   \nscope        function                                                          \nmbc          Command and Control::C2 Communication::Receive Data [B0030.002]   \ndescription  all known techniques for receiving data from a potential C2 server\nfunction @ token(0x6000033)\n  or:\n    match: read data from Internet @ token(0x6000033)\n      and:\n        or:\n          api: System.Net.WebClient::DownloadString @ token(0x6000033)+0xC\n\nsend data (3 matches)\nnamespace    communication                                                 \nauthor       william.ballenthin@mandiant.com, joakim@intezer.com           \nscope        function                                                      \nmbc          Command and Control::C2 Communication::Send Data [B0030.001]  \ndescription  all known techniques for sending data to a potential C2 server\nfunction @ token(0x600002C)\n  or:\n    and:\n      os: windows\n      or:\n        match: send data to Internet @ token(0x600002C)\n          and:\n            or:\n              api: System.Net.WebClient::UploadValues @ token(0x600002C)+0x1C\nfunction @ token(0x600002D)\n  or:\n    and:\n      os: windows\n      or:\n        match: send data to Internet @ token(0x600002D)\n          and:\n            or:\n              api: System.Net.WebClient::UploadFileTaskAsync @ token(0x600002D)+0x4C\nfunction @ token(0x600002E)\n  or:\n    and:\n      os: windows\n      or:\n        match: send data to Internet @ token(0x600002E)\n          and:\n            or:\n              api: System.Net.WebClient::UploadValues @ token(0x600002E)+0x1C\n\nread data from Internet\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Get Response [C0002.017]  \nfunction @ token(0x6000033)\n  and:\n    or:\n      api: System.Net.WebClient::DownloadString @ token(0x6000033)+0xC\n\nsend data to Internet (3 matches)\nnamespace  communication/http/client   \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x600002C)\n  and:\n    or:\n      api: System.Net.WebClient::UploadValues @ token(0x600002C)+0x1C\nfunction @ token(0x600002D)\n  and:\n    or:\n      api: System.Net.WebClient::UploadFileTaskAsync @ token(0x600002D)+0x4C\nfunction @ token(0x600002E)\n  and:\n    or:\n      api: System.Net.WebClient::UploadValues @ token(0x600002E)+0x1C\n\ndecode data using Base64 in .NET\nnamespace  data-manipulation/encoding/base64                               \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \natt&ck     Defense Evasion::Deobfuscate/Decode Files or Information [T1140]\nmbc        Data::Decode Data::Base64 [C0053.001]                           \nfunction @ token(0x6000071)\n  or:\n    api: System.Convert::FromBase64String @ token(0x6000071)+0x2D\n\nencode data using Base64\nnamespace  data-manipulation/encoding/base64                                    \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::Base64 [C0026.001]         \nfunction @ token(0x6000070)\n  or:\n    api: System.Convert::ToBase64String @ token(0x6000070)+0xC9\n\nencrypt data using AES via .NET\nnamespace  data-manipulation/encryption/aes                                     \nauthor     william.ballenthin@mandiant.com                                      \nscope      file                                                                 \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encryption-Standard\n           Algorithm [E1027.m05], Cryptography::Encrypt Data::AES [C0027.001]   \nand:\n  class: System.Security.Cryptography.RijndaelManaged @ token(0x1000039)\n  class: System.Security.Cryptography.CryptoStream @ token(0x100003D)\n\nhash data with MD5\nnamespace   data-manipulation/hashing/md5                                       \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,         \n            michael.hunhoff@mandiant.com                                        \nscope       function                                                            \nmbc         Cryptography::Cryptographic Hash::MD5 [C0029.001]                   \nreferences  https://github.com/rwfpl/rewolf-x86-virtualizer/blob/master/src/tes…\nfunction @ token(0x600005F)\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Security.Cryptography.MD5::Create @ token(0x600005F)+0x0\n      optional:\n        api: System.Security.Cryptography.HashAlgorithm::ComputeHash @ token(0x600005F)+0x12\n\ngenerate random bytes in .NET\nnamespace  data-manipulation/prng                                            \nauthor     michael.hunhoff@mandiant.com                                      \nscope      function                                                          \nmbc        Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\nfunction @ token(0x60002C0)\n  or:\n    api: System.Security.Cryptography.RandomNumberGenerator::GetBytes @ token(0x60002C0)+0x25\n\ngenerate random numbers in .NET (3 matches)\nnamespace  data-manipulation/prng                                            \nauthor     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com     \nscope      function                                                          \nmbc        Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\nfunction @ token(0x60001D1)\n  or:\n    api: System.Random::NextBytes @ token(0x60001D1)+0xE\nfunction @ token(0x600024A)\n  or:\n    api: System.Random::NextBytes @ token(0x600024A)+0x2A\nfunction @ token(0x600032F)\n  or:\n    api: System.Random::NextBytes @ token(0x600032F)+0x18\n\nfind data using regex in .NET (7 matches)\nnamespace  data-manipulation/regex     \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x6000059)\n  or:\n    api: System.Text.RegularExpressions.Regex::Replace @ token(0x6000059)+0xB\nfunction @ token(0x600005A)\n  or:\n    api: System.Text.RegularExpressions.Regex::Replace @ token(0x600005A)+0xB\nfunction @ token(0x6000379)\n  or:\n    api: System.Text.RegularExpressions.Regex::ctor @ token(0x6000379)+0x5\nfunction @ token(0x600037A)\n  or:\n    api: System.Text.RegularExpressions.Regex::ctor @ token(0x600037A)+0x78\nfunction @ token(0x600037D)\n  or:\n    api: System.Text.RegularExpressions.Regex::IsMatch @ token(0x600037D)+0x2D\nfunction @ token(0x600037E)\n  or:\n    api: System.Text.RegularExpressions.Regex::IsMatch @ token(0x600037E)+0x1C\nfunction @ token(0x6000380)\n  or:\n    api: System.Text.RegularExpressions.Regex::ctor @ token(0x6000380)+0x97, token(0x6000380)+0xAD\n\ncontains PDB path\nnamespace  executable/pe/pdb        \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nregex: /:\\\\.*\\.pdb/\n  - \"C:\\\\Users\\\\The \nInvincible\\\\Desktop\\\\gx\\\\gx-current-program\\\\LSASS\\\\obj\\\\Release\\\\LSASS.pdb\" @ file+0x9FE70\n  - \"c:\\\\sources\\\\cecil\\\\obj\\\\net_2_0_Release\\\\Mono.Cecil.pdb\" @ file+0x9F594\n\naccess .NET resource (3 matches)\nnamespace  executable/resource\nauthor     @mr-tz             \nscope      function           \nfunction @ token(0x6000006)\n  and:\n    format: dotnet\n    or:\n      api: System.Reflection.Assembly::GetManifestResourceStream @ token(0x6000006)+0x48\nfunction @ token(0x6000492)\n  and:\n    format: dotnet\n    or:\n      api: System.Reflection.Assembly::GetManifestResourceStream @ token(0x6000492)+0x1E\nfunction @ token(0x6000493)\n  and:\n    format: dotnet\n    or:\n      api: System.Reflection.Assembly::GetManifestResourceStream @ token(0x6000493)+0x12\n\nextract resource via kernel32 functions (4 matches)\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ token(0x60003FE)\n  or:\n    and:\n      or:\n        api: LoadResource @ token(0x60003FE)+0x5D\n        api: LockResource @ token(0x60003FE)+0x7A\n      optional:\n        or:\n          api: FindResourceEx @ token(0x60003FE)+0x3D\n        api: SizeofResource @ token(0x60003FE)+0x9C\nfunction @ token(0x600041F)\n  or:\n    and:\n      or:\n        api: LockResource @ token(0x600041F)+0xF\nfunction @ token(0x6000422)\n  or:\n    and:\n      or:\n        api: LoadResource @ token(0x6000422)+0x47\n        api: LockResource @ token(0x6000422)+0x66\n      optional:\n        or:\n          api: FindResourceEx @ token(0x6000422)+0x27\n        api: SizeofResource @ token(0x6000422)+0x87\nfunction @ token(0x6000442)\n  or:\n    and:\n      or:\n        api: LoadResource @ token(0x6000442)+0x40\n      optional:\n        or:\n          api: FindResourceEx @ token(0x6000442)+0x38\n        api: SizeofResource @ token(0x6000442)+0x49\n\nenumerate drives\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x6000474)\n  or:\n    api: System.IO.DriveInfo::GetDrives @ token(0x6000474)+0x11\n\ngenerate random filename in .NET (2 matches)\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x60001E7)\n  or:\n    api: System.IO.Path::GetTempFileName @ token(0x60001E7)+0x31\nfunction @ token(0x60001EC)\n  or:\n    api: System.IO.Path::GetTempFileName @ token(0x60001EC)+0x5\n\nget common file path (2 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ token(0x6000001)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x6000001)+0x42\nfunction @ token(0x600006B)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x600006B)+0x13\n\ncopy file (2 matches)\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ token(0x600007A)\n  or:\n    api: System.IO.File::Copy @ token(0x600007A)+0x12\nfunction @ token(0x60001E9)\n  or:\n    api: System.IO.File::Copy @ token(0x60001E9)+0x25\n\ncreate directory (7 matches)\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ token(0x600006B)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x600006B)+0x6C, token(0x600006B)+0x95, token(0x600006B)+0xA5\nfunction @ token(0x600006D)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x600006D)+0x92\nfunction @ token(0x6000075)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000075)+0x6\nfunction @ token(0x6000077)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000077)+0x6\nfunction @ token(0x60000A4)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60000A4)+0x87\nfunction @ token(0x6000469)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000469)+0x6\nfunction @ token(0x6000482)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000482)+0x26\n\ndelete file (3 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ token(0x6000079)\n  or:\n    api: System.IO.File::Delete @ token(0x6000079)+0x9\nfunction @ token(0x60001C3)\n  or:\n    api: System.IO.File::Delete @ token(0x60001C3)+0x359\nfunction @ token(0x60001E8)\n  or:\n    api: System.IO.File::Delete @ token(0x60001E8)+0x4F, token(0x60001E8)+0x7D\n\ncheck if directory exists\nnamespace  host-interaction/file-system/exists            \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nfunction @ token(0x60000A4)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60000A4)+0x6E\n\ncheck if file exists (17 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ token(0x6000001)\n  or:\n    api: System.IO.File::Exists @ token(0x6000001)+0x53\nfunction @ token(0x600002D)\n  or:\n    api: System.IO.File::Exists @ token(0x600002D)+0x1\nfunction @ token(0x600006D)\n  or:\n    api: System.IO.File::Exists @ token(0x600006D)+0x1\nfunction @ token(0x6000076)\n  or:\n    api: System.IO.File::Exists @ token(0x6000076)+0x1\nfunction @ token(0x6000078)\n  or:\n    api: System.IO.File::Exists @ token(0x6000078)+0x1\nfunction @ token(0x6000079)\n  or:\n    api: System.IO.File::Exists @ token(0x6000079)+0x1\nfunction @ token(0x600007A)\n  or:\n    api: System.IO.File::Exists @ token(0x600007A)+0x1, token(0x600007A)+0x9\nfunction @ token(0x60000A3)\n  or:\n    api: System.IO.File::Exists @ token(0x60000A3)+0xC\nfunction @ token(0x6000112)\n  or:\n    property/read: System.IO.FileSystemInfo::Exists @ token(0x6000112)+0x3D\nfunction @ token(0x6000114)\n  or:\n    property/read: System.IO.FileSystemInfo::Exists @ token(0x6000114)+0x3B\nfunction @ token(0x60001EC)\n  or:\n    api: System.IO.File::Exists @ token(0x60001EC)+0x3E\nfunction @ token(0x6000469)\n  or:\n    api: System.IO.File::Exists @ token(0x6000469)+0x51\nfunction @ token(0x6000490)\n  or:\n    api: System.IO.File::Exists @ token(0x6000490)+0x16\nfunction @ token(0x6000491)\n  or:\n    api: System.IO.File::Exists @ token(0x6000491)+0x27\nfunction @ token(0x6000495)\n  or:\n    api: System.IO.File::Exists @ token(0x6000495)+0x1\nfunction @ token(0x6000496)\n  or:\n    api: System.IO.File::Exists @ token(0x6000496)+0x1\nfunction @ token(0x60004A8)\n  or:\n    property/read: System.IO.FileSystemInfo::Exists @ token(0x60004A8)+0x1\n\nenumerate files in .NET (2 matches)\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ token(0x600006C)\n  or:\n    api: System.IO.DirectoryInfo::EnumerateFiles @ token(0x600006C)+0x29\n    api: System.IO.DirectoryInfo::EnumerateDirectories @ token(0x600006C)+0x90\nfunction @ token(0x6000374)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x6000374)+0x1\n    api: System.IO.Directory::GetDirectories @ token(0x6000374)+0xA3\n\nget file attributes (3 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ token(0x60000A5) in function token(0x60000A5)\n  or:\n    property/read: System.IO.FileSystemInfo::Attributes @ token(0x60000A5)+0x1\nbasic block @ token(0x6000112) in function token(0x6000112)\n  or:\n    property/read: System.IO.FileSystemInfo::Attributes @ token(0x6000112)+0xF0\nbasic block @ token(0x6000114) in function token(0x6000114)\n  or:\n    property/read: System.IO.FileSystemInfo::Attributes @ token(0x6000114)+0xDE\n\nget file size (6 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ token(0x600006D)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x600006D)+0x11\nfunction @ token(0x6000112)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x6000112)+0xE3\nfunction @ token(0x6000386)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x6000386)+0x19, token(0x6000386)+0x27\nfunction @ token(0x6000390)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x6000390)+0x11\nfunction @ token(0x60004A8)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x60004A8)+0x1B\nfunction @ token(0x60004A9)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x60004A9)+0x13\n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ token(0x600006B) in function token(0x600006B)\n  or:\n    property/write: System.IO.FileSystemInfo::Attributes @ token(0x600006B)+0x86\nbasic block @ token(0x60000A3) in function token(0x60000A3)\n  or:\n    api: System.IO.File::SetAttributes @ token(0x60000A3)+0x156\n    api: System.IO.File::SetLastWriteTime @ token(0x60000A3)+0x127\n\nmove file\nnamespace  host-interaction/file-system/move                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Move File [C0063]                         \nfunction @ token(0x60001E8)\n  or:\n    api: System.IO.File::Move @ token(0x60001E8)+0x36, token(0x60001E8)+0x47, token(0x60001E8)+0x72\n\nread file on Windows (5 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ token(0x6000001)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x6000001)+0x71\nfunction @ token(0x6000076)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x6000076)+0x9\nfunction @ token(0x6000078)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x6000078)+0x9\nfunction @ token(0x60003E4)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x60003E4)+0x1\nfunction @ token(0x6000495)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x6000495)+0xB9\n\nwrite file on Windows (3 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ token(0x6000075)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x6000075)+0x18\nfunction @ token(0x6000077)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x6000077)+0x22\nfunction @ token(0x6000464)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x6000464)+0xA1\n\nenumerate gui resources\nnamespace  host-interaction/gui                           \nauthor     johnk3r, anushka.virgaonkar@mandiant.com       \nscope      function                                       \natt&ck     Discovery::Application Window Discovery [T1010]\nfunction @ token(0x600043E)\n  or:\n    api: EnumResourceTypes @ token(0x600043E)+0x62\n\nget disk information\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ token(0x6000522)\n  or:\n    property/read: System.IO.DriveInfo::DriveType @ token(0x6000522)+0x1, token(0x6000522)+0xA\n    property/read: System.IO.DriveInfo::Name @ token(0x6000522)+0x1F, token(0x6000522)+0x37\n\nallocate unmanaged memory in .NET (2 matches)\nnamespace  host-interaction/memory     \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x60003B9)\n  or:\n    api: System.Runtime.InteropServices.Marshal::AllocHGlobal @ token(0x60003B9)+0x17\nfunction @ token(0x60003E4)\n  or:\n    api: System.Runtime.InteropServices.Marshal::AllocHGlobal @ token(0x60003E4)+0xA\n\nmanipulate unmanaged memory in .NET (22 matches)\nnamespace  host-interaction/memory     \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x60003B9)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60003B9)+0x12, token(0x60003B9)+0x17, token(0x60003B9)+0x30, \ntoken(0x60003B9)+0x35, and 2 more...\nfunction @ token(0x60003BF)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60003BF)+0xC, token(0x60003BF)+0x37\nfunction @ token(0x60003C2)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60003C2)+0xB, token(0x60003C2)+0x26\nfunction @ token(0x60003C6)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60003C6)+0x76, token(0x60003C6)+0x7E, token(0x60003C6)+0x90, \ntoken(0x60003C6)+0x95, and 20 more...\nfunction @ token(0x60003C7)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60003C7)+0x70, token(0x60003C7)+0x86, token(0x60003C7)+0x9B, \ntoken(0x60003C7)+0xA6, and 4 more...\nfunction @ token(0x60003C8)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60003C8)+0x3B, token(0x60003C8)+0x98\nfunction @ token(0x60003CD)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60003CD)+0x31\nfunction @ token(0x60003CF)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60003CF)+0x17, token(0x60003CF)+0x3A\nfunction @ token(0x60003E4)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60003E4)+0xA, token(0x60003E4)+0x16, token(0x60003E4)+0x26\nfunction @ token(0x60003E5)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60003E5)+0x17, token(0x60003E5)+0x3A\nfunction @ token(0x60003ED)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60003ED)+0xC, token(0x60003ED)+0x60\nfunction @ token(0x60003F6)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60003F6)+0x30\nfunction @ token(0x60003FE)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60003FE)+0xC, token(0x60003FE)+0x50, token(0x60003FE)+0x6F, \ntoken(0x60003FE)+0x8D, and 1 more...\nfunction @ token(0x600041F)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x600041F)+0x22\nfunction @ token(0x6000422)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x6000422)+0xD, token(0x6000422)+0x3A, token(0x6000422)+0x5A, \ntoken(0x6000422)+0x79, and 1 more...\nfunction @ token(0x600042A)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x600042A)+0x14, token(0x600042A)+0x41, token(0x600042A)+0x54\nfunction @ token(0x6000430)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x6000430)+0xA, token(0x6000430)+0xF\nfunction @ token(0x6000435)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x6000435)+0xE\nfunction @ token(0x6000436)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x6000436)+0x2\nfunction @ token(0x600043E)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x600043E)+0x40, token(0x600043E)+0x69\nfunction @ token(0x600043F)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x600043F)+0x2D\nfunction @ token(0x6000440)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x6000440)+0x1B\n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex                                               \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           mehunhoff@google.com                                                 \nscope      instruction                                                          \nmbc        Process::Create Mutex [C0042]                                        \ninstruction @ token(0x6000005)+0x8\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Threading.Mutex::ctor @ token(0x6000005)+0x8\n\nget hostname (3 matches)\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ token(0x6000042)\n  or:\n    property/read: System.Environment::MachineName @ token(0x6000042)+0x94\nfunction @ token(0x6000043)\n  or:\n    property/read: System.Environment::MachineName @ token(0x6000043)+0x71\nfunction @ token(0x600004F)\n  or:\n    property/read: System.Environment::MachineName @ token(0x600004F)+0x1\n\ncreate a process with modified I/O handles and window\nnamespace   host-interaction/process/create                                     \nauthor      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com      \nscope       function                                                            \nmbc         Process::Create Process [C0017]                                     \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/processthreadsap…\nfunction @ token(0x6000469)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000469)+0x44\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000469)+0x1A\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000469)+0x25\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000469)+0x37\n\ncreate process on Windows (2 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ token(0x6000469) in function token(0x6000469)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000469)+0x44\nbasic block @ token(0x6000491) in function token(0x6000491)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000491)+0x43\n\nenumerate processes\nnamespace  host-interaction/process/list                                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      function                                                             \natt&ck     Discovery::Process Discovery [T1057], Discovery::Software Discovery  \n           [T1518]                                                              \nfunction @ token(0x600046E)\n  or:\n    api: System.Diagnostics.Process::GetProcesses @ token(0x600046E)+0x0\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ token(0x6000469)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x6000469)+0x4B\n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ token(0x600003D)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600003D)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600003D)+0x13\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600003D)+0x13\nfunction @ token(0x600005B)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600005B)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600005B)+0xA\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600005B)+0xA\n\nquery or enumerate registry value (2 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ token(0x600003D)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600003D)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600003D)+0x13\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x600003D)+0x23, token(0x600003D)+0x33\nfunction @ token(0x600005B)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600005B)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600005B)+0xA\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x600005B)+0x21\n\nget session user name (4 matches)\nnamespace  host-interaction/session                                             \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope      function                                                             \natt&ck     Discovery::System Owner/User Discovery [T1033], Discovery::Account   \n           Discovery [T1087]                                                    \nfunction @ token(0x6000042)\n  or:\n    property/read: System.Environment::UserName @ token(0x6000042)+0x88\nfunction @ token(0x6000043)\n  or:\n    property/read: System.Environment::UserName @ token(0x6000043)+0x66\nfunction @ token(0x600004E)\n  or:\n    property/read: System.Environment::UserName @ token(0x600004E)+0x1\nfunction @ token(0x600005C)\n  or:\n    api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x600005C)+0x6, token(0x600005C)+0x1A\n\nsuspend thread (4 matches)\nnamespace  host-interaction/thread/suspend                    \nauthor     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\nscope      basic block                                        \nmbc        Process::Suspend Thread [C0055]                    \nbasic block @ token(0x6000003) in function token(0x6000003)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000003)+0x28\nbasic block @ token(0x600002D) in function token(0x600002D)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x600002D)+0x9A\nbasic block @ token(0x6000031) in function token(0x6000031)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000031)+0x2C\nbasic block @ token(0x600047A) in function token(0x600047A)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x600047A)+0x7\n\nexecute via asynchronous task in .NET\nnamespace  host-interaction/thread/task\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x6000483)\n  or:\n    api: System.Threading.Tasks.Task::ctor @ token(0x6000483)+0xD, token(0x6000483)+0x2F\n\naccess WMI data in .NET (8 matches)\nnamespace  host-interaction/wmi                                 \nauthor     michael.hunhoff@mandiant.com                         \nscope      function                                             \natt&ck     Execution::Windows Management Instrumentation [T1047]\nfunction @ token(0x600003E)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x600003E)+0x13\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x600003E)+0xE\nfunction @ token(0x600003F)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x600003F)+0x13\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x600003F)+0xC\nfunction @ token(0x6000040)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000040)+0x15\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000040)+0x10\nfunction @ token(0x6000041)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000041)+0x15\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000041)+0x10\nfunction @ token(0x6000042)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000042)+0x16\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000042)+0x11\nfunction @ token(0x600004B)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x600004B)+0x11\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x600004B)+0xC\nfunction @ token(0x600005D)\n  or:\n    and:\n      api: System.Management.ManagementClass::ctor @ token(0x600005D)+0xB\n      optional:\n        api: System.Management.ManagementClass::GetInstances @ token(0x600005D)+0x10\n        api: System.Management.ManagementObjectCollection::GetEnumerator @ token(0x600005D)+0x15\nfunction @ token(0x6000062)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000062)+0xA\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000062)+0x5\n\n(internal) .NET file limitation\nnamespace    internal/limitation/dynamic                        \nauthor       @v1bh475u                                          \nscope        file                                               \ndescription  This dynamic analysis trace describes a .NET file. \n                                                                \n             capa rules are not yet tuned for the .NET runtime, \n             so its analysis may be incomplete or misleading.   \n                                                                \nor:\n  format: dotnet\n\nload .NET assembly\nnamespace  load-code/dotnet                                \nauthor     anushka.virgaonkar@mandiant.com                 \nscope      function                                        \natt&ck     Defense Evasion::Reflective Code Loading [T1620]\nfunction @ token(0x6000006)\n  or:\n    api: System.Reflection.Assembly::Load @ token(0x6000006)+0x68\n\nunmanaged call (13 matches)\nnamespace    runtime                                                       \nauthor       michael.hunhoff@mandiant.com                                  \nscope        function                                                      \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nfunction @ token(0x60003C6)\n  or:\n    characteristic: unmanaged call @ token(0x60003C6)+0x2F, token(0x60003C6)+0x4E, token(0x60003C6)+0x56, \ntoken(0x60003C6)+0x196, and 2 more...\nfunction @ token(0x60003C7)\n  or:\n    characteristic: unmanaged call @ token(0x60003C7)+0x36, token(0x60003C7)+0x3D, token(0x60003C7)+0x5C, \ntoken(0x60003C7)+0x64, and 4 more...\nfunction @ token(0x60003C8)\n  or:\n    characteristic: unmanaged call @ token(0x60003C8)+0x28, token(0x60003C8)+0x6D, token(0x60003C8)+0x7F, \ntoken(0x60003C8)+0xBE, and 2 more...\nfunction @ token(0x60003FE)\n  or:\n    characteristic: unmanaged call @ token(0x60003FE)+0x3D, token(0x60003FE)+0x5D, token(0x60003FE)+0x7A, \ntoken(0x60003FE)+0x9C\nfunction @ token(0x600041F)\n  or:\n    characteristic: unmanaged call @ token(0x600041F)+0xF\nfunction @ token(0x6000421)\n  or:\n    characteristic: unmanaged call @ token(0x6000421)+0xD, token(0x6000421)+0x2E\nfunction @ token(0x6000422)\n  or:\n    characteristic: unmanaged call @ token(0x6000422)+0x27, token(0x6000422)+0x47, token(0x6000422)+0x66, \ntoken(0x6000422)+0x87\nfunction @ token(0x600042A)\n  or:\n    characteristic: unmanaged call @ token(0x600042A)+0x2, token(0x600042A)+0x3A, token(0x600042A)+0x4D\nfunction @ token(0x600043D)\n  or:\n    characteristic: unmanaged call @ token(0x600043D)+0x18\nfunction @ token(0x600043E)\n  or:\n    characteristic: unmanaged call @ token(0x600043E)+0x24, token(0x600043E)+0x62\nfunction @ token(0x600043F)\n  or:\n    characteristic: unmanaged call @ token(0x600043F)+0x26\nfunction @ token(0x6000440)\n  or:\n    characteristic: unmanaged call @ token(0x6000440)+0x14\nfunction @ token(0x6000442)\n  or:\n    characteristic: unmanaged call @ token(0x6000442)+0x38, token(0x6000442)+0x40, token(0x6000442)+0x49\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  format: dotnet\n\n\n\n"},"hashes":{"md5":"ec629f648434fc3d17e9561532d038c8","sha1":"1a1b5976acb4cd25c1e225473a64a67438222768","sha256":"1c0ea462f0bbd7acfdf4c6daf3cb8ce09e1375b766fbd3ff89f40c0aa3f4fc96"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 1219</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 32612</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Win32.G\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"ec629f648434fc3d17e9561532d038c8\",\n        \"sha256\": \"1c0ea462f0bbd7acfdf4c6daf3cb8ce09e1375b766fbd3ff89f40c0\",\n        \"arch\": \"i386\",\n        \"os\": \"any\",\n        \"format\": \"dotnet\"\n      }\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_Microsoft\",\n      \"label\": \"Microsoft\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings\",\n      \"label\": \"reference anti-VM strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_parallels\",\n      \"label\": \"reference anti-VM strings targeting Parallels\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_vmware\",\n      \"label\": \"reference anti-VM strings targeting VMWare\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com___johnk3r\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, @johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_virtualbox\",\n      \"label\": \"reference anti-VM strings targeting VirtualBox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_virtualpc\",\n      \"label\": \"reference anti-VM strings targeting VirtualPC\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_wmi_statements__2_matches_\",\n      \"label\": \"reference WMI statements (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_mac_address_in__net\",\n      \"label\": \"get MAC address in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_System\",\n      \"label\": \"System\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_echernofsky_google_com\",\n      \"label\": \"echernofsky@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_data\",\n      \"label\": \"receive data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data__3_matches_\",\n      \"label\": \"send data (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_data_from_internet\",\n      \"label\": \"read data from Internet\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data_to_internet__3_matches_\",\n      \"label\": \"send data to Internet (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_decode_data_using_base64_in__net\",\n      \"label\": \"decode data using Base64 in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decode Data::Base64 [C0053.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encode_data_using_base64\",\n      \"label\": \"encode data using Base64\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_aes_via__net\",\n      \"label\": \"encrypt data using AES via .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encryption-Standard\",\n        \"Algorithm [E1027.m05]\",\n        \"Cryptography::Encrypt Data::AES [C0027.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encryption-Standard\",\n        \"Algorithm [E1027.m05]\",\n        \"Cryptography::Encrypt Data::AES [C0027.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_with_md5\",\n      \"label\": \"hash data with MD5\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash::MD5 [C0029.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_bytes_in__net\",\n      \"label\": \"generate random bytes in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_in__net__3_matches_\",\n      \"label\": \"generate random numbers in .NET (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_data_using_regex_in__net__7_matches_\",\n      \"label\": \"find data using regex in .NET (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_contains_pdb_path\",\n      \"label\": \"contains PDB path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_access__net_resource__3_matches_\",\n      \"label\": \"access .NET resource (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz\",\n      \"label\": \"author     @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions__4_matches_\",\n      \"label\": \"extract resource via kernel32 functions (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResourceEx\",\n      \"label\": \"FindResourceEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_enumerate_drives\",\n      \"label\": \"enumerate drives\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_generate_random_filename_in__net__2_matches_\",\n      \"label\": \"generate random filename in .NET (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__2_matches_\",\n      \"label\": \"get common file path (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_copy_file__2_matches_\",\n      \"label\": \"copy file (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory__7_matches_\",\n      \"label\": \"create directory (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_file__3_matches_\",\n      \"label\": \"delete file (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_directory_exists\",\n      \"label\": \"check if directory exists\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__17_matches_\",\n      \"label\": \"check if file exists (17 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_in__net__2_matches_\",\n      \"label\": \"enumerate files in .NET (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes__3_matches_\",\n      \"label\": \"get file attributes (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size__6_matches_\",\n      \"label\": \"get file size (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_file_attributes__2_matches_\",\n      \"label\": \"set file attributes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"cap_move_file\",\n      \"label\": \"move file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__5_matches_\",\n      \"label\": \"read file on Windows (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__3_matches_\",\n      \"label\": \"write file on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_gui_resources\",\n      \"label\": \"enumerate gui resources\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"api_EnumResourceTypes\",\n      \"label\": \"EnumResourceTypes\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     johnk3r, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_disk_information\",\n      \"label\": \"get disk information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_allocate_unmanaged_memory_in__net__2_matches_\",\n      \"label\": \"allocate unmanaged memory in .NET (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_manipulate_unmanaged_memory_in__net__22_matches_\",\n      \"label\": \"manipulate unmanaged memory in .NET (22 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_or_open_mutex_on_windows\",\n      \"label\": \"create or open mutex on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_mehunhoff_google_com\",\n      \"label\": \"mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_hostname__3_matches_\",\n      \"label\": \"get hostname (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_a_process_with_modified_i_o_handles_and_window\",\n      \"label\": \"create a process with modified I/O handles and window\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__2_matches_\",\n      \"label\": \"create process on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_processes\",\n      \"label\": \"enumerate processes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\",\n        \"Discovery::Software Discovery\",\n        \"[T1518]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"label\": \"query or enumerate registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"label\": \"query or enumerate registry value (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_session_user_name__4_matches_\",\n      \"label\": \"get session user name (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\",\n        \"Discovery::Account\",\n        \"Discovery [T1087]\"\n      ]\n    },\n    {\n      \"id\": \"cap_suspend_thread__4_matches_\",\n      \"label\": \"suspend thread (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Suspend Thread [C0055]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Suspend Thread [C0055]\"\n      ]\n    },\n    {\n      \"id\": \"cap_execute_via_asynchronous_task_in__net\",\n      \"label\": \"execute via asynchronous task in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_access_wmi_data_in__net__8_matches_\",\n      \"label\": \"access WMI data in .NET (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Windows Management Instrumentation [T1047]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal___net_file_limitation\",\n      \"label\": \"(internal) .NET file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author________v1bh475u\",\n      \"label\": \"author       @v1bh475u\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_load__net_assembly\",\n      \"label\": \"load .NET assembly\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_unmanaged_call__13_matches_\",\n      \"label\": \"unmanaged call (13 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"label\": \"author       michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compiled_to_the__net_platform\",\n      \"label\": \"compiled to the .NET platform\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_parallels\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_vmware\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com___johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_virtualbox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_virtualpc\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_wmi_statements__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_mac_address_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_echernofsky_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_data_from_internet\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data_to_internet__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decode_data_using_base64_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encode_data_using_base64\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_aes_via__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_md5\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_bytes_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_in__net__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_data_using_regex_in__net__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contains_pdb_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access__net_resource__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_drives\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_filename_in__net__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_directory_exists\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__17_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_in__net__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_move_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_gui_resources\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_unmanaged_memory_in__net__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_manipulate_unmanaged_memory_in__net__22_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_mutex_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_a_process_with_modified_i_o_handles_and_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_processes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_user_name__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_suspend_thread__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_execute_via_asynchronous_task_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_wmi_data_in__net__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal___net_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________v1bh475u\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_load__net_assembly\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_unmanaged_call__13_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_to_the__net_platform\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-10 01:00:39.228416\",\n    \"total_functions\": \"1219\",\n    \"total_features\": \"32612\",\n    \"pdb_path\": \"C:\\\\\\\\Users\\\\\\\\The \\nInvincible\\\\\\\\Desktop\\\\\\\\gx\\\\\\\\gx-current-program\\\\\\\\LSASS\\\\\\\\obj\\\\\\\\Release\\\\\\\\LSASS.pdb\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-10 01:00:40"}
{"_id":{"$oid":"6a4ff7b50108394cb24cdd13"},"sha256":"653bc2b16b1624e045c1225810185e9aa3694dc378fe0095e2052b7f1e265d01","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_n9vtsb9e/Win32.WannaPeace-019f46ce0d7779f2805a33c6e5a59710.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_n9vtsb9e/Win32.WannaPeace-019f46ce0d7779f2805a33c6e5a59710.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_n9vtsb9e/Win32.WannaPeace-019f46ce0d7779f2805a33c6e5a59710.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ eefa6f98681d78b63f15d7e58934c6cc                                  │\n│ sha1     │ 586b5a65430263f62d656c96624967122568e274                          │\n│ sha256   │ 653bc2b16b1624e045c1225810185e9aa3694dc378fe0095e2052b7f1e265d01  │\n│ analysis │ static                                                            │\n│ os       │ any                                                               │\n│ format   │ dotnet                                                            │\n│ arch     │ any                                                               │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/Win32.WannaPeace… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Data from Information Repositories [T1213]            │\n│ DEFENSE EVASION      │ Deobfuscate/Decode Files or Information [T1140]       │\n│                      │ Obfuscated Files or Information [T1027]               │\n│                      │ Obfuscated Files or Information::Compile After        │\n│                      │ Delivery [T1027.004]                                  │\n│ DISCOVERY            │ File and Directory Discovery [T1083]                  │\n│ EXECUTION            │ Windows Management Instrumentation [T1047]            │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ CRYPTOGRAPHY         │ Encrypt Data::AES [C0027.001]                         │\n│                      │ Generate Pseudo-random Sequence::Use API [C0021.003]  │\n│ DATA                 │ Decode Data::Base64 [C0053.001]                       │\n│                      │ Encode Data::Base64 [C0026.001]                       │\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Encoding-Standard    │\n│                      │ Algorithm [E1027.m02]                                 │\n│                      │ Obfuscated Files or Information::Encryption-Standard  │\n│                      │ Algorithm [E1027.m05]                                 │\n│ DISCOVERY            │ File and Directory Discovery [E1083]                  │\n│ FILE SYSTEM          │ Copy File [C0045]                                     │\n│                      │ Create Directory [C0046]                              │\n│                      │ Delete Directory [C0048]                              │\n│                      │ Delete File [C0047]                                   │\n│                      │ Get File Attributes [C0049]                           │\n│ IMPACT               │ Clipboard Modification [E1510]                        │\n│ OPERATING SYSTEM     │ Console [C0033]                                       │\n│ PROCESS              │ Create Process [C0017]                                │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ reference WMI statements (13 matches) │ collection/database/wmi              │\n│ decode data using Base64 in .NET      │ data-manipulation/encoding/base64    │\n│ encode data using Base64 (2 matches)  │ data-manipulation/encoding/base64    │\n│ encrypt data using AES via .NET       │ data-manipulation/encryption/aes     │\n│ generate random numbers in .NET (2    │ data-manipulation/prng               │\n│ matches)                              │                                      │\n│ contains PDB path                     │ executable/pe/pdb                    │\n│ access .NET resource (2 matches)      │ executable/resource                  │\n│ write clipboard data                  │ host-interaction/clipboard           │\n│ manipulate console buffer (6 matches) │ host-interaction/console             │\n│ check file extension in .NET (2       │ host-interaction/file-system         │\n│ matches)                              │                                      │\n│ get common file path (7 matches)      │ host-interaction/file-system         │\n│ copy file (2 matches)                 │ host-interaction/file-system/copy    │\n│ create directory                      │ host-interaction/file-system/create  │\n│ delete directory                      │ host-interaction/file-system/delete  │\n│ delete file (7 matches)               │ host-interaction/file-system/delete  │\n│ check if directory exists (4 matches) │ host-interaction/file-system/exists  │\n│ check if file exists (9 matches)      │ host-interaction/file-system/exists  │\n│ enumerate files in .NET (2 matches)   │ host-interaction/file-system/files/… │\n│ get file attributes                   │ host-interaction/file-system/meta    │\n│ create a process with modified I/O    │ host-interaction/process/create      │\n│ handles and window                    │                                      │\n│ create process on Windows (3 matches) │ host-interaction/process/create      │\n│ access WMI data in .NET (13 matches)  │ host-interaction/wmi                 │\n│ compile .NET assembly (2 matches)     │ load-code/dotnet                     │\n│ unmanaged call                        │ runtime                              │\n│ compiled to the .NET platform         │ runtime/dotnet                       │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     eefa6f98681d78b63f15d7e58934c6cc                        \nsha1                    586b5a65430263f62d656c96624967122568e274                \nsha256                  653bc2b16b1624e045c1225810185e9aa3694dc378fe0095e2052b7…\npath                    /home/apogean/projects/malware/windows/all_runs/Win32.W…\ntimestamp               2026-07-10 01:04:10.820839                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    any                                                     \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIzQZoGF/rules                                   \nfunction count          77                                                      \nlibrary function count  0                                                       \ntotal feature count     9462                                                    \n\nreference WMI statements (13 matches)\nnamespace  collection/database/wmi\nscope      function               \nmatches    token(0x600001D)       \n           token(0x600001E)       \n           token(0x600001F)       \n           token(0x6000020)       \n           token(0x6000021)       \n           token(0x6000022)       \n           token(0x6000023)       \n           token(0x6000024)       \n           token(0x6000026)       \n           token(0x6000027)       \n           token(0x6000028)       \n           token(0x6000029)       \n           token(0x600002A)       \n\ndecode data using Base64 in .NET\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    token(0x600000E)                 \n\nencode data using Base64 (2 matches)\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    token(0x600000F)                 \n           token(0x6000010)                 \n\nencrypt data using AES via .NET\nnamespace  data-manipulation/encryption/aes\nscope      file                            \n\ngenerate random numbers in .NET (2 matches)\nnamespace  data-manipulation/prng\nscope      function              \nmatches    token(0x600000B)      \n           token(0x600000C)      \n\ncontains PDB path\nnamespace  executable/pe/pdb\nscope      file             \n\naccess .NET resource (2 matches)\nnamespace  executable/resource\nscope      function           \nmatches    token(0x6000002)   \n           token(0x600004C)   \n\nwrite clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    token(0x6000035)          \n\nmanipulate console buffer (6 matches)\nnamespace  host-interaction/console\nscope      function                \nmatches    token(0x600000F)        \n           token(0x6000010)        \n           token(0x6000011)        \n           token(0x6000014)        \n           token(0x600004A)        \n           token(0x600004B)        \n\ncheck file extension in .NET (2 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x6000014)            \n           token(0x6000015)            \n\nget common file path (7 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x6000030)            \n           token(0x6000031)            \n           token(0x600003A)            \n           token(0x600003B)            \n           token(0x600003D)            \n           token(0x600003E)            \n           token(0x600003F)            \n\ncopy file (2 matches)\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    token(0x6000014)                 \n           token(0x6000015)                 \n\ncreate directory\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    token(0x600004D)                   \n\ndelete directory\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    token(0x6000032)                   \n\ndelete file (7 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    token(0x600000F)                   \n           token(0x6000010)                   \n           token(0x6000014)                   \n           token(0x6000015)                   \n           token(0x6000030)                   \n           token(0x6000031)                   \n           token(0x600004A)                   \n\ncheck if directory exists (4 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x600000F)                   \n           token(0x6000010)                   \n           token(0x6000032)                   \n           token(0x600004D)                   \n\ncheck if file exists (9 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x600000F)                   \n           token(0x6000010)                   \n           token(0x6000030)                   \n           token(0x6000031)                   \n           token(0x600003A)                   \n           token(0x600003B)                   \n           token(0x600003D)                   \n           token(0x600003E)                   \n           token(0x600003F)                   \n\nenumerate files in .NET (2 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    token(0x6000011)                       \n           token(0x600004B)                       \n\nget file attributes\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    token(0x600003B)                 \n\ncreate a process with modified I/O handles and window\nnamespace  host-interaction/process/create\nscope      function                       \nmatches    token(0x600003D)               \n\ncreate process on Windows (3 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    token(0x6000033)               \n           token(0x6000037)               \n           token(0x600003D)               \n\naccess WMI data in .NET (13 matches)\nnamespace  host-interaction/wmi\nscope      function            \nmatches    token(0x600001D)    \n           token(0x600001E)    \n           token(0x600001F)    \n           token(0x6000020)    \n           token(0x6000021)    \n           token(0x6000022)    \n           token(0x6000023)    \n           token(0x6000024)    \n           token(0x6000026)    \n           token(0x6000027)    \n           token(0x6000028)    \n           token(0x6000029)    \n           token(0x600002A)    \n\ncompile .NET assembly (2 matches)\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x600003A)\n           token(0x600004A)\n\nunmanaged call\nnamespace    runtime                                                       \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nscope        function                                                      \nmatches      token(0x600001C)                                              \n\ncompiled to the .NET platform\nnamespace  runtime/dotnet\nscope      file          \n\n\n\n","very_verbose":"md5                     eefa6f98681d78b63f15d7e58934c6cc                        \nsha1                    586b5a65430263f62d656c96624967122568e274                \nsha256                  653bc2b16b1624e045c1225810185e9aa3694dc378fe0095e2052b7…\npath                    /home/apogean/projects/malware/windows/all_runs/Win32.W…\ntimestamp               2026-07-10 01:04:13.526385                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    any                                                     \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEILOT4nt/rules                                   \nfunction count          77                                                      \nlibrary function count  0                                                       \ntotal feature count     9462                                                    \n\ncontain loop (2 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ token(0x6000011)\n  or:\n    characteristic: recursive call @ token(0x6000011)\n\nreference WMI statements (13 matches)\nnamespace  collection/database/wmi                               \nauthor     michael.hunhoff@mandiant.com                          \nscope      function                                              \natt&ck     Collection::Data from Information Repositories [T1213]\nfunction @ token(0x600001D)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_LogicalDisk\" @ token(0x600001D)+0x6\nfunction @ token(0x600001E)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_BaseBoard\" @ token(0x600001E)+0x6\nfunction @ token(0x600001F)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_BaseBoard\" @ token(0x600001F)+0x6\nfunction @ token(0x6000020)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_BaseBoard\" @ token(0x6000020)+0x6\nfunction @ token(0x6000021)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_CacheMemory\" @ token(0x6000021)+0x6\nfunction @ token(0x6000022)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_CacheMemory\" @ token(0x6000022)+0x6\nfunction @ token(0x6000023)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_CacheMemory\" @ token(0x6000023)+0x6\nfunction @ token(0x6000024)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_CDROMDrive\" @ token(0x6000024)+0x6\nfunction @ token(0x6000026)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_UserAccount\" @ token(0x6000026)+0x6\nfunction @ token(0x6000027)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_BIOS\" @ token(0x6000027)+0x6\nfunction @ token(0x6000028)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_BIOS\" @ token(0x6000028)+0x6\nfunction @ token(0x6000029)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_BIOS\" @ token(0x6000029)+0x6\nfunction @ token(0x600002A)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_BootConfiguration\" @ token(0x600002A)+0x6\n\ndecode data using Base64 in .NET\nnamespace  data-manipulation/encoding/base64                               \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \natt&ck     Defense Evasion::Deobfuscate/Decode Files or Information [T1140]\nmbc        Data::Decode Data::Base64 [C0053.001]                           \nfunction @ token(0x600000E)\n  or:\n    api: System.Convert::FromBase64String @ token(0x600000E)+0xE\n\nencode data using Base64 (2 matches)\nnamespace  data-manipulation/encoding/base64                                    \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::Base64 [C0026.001]         \nfunction @ token(0x600000F)\n  or:\n    api: System.Convert::ToBase64String @ token(0x600000F)+0xEF, token(0x600000F)+0x103\nfunction @ token(0x6000010)\n  or:\n    api: System.Convert::ToBase64String @ token(0x6000010)+0xA2, token(0x6000010)+0xB6\n\nencrypt data using AES via .NET\nnamespace  data-manipulation/encryption/aes                                     \nauthor     william.ballenthin@mandiant.com                                      \nscope      file                                                                 \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encryption-Standard\n           Algorithm [E1027.m05], Cryptography::Encrypt Data::AES [C0027.001]   \nand:\n  class: System.Security.Cryptography.RijndaelManaged @ token(0x1000026)\n  class: System.Security.Cryptography.CryptoStream @ token(0x1000024)\n\ngenerate random numbers in .NET (2 matches)\nnamespace  data-manipulation/prng                                            \nauthor     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com     \nscope      function                                                          \nmbc        Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\nfunction @ token(0x600000B)\n  or:\n    api: System.Random::NextDouble @ token(0x600000B)+0x1C\nfunction @ token(0x600000C)\n  or:\n    api: System.Random::Next @ token(0x600000C)+0xE, token(0x600000C)+0x30, token(0x600000C)+0x57, \ntoken(0x600000C)+0x7A\n\ncontains PDB path\nnamespace  executable/pe/pdb        \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nregex: /:\\\\.*\\.pdb/\n  - \"E:\\\\Users\\\\SCORPION\\\\Downloads\\\\privatelocker_version2\\\\PrivateLocker\\\\obj\\\\Deb\nug\\\\RzW.pdb\" @ file+0x9F4A8\n\naccess .NET resource (2 matches)\nnamespace  executable/resource\nauthor     @mr-tz             \nscope      function           \nfunction @ token(0x6000002)\n  and:\n    format: dotnet\n    or:\n      api: System.Resources.ResourceManager::ctor @ token(0x6000002)+0x22\nfunction @ token(0x600004C)\n  and:\n    format: dotnet\n    or:\n      api: System.Reflection.Assembly::GetManifestResourceStream @ token(0x600004C)+0x69\n\nwrite clipboard data\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \nmbc         Impact::Clipboard Modification [E1510]                              \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ token(0x6000035)\n  and:\n    or:\n      api: System.Windows.Forms.Clipboard::SetText @ token(0x6000035)+0xC\n\nmanipulate console buffer (6 matches)\nnamespace   host-interaction/console                                     \nauthor      william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope       function                                                     \nmbc         Operating System::Console [C0033]                            \nreferences  https://stackoverflow.com/a/15770935/87207                   \nfunction @ token(0x600000F)\n  or:\n    api: System.Console::WriteLine @ token(0x600000F)+0x13E\nfunction @ token(0x6000010)\n  or:\n    api: System.Console::WriteLine @ token(0x6000010)+0x13E\nfunction @ token(0x6000011)\n  or:\n    api: System.Console::WriteLine @ token(0x6000011)+0x3B\nfunction @ token(0x6000014)\n  or:\n    api: System.Console::WriteLine @ token(0x6000014)+0xA7\nfunction @ token(0x600004A)\n  or:\n    api: System.Console::WriteLine @ token(0x600004A)+0x6E, token(0x600004A)+0x1D5, token(0x600004A)+0x207, \ntoken(0x600004A)+0x20D, and 2 more...\nfunction @ token(0x600004B)\n  or:\n    api: System.Console::WriteLine @ token(0x600004B)+0x3B\n\ncheck file extension in .NET (2 matches)\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x6000014)\n  or:\n    api: System.IO.Path::GetExtension @ token(0x6000014)+0x3\nfunction @ token(0x6000015)\n  or:\n    api: System.IO.Path::GetExtension @ token(0x6000015)+0x2\n\nget common file path (7 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ token(0x6000030)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x6000030)+0x9B\nfunction @ token(0x6000031)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x6000031)+0x6E\nfunction @ token(0x600003A)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x600003A)+0x3\nfunction @ token(0x600003B)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x600003B)+0x68\nfunction @ token(0x600003D)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x600003D)+0x3\nfunction @ token(0x600003E)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x600003E)+0x59\nfunction @ token(0x600003F)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x600003F)+0x3\n\ncopy file (2 matches)\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ token(0x6000014)\n  or:\n    api: System.IO.File::Copy @ token(0x6000014)+0x8D\nfunction @ token(0x6000015)\n  or:\n    api: System.IO.File::Copy @ token(0x6000015)+0x89\n\ncreate directory\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ token(0x600004D)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x600004D)+0x2A\n\ndelete directory\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ token(0x6000032)\n  or:\n    api: System.IO.Directory::Delete @ token(0x6000032)+0x3B\n\ndelete file (7 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ token(0x600000F)\n  or:\n    api: System.IO.File::Delete @ token(0x600000F)+0xB6\nfunction @ token(0x6000010)\n  or:\n    api: System.IO.File::Delete @ token(0x6000010)+0x10A\nfunction @ token(0x6000014)\n  or:\n    api: System.IO.File::Delete @ token(0x6000014)+0x85, token(0x6000014)+0x94\nfunction @ token(0x6000015)\n  or:\n    api: System.IO.File::Delete @ token(0x6000015)+0x81, token(0x6000015)+0x90\nfunction @ token(0x6000030)\n  or:\n    api: System.IO.File::Delete @ token(0x6000030)+0xC9\nfunction @ token(0x6000031)\n  or:\n    api: System.IO.File::Delete @ token(0x6000031)+0x9C\nfunction @ token(0x600004A)\n  or:\n    api: System.IO.File::Delete @ token(0x600004A)+0x29C\n\ncheck if directory exists (4 matches)\nnamespace  host-interaction/file-system/exists            \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nfunction @ token(0x600000F)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600000F)+0x13\nfunction @ token(0x6000010)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000010)+0x13\nfunction @ token(0x6000032)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000032)+0x25\nfunction @ token(0x600004D)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600004D)+0x17\n\ncheck if file exists (9 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ token(0x600000F)\n  or:\n    api: System.IO.File::Exists @ token(0x600000F)+0xA3\nfunction @ token(0x6000010)\n  or:\n    api: System.IO.File::Exists @ token(0x6000010)+0xF7\nfunction @ token(0x6000030)\n  or:\n    api: System.IO.File::Exists @ token(0x6000030)+0xB5\nfunction @ token(0x6000031)\n  or:\n    api: System.IO.File::Exists @ token(0x6000031)+0x88\nfunction @ token(0x600003A)\n  or:\n    api: System.IO.File::Exists @ token(0x600003A)+0x1D, token(0x600003A)+0xE2\nfunction @ token(0x600003B)\n  or:\n    api: System.IO.File::Exists @ token(0x600003B)+0x82, token(0x600003B)+0xE7\nfunction @ token(0x600003D)\n  or:\n    api: System.IO.File::Exists @ token(0x600003D)+0x1D\nfunction @ token(0x600003E)\n  or:\n    api: System.IO.File::Exists @ token(0x600003E)+0x73, token(0x600003E)+0xC5\nfunction @ token(0x600003F)\n  or:\n    api: System.IO.File::Exists @ token(0x600003F)+0x1D, token(0x600003F)+0x6D\n\nenumerate files in .NET (2 matches)\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ token(0x6000011)\n  or:\n    api: System.IO.DirectoryInfo::GetFiles @ token(0x6000011)+0x5\n    api: System.IO.DirectoryInfo::GetDirectories @ token(0x6000011)+0x45\nfunction @ token(0x600004B)\n  or:\n    api: System.IO.DirectoryInfo::GetFiles @ token(0x600004B)+0x5\n    api: System.IO.DirectoryInfo::GetDirectories @ token(0x600004B)+0x46\n\nget file attributes\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ token(0x600003B) in function token(0x600003B)\n  or:\n    api: System.IO.File::GetLastWriteTime @ token(0x600003B)+0x8D, token(0x600003B)+0xB5\n\ncreate a process with modified I/O handles and window\nnamespace   host-interaction/process/create                                     \nauthor      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com      \nscope       function                                                            \nmbc         Process::Create Process [C0017]                                     \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/processthreadsap…\nfunction @ token(0x600003D)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600003D)+0x51\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600003D)+0x4A\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600003D)+0x42\n\ncreate process on Windows (3 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ token(0x6000033) in function token(0x6000033)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000033)+0x8\nbasic block @ token(0x6000037) in function token(0x6000037)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000037)+0x8\nbasic block @ token(0x600003D) in function token(0x600003D)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600003D)+0x51\n\naccess WMI data in .NET (13 matches)\nnamespace  host-interaction/wmi                                 \nauthor     michael.hunhoff@mandiant.com                         \nscope      function                                             \natt&ck     Execution::Windows Management Instrumentation [T1047]\nfunction @ token(0x600001D)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x600001D)+0x19\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x600001D)+0xB\nfunction @ token(0x600001E)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x600001E)+0x13\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x600001E)+0xB\nfunction @ token(0x600001F)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x600001F)+0x13\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x600001F)+0xB\nfunction @ token(0x6000020)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000020)+0x13\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000020)+0xB\nfunction @ token(0x6000021)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000021)+0x13\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000021)+0xB\nfunction @ token(0x6000022)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000022)+0x13\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000022)+0xB\nfunction @ token(0x6000023)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000023)+0x13\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000023)+0xB\nfunction @ token(0x6000024)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000024)+0x13\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000024)+0xB\nfunction @ token(0x6000026)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000026)+0x13\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000026)+0xB\nfunction @ token(0x6000027)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000027)+0x13\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000027)+0xB\nfunction @ token(0x6000028)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000028)+0x13\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000028)+0xB\nfunction @ token(0x6000029)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000029)+0x13\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000029)+0xB\nfunction @ token(0x600002A)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x600002A)+0x13\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x600002A)+0xB\n\n(internal) .NET file limitation\nnamespace    internal/limitation/dynamic                        \nauthor       @v1bh475u                                          \nscope        file                                               \ndescription  This dynamic analysis trace describes a .NET file. \n                                                                \n             capa rules are not yet tuned for the .NET runtime, \n             so its analysis may be incomplete or misleading.   \n                                                                \nor:\n  format: dotnet\n\ncompile .NET assembly (2 matches)\nnamespace  load-code/dotnet                                                     \nauthor     anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information::Compile After      \n           Delivery [T1027.004]                                                 \nfunction @ token(0x600003A)\n  or:\n    api: System.CodeDom.Compiler.CodeDomProvider::CompileAssemblyFromSource @ token(0x600003A)+0xD0\nfunction @ token(0x600004A)\n  or:\n    api: System.CodeDom.Compiler.CodeDomProvider::CompileAssemblyFromFile @ token(0x600004A)+0x1AB\n\nunmanaged call\nnamespace    runtime                                                       \nauthor       michael.hunhoff@mandiant.com                                  \nscope        function                                                      \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nfunction @ token(0x600001C)\n  or:\n    characteristic: unmanaged call @ token(0x600001C)+0x5\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  format: dotnet\n\n\n\n"},"hashes":{"md5":"eefa6f98681d78b63f15d7e58934c6cc","sha1":"586b5a65430263f62d656c96624967122568e274","sha256":"653bc2b16b1624e045c1225810185e9aa3694dc378fe0095e2052b7f1e265d01"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 77</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 9462</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Win32.W\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"eefa6f98681d78b63f15d7e58934c6cc\",\n        \"sha256\": \"653bc2b16b1624e045c1225810185e9aa3694dc378fe0095e2052b7\",\n        \"arch\": \"any\",\n        \"os\": \"any\",\n        \"format\": \"dotnet\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_reference_wmi_statements__13_matches_\",\n      \"label\": \"reference WMI statements (13 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_decode_data_using_base64_in__net\",\n      \"label\": \"decode data using Base64 in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decode Data::Base64 [C0053.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_System\",\n      \"label\": \"System\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_encode_data_using_base64__2_matches_\",\n      \"label\": \"encode data using Base64 (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_aes_via__net\",\n      \"label\": \"encrypt data using AES via .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encryption-Standard\",\n        \"Algorithm [E1027.m05]\",\n        \"Cryptography::Encrypt Data::AES [C0027.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encryption-Standard\",\n        \"Algorithm [E1027.m05]\",\n        \"Cryptography::Encrypt Data::AES [C0027.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_in__net__2_matches_\",\n      \"label\": \"generate random numbers in .NET (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contains_pdb_path\",\n      \"label\": \"contains PDB path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_access__net_resource__2_matches_\",\n      \"label\": \"access .NET resource (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz\",\n      \"label\": \"author     @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_write_clipboard_data\",\n      \"label\": \"write clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"cap_manipulate_console_buffer__6_matches_\",\n      \"label\": \"manipulate console buffer (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Console [C0033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Console [C0033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_file_extension_in__net__2_matches_\",\n      \"label\": \"check file extension in .NET (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__7_matches_\",\n      \"label\": \"get common file path (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_copy_file__2_matches_\",\n      \"label\": \"copy file (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory\",\n      \"label\": \"create directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_directory\",\n      \"label\": \"delete directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_file__7_matches_\",\n      \"label\": \"delete file (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_directory_exists__4_matches_\",\n      \"label\": \"check if directory exists (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__9_matches_\",\n      \"label\": \"check if file exists (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_in__net__2_matches_\",\n      \"label\": \"enumerate files in .NET (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes\",\n      \"label\": \"get file attributes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_a_process_with_modified_i_o_handles_and_window\",\n      \"label\": \"create a process with modified I/O handles and window\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__3_matches_\",\n      \"label\": \"create process on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_access_wmi_data_in__net__13_matches_\",\n      \"label\": \"access WMI data in .NET (13 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Windows Management Instrumentation [T1047]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal___net_file_limitation\",\n      \"label\": \"(internal) .NET file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author________v1bh475u\",\n      \"label\": \"author       @v1bh475u\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compile__net_assembly__2_matches_\",\n      \"label\": \"compile .NET assembly (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Compile After\",\n        \"Delivery [T1027.004]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Compile After\",\n        \"Delivery [T1027.004]\"\n      ]\n    },\n    {\n      \"id\": \"cap_unmanaged_call\",\n      \"label\": \"unmanaged call\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"label\": \"author       michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compiled_to_the__net_platform\",\n      \"label\": \"compiled to the .NET platform\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_wmi_statements__13_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decode_data_using_base64_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encode_data_using_base64__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_aes_via__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_in__net__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contains_pdb_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access__net_resource__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_manipulate_console_buffer__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_file_extension_in__net__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_directory_exists__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_in__net__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_a_process_with_modified_i_o_handles_and_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_wmi_data_in__net__13_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal___net_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________v1bh475u\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compile__net_assembly__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_unmanaged_call\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_to_the__net_platform\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-10 01:04:13.526385\",\n    \"total_functions\": \"77\",\n    \"total_features\": \"9462\",\n    \"pdb_path\": \"E:\\\\\\\\Users\\\\\\\\SCORPION\\\\\\\\Downloads\\\\\\\\privatelocker_version2\\\\\\\\PrivateLocker\\\\\\\\obj\\\\\\\\Deb\\nug\\\\\\\\RzW.pdb\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-10 01:04:13"}
{"_id":{"$oid":"6a4ff8fd0108394cb24cdd16"},"sha256":"c7dc529d8aae76b4e797e4e9e3ea7cd69669e6c3bb3f94d80f1974d1b9f69378","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_qbjpw4yn/CryptoLocker_20Nov2013-019f46ce41d271419d80e3344372fac8.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_qbjpw4yn/CryptoLocker_20Nov2013-019f46ce41d271419d80e3344372fac8.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_qbjpw4yn/CryptoLocker_20Nov2013-019f46ce41d271419d80e3344372fac8.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 7f9c454a2e016e533e181d53eba113bc                                  │\n│ sha1     │ 694dc7713537a7237030f7623881423fcb8d8c5c                          │\n│ sha256   │ c7dc529d8aae76b4e797e4e9e3ea7cd69669e6c3bb3f94d80f1974d1b9f69378  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/CryptoLocker_20N… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic               ┃ ATT&CK Technique                               ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DISCOVERY                   │ System Information Discovery [T1082]           │\n│ EXECUTION                   │ Shared Modules [T1129]                         │\n└─────────────────────────────┴────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective              ┃ MBC Behavior                                    ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DISCOVERY                  │ System Information Discovery [E1082]            │\n│ FILE SYSTEM                │ Writes File [C0052]                             │\n│ PROCESS                    │ Allocate Thread Local Storage [C0040]           │\n│                            │ Set Thread Local Storage Value [C0041]          │\n│                            │ Terminate Process [C0018]                       │\n└────────────────────────────┴─────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                              ┃ Namespace                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ write file on Windows (2 matches)       │ host-interaction/file-system/write │\n│ check OS version                        │ host-interaction/os/version        │\n│ get thread local storage value          │ host-interaction/process           │\n│ terminate process                       │ host-interaction/process/terminate │\n│ allocate thread local storage           │ host-interaction/thread/tls        │\n│ set thread local storage value          │ host-interaction/thread/tls        │\n│ link function at runtime on Windows (7  │ linking/runtime-linking            │\n│ matches)                                │                                    │\n│ link many functions at runtime          │ linking/runtime-linking            │\n└─────────────────────────────────────────┴────────────────────────────────────┘\n\n","verbose":"md5                     7f9c454a2e016e533e181d53eba113bc                        \nsha1                    694dc7713537a7237030f7623881423fcb8d8c5c                \nsha256                  c7dc529d8aae76b4e797e4e9e3ea7cd69669e6c3bb3f94d80f1974d…\npath                    /home/apogean/projects/malware/windows/all_runs/CryptoL…\ntimestamp               2026-07-10 01:09:27.158554                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIJ7VJDQ/rules                                   \nfunction count          255                                                     \nlibrary function count  531                                                     \ntotal feature count     16225                                                   \n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x441374                          \n           0x448357                          \n\ncheck OS version\nnamespace  host-interaction/os/version\nscope      function                   \nmatches    0x44C5D1                   \n\nget thread local storage value\nnamespace  host-interaction/process\nscope      function                \nmatches    0x442772                \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x43CD62                          \n\nallocate thread local storage\nnamespace  host-interaction/thread/tls\nscope      function                   \nmatches    0x442769                   \n\nset thread local storage value\nnamespace  host-interaction/thread/tls\nscope      function                   \nmatches    0x442772                   \n\nlink function at runtime on Windows (7 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x4391DE               \n           0x43927C               \n           0x4473D3               \n           0x4473F0               \n           0x447405               \n           0x44743A               \n           0x447452               \n\nlink many functions at runtime\nnamespace  linking/runtime-linking\nscope      function               \nmatches    0x44738A               \n\n\n\n","very_verbose":"md5                     7f9c454a2e016e533e181d53eba113bc                        \nsha1                    694dc7713537a7237030f7623881423fcb8d8c5c                \nsha256                  c7dc529d8aae76b4e797e4e9e3ea7cd69669e6c3bb3f94d80f1974d…\npath                    /home/apogean/projects/malware/windows/all_runs/CryptoL…\ntimestamp               2026-07-10 01:09:41.081943                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIk01VOj/rules                                   \nfunction count          255                                                     \nlibrary function count  531                                                     \ntotal feature count     16225                                                   \n\ncalculate modulo 256 via x86 assembly (library rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x44B773\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x44B773\n    or:\n      number: 0xFF @ 0x44B773\n\ncontain loop (20 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x4013A4\n  or:\n    characteristic: loop @ 0x4013A4\n\ncreate or open file (library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x44BDA4\n  or:\n    api: CreateFile @ 0x44BDA4\n\nget OS version (library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x44C5D1\n  or:\n    api: GetVersionEx @ 0x44C60C\n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x441374\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x441508\nfunction @ 0x448357\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x448521\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x448741\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x448785, 0x448790\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x448606\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x448626\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x448618\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x44842C\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x448776\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x448794\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x448806\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4483E3\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4484F2\n      or:\n        api: WriteFile @ 0x448598, 0x4485E2, 0x448712, 0x4487BD, and 2 more...\n\ncheck OS version\nnamespace  host-interaction/os/version                    \nauthor     michael.hunhoff@mandiant.com, johnk3r          \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x44C5D1\n  and:\n    match: get OS version @ 0x44C5D1\n      or:\n        api: GetVersionEx @ 0x44C60C\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x44C618\n            number: 0x5 = Windows 2000 @ 0x44C618\n        optional:\n          instruction:\n            and:\n              mnemonic: cmp @ 0x44C620\n              or:\n                number: 0x1 = Windows XP @ 0x44C620\n            and:\n              mnemonic: cmp @ 0x44C612\n              or:\n                number: 0x2 = Windows XP 64-bit / Windows Server 2003 / Windows Server 2003 R2 @ 0x44C612\n            and:\n              mnemonic: cmp @ 0x44C62E\n              or:\n                number: 0x0 @ 0x44C62E\n\nget thread local storage value\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x442772\n  and:\n    api: TlsGetValue @ 0x442779\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x43CD62\n  or:\n    and:\n      or:\n        api: TerminateProcess @ 0x4404E7\n\nallocate thread local storage\nnamespace  host-interaction/thread/tls                   \nauthor     michael.hunhoff@mandiant.com                  \nscope      function                                      \nmbc        Process::Allocate Thread Local Storage [C0040]\nfunction @ 0x442769\n  or:\n    api: TlsAlloc @ 0x442769\n\nset thread local storage value\nnamespace  host-interaction/thread/tls                    \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \nmbc        Process::Set Thread Local Storage Value [C0041]\nfunction @ 0x442772\n  and:\n    api: TlsSetValue @ 0x44279A\n\nlink function at runtime on Windows (7 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x4391DE\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4391DE\ninstruction @ 0x43927C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x43927C\ninstruction @ 0x4473D3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4473D3\ninstruction @ 0x4473F0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4473F0\ninstruction @ 0x447405\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x447405\ninstruction @ 0x44743A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x44743A\ninstruction @ 0x447452\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x447452\n\nlink many functions at runtime\nnamespace  linking/runtime-linking                      \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com\nscope      function                                     \natt&ck     Execution::Shared Modules [T1129]            \nfunction @ 0x44738A\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x4473D3, 0x4473F0, 0x447405, 0x44743A, and 1 more...\n\n\n\n"},"hashes":{"md5":"7f9c454a2e016e533e181d53eba113bc","sha1":"694dc7713537a7237030f7623881423fcb8d8c5c","sha256":"c7dc529d8aae76b4e797e4e9e3ea7cd69669e6c3bb3f94d80f1974d1b9f69378"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 255</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 16225</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"CryptoL\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"7f9c454a2e016e533e181d53eba113bc\",\n        \"sha256\": \"c7dc529d8aae76b4e797e4e9e3ea7cd69669e6c3bb3f94d80f1974d\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__20_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (20 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x4013A4\",\n      \"label\": \"Function 0x4013A4\",\n      \"type\": \"function\",\n      \"address\": \"0x4013A4\"\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__2_matches_\",\n      \"label\": \"write file on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x441374\",\n      \"label\": \"Function 0x441374\",\n      \"type\": \"function\",\n      \"address\": \"0x441374\"\n    },\n    {\n      \"id\": \"func_0x448357\",\n      \"label\": \"Function 0x448357\",\n      \"type\": \"function\",\n      \"address\": \"0x448357\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_os_version\",\n      \"label\": \"check OS version\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x44C5D1\",\n      \"label\": \"Function 0x44C5D1\",\n      \"type\": \"function\",\n      \"address\": \"0x44C5D1\"\n    },\n    {\n      \"id\": \"api_GetVersionEx\",\n      \"label\": \"GetVersionEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_thread_local_storage_value\",\n      \"label\": \"get thread local storage value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x442772\",\n      \"label\": \"Function 0x442772\",\n      \"type\": \"function\",\n      \"address\": \"0x442772\"\n    },\n    {\n      \"id\": \"api_TlsGetValue\",\n      \"label\": \"TlsGetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x43CD62\",\n      \"label\": \"Function 0x43CD62\",\n      \"type\": \"function\",\n      \"address\": \"0x43CD62\"\n    },\n    {\n      \"id\": \"api_TerminateProcess\",\n      \"label\": \"TerminateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_allocate_thread_local_storage\",\n      \"label\": \"allocate thread local storage\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Allocate Thread Local Storage [C0040]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x442769\",\n      \"label\": \"Function 0x442769\",\n      \"type\": \"function\",\n      \"address\": \"0x442769\"\n    },\n    {\n      \"id\": \"api_TlsAlloc\",\n      \"label\": \"TlsAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_thread_local_storage_value\",\n      \"label\": \"set thread local storage value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Set Thread Local Storage Value [C0041]\"\n      ]\n    },\n    {\n      \"id\": \"api_TlsSetValue\",\n      \"label\": \"TlsSetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__7_matches_\",\n      \"label\": \"link function at runtime on Windows (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_many_functions_at_runtime\",\n      \"label\": \"link many functions at runtime\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x44738A\",\n      \"label\": \"Function 0x44738A\",\n      \"type\": \"function\",\n      \"address\": \"0x44738A\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__20_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__20_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x4013A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x441374\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x448357\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x441374\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448357\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x441374\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x448357\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x441374\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x448357\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_os_version\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_os_version\",\n      \"target\": \"func_0x44C5D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x44C5D1\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x44C5D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x44C5D1\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_thread_local_storage_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value\",\n      \"target\": \"func_0x442772\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x442772\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x442772\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x442772\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x43CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x43CD62\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x43CD62\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x43CD62\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_thread_local_storage\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_thread_local_storage\",\n      \"target\": \"func_0x442769\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x442769\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x442769\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x442769\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_thread_local_storage_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value\",\n      \"target\": \"func_0x442772\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x442772\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x442772\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x442772\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_many_functions_at_runtime\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime\",\n      \"target\": \"func_0x44738A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x44738A\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-10 01:09:41.081943\",\n    \"total_functions\": \"255\",\n    \"total_features\": \"16225\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-10 01:09:41"}
{"_id":{"$oid":"6a4ff9e90108394cb24cdd1a"},"sha256":"dce2d575bef073079c658edfa872a15546b422ad2b74267d33b386dc7cc85b47","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa__rm9yszw/001_upx_unpacked.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa__rm9yszw/001_upx_unpacked.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa__rm9yszw/001_upx_unpacked.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 4b724b463f426bf1959af5558ac034a5                                  │\n│ sha1     │ 442ae99b184c89d84cbd5992d9ae7fad020a1107                          │\n│ sha256   │ 61144cbc28456a34ca9b6fbbd56d7114f08996df8f004bfa2d634c65dc0f6540  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /tmp/sdm_unpack_7_n34ps2/Win32.DarkTequila-019f46ceb07d75e385ced… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic             ┃ ATT&CK Technique                                 ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION           │ Obfuscated Files or Information [T1027]          │\n│                           │ Virtualization/Sandbox Evasion [T1497]           │\n│ EXECUTION                 │ Shared Modules [T1129]                           │\n└───────────────────────────┴──────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Virtual Machine Detection::Instruction Testing    │\n│                          │ [B0009.029]                                       │\n│ CRYPTOGRAPHY             │ Encrypt Data::RC4 [C0027.009]                     │\n│                          │ Encryption Key::RC4 KSA [C0028.002]               │\n│                          │ Generate Pseudo-random Sequence::RC4 PRGA         │\n│                          │ [C0021.004]                                       │\n│ DATA                     │ Encode Data::XOR [C0026.002]                      │\n│ DEFENSE EVASION          │ Obfuscated Files or                               │\n│                          │ Information::Encoding-Standard Algorithm          │\n│                          │ [E1027.m02]                                       │\n│ PROCESS                  │ Create Thread [C0038]                             │\n│                          │ Terminate Process [C0018]                         │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                           ┃ Namespace                             ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ check for VM using instruction       │ anti-analysis/anti-vm/vm-detection    │\n│ VPCEXT                               │                                       │\n│ encode data using XOR (137 matches)  │ data-manipulation/encoding/xor        │\n│ encrypt data using RC4 KSA           │ data-manipulation/encryption/rc4      │\n│ encrypt data using RC4 PRGA          │ data-manipulation/encryption/rc4      │\n│ print debug messages                 │ host-interaction/log/debug/write-eve… │\n│ terminate process                    │ host-interaction/process/terminate    │\n│ create thread (3 matches)            │ host-interaction/thread/create        │\n│ link function at runtime on Windows  │ linking/runtime-linking               │\n│ (70 matches)                         │                                       │\n│ link many functions at runtime (2    │ linking/runtime-linking               │\n│ matches)                             │                                       │\n│ parse PE header (2 matches)          │ load-code/pe                          │\n│ resolve function by parsing PE       │ load-code/pe                          │\n│ exports                              │                                       │\n└──────────────────────────────────────┴───────────────────────────────────────┘\n\n","verbose":"md5                     4b724b463f426bf1959af5558ac034a5                        \nsha1                    442ae99b184c89d84cbd5992d9ae7fad020a1107                \nsha256                  61144cbc28456a34ca9b6fbbd56d7114f08996df8f004bfa2d634c6…\npath                    /tmp/sdm_unpack_7_n34ps2/Win32.DarkTequila-019f46ceb07d…\ntimestamp               2026-07-10 01:13:23.192353                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIfvbD5x/rules                                   \nfunction count          168                                                     \nlibrary function count  35                                                      \ntotal feature count     19956                                                   \n\ncheck for VM using instruction VPCEXT\nnamespace    anti-analysis/anti-vm/vm-detection                                 \ndescription  Detects virtualization using VPCEXT (visual property container     \n             extender) instruction. Execution of this instruction will cause an \n             illegal instruction exception outside of a virtual environment     \n             otherwise return 0                                                 \nscope        function                                                           \nmatches      0x401500                                                           \n\nencode data using XOR (137 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x4034C0                      \n           0x4035A0                      \n           0x403680                      \n           0x403700                      \n           0x403790                      \n           0x403820                      \n           0x4038C0                      \n           0x403950                      \n           0x4039F0                      \n           0x403A90                      \n           0x403B90                      \n           0x403C60                      \n           0x403D80                      \n           0x403E50                      \n           0x403EF0                      \n           0x403F62                      \n           0x403FE0                      \n           0x404080                      \n           0x404120                      \n           0x4041B0                      \n           0x404222                      \n           0x4042B0                      \n           0x404350                      \n           0x4043F0                      \n           0x404500                      \n           0x404580                      \n           0x404640                      \n           0x4046B2                      \n           0x404790                      \n           0x404810                      \n           0x404880                      \n           0x4048F0                      \n           0x4049B0                      \n           0x404A20                      \n           0x404B10                      \n           0x404B90                      \n           0x404C02                      \n           0x404CC0                      \n           0x404D40                      \n           0x404DC0                      \n           0x404E40                      \n           0x404EB2                      \n           0x404F30                      \n           0x404FB0                      \n           0x405020                      \n           0x405130                      \n           0x4051B0                      \n           0x405240                      \n           0x4052D0                      \n           0x4053D0                      \n           0x405450                      \n           0x4054D0                      \n           0x405550                      \n           0x4055D0                      \n           0x405670                      \n           0x405700                      \n           0x405790                      \n           0x405820                      \n           0x4058C0                      \n           0x405960                      \n           0x4059F0                      \n           0x405A80                      \n           0x405B10                      \n           0x405B90                      \n           0x405C02                      \n           0x405C80                      \n           0x405D10                      \n           0x405D90                      \n           0x405E10                      \n           0x405E90                      \n           0x405F10                      \n           0x405F90                      \n           0x406020                      \n           0x4060C0                      \n           0x406140                      \n           0x4061E0                      \n           0x406280                      \n           0x4062F2                      \n           0x406372                      \n           0x406400                      \n           0x406490                      \n           0x406510                      \n           0x4065A0                      \n           0x406620                      \n           0x4066A0                      \n           0x406740                      \n           0x406862                      \n           0x406900                      \n           0x406972                      \n           0x4069F0                      \n           0x406A90                      \n           0x406B20                      \n           0x406B92                      \n           0x406C62                      \n           0x406D90                      \n           0x406862                      \n           0x406900                      \n           0x406972                      \n           0x4069F0                      \n           0x406A90                      \n           0x406B20                      \n           0x406B92                      \n           0x406C62                      \n           0x406D90                      \n           0x406E51                      \n           0x406EF0                      \n           0x406F90                      \n           0x407030                      \n           0x4070C0                      \n           0x407150                      \n           0x4071D0                      \n           0x407270                      \n           0x407300                      \n           0x407390                      \n           0x407420                      \n           0x4074A0                      \n           0x407530                      \n           0x4075B0                      \n           0x407630                      \n           0x4076A2                      \n           0x407730                      \n           0x4077B0                      \n           0x407840                      \n           0x4078C0                      \n           0x407950                      \n           0x4079E0                      \n           0x407A80                      \n           0x407B70                      \n           0x407C20                      \n           0x407CA0                      \n           0x407D20                      \n           0x407DC0                      \n           0x407E60                      \n           0x407EF0                      \n           0x4087A0                      \n           0x408800                      \n           0x408B00                      \n\nencrypt data using RC4 KSA\nnamespace  data-manipulation/encryption/rc4\nscope      function                        \nmatches    0x407F50                        \n\nencrypt data using RC4 PRGA\nnamespace  data-manipulation/encryption/rc4\nscope      function                        \nmatches    0x407F50                        \n\nprint debug messages\nnamespace  host-interaction/log/debug/write-event\nscope      function                              \nmatches    0x40A03E                              \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x40A99E                          \n\ncreate thread (3 matches)\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x408D75                      \n           0x409530                      \n           0x4095C9                      \n\nlink function at runtime on Windows (70 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x401FAE               \n           0x402106               \n           0x402669               \n           0x402A5D               \n           0x402A6F               \n           0x402A82               \n           0x402A95               \n           0x402AA7               \n           0x402ABA               \n           0x402D9A               \n           0x402DB5               \n           0x402DD0               \n           0x402DEB               \n           0x402E06               \n           0x402E21               \n           0x402E3C               \n           0x402E57               \n           0x402E72               \n           0x402E8D               \n           0x402EA8               \n           0x402EC3               \n           0x402EDE               \n           0x402EF9               \n           0x402F14               \n           0x402F2F               \n           0x402F4A               \n           0x402F65               \n           0x402F80               \n           0x402F9B               \n           0x402FB6               \n           0x402FD1               \n           0x402FEC               \n           0x403007               \n           0x40301F               \n           0x40306A               \n           0x403085               \n           0x4030A0               \n           0x4030BB               \n           0x4030D6               \n           0x4030F1               \n           0x40310C               \n           0x403127               \n           0x403142               \n           0x40315D               \n           0x403178               \n           0x403193               \n           0x4031AE               \n           0x4031F5               \n           0x40323C               \n           0x403257               \n           0x403272               \n           0x40328D               \n           0x4032A8               \n           0x4032C3               \n           0x4032DE               \n           0x4032F9               \n           0x403314               \n           0x40332F               \n           0x40334A               \n           0x403365               \n           0x403380               \n           0x4033BF               \n           0x4033D6               \n           0x4033ED               \n           0x4086C2               \n           0x409372               \n           0x4098ED               \n           0x409904               \n           0x409920               \n           0x409C73               \n\nlink many functions at runtime (2 matches)\nnamespace  linking/runtime-linking\nscope      function               \nmatches    0x402960               \n           0x402D60               \n\nparse PE header (2 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x4026D0    \n           0x40BB5C    \n\nresolve function by parsing PE exports\nnamespace  load-code/pe\nscope      function    \nmatches    0x4019F0    \n\n\n\n","very_verbose":"md5                     4b724b463f426bf1959af5558ac034a5                        \nsha1                    442ae99b184c89d84cbd5992d9ae7fad020a1107                \nsha256                  61144cbc28456a34ca9b6fbbd56d7114f08996df8f004bfa2d634c6…\npath                    /tmp/sdm_unpack_7_n34ps2/Win32.DarkTequila-019f46ceb07d…\ntimestamp               2026-07-10 01:13:35.155007                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIaR2BIM/rules                                   \nfunction count          168                                                     \nlibrary function count  35                                                      \ntotal feature count     19956                                                   \n\ncalculate modulo 256 via x86 assembly (5 matches, only showing first match of \nlibrary rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x407FD0\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x407FD0\n    or:\n      number: 0xFF @ 0x407FD0\n\ncontain loop (46 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x4018F0\n  or:\n    characteristic: loop @ 0x4018F0\n\ndelay execution (3 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x408C7C in function 0x408B90\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x408C81\n\ncheck for VM using instruction VPCEXT\nnamespace    anti-analysis/anti-vm/vm-detection                                 \nauthor       richard.weiss@mandiant.com                                         \nscope        function                                                           \natt&ck       Defense Evasion::Virtualization/Sandbox Evasion [T1497]            \nmbc          Anti-Behavioral Analysis::Virtual Machine Detection::Instruction   \n             Testing [B0009.029]                                                \nreferences   https://unprotect.it/technique/vpcext/,                            \n             https://research.nccgroup.com/2017/12/13/hidden-cobra-volgmer-a-te…\n             https://shasaurabh.blogspot.com/2017/07/virtual-machine-detection-…\ndescription  Detects virtualization using VPCEXT (visual property container     \n             extender) instruction. Execution of this instruction will cause an \n             illegal instruction exception outside of a virtual environment     \n             otherwise return 0                                                 \nfunction @ 0x401500\n  mnemonic: vpcext @ 0x401546\n\nencode data using XOR (137 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x4034C0 in function 0x403410\n  and:\n    characteristic: tight loop @ 0x4034C0\n    characteristic: nzxor @ 0x4034C6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4035A0 in function 0x403410\n  and:\n    characteristic: tight loop @ 0x4035A0\n    characteristic: nzxor @ 0x4035A6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403680 in function 0x403410\n  and:\n    characteristic: tight loop @ 0x403680\n    characteristic: nzxor @ 0x403686\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403700 in function 0x403410\n  and:\n    characteristic: tight loop @ 0x403700\n    characteristic: nzxor @ 0x403706\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403790 in function 0x403410\n  and:\n    characteristic: tight loop @ 0x403790\n    characteristic: nzxor @ 0x403796\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403820 in function 0x403410\n  and:\n    characteristic: tight loop @ 0x403820\n    characteristic: nzxor @ 0x403826\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4038C0 in function 0x403410\n  and:\n    characteristic: tight loop @ 0x4038C0\n    characteristic: nzxor @ 0x4038C6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403950 in function 0x403410\n  and:\n    characteristic: tight loop @ 0x403950\n    characteristic: nzxor @ 0x403956\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4039F0 in function 0x403410\n  and:\n    characteristic: tight loop @ 0x4039F0\n    characteristic: nzxor @ 0x4039F6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403A90 in function 0x403410\n  and:\n    characteristic: tight loop @ 0x403A90\n    characteristic: nzxor @ 0x403A96\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403B90 in function 0x403B00\n  and:\n    characteristic: tight loop @ 0x403B90\n    characteristic: nzxor @ 0x403B96\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403C60 in function 0x403B00\n  and:\n    characteristic: tight loop @ 0x403C60\n    characteristic: nzxor @ 0x403C66\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403D80 in function 0x403B00\n  and:\n    characteristic: tight loop @ 0x403D80\n    characteristic: nzxor @ 0x403D86\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403E50 in function 0x403B00\n  and:\n    characteristic: tight loop @ 0x403E50\n    characteristic: nzxor @ 0x403E56\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403EF0 in function 0x403B00\n  and:\n    characteristic: tight loop @ 0x403EF0\n    characteristic: nzxor @ 0x403EF6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403F62 in function 0x403B00\n  and:\n    characteristic: tight loop @ 0x403F62\n    characteristic: nzxor @ 0x403F68\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x403FE0 in function 0x403B00\n  and:\n    characteristic: tight loop @ 0x403FE0\n    characteristic: nzxor @ 0x403FE6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404080 in function 0x403B00\n  and:\n    characteristic: tight loop @ 0x404080\n    characteristic: nzxor @ 0x404086\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404120 in function 0x403B00\n  and:\n    characteristic: tight loop @ 0x404120\n    characteristic: nzxor @ 0x404126\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4041B0 in function 0x403B00\n  and:\n    characteristic: tight loop @ 0x4041B0\n    characteristic: nzxor @ 0x4041B6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404222 in function 0x403B00\n  and:\n    characteristic: tight loop @ 0x404222\n    characteristic: nzxor @ 0x404228\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4042B0 in function 0x403B00\n  and:\n    characteristic: tight loop @ 0x4042B0\n    characteristic: nzxor @ 0x4042B6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404350 in function 0x403B00\n  and:\n    characteristic: tight loop @ 0x404350\n    characteristic: nzxor @ 0x404356\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4043F0 in function 0x403B00\n  and:\n    characteristic: tight loop @ 0x4043F0\n    characteristic: nzxor @ 0x4043F6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404500 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404500\n    characteristic: nzxor @ 0x404506\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404580 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404580\n    characteristic: nzxor @ 0x404586\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404640 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404640\n    characteristic: nzxor @ 0x404646\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4046B2 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x4046B2\n    characteristic: nzxor @ 0x4046B8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404790 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404790\n    characteristic: nzxor @ 0x404796\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404810 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404810\n    characteristic: nzxor @ 0x404816\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404880 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404880\n    characteristic: nzxor @ 0x404886\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4048F0 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x4048F0\n    characteristic: nzxor @ 0x4048F6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4049B0 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x4049B0\n    characteristic: nzxor @ 0x4049B6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404A20 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404A20\n    characteristic: nzxor @ 0x404A26\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404B10 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404B10\n    characteristic: nzxor @ 0x404B16\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404B90 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404B90\n    characteristic: nzxor @ 0x404B96\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404C02 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404C02\n    characteristic: nzxor @ 0x404C08\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404CC0 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404CC0\n    characteristic: nzxor @ 0x404CC6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404D40 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404D40\n    characteristic: nzxor @ 0x404D46\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404DC0 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404DC0\n    characteristic: nzxor @ 0x404DC6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404E40 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404E40\n    characteristic: nzxor @ 0x404E46\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404EB2 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404EB2\n    characteristic: nzxor @ 0x404EB8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404F30 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404F30\n    characteristic: nzxor @ 0x404F36\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x404FB0 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x404FB0\n    characteristic: nzxor @ 0x404FB6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405020 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x405020\n    characteristic: nzxor @ 0x405026\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405130 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x405130\n    characteristic: nzxor @ 0x405136\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4051B0 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x4051B0\n    characteristic: nzxor @ 0x4051B6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405240 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x405240\n    characteristic: nzxor @ 0x405246\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4052D0 in function 0x404470\n  and:\n    characteristic: tight loop @ 0x4052D0\n    characteristic: nzxor @ 0x4052D6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4053D0 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x4053D0\n    characteristic: nzxor @ 0x4053D6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405450 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405450\n    characteristic: nzxor @ 0x405456\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4054D0 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x4054D0\n    characteristic: nzxor @ 0x4054D6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405550 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405550\n    characteristic: nzxor @ 0x405556\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4055D0 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x4055D0\n    characteristic: nzxor @ 0x4055D6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405670 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405670\n    characteristic: nzxor @ 0x405676\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405700 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405700\n    characteristic: nzxor @ 0x405706\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405790 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405790\n    characteristic: nzxor @ 0x405796\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405820 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405820\n    characteristic: nzxor @ 0x405826\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4058C0 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x4058C0\n    characteristic: nzxor @ 0x4058C6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405960 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405960\n    characteristic: nzxor @ 0x405966\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4059F0 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x4059F0\n    characteristic: nzxor @ 0x4059F6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405A80 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405A80\n    characteristic: nzxor @ 0x405A86\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405B10 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405B10\n    characteristic: nzxor @ 0x405B16\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405B90 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405B90\n    characteristic: nzxor @ 0x405B96\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405C02 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405C02\n    characteristic: nzxor @ 0x405C08\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405C80 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405C80\n    characteristic: nzxor @ 0x405C86\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405D10 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405D10\n    characteristic: nzxor @ 0x405D16\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405D90 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405D90\n    characteristic: nzxor @ 0x405D96\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405E10 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405E10\n    characteristic: nzxor @ 0x405E16\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405E90 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405E90\n    characteristic: nzxor @ 0x405E96\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405F10 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405F10\n    characteristic: nzxor @ 0x405F16\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405F90 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x405F90\n    characteristic: nzxor @ 0x405F96\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406020 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x406020\n    characteristic: nzxor @ 0x406026\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4060C0 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x4060C0\n    characteristic: nzxor @ 0x4060C6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406140 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x406140\n    characteristic: nzxor @ 0x406146\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4061E0 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x4061E0\n    characteristic: nzxor @ 0x4061E6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406280 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x406280\n    characteristic: nzxor @ 0x406286\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4062F2 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x4062F2\n    characteristic: nzxor @ 0x4062F8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406372 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x406372\n    characteristic: nzxor @ 0x406378\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406400 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x406400\n    characteristic: nzxor @ 0x406406\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406490 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x406490\n    characteristic: nzxor @ 0x406496\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406510 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x406510\n    characteristic: nzxor @ 0x406516\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4065A0 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x4065A0\n    characteristic: nzxor @ 0x4065A6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406620 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x406620\n    characteristic: nzxor @ 0x406626\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4066A0 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x4066A0\n    characteristic: nzxor @ 0x4066A6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406740 in function 0x405380\n  and:\n    characteristic: tight loop @ 0x406740\n    characteristic: nzxor @ 0x406746\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406862 in function 0x406817\n  and:\n    characteristic: tight loop @ 0x406862\n    characteristic: nzxor @ 0x406868\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406862 in function 0x406817\n  and:\n    characteristic: tight loop @ 0x406862\n    characteristic: nzxor @ 0x406868\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406900 in function 0x40689D\n  and:\n    characteristic: tight loop @ 0x406900\n    characteristic: nzxor @ 0x406906\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406900 in function 0x40689D\n  and:\n    characteristic: tight loop @ 0x406900\n    characteristic: nzxor @ 0x406906\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406972 in function 0x40693B\n  and:\n    characteristic: tight loop @ 0x406972\n    characteristic: nzxor @ 0x406978\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406972 in function 0x40693B\n  and:\n    characteristic: tight loop @ 0x406972\n    characteristic: nzxor @ 0x406978\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4069F0 in function 0x4069AD\n  and:\n    characteristic: tight loop @ 0x4069F0\n    characteristic: nzxor @ 0x4069F6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4069F0 in function 0x4069AD\n  and:\n    characteristic: tight loop @ 0x4069F0\n    characteristic: nzxor @ 0x4069F6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406A90 in function 0x406A2B\n  and:\n    characteristic: tight loop @ 0x406A90\n    characteristic: nzxor @ 0x406A96\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406A90 in function 0x406A2B\n  and:\n    characteristic: tight loop @ 0x406A90\n    characteristic: nzxor @ 0x406A96\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406B20 in function 0x406ACB\n  and:\n    characteristic: tight loop @ 0x406B20\n    characteristic: nzxor @ 0x406B26\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406B20 in function 0x406ACB\n  and:\n    characteristic: tight loop @ 0x406B20\n    characteristic: nzxor @ 0x406B26\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406B92 in function 0x406B5B\n  and:\n    characteristic: tight loop @ 0x406B92\n    characteristic: nzxor @ 0x406B98\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406B92 in function 0x406B5B\n  and:\n    characteristic: tight loop @ 0x406B92\n    characteristic: nzxor @ 0x406B98\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406C62 in function 0x406BCD\n  and:\n    characteristic: tight loop @ 0x406C62\n    characteristic: nzxor @ 0x406C68\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406C62 in function 0x406BCD\n  and:\n    characteristic: tight loop @ 0x406C62\n    characteristic: nzxor @ 0x406C68\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406D90 in function 0x406C9D\n  and:\n    characteristic: tight loop @ 0x406D90\n    characteristic: nzxor @ 0x406D96\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406D90 in function 0x406C9D\n  and:\n    characteristic: tight loop @ 0x406D90\n    characteristic: nzxor @ 0x406D96\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406E51 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x406E51\n    characteristic: nzxor @ 0x406E57\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406EF0 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x406EF0\n    characteristic: nzxor @ 0x406EF6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406F90 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x406F90\n    characteristic: nzxor @ 0x406F96\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407030 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x407030\n    characteristic: nzxor @ 0x407036\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4070C0 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x4070C0\n    characteristic: nzxor @ 0x4070C6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407150 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x407150\n    characteristic: nzxor @ 0x407156\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4071D0 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x4071D0\n    characteristic: nzxor @ 0x4071D6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407270 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x407270\n    characteristic: nzxor @ 0x407276\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407300 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x407300\n    characteristic: nzxor @ 0x407306\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407390 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x407390\n    characteristic: nzxor @ 0x407396\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407420 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x407420\n    characteristic: nzxor @ 0x407426\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4074A0 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x4074A0\n    characteristic: nzxor @ 0x4074A6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407530 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x407530\n    characteristic: nzxor @ 0x407536\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4075B0 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x4075B0\n    characteristic: nzxor @ 0x4075B6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407630 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x407630\n    characteristic: nzxor @ 0x407636\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4076A2 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x4076A2\n    characteristic: nzxor @ 0x4076A8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407730 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x407730\n    characteristic: nzxor @ 0x407736\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4077B0 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x4077B0\n    characteristic: nzxor @ 0x4077B6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407840 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x407840\n    characteristic: nzxor @ 0x407846\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4078C0 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x4078C0\n    characteristic: nzxor @ 0x4078C6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407950 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x407950\n    characteristic: nzxor @ 0x407956\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4079E0 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x4079E0\n    characteristic: nzxor @ 0x4079E6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407A80 in function 0x406E00\n  and:\n    characteristic: tight loop @ 0x407A80\n    characteristic: nzxor @ 0x407A86\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407B70 in function 0x407B20\n  and:\n    characteristic: tight loop @ 0x407B70\n    characteristic: nzxor @ 0x407B76\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407C20 in function 0x407B20\n  and:\n    characteristic: tight loop @ 0x407C20\n    characteristic: nzxor @ 0x407C26\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407CA0 in function 0x407B20\n  and:\n    characteristic: tight loop @ 0x407CA0\n    characteristic: nzxor @ 0x407CA6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407D20 in function 0x407B20\n  and:\n    characteristic: tight loop @ 0x407D20\n    characteristic: nzxor @ 0x407D26\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407DC0 in function 0x407B20\n  and:\n    characteristic: tight loop @ 0x407DC0\n    characteristic: nzxor @ 0x407DC6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407E60 in function 0x407B20\n  and:\n    characteristic: tight loop @ 0x407E60\n    characteristic: nzxor @ 0x407E66\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x407EF0 in function 0x407B20\n  and:\n    characteristic: tight loop @ 0x407EF0\n    characteristic: nzxor @ 0x407EF6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4087A0 in function 0x408770\n  and:\n    characteristic: tight loop @ 0x4087A0\n    characteristic: nzxor @ 0x4087AA, 0x4087AF\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x408800 in function 0x408770\n  and:\n    characteristic: tight loop @ 0x408800\n    characteristic: nzxor @ 0x40880A, 0x408811\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x408B00 in function 0x408880\n  and:\n    characteristic: tight loop @ 0x408B00\n    characteristic: nzxor @ 0x408B07\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nencrypt data using RC4 KSA\nnamespace  data-manipulation/encryption/rc4                                     \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Encrypt Data::RC4 [C0027.009], Cryptography::Encryption\n           Key::RC4 KSA [C0028.002]                                             \nfunction @ 0x407F50\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x407FA3\n          or:\n            number: 0x100 @ 0x407FAB\n        and: = initialize S\n          characteristic: tight loop @ 0x407FB5\n          or:\n            number: 0xFF @ 0x407FD0\n            number: 0x100 @ 0x407FEB\n      or: = modulo 256\n        match: calculate modulo 256 via x86 assembly @ 0x407FD0, 0x408001, 0x408011, 0x408037\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x407FD0\n            or:\n              number: 0xFF @ 0x407FD0\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x408001\n            or:\n              number: 0xFF @ 0x408001\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x408011\n            or:\n              number: 0xFF @ 0x408011\n          and:\n            or:\n              arch: i386\n            mnemonic: and @ 0x408037\n            or:\n              number: 0x800000FF @ 0x408037\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x408007, 0x408017, 0x40802D\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x407FBF, 0x407FC8\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: div @ 0x407FB9\n\nencrypt data using RC4 PRGA\nnamespace  data-manipulation/encryption/rc4                                     \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Encrypt Data::RC4 [C0027.009], Cryptography::Generate  \n           Pseudo-random Sequence::RC4 PRGA [C0021.004]                         \nfunction @ 0x407F50\n  and:\n    match: contain loop @ 0x407F50\n      or:\n        characteristic: loop @ 0x407F50\n        characteristic: tight loop @ 0x407FA3, 0x407FB5\n    count(characteristic(nzxor)): 1 @ 0x408055\n    count(characteristic(calls from)): 4 or fewer @ 0x40A050, 0x40AB36\n    count(basic block): between 4 and 50 @ 0x407F50, 0x407F80, 0x407F88, 0x407FA3, and 8 more...\n    or:\n      match: calculate modulo 256 via x86 assembly @ 0x407FD0, 0x408001, 0x408011, 0x408037\n        and:\n          or:\n            arch: i386\n          mnemonic: and @ 0x407FD0\n          or:\n            number: 0xFF @ 0x407FD0\n        and:\n          or:\n            arch: i386\n          mnemonic: and @ 0x408001\n          or:\n            number: 0xFF @ 0x408001\n        and:\n          or:\n            arch: i386\n          mnemonic: and @ 0x408011\n          or:\n            number: 0xFF @ 0x408011\n        and:\n          or:\n            arch: i386\n          mnemonic: and @ 0x408037\n          or:\n            number: 0x800000FF @ 0x408037\n      count(mnemonic(movzx)): 4 or more @ 0x407FBF, 0x407FC8, 0x408007, 0x408017, and 2 more...\n    optional:\n      or:\n        number: 0xFF @ 0x407FD0, 0x408001, 0x408011\n        number: 0x100 @ 0x407F89, 0x407FAB, 0x407FEB\n\nprint debug messages\nnamespace  host-interaction/log/debug/write-event\nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \nfunction @ 0x40A03E\n  or:\n    api: OutputDebugString @ 0x40A02C\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x40A99E\n  or:\n    api: exit @ 0x40A84E\n\ncreate thread (3 matches)\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x408D75 in function 0x408D60\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthreadex @ 0x408D91\nbasic block @ 0x409530 in function 0x409510\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthreadex @ 0x409542\nbasic block @ 0x4095C9 in function 0x4095C0\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthreadex @ 0x4095D3\n\nlink function at runtime on Windows (70 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x401FAE\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401FAE\ninstruction @ 0x402106\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402106\ninstruction @ 0x402669\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402669\ninstruction @ 0x402A5D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402A5D\ninstruction @ 0x402A6F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402A6F\ninstruction @ 0x402A82\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402A82\ninstruction @ 0x402A95\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402A95\ninstruction @ 0x402AA7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402AA7\ninstruction @ 0x402ABA\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402ABA\ninstruction @ 0x402D9A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402D9A\ninstruction @ 0x402DB5\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402DB5\ninstruction @ 0x402DD0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402DD0\ninstruction @ 0x402DEB\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402DEB\ninstruction @ 0x402E06\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402E06\ninstruction @ 0x402E21\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402E21\ninstruction @ 0x402E3C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402E3C\ninstruction @ 0x402E57\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402E57\ninstruction @ 0x402E72\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402E72\ninstruction @ 0x402E8D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402E8D\ninstruction @ 0x402EA8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402EA8\ninstruction @ 0x402EC3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402EC3\ninstruction @ 0x402EDE\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402EDE\ninstruction @ 0x402EF9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402EF9\ninstruction @ 0x402F14\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402F14\ninstruction @ 0x402F2F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402F2F\ninstruction @ 0x402F4A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402F4A\ninstruction @ 0x402F65\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402F65\ninstruction @ 0x402F80\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402F80\ninstruction @ 0x402F9B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402F9B\ninstruction @ 0x402FB6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402FB6\ninstruction @ 0x402FD1\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402FD1\ninstruction @ 0x402FEC\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402FEC\ninstruction @ 0x403007\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x403007\ninstruction @ 0x40301F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40301F\ninstruction @ 0x40306A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40306A\ninstruction @ 0x403085\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x403085\ninstruction @ 0x4030A0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4030A0\ninstruction @ 0x4030BB\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4030BB\ninstruction @ 0x4030D6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4030D6\ninstruction @ 0x4030F1\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4030F1\ninstruction @ 0x40310C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40310C\ninstruction @ 0x403127\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x403127\ninstruction @ 0x403142\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x403142\ninstruction @ 0x40315D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40315D\ninstruction @ 0x403178\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x403178\ninstruction @ 0x403193\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x403193\ninstruction @ 0x4031AE\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4031AE\ninstruction @ 0x4031F5\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4031F5\ninstruction @ 0x40323C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40323C\ninstruction @ 0x403257\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x403257\ninstruction @ 0x403272\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x403272\ninstruction @ 0x40328D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40328D\ninstruction @ 0x4032A8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4032A8\ninstruction @ 0x4032C3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4032C3\ninstruction @ 0x4032DE\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4032DE\ninstruction @ 0x4032F9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4032F9\ninstruction @ 0x403314\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x403314\ninstruction @ 0x40332F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40332F\ninstruction @ 0x40334A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40334A\ninstruction @ 0x403365\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x403365\ninstruction @ 0x403380\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x403380\ninstruction @ 0x4033BF\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4033BF\ninstruction @ 0x4033D6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4033D6\ninstruction @ 0x4033ED\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4033ED\ninstruction @ 0x4086C2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4086C2\ninstruction @ 0x409372\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x409372\ninstruction @ 0x4098ED\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4098ED\ninstruction @ 0x409904\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x409904\ninstruction @ 0x409920\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x409920\ninstruction @ 0x409C73\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x409C73\n\nlink many functions at runtime (2 matches)\nnamespace  linking/runtime-linking                      \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com\nscope      function                                     \natt&ck     Execution::Shared Modules [T1129]            \nfunction @ 0x402960\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x402A5D, 0x402A6F, 0x402A82, 0x402A95, and 2 more...\nfunction @ 0x402D60\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x402D9A, 0x402DB5, 0x402DD0, 0x402DEB, and 51 more...\n\nparse PE header (2 matches)\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x4026D0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x4026DC, 0x4026ED, 0x40274C\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x4026ED\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x4026D7\n      optional:\n        and:\n          operand[1].offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x4026E8, 0x402791, 0x40279F\n          or:\n            and:\n              arch: i386\n              operand[1].offset: 0x50 = IMAGE_NT_HEADERS.OptionalHeader.SizeOfImage @ 0x4026FC, 0x402718, 0x402762\n              operand[1].offset: 0x34 = IMAGE_NT_HEADERS.OptionalHeader.ImageBase @ 0x4026FF, 0x4027B7\nfunction @ 0x40BB5C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x40BB71, 0x40BB7E, 0x40BB8A, 0x40BB98\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x40BB98\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x40BB79\n\nresolve function by parsing PE exports\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x4019F0\n  and:\n    os: windows\n    or:\n      mnemonic: movzx @ 0x401D70\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x401B7C, 0x401C63\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x401D0D\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x401BCA\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x401AB6, 0x401CA1, 0x401DB5\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x401D19\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x401AB2, 0x401BA7, 0x401C16, 0x401C6A, and 3 more...\n\n\n\n"},"hashes":{"md5":"4b724b463f426bf1959af5558ac034a5","sha1":"442ae99b184c89d84cbd5992d9ae7fad020a1107","sha256":"61144cbc28456a34ca9b6fbbd56d7114f08996df8f004bfa2d634c65dc0f6540"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 168</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 19956</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Win32.DarkTequila-019f46ceb07d\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"4b724b463f426bf1959af5558ac034a5\",\n        \"sha256\": \"61144cbc28456a34ca9b6fbbd56d7114f08996df8f004bfa2d634c6\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_library_rule_\",\n      \"label\": \"library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Modulo [C0058]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_loop__46_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (46 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x4018F0\",\n      \"label\": \"Function 0x4018F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4018F0\"\n    },\n    {\n      \"id\": \"cap_delay_execution__3_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (3 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x408C7C\",\n      \"label\": \"Block 0x408C7C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x408C7C\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_check_for_vm_using_instruction_vpcext\",\n      \"label\": \"check for VM using instruction VPCEXT\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection::Instruction\",\n        \"Testing [B0009.029]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401500\",\n      \"label\": \"Function 0x401500\",\n      \"type\": \"function\",\n      \"address\": \"0x401500\"\n    },\n    {\n      \"id\": \"cap_author_______richard_weiss_mandiant_com\",\n      \"label\": \"author       richard.weiss@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection::Instruction\",\n        \"Testing [B0009.029]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_rc4_ksa\",\n      \"label\": \"encrypt data using RC4 KSA\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data::RC4 [C0027.009]\",\n        \"Cryptography::Encryption\",\n        \"Key::RC4 KSA [C0028.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407F50\",\n      \"label\": \"Function 0x407F50\",\n      \"type\": \"function\",\n      \"address\": \"0x407F50\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data::RC4 [C0027.009]\",\n        \"Cryptography::Encryption\",\n        \"Key::RC4 KSA [C0028.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_rc4_prga\",\n      \"label\": \"encrypt data using RC4 PRGA\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data::RC4 [C0027.009]\",\n        \"Cryptography::Generate\",\n        \"Pseudo-random Sequence::RC4 PRGA [C0021.004]\"\n      ]\n    },\n    {\n      \"id\": \"cap_print_debug_messages\",\n      \"label\": \"print debug messages\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x40A03E\",\n      \"label\": \"Function 0x40A03E\",\n      \"type\": \"function\",\n      \"address\": \"0x40A03E\"\n    },\n    {\n      \"id\": \"api_OutputDebugString\",\n      \"label\": \"OutputDebugString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40A99E\",\n      \"label\": \"Function 0x40A99E\",\n      \"type\": \"function\",\n      \"address\": \"0x40A99E\"\n    },\n    {\n      \"id\": \"api_exit\",\n      \"label\": \"exit\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_thread__3_matches_\",\n      \"label\": \"create thread (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x408D75\",\n      \"label\": \"Block 0x408D75\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x408D75\"\n    },\n    {\n      \"id\": \"bb_0x4095C9\",\n      \"label\": \"Block 0x4095C9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4095C9\"\n    },\n    {\n      \"id\": \"bb_0x409530\",\n      \"label\": \"Block 0x409530\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x409530\"\n    },\n    {\n      \"id\": \"api__beginthreadex\",\n      \"label\": \"_beginthreadex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__70_matches_\",\n      \"label\": \"link function at runtime on Windows (70 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_many_functions_at_runtime__2_matches_\",\n      \"label\": \"link many functions at runtime (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402960\",\n      \"label\": \"Function 0x402960\",\n      \"type\": \"function\",\n      \"address\": \"0x402960\"\n    },\n    {\n      \"id\": \"func_0x402D60\",\n      \"label\": \"Function 0x402D60\",\n      \"type\": \"function\",\n      \"address\": \"0x402D60\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header__2_matches_\",\n      \"label\": \"parse PE header (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4026D0\",\n      \"label\": \"Function 0x4026D0\",\n      \"type\": \"function\",\n      \"address\": \"0x4026D0\"\n    },\n    {\n      \"id\": \"func_0x40BB5C\",\n      \"label\": \"Function 0x40BB5C\",\n      \"type\": \"function\",\n      \"address\": \"0x40BB5C\"\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"label\": \"resolve function by parsing PE exports\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x4019F0\",\n      \"label\": \"Function 0x4019F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4019F0\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__46_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__46_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x4018F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__3_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__3_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x408C7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_vm_using_instruction_vpcext\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_vm_using_instruction_vpcext\",\n      \"target\": \"func_0x401500\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______richard_weiss_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______richard_weiss_mandiant_com\",\n      \"target\": \"func_0x401500\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_rc4_ksa\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa\",\n      \"target\": \"func_0x407F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x407F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_rc4_prga\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga\",\n      \"target\": \"func_0x407F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x407F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_print_debug_messages\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_print_debug_messages\",\n      \"target\": \"func_0x40A03E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A03E\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40A03E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A03E\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x40A99E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A99E\",\n      \"target\": \"api_exit\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40A99E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A99E\",\n      \"target\": \"api_exit\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread__3_matches_\",\n      \"target\": \"bb_0x408D75\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__3_matches_\",\n      \"target\": \"bb_0x4095C9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__3_matches_\",\n      \"target\": \"bb_0x409530\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x408D75\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4095C9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x409530\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__70_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_many_functions_at_runtime__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__2_matches_\",\n      \"target\": \"func_0x402960\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__2_matches_\",\n      \"target\": \"func_0x402D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x402960\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x402D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__2_matches_\",\n      \"target\": \"func_0x4026D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__2_matches_\",\n      \"target\": \"func_0x40BB5C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4026D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x40BB5C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"target\": \"func_0x4019F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x4019F0\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-10 01:13:35.155007\",\n    \"total_functions\": \"168\",\n    \"total_features\": \"19956\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-10 01:13:37"}
{"_id":{"$oid":"6a4ffe810108394cb24cdd1d"},"sha256":"517ac5506a5488a1193686f66cb57ad3288c2258c510004edb2f361b674526cc","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_1gpww1kx/Ransomware.Unnamed_0-019f46cf07d27c50852ca64be62892a7.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_1gpww1kx/Ransomware.Unnamed_0-019f46cf07d27c50852ca64be62892a7.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_1gpww1kx/Ransomware.Unnamed_0-019f46cf07d27c50852ca64be62892a7.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 96afc9cdef3c623e0c5420e339c57283                                  │\n│ sha1     │ ccbdff85419e61987fdb7291f9966a046b0e4b25                          │\n│ sha256   │ 517ac5506a5488a1193686f66cb57ad3288c2258c510004edb2f361b674526cc  │\n│ analysis │ static                                                            │\n│ os       │ any                                                               │\n│ format   │ dotnet                                                            │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/Ransomware.Unnam… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION      │ Deobfuscate/Decode Files or Information [T1140]       │\n│                      │ Obfuscated Files or Information::Compile After        │\n│                      │ Delivery [T1027.004]                                  │\n│                      │ Reflective Code Loading [T1620]                       │\n│                      │ Virtualization/Sandbox Evasion::System Checks         │\n│                      │ [T1497.001]                                           │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Virtual Machine Detection [B0009]                 │\n│ DATA                     │ Decode Data::Base64 [C0053.001]                   │\n│ DISCOVERY                │ Analysis Tool Discovery::Process detection        │\n│                          │ [B0013.001]                                       │\n│ FILE SYSTEM              │ Read File [C0051]                                 │\n│ PROCESS                  │ Terminate Process [C0018]                         │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                              ┃ Namespace                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ reference analysis tools strings        │ anti-analysis                      │\n│ reference anti-VM strings targeting Xen │ anti-analysis/anti-vm/vm-detection │\n│ decode data using Base64 in .NET        │ data-manipulation/encoding/base64  │\n│ read file on Windows (10 matches)       │ host-interaction/file-system/read  │\n│ terminate process (4 matches)           │ host-interaction/process/terminate │\n│ invoke .NET assembly method             │ load-code/dotnet                   │\n│ compile CSharp in .NET                  │ load-code/dotnet/csharp            │\n│ compiled to the .NET platform           │ runtime/dotnet                     │\n└─────────────────────────────────────────┴────────────────────────────────────┘\n\n","verbose":"md5                     96afc9cdef3c623e0c5420e339c57283                        \nsha1                    ccbdff85419e61987fdb7291f9966a046b0e4b25                \nsha256                  517ac5506a5488a1193686f66cb57ad3288c2258c510004edb2f361…\npath                    /home/apogean/projects/malware/windows/all_runs/Ransomw…\ntimestamp               2026-07-10 01:33:09.753128                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIGeNDjM/rules                                   \nfunction count          40                                                      \nlibrary function count  0                                                       \ntotal feature count     11058                                                   \n\nreference analysis tools strings\nnamespace  anti-analysis\nscope      file         \n\nreference anti-VM strings targeting Xen\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\ndecode data using Base64 in .NET\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    token(0x6000001)                 \n\nread file on Windows (10 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    token(0x6000005)                 \n           token(0x6000006)                 \n           token(0x600000B)                 \n           token(0x600000C)                 \n           token(0x6000011)                 \n           token(0x6000012)                 \n           token(0x600001A)                 \n           token(0x600001B)                 \n           token(0x600001D)                 \n           token(0x6000020)                 \n\nterminate process (4 matches)\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    token(0x6000014)                  \n           token(0x600001D)                  \n           token(0x6000020)                  \n           token(0x6000023)                  \n\ncompile .NET assembly\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x6000025)\n\ninvoke .NET assembly method\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x6000026)\n\ncompile CSharp in .NET\nnamespace  load-code/dotnet/csharp\nscope      function               \nmatches    token(0x6000025)       \n\ncompiled to the .NET platform\nnamespace  runtime/dotnet\nscope      file          \n\n\n\n","very_verbose":"md5                     96afc9cdef3c623e0c5420e339c57283                        \nsha1                    ccbdff85419e61987fdb7291f9966a046b0e4b25                \nsha256                  517ac5506a5488a1193686f66cb57ad3288c2258c510004edb2f361…\npath                    /home/apogean/projects/malware/windows/all_runs/Ransomw…\ntimestamp               2026-07-10 01:33:13.244910                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIt5rd9b/rules                                   \nfunction count          40                                                      \nlibrary function count  0                                                       \ntotal feature count     11058                                                   \n\nreference analysis tools strings\nnamespace   anti-analysis                                                       \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \nmbc         Discovery::Analysis Tool Discovery::Process detection [B0013.001]   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /(?<!\\w)ida?(\\.exe)?$/i\n    - \"'IDAT\" @ file+0xD62E7\n    - \"IDAT\" @ file+0x262E8, file+0x562E8, file+0x662E8, file+0x862E8, and 1 more...\n\nreference anti-VM strings targeting Xen\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /^Xen/i\n    - \"xEnB\" @ file+0x84706\n\ndecode data using Base64 in .NET\nnamespace  data-manipulation/encoding/base64                               \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \natt&ck     Defense Evasion::Deobfuscate/Decode Files or Information [T1140]\nmbc        Data::Decode Data::Base64 [C0053.001]                           \nfunction @ token(0x6000001)\n  or:\n    api: System.Convert::FromBase64String @ token(0x6000001)+0x4\n\nread file on Windows (10 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ token(0x6000005)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x6000005)+0xA\nfunction @ token(0x6000006)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x6000006)+0xA\nfunction @ token(0x600000B)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x600000B)+0xA\nfunction @ token(0x600000C)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x600000C)+0xA\nfunction @ token(0x6000011)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x6000011)+0xA\nfunction @ token(0x6000012)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x6000012)+0xA\nfunction @ token(0x600001A)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x600001A)+0xA\nfunction @ token(0x600001B)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x600001B)+0xA\nfunction @ token(0x600001D)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x600001D)+0xA\nfunction @ token(0x6000020)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x6000020)+0xA\n\nterminate process (4 matches)\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ token(0x6000014)\n  or:\n    api: System.Environment::Exit @ token(0x6000014)+0x1\nfunction @ token(0x600001D)\n  or:\n    api: System.Environment::Exit @ token(0x600001D)+0x11\nfunction @ token(0x6000020)\n  or:\n    api: System.Environment::Exit @ token(0x6000020)+0x11\nfunction @ token(0x6000023)\n  or:\n    api: System.Environment::Exit @ token(0x6000023)+0x1\n\n(internal) .NET file limitation\nnamespace    internal/limitation/dynamic                        \nauthor       @v1bh475u                                          \nscope        file                                               \ndescription  This dynamic analysis trace describes a .NET file. \n                                                                \n             capa rules are not yet tuned for the .NET runtime, \n             so its analysis may be incomplete or misleading.   \n                                                                \nor:\n  format: dotnet\n\ncompile .NET assembly\nnamespace  load-code/dotnet                                                     \nauthor     anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information::Compile After      \n           Delivery [T1027.004]                                                 \nfunction @ token(0x6000025)\n  or:\n    api: System.CodeDom.Compiler.CodeDomProvider::CompileAssemblyFromSource @ token(0x6000025)+0xBE\n\ninvoke .NET assembly method\nnamespace  load-code/dotnet                                     \nauthor     anushka.virgaonkar@mandiant.com, mehunhoff@google.com\nscope      function                                             \natt&ck     Defense Evasion::Reflective Code Loading [T1620]     \nfunction @ token(0x6000026)\n  and:\n    format: dotnet\n    or:\n      api: System.Reflection.MethodBase::Invoke @ token(0x6000026)+0xC\n\ncompile CSharp in .NET\nnamespace  load-code/dotnet/csharp                                              \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information::Compile After      \n           Delivery [T1027.004]                                                 \nfunction @ token(0x6000025)\n  and:\n    match: compile .NET assembly @ token(0x6000025)\n      or:\n        api: System.CodeDom.Compiler.CodeDomProvider::CompileAssemblyFromSource @ token(0x6000025)+0xBE\n    api: Microsoft.CSharp.CSharpCodeProvider::ctor @ token(0x6000025)+0x0\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  format: dotnet\n\n\n\n"},"hashes":{"md5":"96afc9cdef3c623e0c5420e339c57283","sha1":"ccbdff85419e61987fdb7291f9966a046b0e4b25","sha256":"517ac5506a5488a1193686f66cb57ad3288c2258c510004edb2f361b674526cc"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 40</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 11058</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Ransomw\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"96afc9cdef3c623e0c5420e339c57283\",\n        \"sha256\": \"517ac5506a5488a1193686f66cb57ad3288c2258c510004edb2f361\",\n        \"arch\": \"i386\",\n        \"os\": \"any\",\n        \"format\": \"dotnet\"\n      }\n    },\n    {\n      \"id\": \"cap_reference_analysis_tools_strings\",\n      \"label\": \"reference analysis tools strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"label\": \"reference anti-VM strings targeting Xen\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_decode_data_using_base64_in__net\",\n      \"label\": \"decode data using Base64 in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decode Data::Base64 [C0053.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_System\",\n      \"label\": \"System\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decode Data::Base64 [C0053.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__10_matches_\",\n      \"label\": \"read file on Windows (10 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process__4_matches_\",\n      \"label\": \"terminate process (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal___net_file_limitation\",\n      \"label\": \"(internal) .NET file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author________v1bh475u\",\n      \"label\": \"author       @v1bh475u\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compile__net_assembly\",\n      \"label\": \"compile .NET assembly\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Compile After\",\n        \"Delivery [T1027.004]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Compile After\",\n        \"Delivery [T1027.004]\"\n      ]\n    },\n    {\n      \"id\": \"cap_invoke__net_assembly_method\",\n      \"label\": \"invoke .NET assembly method\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_compile_csharp_in__net\",\n      \"label\": \"compile CSharp in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Compile After\",\n        \"Delivery [T1027.004]\"\n      ]\n    },\n    {\n      \"id\": \"api_Microsoft\",\n      \"label\": \"Microsoft\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_compiled_to_the__net_platform\",\n      \"label\": \"compiled to the .NET platform\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_analysis_tools_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decode_data_using_base64_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__10_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal___net_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________v1bh475u\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compile__net_assembly\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_invoke__net_assembly_method\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compile_csharp_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_to_the__net_platform\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-10 01:33:13.244910\",\n    \"total_functions\": \"40\",\n    \"total_features\": \"11058\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-10 01:33:13"}
{"_id":{"$oid":"6a5000d50108394cb24cdd20"},"sha256":"2fd5b075ab9dffe8b421a4942ecdac322d8f0fceca597a644a6a9e631901e8bc","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":true,"path":"/tmp/sdm_capa_5jfshews/Trojan.Dropper.Gen-019f46cf44ca7e83b22b70b6b91c7586.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_5jfshews/Trojan.Dropper.Gen-019f46cf44ca7e83b22b70b6b91c7586.exe_very_verbose.txt"}},"outputs":{"normal":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"md5                     f88e9b7446a6e57943728cce3cc70720                        \nsha1                    0030e2b87acebaa040e3f872c13e39af88b733b9                \nsha256                  2fd5b075ab9dffe8b421a4942ecdac322d8f0fceca597a644a6a9e6…\npath                    /home/apogean/projects/malware/windows/all_runs/Trojan.…\ntimestamp               2026-07-10 01:42:59.732890                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEINal79G/rules                                   \nfunction count          85                                                      \nlibrary function count  0                                                       \ntotal feature count     25778                                                   \n\ncheck for time delay via GetTickCount\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    0x402EB2                                       \n\ncapture webcam image\nnamespace  collection/webcam\nscope      function         \nmatches    0x404747         \n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32\nscope      function                        \nmatches    0x405E7C                        \n\nencode data using XOR (2 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x405E92                      \n           0x405ECE                      \n\npackaged as a NSIS installer\nnamespace  executable/installer/nsis\nscope      file                     \n\naccept command line arguments\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x403121            \n\nopen clipboard\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x404F66                  \n\nwrite clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x404F66                  \n\nquery environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x401459                             \n\nget common file path (3 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x403121                    \n           0x4057BE                    \n           0x405AEE                    \n\nget file system object information\nnamespace  host-interaction/file-system\nscope      basic block                 \nmatches    0x403121                    \n\nset current directory (2 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x401459                    \n           0x403121                    \n\ncopy file (2 matches)\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    0x401459                         \n           0x403121                         \n\ncreate directory (3 matches)\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x401459                           \n           0x4030ED                           \n           0x403121                           \n\ndelete directory\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x4053D0                           \n\ndelete file (3 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x401459                           \n           0x403121                           \n           0x4053D0                           \n\ncheck if file exists (3 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x40357E                           \n           0x405686                           \n           0x405770                           \n\nenumerate files on Windows (2 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x401459                               \n           0x4053D0                               \n\nenumerate files recursively\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x4053D0                               \n\nget file attributes (5 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x40161A                         \n           0x403681                         \n           0x4056E3                         \n           0x405770                         \n           0x40578F                         \n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x402C74                         \n           0x405807                         \n\nget file version info\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x401459                         \n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x4015BD                         \n           0x40577F                         \n\nmove file\nnamespace  host-interaction/file-system/move\nscope      function                         \nmatches    0x401459                         \n\nread .ini file\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x401459                         \n\nread file on Windows (3 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x401459                         \n           0x4030A4                         \n           0x405807                         \n\nwrite file on Windows (3 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x401459                          \n           0x402EB2                          \n           0x405807                          \n\nfind graphical window\nnamespace  host-interaction/gui/window/find\nscope      instruction                     \nmatches    0x401C97                        \n\nget disk size\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x404232                         \n\nshutdown system\nnamespace  host-interaction/os\nscope      function           \nmatches    0x403121           \n\ncreate process on Windows (3 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x401E05                       \n           0x404114                       \n           0x4052EF                       \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x403121                          \n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x401459                 \n           0x402A7C                 \n\nquery or enumerate registry value (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x401459                 \n           0x4059A0                 \n\nset registry value\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x401459                        \n\ndelete registry key\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x402A7C                        \n\ndelete registry value\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x401459                        \n\ncreate thread\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x40511D                      \n\nlink function at runtime on Windows (2 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x401FE3               \n           0x405E34               \n\ncreate shortcut via IShellLink\nnamespace  persistence\nscope      function   \nmatches    0x401459   \n\n\n\n","very_verbose":"md5                     f88e9b7446a6e57943728cce3cc70720                        \nsha1                    0030e2b87acebaa040e3f872c13e39af88b733b9                \nsha256                  2fd5b075ab9dffe8b421a4942ecdac322d8f0fceca597a644a6a9e6…\npath                    /home/apogean/projects/malware/windows/all_runs/Trojan.…\ntimestamp               2026-07-10 01:43:09.018178                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIUiUaG7/rules                                   \nfunction count          85                                                      \nlibrary function count  0                                                       \ntotal feature count     25778                                                   \n\ncalculate modulo 256 via x86 assembly (2 matches, only showing first match of \nlibrary rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x402130\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x402130\n    or:\n      number: 0xFF @ 0x402130\n\ncontain loop (38 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401000\n  or:\n    characteristic: tight loop @ 0x401077\n\ncreate or open file (library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x4057B5\n  or:\n    api: CreateFile @ 0x4057B5\n\ncreate or open registry key (4 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x402347 in function 0x401459\n  or:\n    api: RegCreateKeyEx @ 0x402385\n\ndelay execution (2 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x401504 in function 0x401459\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x401505\n\nget OS version (library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x405AEE\n  or:\n    api: GetVersion @ 0x405B9F\n\ncheck for time delay via GetTickCount\nnamespace  anti-analysis/anti-debugging/debugger-detection                      \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check     \n           GetTickCount [B0001.032]                                             \nfunction @ 0x402EB2\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x402FA2\n        mnemonic: cmp @ 0x402FA5\n    count(api(GetTickCount)): 2 or more @ 0x402F10, 0x402F91\n\ncapture webcam image\nnamespace  collection/webcam                \nauthor     johnk3r                          \nscope      function                         \natt&ck     Collection::Video Capture [T1125]\nfunction @ 0x404747\n  or:\n    basic block:\n      and:\n        api: SendMessage @ 0x404A9C\n        number: 0x419 = WM_CAP_FILE_SAVEDIB @ 0x404A94\n\nwrite and execute a file\nnamespace              communication/c2/file-transfer               \nmaec/malware-category  launcher                                     \nauthor                 moritz.raabe@mandiant.com                    \nscope                  function                                     \nmbc                    Execution::Install Additional Program [B0023]\nfunction @ 0x401459\n  and:\n    match: host-interaction/file-system/write @ 0x401459\n      or:\n        and:\n          os: windows\n          optional:\n            basic block:\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401C43\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402684\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402355, 0x402374\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401548\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x40243B\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x40254A\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401CCE\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401C0F\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401A9A\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x40261B\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402325\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401EDC\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401D74, 0x401DAF\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401B27\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401523\n              or:\n                number: 0x40000000 = GENERIC_WRITE @ 0x4026EE\n                number: 0x2 = FILE_WRITE_DATA @ 0x4026EC\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401C2C\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402078\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x4021EF\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x40196F\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x4022F0\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401880\n              or:\n                number: 0x40000000 = GENERIC_WRITE @ 0x401806\n          or:\n            api: WriteFile @ 0x40253F, 0x40277D\n    match: host-interaction/process/create @ 0x401E05\n      or:\n        api: ShellExecute @ 0x401E4B\n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32 \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \nmbc        Data::Checksum::CRC32 [C0032.001]\nfunction @ 0x405E7C\n  or:\n    and:\n      number: 0x1 = bits in a byte @ 0x405E94, 0x405EA1, 0x405EC7\n      instruction:\n        and:\n          operand[1].number: 0x1 @ 0x405E94\n          or:\n            mnemonic: and @ 0x405E94\n      instruction:\n        and:\n          mnemonic: shr @ 0x405EA1\n          number: 0x1 @ 0x405EA1\n      characteristic: nzxor @ 0x405EA3, 0x405ED9, 0x405EE5\n      operand[1].number: 0xEDB88320 @ 0x405E9B\n\nencode data using XOR (2 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x405E92 in function 0x405E7C\n  and:\n    characteristic: tight loop @ 0x405E92\n    characteristic: nzxor @ 0x405EA3\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405ECE in function 0x405E7C\n  and:\n    characteristic: tight loop @ 0x405ECE\n    characteristic: nzxor @ 0x405ED9, 0x405EE5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\npackaged as a NSIS installer\nnamespace   executable/installer/nsis            \nauthor      moritz.raabe@mandiant.com            \nscope       file                                 \nreferences  https://nsis.sourceforge.io/Main_Page\nor:\n  substring: http://nsis.sf.net\n    - \"http://nsis.sf.net/NSIS_Error\" @ file+0x72E2\n\naccept command line arguments\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x403121\n  or:\n    api: GetCommandLine @ 0x40318F\n\nopen clipboard\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ 0x404F66\n  and:\n    api: OpenClipboard @ 0x40528C\n    optional:\n      api: CloseClipboard @ 0x4052E2\n\nwrite clipboard data\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \nmbc         Impact::Clipboard Modification [E1510]                              \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ 0x404F66\n  and:\n    optional:\n      match: open clipboard @ 0x404F66\n        and:\n          api: OpenClipboard @ 0x40528C\n          optional:\n            api: CloseClipboard @ 0x4052E2\n      api: EmptyClipboard @ 0x405292\n    or:\n      api: SetClipboardData @ 0x4052DC\n\nquery environment variable\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x401459\n  or:\n    api: ExpandEnvironmentStrings @ 0x401A34\n\nget common file path (3 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x403121\n  or:\n    api: GetTempPath @ 0x40325E\n    api: GetWindowsDirectory @ 0x403273\nfunction @ 0x4057BE\n  or:\n    api: GetTempFileName @ 0x4057EA\nfunction @ 0x405AEE\n  or:\n    api: GetSystemDirectory @ 0x405C17\n    api: GetWindowsDirectory @ 0x405C2A\n    api: SHGetSpecialFolderLocation @ 0x405C6A\n\nget file system object information\nnamespace  host-interaction/file-system                   \nauthor     michael.hunhoff@mandiant.com                   \nscope      basic block                                    \natt&ck     Discovery::File and Directory Discovery [T1083]\nbasic block @ 0x403121 in function 0x403121\n  or:\n    api: SHGetFileInfo @ 0x40317A\n\nset current directory (2 matches)\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x401459\n  or:\n    api: SetCurrentDirectory @ 0x40164A\nfunction @ 0x403121\n  or:\n    api: SetCurrentDirectory @ 0x40335B\n\ncopy file (2 matches)\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ 0x401459\n  or:\n    basic block:\n      and:\n        number: 0x2 = FO_COPY @ 0x4021EF\n        or:\n          api: SHFileOperation @ 0x402228\nfunction @ 0x403121\n  or:\n    api: CopyFile @ 0x4033B9\n\ncreate directory (3 matches)\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x401459\n  or:\n    api: CreateDirectory @ 0x401603\nfunction @ 0x4030ED\n  or:\n    api: CreateDirectory @ 0x40310E\nfunction @ 0x403121\n  or:\n    api: CreateDirectory @ 0x403354\n\ndelete directory\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ 0x4053D0\n  or:\n    api: RemoveDirectory @ 0x405574\n\ndelete file (3 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x401459\n  or:\n    api: DeleteFile @ 0x4027B0\nfunction @ 0x403121\n  or:\n    api: DeleteFile @ 0x403292, 0x4033A5\nfunction @ 0x4053D0\n  or:\n    api: DeleteFile @ 0x4053EE, 0x4054EB\n\ncheck if file exists (3 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x40357E\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x403682\n        instruction:\n          and:\n            mnemonic: cmp @ 0x403688\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x403688\nfunction @ 0x405686\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x4056E9\n        instruction:\n          and:\n            mnemonic: cmp @ 0x4056F1\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x4056F1\nfunction @ 0x405770\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x405774\n        instruction:\n          and:\n            mnemonic: cmp @ 0x40577A\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x40577A\n\nenumerate files on Windows (2 matches)\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ 0x401459\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x402693\n      or:\n        api: FindNextFile @ 0x40266E\n      optional:\n        api: FindClose @ 0x40264D\n        match: contain loop @ 0x401459\n          or:\n            characteristic: loop @ 0x401459\nfunction @ 0x4053D0\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x405470\n      or:\n        api: FindNextFile @ 0x405527\n      optional:\n        api: FindClose @ 0x405538\n        match: contain loop @ 0x4053D0\n          or:\n            characteristic: loop @ 0x4053D0\n            characteristic: recursive call @ 0x4053D0\n\nenumerate files recursively\nnamespace  host-interaction/file-system/files/list        \nauthor     @_re_fox, anushka.virgaonkar@mandiant.com      \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nmbc        Discovery::File and Directory Discovery [E1083]\nfunction @ 0x4053D0\n  and:\n    characteristic: recursive call @ 0x4053D0\n    or:\n      match: enumerate files on Windows @ 0x4053D0\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x405470\n            or:\n              api: FindNextFile @ 0x405527\n            optional:\n              api: FindClose @ 0x405538\n              match: contain loop @ 0x4053D0\n                or:\n                  characteristic: loop @ 0x4053D0\n                  characteristic: recursive call @ 0x4053D0\n\nget file attributes (5 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x40161A in function 0x401459\n  or:\n    api: GetFileAttributes @ 0x40161B\nbasic block @ 0x403681 in function 0x40357E\n  or:\n    api: GetFileAttributes @ 0x403682\nbasic block @ 0x4056E3 in function 0x405686\n  or:\n    api: GetFileAttributes @ 0x4056E9\nbasic block @ 0x405770 in function 0x405770\n  or:\n    api: GetFileAttributes @ 0x405774\nbasic block @ 0x40578F in function 0x40578F\n  or:\n    api: GetFileAttributes @ 0x405793\n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x402C74\n  or:\n    api: GetFileSize @ 0x402CED\nfunction @ 0x405807\n  or:\n    api: GetFileSize @ 0x4058D3\n\nget file version info\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x401459\n  and:\n    or:\n      api: GetFileVersionInfo @ 0x401F52\n    optional: = retrieve specified version information from the version-information resource\n      api: VerQueryValue @ 0x401F6B\n      or:\n        api: GetFileVersionInfoSize @ 0x401F1B\n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ 0x4015BD in function 0x401459\n  or:\n    api: SetFileAttributes @ 0x4015C8\nbasic block @ 0x40577F in function 0x405770\n  or:\n    api: SetFileAttributes @ 0x405786\n\nmove file\nnamespace  host-interaction/file-system/move                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Move File [C0063]                         \nfunction @ 0x401459\n  or:\n    api: MoveFile @ 0x401688\n\nread .ini file\nnamespace  host-interaction/file-system/read     \nauthor     @_re_fox, michael.hunhoff@mandiant.com\nscope      function                              \nmbc        File System::Read File [C0051]        \nfunction @ 0x401459\n  and:\n    optional:\n      api: GetFullPathName @ 0x4016D1\n    or:\n      api: GetPrivateProfileString @ 0x4022DB\n\nread file on Windows (3 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x401459\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x402596\nfunction @ 0x4030A4\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x4030BB\nfunction @ 0x405807\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x4058F8\n\nwrite file on Windows (3 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x401459\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401C43\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402684\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402355, 0x402374\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401548\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x40243B\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x40254A\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401CCE\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401C0F\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401A9A\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x40261B\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402325\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401EDC\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401D74, 0x401DAF\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401B27\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401523\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x4026EE\n            number: 0x2 = FILE_WRITE_DATA @ 0x4026EC\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401C2C\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402078\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4021EF\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x40196F\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4022F0\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401880\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x401806\n      or:\n        api: WriteFile @ 0x40253F, 0x40277D\nfunction @ 0x402EB2\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x402FFA, 0x403068\nfunction @ 0x405807\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x405950\n\nfind graphical window\nnamespace  host-interaction/gui/window/find               \nauthor     moritz.raabe@mandiant.com                      \nscope      instruction                                    \natt&ck     Discovery::Application Window Discovery [T1010]\ninstruction @ 0x401C97\n  or:\n    api: FindWindowEx @ 0x401C97\n\nget disk size\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ 0x404232\n  or:\n    api: GetDiskFreeSpace @ 0x404472\n\nshutdown system\nnamespace  host-interaction/os                   \nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \natt&ck     Impact::System Shutdown/Reboot [T1529]\nfunction @ 0x403121\n  or:\n    api: ExitWindowsEx @ 0x403477\n\ncreate process on Windows (3 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x401E05 in function 0x401459\n  or:\n    api: ShellExecute @ 0x401E4B\nbasic block @ 0x404114 in function 0x403F3B\n  or:\n    api: ShellExecute @ 0x40414B\nbasic block @ 0x4052EF in function 0x4052EF\n  or:\n    api: CreateProcess @ 0x405314\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x403121\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x403330, 0x40349A\n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ 0x401459\n  and:\n    optional:\n      match: create or open registry key @ 0x402347\n        or:\n          api: RegCreateKeyEx @ 0x402385\n    or:\n      api: RegEnumKey @ 0x402499\nfunction @ 0x402A7C\n  and:\n    optional:\n      match: create or open registry key @ 0x402A7C\n        or:\n          api: RegOpenKeyEx @ 0x402A9D\n    or:\n      api: RegEnumKey @ 0x402ABE\n\nquery or enumerate registry value (2 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x401459\n  and:\n    optional:\n      match: create or open registry key @ 0x402347\n        or:\n          api: RegCreateKeyEx @ 0x402385\n    or:\n      api: RegEnumValue @ 0x4024AC\n      api: RegQueryValueEx @ 0x402423\nfunction @ 0x4059A0\n  and:\n    optional:\n      match: create or open registry key @ 0x4059A0\n        or:\n          api: RegOpenKeyEx @ 0x4059C9\n    or:\n      api: RegQueryValueEx @ 0x4059EA\n\nset registry value\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x401459\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x402347\n          or:\n            api: RegCreateKeyEx @ 0x402385\n      or:\n        api: RegSetValueEx @ 0x4023DE\n\ndelete registry key\nnamespace  host-interaction/registry/delete                                \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\nscope      function                                                        \natt&ck     Defense Evasion::Modify Registry [T1112]                        \nmbc        Operating System::Registry::Delete Registry Key [C0036.002]     \nfunction @ 0x402A7C\n  and:\n    optional:\n      match: create or open registry key @ 0x402A7C\n        or:\n          api: RegOpenKeyEx @ 0x402A9D\n    or:\n      api: RegDeleteKey @ 0x402B31\n\ndelete registry value\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ 0x401459\n  and:\n    optional:\n      match: create or open registry key @ 0x402347\n        or:\n          api: RegCreateKeyEx @ 0x402385\n    or:\n      api: RegDeleteValue @ 0x40230A\n\ncreate thread\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x40511D in function 0x404F66\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x405138\n\n(internal) installer file limitation\nnamespace    internal/limitation/static                                         \nauthor       william.ballenthin@mandiant.com                                    \nscope        file                                                               \ndescription  This sample appears to be an installer.                            \n                                                                                \n             capa cannot handle installers well. This means the results may be  \n             misleading or incomplete.                                          \n             You should try to understand the install mechanism and analyze     \n             created files with capa.                                           \n                                                                                \nor:\n  match: executable/installer @ global\n    or:\n      substring: http://nsis.sf.net\n        - \"http://nsis.sf.net/NSIS_Error\" @ file+0x72E2\n\nlink function at runtime on Windows (2 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x401FE3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401FE3\ninstruction @ 0x405E34\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x405E34\n\ncreate shortcut via IShellLink\nnamespace   persistence                                                         \nauthor      matthew.williams@mandiant.com                                       \nscope       function                                                            \natt&ck      Persistence::Boot or Logon Autostart Execution::Shortcut            \n            Modification [T1547.009]                                            \nreferences  https://docs.microsoft.com/en-us/windows/win32/shell/links#creating…\nfunction @ 0x401459\n  and:\n    offset: 0x50 = psl->SetPath @ 0x4020EA\n    offset: 0x18 = ppf->Save @ 0x401EFB, 0x402184, 0x4027F2, 0x40281D\n    api: CoCreateInstance @ 0x4020BA\n    bytes: 0114020000000000c000000000000046 = CLSID_ShellLink @ 0x4020B5\n    bytes: 0b01000000000000c000000000000046 = IID_IPersistFile @ 0x4020CF\n    or:\n      bytes: ee14020000000000c000000000000046 = IID_IShellLinkA @ 0x4020AD\n\n\n\n"},"hashes":{"md5":"f88e9b7446a6e57943728cce3cc70720","sha1":"0030e2b87acebaa040e3f872c13e39af88b733b9","sha256":"2fd5b075ab9dffe8b421a4942ecdac322d8f0fceca597a644a6a9e631901e8bc"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 85</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 25778</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Trojan.\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"f88e9b7446a6e57943728cce3cc70720\",\n        \"sha256\": \"2fd5b075ab9dffe8b421a4942ecdac322d8f0fceca597a644a6a9e6\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_library_rule_\",\n      \"label\": \"library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Modulo [C0058]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_loop__38_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (38 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401000\",\n      \"label\": \"Function 0x401000\",\n      \"type\": \"function\",\n      \"address\": \"0x401000\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x402347\",\n      \"label\": \"Block 0x402347\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x402347\"\n    },\n    {\n      \"id\": \"api_RegCreateKeyEx\",\n      \"label\": \"RegCreateKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401504\",\n      \"label\": \"Block 0x401504\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401504\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_check_for_time_delay_via_gettickcount\",\n      \"label\": \"check for time delay via GetTickCount\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"GetTickCount [B0001.032]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402EB2\",\n      \"label\": \"Function 0x402EB2\",\n      \"type\": \"function\",\n      \"address\": \"0x402EB2\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"GetTickCount [B0001.032]\"\n      ]\n    },\n    {\n      \"id\": \"cap_capture_webcam_image\",\n      \"label\": \"capture webcam image\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Video Capture [T1125]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404747\",\n      \"label\": \"Function 0x404747\",\n      \"type\": \"function\",\n      \"address\": \"0x404747\"\n    },\n    {\n      \"id\": \"api_SendMessage\",\n      \"label\": \"SendMessage\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____johnk3r\",\n      \"label\": \"author     johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Video Capture [T1125]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_and_execute_a_file\",\n      \"label\": \"write and execute a file\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401459\",\n      \"label\": \"Function 0x401459\",\n      \"type\": \"function\",\n      \"address\": \"0x401459\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_ShellExecute\",\n      \"label\": \"ShellExecute\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_maec_malware_category__launcher\",\n      \"label\": \"maec/malware-category  launcher\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_with_crc32\",\n      \"label\": \"hash data with CRC32\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405E7C\",\n      \"label\": \"Function 0x405E7C\",\n      \"type\": \"function\",\n      \"address\": \"0x405E7C\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_packaged_as_a_nsis_installer\",\n      \"label\": \"packaged as a NSIS installer\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments\",\n      \"label\": \"accept command line arguments\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x403121\",\n      \"label\": \"Function 0x403121\",\n      \"type\": \"function\",\n      \"address\": \"0x403121\"\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_open_clipboard\",\n      \"label\": \"open clipboard\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404F66\",\n      \"label\": \"Function 0x404F66\",\n      \"type\": \"function\",\n      \"address\": \"0x404F66\"\n    },\n    {\n      \"id\": \"api_OpenClipboard\",\n      \"label\": \"OpenClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CloseClipboard\",\n      \"label\": \"CloseClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_write_clipboard_data\",\n      \"label\": \"write clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"api_SetClipboardData\",\n      \"label\": \"SetClipboardData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_EmptyClipboard\",\n      \"label\": \"EmptyClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable\",\n      \"label\": \"query environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_ExpandEnvironmentStrings\",\n      \"label\": \"ExpandEnvironmentStrings\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path__3_matches_\",\n      \"label\": \"get common file path (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4057BE\",\n      \"label\": \"Function 0x4057BE\",\n      \"type\": \"function\",\n      \"address\": \"0x4057BE\"\n    },\n    {\n      \"id\": \"func_0x405AEE\",\n      \"label\": \"Function 0x405AEE\",\n      \"type\": \"function\",\n      \"address\": \"0x405AEE\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempFileName\",\n      \"label\": \"GetTempFileName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHGetSpecialFolderLocation\",\n      \"label\": \"SHGetSpecialFolderLocation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_system_object_information\",\n      \"label\": \"get file system object information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x403121\",\n      \"label\": \"Block 0x403121\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x403121\"\n    },\n    {\n      \"id\": \"api_SHGetFileInfo\",\n      \"label\": \"SHGetFileInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_current_directory__2_matches_\",\n      \"label\": \"set current directory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_SetCurrentDirectory\",\n      \"label\": \"SetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_copy_file__2_matches_\",\n      \"label\": \"copy file (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"api_CopyFile\",\n      \"label\": \"CopyFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHFileOperation\",\n      \"label\": \"SHFileOperation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory__3_matches_\",\n      \"label\": \"create directory (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4030ED\",\n      \"label\": \"Function 0x4030ED\",\n      \"type\": \"function\",\n      \"address\": \"0x4030ED\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_delete_directory\",\n      \"label\": \"delete directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4053D0\",\n      \"label\": \"Function 0x4053D0\",\n      \"type\": \"function\",\n      \"address\": \"0x4053D0\"\n    },\n    {\n      \"id\": \"api_RemoveDirectory\",\n      \"label\": \"RemoveDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_file__3_matches_\",\n      \"label\": \"delete file (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__3_matches_\",\n      \"label\": \"check if file exists (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405770\",\n      \"label\": \"Function 0x405770\",\n      \"type\": \"function\",\n      \"address\": \"0x405770\"\n    },\n    {\n      \"id\": \"func_0x405686\",\n      \"label\": \"Function 0x405686\",\n      \"type\": \"function\",\n      \"address\": \"0x405686\"\n    },\n    {\n      \"id\": \"func_0x40357E\",\n      \"label\": \"Function 0x40357E\",\n      \"type\": \"function\",\n      \"address\": \"0x40357E\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"label\": \"enumerate files on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindClose\",\n      \"label\": \"FindClose\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindFirstFile\",\n      \"label\": \"FindFirstFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindNextFile\",\n      \"label\": \"FindNextFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_recursively\",\n      \"label\": \"enumerate files recursively\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     @_re_fox, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes__5_matches_\",\n      \"label\": \"get file attributes (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40161A\",\n      \"label\": \"Block 0x40161A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40161A\"\n    },\n    {\n      \"id\": \"bb_0x40578F\",\n      \"label\": \"Block 0x40578F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40578F\"\n    },\n    {\n      \"id\": \"bb_0x403681\",\n      \"label\": \"Block 0x403681\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x403681\"\n    },\n    {\n      \"id\": \"bb_0x4056E3\",\n      \"label\": \"Block 0x4056E3\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4056E3\"\n    },\n    {\n      \"id\": \"bb_0x405770\",\n      \"label\": \"Block 0x405770\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x405770\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size__2_matches_\",\n      \"label\": \"get file size (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405807\",\n      \"label\": \"Function 0x405807\",\n      \"type\": \"function\",\n      \"address\": \"0x405807\"\n    },\n    {\n      \"id\": \"func_0x402C74\",\n      \"label\": \"Function 0x402C74\",\n      \"type\": \"function\",\n      \"address\": \"0x402C74\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_file_version_info\",\n      \"label\": \"get file version info\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetFileVersionInfoSize\",\n      \"label\": \"GetFileVersionInfoSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfo\",\n      \"label\": \"GetFileVersionInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_VerQueryValue\",\n      \"label\": \"VerQueryValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_file_attributes__2_matches_\",\n      \"label\": \"set file attributes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40577F\",\n      \"label\": \"Block 0x40577F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40577F\"\n    },\n    {\n      \"id\": \"bb_0x4015BD\",\n      \"label\": \"Block 0x4015BD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4015BD\"\n    },\n    {\n      \"id\": \"api_SetFileAttributes\",\n      \"label\": \"SetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_move_file\",\n      \"label\": \"move file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"api_MoveFile\",\n      \"label\": \"MoveFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read__ini_file\",\n      \"label\": \"read .ini file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetPrivateProfileString\",\n      \"label\": \"GetPrivateProfileString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFullPathName\",\n      \"label\": \"GetFullPathName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__3_matches_\",\n      \"label\": \"read file on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4030A4\",\n      \"label\": \"Function 0x4030A4\",\n      \"type\": \"function\",\n      \"address\": \"0x4030A4\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__3_matches_\",\n      \"label\": \"write file on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_graphical_window\",\n      \"label\": \"find graphical window\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindWindowEx\",\n      \"label\": \"FindWindowEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_size\",\n      \"label\": \"get disk size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404232\",\n      \"label\": \"Function 0x404232\",\n      \"type\": \"function\",\n      \"address\": \"0x404232\"\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpace\",\n      \"label\": \"GetDiskFreeSpace\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_shutdown_system\",\n      \"label\": \"shutdown system\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::System Shutdown/Reboot [T1529]\"\n      ]\n    },\n    {\n      \"id\": \"api_ExitWindowsEx\",\n      \"label\": \"ExitWindowsEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__3_matches_\",\n      \"label\": \"create process on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x404114\",\n      \"label\": \"Block 0x404114\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x404114\"\n    },\n    {\n      \"id\": \"bb_0x401E05\",\n      \"label\": \"Block 0x401E05\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401E05\"\n    },\n    {\n      \"id\": \"bb_0x4052EF\",\n      \"label\": \"Block 0x4052EF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4052EF\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"api_ExitProcess\",\n      \"label\": \"ExitProcess\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"label\": \"query or enumerate registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402A7C\",\n      \"label\": \"Function 0x402A7C\",\n      \"type\": \"function\",\n      \"address\": \"0x402A7C\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"api_RegEnumKey\",\n      \"label\": \"RegEnumKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"label\": \"query or enumerate registry value (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4059A0\",\n      \"label\": \"Function 0x4059A0\",\n      \"type\": \"function\",\n      \"address\": \"0x4059A0\"\n    },\n    {\n      \"id\": \"api_RegEnumValue\",\n      \"label\": \"RegEnumValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value\",\n      \"label\": \"set registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delete_registry_key\",\n      \"label\": \"delete registry key\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegDeleteKey\",\n      \"label\": \"RegDeleteKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_value\",\n      \"label\": \"delete registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegDeleteValue\",\n      \"label\": \"RegDeleteValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_thread\",\n      \"label\": \"create thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40511D\",\n      \"label\": \"Block 0x40511D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40511D\"\n    },\n    {\n      \"id\": \"api_CreateThread\",\n      \"label\": \"CreateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal__installer_file_limitation\",\n      \"label\": \"(internal) installer file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__2_matches_\",\n      \"label\": \"link function at runtime on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_shortcut_via_ishelllink\",\n      \"label\": \"create shortcut via IShellLink\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    },\n    {\n      \"id\": \"api_CoCreateInstance\",\n      \"label\": \"CoCreateInstance\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__38_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__38_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x402347\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x401504\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_time_delay_via_gettickcount\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount\",\n      \"target\": \"func_0x402EB2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x402EB2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_capture_webcam_image\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_capture_webcam_image\",\n      \"target\": \"func_0x404747\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404747\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____johnk3r\",\n      \"target\": \"func_0x404747\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404747\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_and_execute_a_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_and_execute_a_file\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_ShellExecute\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_maec_malware_category__launcher\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_maec_malware_category__launcher\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_ShellExecute\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_crc32\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_with_crc32\",\n      \"target\": \"func_0x405E7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x405E7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_packaged_as_a_nsis_installer\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_clipboard\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_clipboard\",\n      \"target\": \"func_0x404F66\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x404F66\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_clipboard_data\",\n      \"target\": \"func_0x404F66\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404F66\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x4057BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x405AEE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4057BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405AEE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_system_object_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_system_object_information\",\n      \"target\": \"bb_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_current_directory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__2_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__2_matches_\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_copy_file__2_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_copy_file__2_matches_\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory__3_matches_\",\n      \"target\": \"func_0x4030ED\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__3_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__3_matches_\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4030ED\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4030ED\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4030ED\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_directory\",\n      \"target\": \"func_0x4053D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4053D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x4053D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4053D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x405770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x405686\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x40357E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405770\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405686\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40357E\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405686\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40357E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405770\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405686\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40357E\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"target\": \"func_0x4053D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4053D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_recursively\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively\",\n      \"target\": \"func_0x4053D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4053D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x40161A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x40578F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x403681\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x4056E3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x405770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40161A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40578F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x403681\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4056E3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x405770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x405807\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x402C74\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405807\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402C74\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405807\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402C74\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405807\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402C74\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_version_info\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_version_info\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__2_matches_\",\n      \"target\": \"bb_0x40577F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__2_matches_\",\n      \"target\": \"bb_0x4015BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40577F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4015BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_move_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_move_file\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read__ini_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read__ini_file\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_GetFullPathName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_GetFullPathName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__3_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__3_matches_\",\n      \"target\": \"func_0x405807\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__3_matches_\",\n      \"target\": \"func_0x4030A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405807\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4030A4\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405807\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4030A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405807\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4030A4\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__3_matches_\",\n      \"target\": \"func_0x402EB2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__3_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__3_matches_\",\n      \"target\": \"func_0x405807\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402EB2\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405807\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402EB2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405807\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402EB2\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405807\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_graphical_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_size\",\n      \"target\": \"func_0x404232\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404232\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404232\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404232\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_shutdown_system\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_shutdown_system\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__3_matches_\",\n      \"target\": \"bb_0x404114\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__3_matches_\",\n      \"target\": \"bb_0x401E05\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__3_matches_\",\n      \"target\": \"bb_0x4052EF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x404114\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x401E05\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4052EF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"target\": \"func_0x402A7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x402A7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"target\": \"func_0x4059A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4059A0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4059A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4059A0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key\",\n      \"target\": \"func_0x402A7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x402A7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread\",\n      \"target\": \"bb_0x40511D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40511D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal__installer_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_shortcut_via_ishelllink\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_shortcut_via_ishelllink\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______matthew_williams_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-10 01:43:09.018178\",\n    \"total_functions\": \"85\",\n    \"total_features\": \"25778\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-10 01:43:09"}
{"_id":{"$oid":"6a50027a0108394cb24cdd22"},"sha256":"d24d79011d003dc7a4cadbc1b7b3efb89947f9a84f814c6739a01c1c38e227b8","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":true,"path":"/tmp/sdm_capa_w3415bml/Trojan.NSIS.Win32-019f46cf7cd476728ac181ce86697559.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_w3415bml/Trojan.NSIS.Win32-019f46cf7cd476728ac181ce86697559.exe_very_verbose.txt"}},"outputs":{"normal":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"md5                     663fbf2a248971ea69c6234480a4bdcb                        \nsha1                    1468417788f4e006b8983add7ab339e2f661b620                \nsha256                  d24d79011d003dc7a4cadbc1b7b3efb89947f9a84f814c6739a01c1…\npath                    /home/apogean/projects/malware/windows/all_runs/Trojan.…\ntimestamp               2026-07-10 01:49:57.325570                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIFab8Fl/rules                                   \nfunction count          85                                                      \nlibrary function count  0                                                       \ntotal feature count     27205                                                   \n\nreference analysis tools strings\nnamespace  anti-analysis\nscope      file         \n\ncheck for time delay via GetTickCount\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    0x402EB2                                       \n\ncapture webcam image\nnamespace  collection/webcam\nscope      function         \nmatches    0x404747         \n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32\nscope      function                        \nmatches    0x405E7C                        \n\nencode data using XOR (2 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x405E92                      \n           0x405ECE                      \n\npackaged as a NSIS installer\nnamespace  executable/installer/nsis\nscope      file                     \n\naccept command line arguments\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x403121            \n\nopen clipboard\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x404F66                  \n\nwrite clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x404F66                  \n\nquery environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x401459                             \n\nget common file path (3 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x403121                    \n           0x4057BE                    \n           0x405AEE                    \n\nget file system object information\nnamespace  host-interaction/file-system\nscope      basic block                 \nmatches    0x403121                    \n\nset current directory (2 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x401459                    \n           0x403121                    \n\ncopy file (2 matches)\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    0x401459                         \n           0x403121                         \n\ncreate directory (3 matches)\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x401459                           \n           0x4030ED                           \n           0x403121                           \n\ndelete directory\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x4053D0                           \n\ndelete file (3 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x401459                           \n           0x403121                           \n           0x4053D0                           \n\ncheck if file exists (3 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x40357E                           \n           0x405686                           \n           0x405770                           \n\nenumerate files on Windows (2 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x401459                               \n           0x4053D0                               \n\nenumerate files recursively\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x4053D0                               \n\nget file attributes (5 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x40161A                         \n           0x403681                         \n           0x4056E3                         \n           0x405770                         \n           0x40578F                         \n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x402C74                         \n           0x405807                         \n\nget file version info\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x401459                         \n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x4015BD                         \n           0x40577F                         \n\nmove file\nnamespace  host-interaction/file-system/move\nscope      function                         \nmatches    0x401459                         \n\nread .ini file\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x401459                         \n\nread file on Windows (3 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x401459                         \n           0x4030A4                         \n           0x405807                         \n\nwrite file on Windows (3 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x401459                          \n           0x402EB2                          \n           0x405807                          \n\nfind graphical window\nnamespace  host-interaction/gui/window/find\nscope      instruction                     \nmatches    0x401C97                        \n\nget disk size\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x404232                         \n\nshutdown system\nnamespace  host-interaction/os\nscope      function           \nmatches    0x403121           \n\ncreate process on Windows (3 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x401E05                       \n           0x404114                       \n           0x4052EF                       \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x403121                          \n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x401459                 \n           0x402A7C                 \n\nquery or enumerate registry value (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x401459                 \n           0x4059A0                 \n\nset registry value\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x401459                        \n\ndelete registry key\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x402A7C                        \n\ndelete registry value\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x401459                        \n\ncreate thread\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x40511D                      \n\nlink function at runtime on Windows (2 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x401FE3               \n           0x405E34               \n\ncreate shortcut via IShellLink\nnamespace  persistence\nscope      function   \nmatches    0x401459   \n\n\n\n","very_verbose":"md5                     663fbf2a248971ea69c6234480a4bdcb                        \nsha1                    1468417788f4e006b8983add7ab339e2f661b620                \nsha256                  d24d79011d003dc7a4cadbc1b7b3efb89947f9a84f814c6739a01c1…\npath                    /home/apogean/projects/malware/windows/all_runs/Trojan.…\ntimestamp               2026-07-10 01:50:09.122938                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEInSbi3r/rules                                   \nfunction count          85                                                      \nlibrary function count  0                                                       \ntotal feature count     27205                                                   \n\ncalculate modulo 256 via x86 assembly (2 matches, only showing first match of \nlibrary rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x402130\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x402130\n    or:\n      number: 0xFF @ 0x402130\n\ncontain loop (38 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401000\n  or:\n    characteristic: tight loop @ 0x401077\n\ncreate or open file (library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x4057B5\n  or:\n    api: CreateFile @ 0x4057B5\n\ncreate or open registry key (4 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x402347 in function 0x401459\n  or:\n    api: RegCreateKeyEx @ 0x402385\n\ndelay execution (2 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x401504 in function 0x401459\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x401505\n\nget OS version (library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x405AEE\n  or:\n    api: GetVersion @ 0x405B9F\n\nreference analysis tools strings\nnamespace   anti-analysis                                                       \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \nmbc         Discovery::Analysis Tool Discovery::Process detection [B0013.001]   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /(?<!\\w)ida?(\\.exe)?$/i\n    - \"!IDa\" @ file+0xD6A3\n    - \"IDAT\" @ file+0xF91A, file+0x11926, file+0x1593E, file+0x1794A, and 1 more...\n\ncheck for time delay via GetTickCount\nnamespace  anti-analysis/anti-debugging/debugger-detection                      \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check     \n           GetTickCount [B0001.032]                                             \nfunction @ 0x402EB2\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x402FA2\n        mnemonic: cmp @ 0x402FA5\n    count(api(GetTickCount)): 2 or more @ 0x402F10, 0x402F91\n\ncapture webcam image\nnamespace  collection/webcam                \nauthor     johnk3r                          \nscope      function                         \natt&ck     Collection::Video Capture [T1125]\nfunction @ 0x404747\n  or:\n    basic block:\n      and:\n        api: SendMessage @ 0x404A9C\n        number: 0x419 = WM_CAP_FILE_SAVEDIB @ 0x404A94\n\nwrite and execute a file\nnamespace              communication/c2/file-transfer               \nmaec/malware-category  launcher                                     \nauthor                 moritz.raabe@mandiant.com                    \nscope                  function                                     \nmbc                    Execution::Install Additional Program [B0023]\nfunction @ 0x401459\n  and:\n    match: host-interaction/file-system/write @ 0x401459\n      or:\n        and:\n          os: windows\n          optional:\n            basic block:\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401C43\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402684\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402355, 0x402374\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401548\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x40243B\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x40254A\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401CCE\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401C0F\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401A9A\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x40261B\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402325\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401EDC\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401D74, 0x401DAF\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401B27\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401523\n              or:\n                number: 0x40000000 = GENERIC_WRITE @ 0x4026EE\n                number: 0x2 = FILE_WRITE_DATA @ 0x4026EC\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401C2C\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x402078\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x4021EF\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x40196F\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x4022F0\n              or:\n                number: 0x2 = FILE_WRITE_DATA @ 0x401880\n              or:\n                number: 0x40000000 = GENERIC_WRITE @ 0x401806\n          or:\n            api: WriteFile @ 0x40253F, 0x40277D\n    match: host-interaction/process/create @ 0x401E05\n      or:\n        api: ShellExecute @ 0x401E4B\n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32 \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \nmbc        Data::Checksum::CRC32 [C0032.001]\nfunction @ 0x405E7C\n  or:\n    and:\n      number: 0x1 = bits in a byte @ 0x405E94, 0x405EA1, 0x405EC7\n      instruction:\n        and:\n          operand[1].number: 0x1 @ 0x405E94\n          or:\n            mnemonic: and @ 0x405E94\n      instruction:\n        and:\n          mnemonic: shr @ 0x405EA1\n          number: 0x1 @ 0x405EA1\n      characteristic: nzxor @ 0x405EA3, 0x405ED9, 0x405EE5\n      operand[1].number: 0xEDB88320 @ 0x405E9B\n\nencode data using XOR (2 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x405E92 in function 0x405E7C\n  and:\n    characteristic: tight loop @ 0x405E92\n    characteristic: nzxor @ 0x405EA3\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x405ECE in function 0x405E7C\n  and:\n    characteristic: tight loop @ 0x405ECE\n    characteristic: nzxor @ 0x405ED9, 0x405EE5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\npackaged as a NSIS installer\nnamespace   executable/installer/nsis            \nauthor      moritz.raabe@mandiant.com            \nscope       file                                 \nreferences  https://nsis.sourceforge.io/Main_Page\nor:\n  substring: http://nsis.sf.net\n    - \"http://nsis.sf.net/NSIS_Error\" @ file+0x72E2\n\naccept command line arguments\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x403121\n  or:\n    api: GetCommandLine @ 0x40318F\n\nopen clipboard\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ 0x404F66\n  and:\n    api: OpenClipboard @ 0x40528C\n    optional:\n      api: CloseClipboard @ 0x4052E2\n\nwrite clipboard data\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \nmbc         Impact::Clipboard Modification [E1510]                              \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ 0x404F66\n  and:\n    optional:\n      match: open clipboard @ 0x404F66\n        and:\n          api: OpenClipboard @ 0x40528C\n          optional:\n            api: CloseClipboard @ 0x4052E2\n      api: EmptyClipboard @ 0x405292\n    or:\n      api: SetClipboardData @ 0x4052DC\n\nquery environment variable\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x401459\n  or:\n    api: ExpandEnvironmentStrings @ 0x401A34\n\nget common file path (3 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x403121\n  or:\n    api: GetTempPath @ 0x40325E\n    api: GetWindowsDirectory @ 0x403273\nfunction @ 0x4057BE\n  or:\n    api: GetTempFileName @ 0x4057EA\nfunction @ 0x405AEE\n  or:\n    api: GetSystemDirectory @ 0x405C17\n    api: GetWindowsDirectory @ 0x405C2A\n    api: SHGetSpecialFolderLocation @ 0x405C6A\n\nget file system object information\nnamespace  host-interaction/file-system                   \nauthor     michael.hunhoff@mandiant.com                   \nscope      basic block                                    \natt&ck     Discovery::File and Directory Discovery [T1083]\nbasic block @ 0x403121 in function 0x403121\n  or:\n    api: SHGetFileInfo @ 0x40317A\n\nset current directory (2 matches)\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x401459\n  or:\n    api: SetCurrentDirectory @ 0x40164A\nfunction @ 0x403121\n  or:\n    api: SetCurrentDirectory @ 0x40335B\n\ncopy file (2 matches)\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ 0x401459\n  or:\n    basic block:\n      and:\n        number: 0x2 = FO_COPY @ 0x4021EF\n        or:\n          api: SHFileOperation @ 0x402228\nfunction @ 0x403121\n  or:\n    api: CopyFile @ 0x4033B9\n\ncreate directory (3 matches)\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x401459\n  or:\n    api: CreateDirectory @ 0x401603\nfunction @ 0x4030ED\n  or:\n    api: CreateDirectory @ 0x40310E\nfunction @ 0x403121\n  or:\n    api: CreateDirectory @ 0x403354\n\ndelete directory\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ 0x4053D0\n  or:\n    api: RemoveDirectory @ 0x405574\n\ndelete file (3 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x401459\n  or:\n    api: DeleteFile @ 0x4027B0\nfunction @ 0x403121\n  or:\n    api: DeleteFile @ 0x403292, 0x4033A5\nfunction @ 0x4053D0\n  or:\n    api: DeleteFile @ 0x4053EE, 0x4054EB\n\ncheck if file exists (3 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x40357E\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x403682\n        instruction:\n          and:\n            mnemonic: cmp @ 0x403688\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x403688\nfunction @ 0x405686\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x4056E9\n        instruction:\n          and:\n            mnemonic: cmp @ 0x4056F1\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x4056F1\nfunction @ 0x405770\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x405774\n        instruction:\n          and:\n            mnemonic: cmp @ 0x40577A\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x40577A\n\nenumerate files on Windows (2 matches)\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ 0x401459\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x402693\n      or:\n        api: FindNextFile @ 0x40266E\n      optional:\n        api: FindClose @ 0x40264D\n        match: contain loop @ 0x401459\n          or:\n            characteristic: loop @ 0x401459\nfunction @ 0x4053D0\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x405470\n      or:\n        api: FindNextFile @ 0x405527\n      optional:\n        api: FindClose @ 0x405538\n        match: contain loop @ 0x4053D0\n          or:\n            characteristic: loop @ 0x4053D0\n            characteristic: recursive call @ 0x4053D0\n\nenumerate files recursively\nnamespace  host-interaction/file-system/files/list        \nauthor     @_re_fox, anushka.virgaonkar@mandiant.com      \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nmbc        Discovery::File and Directory Discovery [E1083]\nfunction @ 0x4053D0\n  and:\n    characteristic: recursive call @ 0x4053D0\n    or:\n      match: enumerate files on Windows @ 0x4053D0\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x405470\n            or:\n              api: FindNextFile @ 0x405527\n            optional:\n              api: FindClose @ 0x405538\n              match: contain loop @ 0x4053D0\n                or:\n                  characteristic: loop @ 0x4053D0\n                  characteristic: recursive call @ 0x4053D0\n\nget file attributes (5 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x40161A in function 0x401459\n  or:\n    api: GetFileAttributes @ 0x40161B\nbasic block @ 0x403681 in function 0x40357E\n  or:\n    api: GetFileAttributes @ 0x403682\nbasic block @ 0x4056E3 in function 0x405686\n  or:\n    api: GetFileAttributes @ 0x4056E9\nbasic block @ 0x405770 in function 0x405770\n  or:\n    api: GetFileAttributes @ 0x405774\nbasic block @ 0x40578F in function 0x40578F\n  or:\n    api: GetFileAttributes @ 0x405793\n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x402C74\n  or:\n    api: GetFileSize @ 0x402CED\nfunction @ 0x405807\n  or:\n    api: GetFileSize @ 0x4058D3\n\nget file version info\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x401459\n  and:\n    or:\n      api: GetFileVersionInfo @ 0x401F52\n    optional: = retrieve specified version information from the version-information resource\n      api: VerQueryValue @ 0x401F6B\n      or:\n        api: GetFileVersionInfoSize @ 0x401F1B\n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ 0x4015BD in function 0x401459\n  or:\n    api: SetFileAttributes @ 0x4015C8\nbasic block @ 0x40577F in function 0x405770\n  or:\n    api: SetFileAttributes @ 0x405786\n\nmove file\nnamespace  host-interaction/file-system/move                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Move File [C0063]                         \nfunction @ 0x401459\n  or:\n    api: MoveFile @ 0x401688\n\nread .ini file\nnamespace  host-interaction/file-system/read     \nauthor     @_re_fox, michael.hunhoff@mandiant.com\nscope      function                              \nmbc        File System::Read File [C0051]        \nfunction @ 0x401459\n  and:\n    optional:\n      api: GetFullPathName @ 0x4016D1\n    or:\n      api: GetPrivateProfileString @ 0x4022DB\n\nread file on Windows (3 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x401459\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x402596\nfunction @ 0x4030A4\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x4030BB\nfunction @ 0x405807\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x4058F8\n\nwrite file on Windows (3 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x401459\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401C43\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402684\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402355, 0x402374\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401548\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x40243B\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x40254A\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401CCE\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401C0F\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401A9A\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x40261B\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402325\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401EDC\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401D74, 0x401DAF\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401B27\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401523\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x4026EE\n            number: 0x2 = FILE_WRITE_DATA @ 0x4026EC\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401C2C\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x402078\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4021EF\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x40196F\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x4022F0\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x401880\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x401806\n      or:\n        api: WriteFile @ 0x40253F, 0x40277D\nfunction @ 0x402EB2\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x402FFA, 0x403068\nfunction @ 0x405807\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x405950\n\nfind graphical window\nnamespace  host-interaction/gui/window/find               \nauthor     moritz.raabe@mandiant.com                      \nscope      instruction                                    \natt&ck     Discovery::Application Window Discovery [T1010]\ninstruction @ 0x401C97\n  or:\n    api: FindWindowEx @ 0x401C97\n\nget disk size\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ 0x404232\n  or:\n    api: GetDiskFreeSpace @ 0x404472\n\nshutdown system\nnamespace  host-interaction/os                   \nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \natt&ck     Impact::System Shutdown/Reboot [T1529]\nfunction @ 0x403121\n  or:\n    api: ExitWindowsEx @ 0x403477\n\ncreate process on Windows (3 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x401E05 in function 0x401459\n  or:\n    api: ShellExecute @ 0x401E4B\nbasic block @ 0x404114 in function 0x403F3B\n  or:\n    api: ShellExecute @ 0x40414B\nbasic block @ 0x4052EF in function 0x4052EF\n  or:\n    api: CreateProcess @ 0x405314\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x403121\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x403330, 0x40349A\n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ 0x401459\n  and:\n    optional:\n      match: create or open registry key @ 0x402347\n        or:\n          api: RegCreateKeyEx @ 0x402385\n    or:\n      api: RegEnumKey @ 0x402499\nfunction @ 0x402A7C\n  and:\n    optional:\n      match: create or open registry key @ 0x402A7C\n        or:\n          api: RegOpenKeyEx @ 0x402A9D\n    or:\n      api: RegEnumKey @ 0x402ABE\n\nquery or enumerate registry value (2 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x401459\n  and:\n    optional:\n      match: create or open registry key @ 0x402347\n        or:\n          api: RegCreateKeyEx @ 0x402385\n    or:\n      api: RegEnumValue @ 0x4024AC\n      api: RegQueryValueEx @ 0x402423\nfunction @ 0x4059A0\n  and:\n    optional:\n      match: create or open registry key @ 0x4059A0\n        or:\n          api: RegOpenKeyEx @ 0x4059C9\n    or:\n      api: RegQueryValueEx @ 0x4059EA\n\nset registry value\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x401459\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x402347\n          or:\n            api: RegCreateKeyEx @ 0x402385\n      or:\n        api: RegSetValueEx @ 0x4023DE\n\ndelete registry key\nnamespace  host-interaction/registry/delete                                \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\nscope      function                                                        \natt&ck     Defense Evasion::Modify Registry [T1112]                        \nmbc        Operating System::Registry::Delete Registry Key [C0036.002]     \nfunction @ 0x402A7C\n  and:\n    optional:\n      match: create or open registry key @ 0x402A7C\n        or:\n          api: RegOpenKeyEx @ 0x402A9D\n    or:\n      api: RegDeleteKey @ 0x402B31\n\ndelete registry value\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ 0x401459\n  and:\n    optional:\n      match: create or open registry key @ 0x402347\n        or:\n          api: RegCreateKeyEx @ 0x402385\n    or:\n      api: RegDeleteValue @ 0x40230A\n\ncreate thread\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x40511D in function 0x404F66\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x405138\n\n(internal) installer file limitation\nnamespace    internal/limitation/static                                         \nauthor       william.ballenthin@mandiant.com                                    \nscope        file                                                               \ndescription  This sample appears to be an installer.                            \n                                                                                \n             capa cannot handle installers well. This means the results may be  \n             misleading or incomplete.                                          \n             You should try to understand the install mechanism and analyze     \n             created files with capa.                                           \n                                                                                \nor:\n  match: executable/installer @ global\n    or:\n      substring: http://nsis.sf.net\n        - \"http://nsis.sf.net/NSIS_Error\" @ file+0x72E2\n\nlink function at runtime on Windows (2 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x401FE3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401FE3\ninstruction @ 0x405E34\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x405E34\n\ncreate shortcut via IShellLink\nnamespace   persistence                                                         \nauthor      matthew.williams@mandiant.com                                       \nscope       function                                                            \natt&ck      Persistence::Boot or Logon Autostart Execution::Shortcut            \n            Modification [T1547.009]                                            \nreferences  https://docs.microsoft.com/en-us/windows/win32/shell/links#creating…\nfunction @ 0x401459\n  and:\n    offset: 0x50 = psl->SetPath @ 0x4020EA\n    offset: 0x18 = ppf->Save @ 0x401EFB, 0x402184, 0x4027F2, 0x40281D\n    api: CoCreateInstance @ 0x4020BA\n    bytes: 0114020000000000c000000000000046 = CLSID_ShellLink @ 0x4020B5\n    bytes: 0b01000000000000c000000000000046 = IID_IPersistFile @ 0x4020CF\n    or:\n      bytes: ee14020000000000c000000000000046 = IID_IShellLinkA @ 0x4020AD\n\n\n\n"},"hashes":{"md5":"663fbf2a248971ea69c6234480a4bdcb","sha1":"1468417788f4e006b8983add7ab339e2f661b620","sha256":"d24d79011d003dc7a4cadbc1b7b3efb89947f9a84f814c6739a01c1c38e227b8"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 85</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 27205</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Trojan.\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"663fbf2a248971ea69c6234480a4bdcb\",\n        \"sha256\": \"d24d79011d003dc7a4cadbc1b7b3efb89947f9a84f814c6739a01c1\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_library_rule_\",\n      \"label\": \"library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Modulo [C0058]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_loop__38_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (38 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401000\",\n      \"label\": \"Function 0x401000\",\n      \"type\": \"function\",\n      \"address\": \"0x401000\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x402347\",\n      \"label\": \"Block 0x402347\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x402347\"\n    },\n    {\n      \"id\": \"api_RegCreateKeyEx\",\n      \"label\": \"RegCreateKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401504\",\n      \"label\": \"Block 0x401504\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401504\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_reference_analysis_tools_strings\",\n      \"label\": \"reference analysis tools strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_for_time_delay_via_gettickcount\",\n      \"label\": \"check for time delay via GetTickCount\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"GetTickCount [B0001.032]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402EB2\",\n      \"label\": \"Function 0x402EB2\",\n      \"type\": \"function\",\n      \"address\": \"0x402EB2\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"GetTickCount [B0001.032]\"\n      ]\n    },\n    {\n      \"id\": \"cap_capture_webcam_image\",\n      \"label\": \"capture webcam image\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Video Capture [T1125]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404747\",\n      \"label\": \"Function 0x404747\",\n      \"type\": \"function\",\n      \"address\": \"0x404747\"\n    },\n    {\n      \"id\": \"api_SendMessage\",\n      \"label\": \"SendMessage\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____johnk3r\",\n      \"label\": \"author     johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Video Capture [T1125]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_and_execute_a_file\",\n      \"label\": \"write and execute a file\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401459\",\n      \"label\": \"Function 0x401459\",\n      \"type\": \"function\",\n      \"address\": \"0x401459\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_ShellExecute\",\n      \"label\": \"ShellExecute\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_maec_malware_category__launcher\",\n      \"label\": \"maec/malware-category  launcher\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_with_crc32\",\n      \"label\": \"hash data with CRC32\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405E7C\",\n      \"label\": \"Function 0x405E7C\",\n      \"type\": \"function\",\n      \"address\": \"0x405E7C\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_packaged_as_a_nsis_installer\",\n      \"label\": \"packaged as a NSIS installer\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments\",\n      \"label\": \"accept command line arguments\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x403121\",\n      \"label\": \"Function 0x403121\",\n      \"type\": \"function\",\n      \"address\": \"0x403121\"\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_open_clipboard\",\n      \"label\": \"open clipboard\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404F66\",\n      \"label\": \"Function 0x404F66\",\n      \"type\": \"function\",\n      \"address\": \"0x404F66\"\n    },\n    {\n      \"id\": \"api_CloseClipboard\",\n      \"label\": \"CloseClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_OpenClipboard\",\n      \"label\": \"OpenClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_write_clipboard_data\",\n      \"label\": \"write clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"api_EmptyClipboard\",\n      \"label\": \"EmptyClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SetClipboardData\",\n      \"label\": \"SetClipboardData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable\",\n      \"label\": \"query environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_ExpandEnvironmentStrings\",\n      \"label\": \"ExpandEnvironmentStrings\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path__3_matches_\",\n      \"label\": \"get common file path (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405AEE\",\n      \"label\": \"Function 0x405AEE\",\n      \"type\": \"function\",\n      \"address\": \"0x405AEE\"\n    },\n    {\n      \"id\": \"func_0x4057BE\",\n      \"label\": \"Function 0x4057BE\",\n      \"type\": \"function\",\n      \"address\": \"0x4057BE\"\n    },\n    {\n      \"id\": \"api_GetTempFileName\",\n      \"label\": \"GetTempFileName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHGetSpecialFolderLocation\",\n      \"label\": \"SHGetSpecialFolderLocation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_system_object_information\",\n      \"label\": \"get file system object information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x403121\",\n      \"label\": \"Block 0x403121\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x403121\"\n    },\n    {\n      \"id\": \"api_SHGetFileInfo\",\n      \"label\": \"SHGetFileInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_current_directory__2_matches_\",\n      \"label\": \"set current directory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_SetCurrentDirectory\",\n      \"label\": \"SetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_copy_file__2_matches_\",\n      \"label\": \"copy file (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"api_SHFileOperation\",\n      \"label\": \"SHFileOperation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CopyFile\",\n      \"label\": \"CopyFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory__3_matches_\",\n      \"label\": \"create directory (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4030ED\",\n      \"label\": \"Function 0x4030ED\",\n      \"type\": \"function\",\n      \"address\": \"0x4030ED\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_delete_directory\",\n      \"label\": \"delete directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4053D0\",\n      \"label\": \"Function 0x4053D0\",\n      \"type\": \"function\",\n      \"address\": \"0x4053D0\"\n    },\n    {\n      \"id\": \"api_RemoveDirectory\",\n      \"label\": \"RemoveDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_file__3_matches_\",\n      \"label\": \"delete file (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__3_matches_\",\n      \"label\": \"check if file exists (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405686\",\n      \"label\": \"Function 0x405686\",\n      \"type\": \"function\",\n      \"address\": \"0x405686\"\n    },\n    {\n      \"id\": \"func_0x405770\",\n      \"label\": \"Function 0x405770\",\n      \"type\": \"function\",\n      \"address\": \"0x405770\"\n    },\n    {\n      \"id\": \"func_0x40357E\",\n      \"label\": \"Function 0x40357E\",\n      \"type\": \"function\",\n      \"address\": \"0x40357E\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"label\": \"enumerate files on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindClose\",\n      \"label\": \"FindClose\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindNextFile\",\n      \"label\": \"FindNextFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindFirstFile\",\n      \"label\": \"FindFirstFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_recursively\",\n      \"label\": \"enumerate files recursively\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     @_re_fox, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes__5_matches_\",\n      \"label\": \"get file attributes (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40578F\",\n      \"label\": \"Block 0x40578F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40578F\"\n    },\n    {\n      \"id\": \"bb_0x403681\",\n      \"label\": \"Block 0x403681\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x403681\"\n    },\n    {\n      \"id\": \"bb_0x4056E3\",\n      \"label\": \"Block 0x4056E3\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4056E3\"\n    },\n    {\n      \"id\": \"bb_0x405770\",\n      \"label\": \"Block 0x405770\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x405770\"\n    },\n    {\n      \"id\": \"bb_0x40161A\",\n      \"label\": \"Block 0x40161A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40161A\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size__2_matches_\",\n      \"label\": \"get file size (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405807\",\n      \"label\": \"Function 0x405807\",\n      \"type\": \"function\",\n      \"address\": \"0x405807\"\n    },\n    {\n      \"id\": \"func_0x402C74\",\n      \"label\": \"Function 0x402C74\",\n      \"type\": \"function\",\n      \"address\": \"0x402C74\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_file_version_info\",\n      \"label\": \"get file version info\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetFileVersionInfoSize\",\n      \"label\": \"GetFileVersionInfoSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_VerQueryValue\",\n      \"label\": \"VerQueryValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfo\",\n      \"label\": \"GetFileVersionInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_file_attributes__2_matches_\",\n      \"label\": \"set file attributes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40577F\",\n      \"label\": \"Block 0x40577F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40577F\"\n    },\n    {\n      \"id\": \"bb_0x4015BD\",\n      \"label\": \"Block 0x4015BD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4015BD\"\n    },\n    {\n      \"id\": \"api_SetFileAttributes\",\n      \"label\": \"SetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_move_file\",\n      \"label\": \"move file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"api_MoveFile\",\n      \"label\": \"MoveFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read__ini_file\",\n      \"label\": \"read .ini file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetFullPathName\",\n      \"label\": \"GetFullPathName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetPrivateProfileString\",\n      \"label\": \"GetPrivateProfileString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__3_matches_\",\n      \"label\": \"read file on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4030A4\",\n      \"label\": \"Function 0x4030A4\",\n      \"type\": \"function\",\n      \"address\": \"0x4030A4\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__3_matches_\",\n      \"label\": \"write file on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_graphical_window\",\n      \"label\": \"find graphical window\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindWindowEx\",\n      \"label\": \"FindWindowEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_size\",\n      \"label\": \"get disk size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404232\",\n      \"label\": \"Function 0x404232\",\n      \"type\": \"function\",\n      \"address\": \"0x404232\"\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpace\",\n      \"label\": \"GetDiskFreeSpace\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_shutdown_system\",\n      \"label\": \"shutdown system\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::System Shutdown/Reboot [T1529]\"\n      ]\n    },\n    {\n      \"id\": \"api_ExitWindowsEx\",\n      \"label\": \"ExitWindowsEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__3_matches_\",\n      \"label\": \"create process on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401E05\",\n      \"label\": \"Block 0x401E05\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401E05\"\n    },\n    {\n      \"id\": \"bb_0x404114\",\n      \"label\": \"Block 0x404114\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x404114\"\n    },\n    {\n      \"id\": \"bb_0x4052EF\",\n      \"label\": \"Block 0x4052EF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4052EF\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"api_ExitProcess\",\n      \"label\": \"ExitProcess\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"label\": \"query or enumerate registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402A7C\",\n      \"label\": \"Function 0x402A7C\",\n      \"type\": \"function\",\n      \"address\": \"0x402A7C\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"api_RegEnumKey\",\n      \"label\": \"RegEnumKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"label\": \"query or enumerate registry value (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4059A0\",\n      \"label\": \"Function 0x4059A0\",\n      \"type\": \"function\",\n      \"address\": \"0x4059A0\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegEnumValue\",\n      \"label\": \"RegEnumValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value\",\n      \"label\": \"set registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delete_registry_key\",\n      \"label\": \"delete registry key\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegDeleteKey\",\n      \"label\": \"RegDeleteKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_value\",\n      \"label\": \"delete registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegDeleteValue\",\n      \"label\": \"RegDeleteValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_thread\",\n      \"label\": \"create thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40511D\",\n      \"label\": \"Block 0x40511D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40511D\"\n    },\n    {\n      \"id\": \"api_CreateThread\",\n      \"label\": \"CreateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal__installer_file_limitation\",\n      \"label\": \"(internal) installer file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__2_matches_\",\n      \"label\": \"link function at runtime on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_shortcut_via_ishelllink\",\n      \"label\": \"create shortcut via IShellLink\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    },\n    {\n      \"id\": \"api_CoCreateInstance\",\n      \"label\": \"CoCreateInstance\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__38_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__38_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x402347\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x401504\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_analysis_tools_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_time_delay_via_gettickcount\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount\",\n      \"target\": \"func_0x402EB2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x402EB2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_capture_webcam_image\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_capture_webcam_image\",\n      \"target\": \"func_0x404747\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404747\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____johnk3r\",\n      \"target\": \"func_0x404747\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404747\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_and_execute_a_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_and_execute_a_file\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_ShellExecute\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_maec_malware_category__launcher\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_maec_malware_category__launcher\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_ShellExecute\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_crc32\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_with_crc32\",\n      \"target\": \"func_0x405E7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x405E7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_packaged_as_a_nsis_installer\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_clipboard\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_clipboard\",\n      \"target\": \"func_0x404F66\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x404F66\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_clipboard_data\",\n      \"target\": \"func_0x404F66\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404F66\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x404F66\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x405AEE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x4057BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405AEE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4057BE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405AEE\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4057BE\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_system_object_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_system_object_information\",\n      \"target\": \"bb_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_current_directory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__2_matches_\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__2_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_copy_file__2_matches_\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_copy_file__2_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory__3_matches_\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__3_matches_\",\n      \"target\": \"func_0x4030ED\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__3_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4030ED\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4030ED\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4030ED\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_directory\",\n      \"target\": \"func_0x4053D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4053D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x4053D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4053D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x405686\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x405770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x40357E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405686\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405770\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40357E\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405686\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40357E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405686\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405770\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40357E\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"target\": \"func_0x4053D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4053D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_recursively\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively\",\n      \"target\": \"func_0x4053D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4053D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4053D0\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x40578F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x403681\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x4056E3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x405770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x40161A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40578F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x403681\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4056E3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x405770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40161A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x405807\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x402C74\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405807\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402C74\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405807\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402C74\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405807\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402C74\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_version_info\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_version_info\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__2_matches_\",\n      \"target\": \"bb_0x40577F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__2_matches_\",\n      \"target\": \"bb_0x4015BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40577F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4015BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_move_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_move_file\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read__ini_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read__ini_file\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_GetFullPathName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_GetFullPathName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__3_matches_\",\n      \"target\": \"func_0x405807\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__3_matches_\",\n      \"target\": \"func_0x4030A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__3_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405807\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4030A4\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405807\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4030A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405807\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4030A4\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__3_matches_\",\n      \"target\": \"func_0x405807\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__3_matches_\",\n      \"target\": \"func_0x402EB2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__3_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405807\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402EB2\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405807\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402EB2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405807\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402EB2\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_graphical_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_size\",\n      \"target\": \"func_0x404232\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404232\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404232\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404232\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_shutdown_system\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_shutdown_system\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__3_matches_\",\n      \"target\": \"bb_0x401E05\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__3_matches_\",\n      \"target\": \"bb_0x404114\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__3_matches_\",\n      \"target\": \"bb_0x4052EF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x401E05\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x404114\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4052EF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403121\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403121\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"target\": \"func_0x402A7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x402A7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"target\": \"func_0x4059A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4059A0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4059A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4059A0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4059A0\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key\",\n      \"target\": \"func_0x402A7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x402A7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402A7C\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread\",\n      \"target\": \"bb_0x40511D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40511D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal__installer_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_shortcut_via_ishelllink\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_shortcut_via_ishelllink\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______matthew_williams_mandiant_com\",\n      \"target\": \"func_0x401459\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401459\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-10 01:50:09.122938\",\n    \"total_functions\": \"85\",\n    \"total_features\": \"27205\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-10 01:50:10"}
{"_id":{"$oid":"6a50071f0108394cb24cdd25"},"sha256":"2ecc525177ed52c74ddaaacd47ad513450e85c01f2616bf179be5b576164bf63","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_m56bxiup/resource_32DCAPI.DLL_105.bin_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_m56bxiup/resource_32DCAPI.DLL_105.bin_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_m56bxiup/resource_32DCAPI.DLL_105.bin_very_verbose.txt"}},"outputs":{"normal":"┌───────────┬──────────────────────────────────────────────────────────────────┐\n│ md5       │ f93c8da34f2c03c8ccdc29343fdb4be7                                 │\n│ sha1      │ 8df2856ab19e1f3b476e751efdef95f08bd3a2d7                         │\n│ sha256    │ 77300d435ee41065e1bee369c31908388cb56a8759471d8ade2028c80950c654 │\n│ analysis  │ static                                                           │\n│ os        │ windows                                                          │\n│ format    │ pe                                                               │\n│ arch      │ i386                                                             │\n│ path      │ /tmp/sdm_decoded_43pdx2vn/resource_32DCAPI.DLL_105.bin           │\n└───────────┴──────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Input Capture::Keylogging [T1056.001]                 │\n│ DEFENSE EVASION      │ Deobfuscate/Decode Files or Information [T1140]       │\n│                      │ Modify Registry [T1112]                               │\n│                      │ Obfuscated Files or Information [T1027]               │\n│                      │ Virtualization/Sandbox Evasion::System Checks         │\n│                      │ [T1497.001]                                           │\n│ DISCOVERY            │ Application Window Discovery [T1010]                  │\n│                      │ File and Directory Discovery [T1083]                  │\n│                      │ Query Registry [T1012]                                │\n│                      │ System Information Discovery [T1082]                  │\n│                      │ System Owner/User Discovery [T1033]                   │\n│ EXECUTION            │ Shared Modules [T1129]                                │\n│                      │ System Services::Service Execution [T1569.002]        │\n│ IMPACT               │ Disk Wipe::Disk Structure Wipe [T1561.002]            │\n│ PERSISTENCE          │ Create or Modify System Process::Windows Service      │\n│                      │ [T1543.003]                                           │\n│ PRIVILEGE ESCALATION │ Access Token Manipulation [T1134]                     │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Virtual Machine Detection::Instruction Testing -  │\n│                          │ CPUID [B0009.034]                                 │\n│ COLLECTION               │ Keylogging::Application Hook [F0002.001]          │\n│ CRYPTOGRAPHY             │ Cryptographic Hash::SHA256 [C0029.003]            │\n│                          │ Decrypt Data::AES [C0031.001]                     │\n│                          │ Encrypt Data::AES [C0027.001]                     │\n│                          │ Encrypt Data::Twofish [C0027.005]                 │\n│                          │ Encryption Key [C0028]                            │\n│                          │ Generate Pseudo-random Sequence::Use API          │\n│                          │ [C0021.003]                                       │\n│ DATA                     │ Checksum::CRC32 [C0032.001]                       │\n│                          │ Encode Data::XOR [C0026.002]                      │\n│ DEFENSE EVASION          │ Obfuscated Files or                               │\n│                          │ Information::Encoding-Standard Algorithm          │\n│                          │ [E1027.m02]                                       │\n│                          │ Obfuscated Files or                               │\n│                          │ Information::Encryption-Standard Algorithm        │\n│                          │ [E1027.m05]                                       │\n│ DISCOVERY                │ Application Window Discovery [E1010]              │\n│                          │ File and Directory Discovery [E1083]              │\n│                          │ System Information Discovery [E1082]              │\n│ FILE SYSTEM              │ Copy File [C0045]                                 │\n│                          │ Delete File [C0047]                               │\n│                          │ Get File Attributes [C0049]                       │\n│                          │ Read File [C0051]                                 │\n│                          │ Writes File [C0052]                               │\n│ IMPACT                   │ Disk Wipe [F0014]                                 │\n│ MEMORY                   │ Allocate Memory [C0007]                           │\n│ OPERATING SYSTEM         │ Registry::Delete Registry Value [C0036.007]       │\n│                          │ Registry::Query Registry Value [C0036.006]        │\n│                          │ Registry::Set Registry Key [C0036.001]            │\n│ PROCESS                  │ Allocate Thread Local Storage [C0040]             │\n│                          │ Create Mutex [C0042]                              │\n│                          │ Set Thread Local Storage Value [C0041]            │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ reference processor manufacturer      │ anti-analysis/anti-vm/vm-detection   │\n│ constants                             │                                      │\n│ log keystrokes via application hook   │ collection/keylog                    │\n│ hash data with CRC32                  │ data-manipulation/checksum/crc32     │\n│ encode data using XOR (17 matches)    │ data-manipulation/encoding/xor       │\n│ create new key via                    │ data-manipulation/encryption         │\n│ CryptAcquireContext                   │                                      │\n│ decrypt data using AES via x86        │ data-manipulation/encryption/aes     │\n│ extensions                            │                                      │\n│ encrypt data using AES via x86        │ data-manipulation/encryption/aes     │\n│ extensions (3 matches)                │                                      │\n│ encrypt data using twofish (7         │ data-manipulation/encryption/twofish │\n│ matches)                              │                                      │\n│ hash data using SHA256 (4 matches)    │ data-manipulation/hashing/sha256     │\n│ generate random numbers via WinAPI    │ data-manipulation/prng               │\n│ extract resource via kernel32         │ executable/resource                  │\n│ functions (4 matches)                 │                                      │\n│ get common file path (4 matches)      │ host-interaction/file-system         │\n│ copy file                             │ host-interaction/file-system/copy    │\n│ delete file (3 matches)               │ host-interaction/file-system/delete  │\n│ check if file exists                  │ host-interaction/file-system/exists  │\n│ enumerate files on Windows            │ host-interaction/file-system/files/… │\n│ get file attributes                   │ host-interaction/file-system/meta    │\n│ get file size (4 matches)             │ host-interaction/file-system/meta    │\n│ read file on Windows (8 matches)      │ host-interaction/file-system/read    │\n│ write file on Windows (7 matches)     │ host-interaction/file-system/write   │\n│ enumerate gui resources               │ host-interaction/gui                 │\n│ get graphical window text             │ host-interaction/gui/window/get-text │\n│ get memory capacity                   │ host-interaction/hardware/memory     │\n│ enumerate disk volumes                │ host-interaction/hardware/storage    │\n│ get disk information via IOCTL (2     │ host-interaction/hardware/storage    │\n│ matches)                              │                                      │\n│ get disk size                         │ host-interaction/hardware/storage    │\n│ get storage device properties         │ host-interaction/hardware/storage    │\n│ unmount volume via IOCTL              │ host-interaction/hardware/storage    │\n│ create or open mutex on Windows       │ host-interaction/mutex               │\n│ check OS version (4 matches)          │ host-interaction/os/version          │\n│ get thread local storage value (27    │ host-interaction/process             │\n│ matches)                              │                                      │\n│ modify access privileges              │ host-interaction/process/modify      │\n│ query or enumerate registry value (3  │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ delete registry value                 │ host-interaction/registry/delete     │\n│ create service                        │ host-interaction/service/create      │\n│ delete service                        │ host-interaction/service/delete      │\n│ get token membership                  │ host-interaction/session             │\n│ allocate thread local storage         │ host-interaction/thread/tls          │\n│ set thread local storage value (16    │ host-interaction/thread/tls          │\n│ matches)                              │                                      │\n│ delete drive layout via IOCTL         │ impact/wipe-disk                     │\n│ link function at runtime on Windows   │ linking/runtime-linking              │\n│ (3 matches)                           │                                      │\n│ execute shellcode via indirect call   │ load-code/shellcode                  │\n│ (2 matches)                           │                                      │\n│ persist via Windows service (2        │ persistence/service                  │\n│ matches)                              │                                      │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     f93c8da34f2c03c8ccdc29343fdb4be7                        \nsha1                    8df2856ab19e1f3b476e751efdef95f08bd3a2d7                \nsha256                  77300d435ee41065e1bee369c31908388cb56a8759471d8ade2028c…\npath                    /tmp/sdm_decoded_43pdx2vn/resource_32DCAPI.DLL_105.bin  \ntimestamp               2026-07-10 02:09:49.126438                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x10000000                                              \nrules                   /tmp/_MEIteotLW/rules                                   \nfunction count          186                                                     \nlibrary function count  21                                                      \ntotal feature count     14649                                                   \n\nreference processor manufacturer constants\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      basic block                       \nmatches    0x10015CD3                        \n\nlog keystrokes via application hook\nnamespace  collection/keylog\nscope      basic block      \nmatches    0x1001C722       \n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32\nscope      function                        \nmatches    0x10016AC0                      \n\nencode data using XOR (17 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x1000295E                    \n           0x100050F4                    \n           0x1000DFE3                    \n           0x1000E140                    \n           0x1000EAB0                    \n           0x10014790                    \n           0x10014840                    \n           0x100155F7                    \n           0x10015717                    \n           0x10015848                    \n           0x10015978                    \n           0x10015A8C                    \n           0x10015B9C                    \n           0x10016AD0                    \n           0x1001CB33                    \n           0x1001CCE0                    \n           0x1001CF60                    \n\ncreate new key via CryptAcquireContext\nnamespace  data-manipulation/encryption\nscope      basic block                 \nmatches    0x1001C76D                  \n\ndecrypt data using AES via x86 extensions\nnamespace  data-manipulation/encryption/aes\nscope      function                        \nmatches    0x1000C1E0                      \n\nencrypt data using AES via x86 extensions (3 matches)\nnamespace  data-manipulation/encryption/aes\nscope      function                        \nmatches    0x1000BF80                      \n           0x1000C1E0                      \n           0x10015C50                      \n\nencrypt data using twofish (7 matches)\nnamespace  data-manipulation/encryption/twofish\nscope      basic block                         \nmatches    0x1000E20B                          \n           0x1000E424                          \n           0x1000E63D                          \n           0x1000E856                          \n           0x1000EA2F                          \n           0x1000EAB0                          \n           0x1000EB84                          \n\nhash data using SHA256 (4 matches)\nnamespace  data-manipulation/hashing/sha256\nscope      function                        \nmatches    0x100146B0                      \n           0x1001C7D0                      \n           0x1001CB10                      \n           0x1001CC80                      \n\ngenerate random numbers via WinAPI\nnamespace  data-manipulation/prng\nscope      function              \nmatches    0x1001C690            \n\nextract resource via kernel32 functions (4 matches)\nnamespace  executable/resource\nscope      function           \nmatches    0x10018100         \n           0x10018650         \n           0x10018700         \n           0x1001C110         \n\ninteract with driver via IOCTL (57 matches)\nnamespace  host-interaction/driver\nscope      instruction            \nmatches    0x10017076             \n           0x10017596             \n           0x100178FF             \n           0x10017AB9             \n           0x10017AEF             \n           0x10017B4D             \n           0x10017B94             \n           0x10017BD4             \n           0x10018E39             \n           0x10018E66             \n           0x10018EB0             \n           0x10018F8C             \n           0x10018FB3             \n           0x10018FC7             \n           0x10019299             \n           0x10019450             \n           0x10019497             \n           0x1001A3F5             \n           0x1001A460             \n           0x1001A4B8             \n           0x1001A539             \n           0x1001A600             \n           0x1001A69B             \n           0x1001A730             \n           0x1001A7CB             \n           0x1001A879             \n           0x1001A8C8             \n           0x1001A9D2             \n           0x1001AAD6             \n           0x1001AB32             \n           0x1001ABF3             \n           0x1001ACF9             \n           0x1001AD89             \n           0x1001AE29             \n           0x1001AEA9             \n           0x1001AF69             \n           0x1001B000             \n           0x1001B0A9             \n           0x1001B139             \n           0x1001B1D9             \n           0x1001B262             \n           0x1001B309             \n           0x1001B3A0             \n           0x1001B449             \n           0x1001B4E0             \n           0x1001B589             \n           0x1001B5EF             \n           0x1001B699             \n           0x1001B70E             \n           0x1001B7C9             \n           0x1001B861             \n           0x1001B8E6             \n           0x1001BD10             \n           0x1001BDE1             \n           0x1001BED4             \n           0x1001C23B             \n           0x1001C84A             \n\nget common file path (4 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x10019B40                  \n           0x10019D90                  \n           0x10019E20                  \n           0x10019F50                  \n\ncopy file\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    0x1001A060                       \n\ndelete file (3 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x10019E20                         \n           0x1001A170                         \n           0x1001D010                         \n\ncheck if file exists\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x10019D90                         \n\nenumerate files on Windows\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x1001CA00                             \n\nget file attributes\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x10019DF9                       \n\nget file size (4 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x10017270                       \n           0x10017E60                       \n           0x10018AE0                       \n           0x1001D010                       \n\nread file on Windows (8 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x10016D60                       \n           0x10016E90                       \n           0x10017270                       \n           0x10017670                       \n           0x10017E60                       \n           0x10018AE0                       \n           0x1001C7D0                       \n           0x1001D010                       \n\nwrite file on Windows (7 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x10016D60                        \n           0x10017310                        \n           0x10017E60                        \n           0x10018650                        \n           0x10018700                        \n           0x10018DB0                        \n           0x1001D010                        \n\nenumerate gui resources\nnamespace  host-interaction/gui\nscope      function            \nmatches    0x1001C480          \n\nset application hook (2 matches)\nnamespace  host-interaction/gui\nscope      instruction         \nmatches    0x1001C73A          \n           0x1001C74D          \n\nget graphical window text\nnamespace  host-interaction/gui/window/get-text\nscope      function                            \nmatches    0x1001C3B0                          \n\nget memory capacity\nnamespace  host-interaction/hardware/memory\nscope      function                        \nmatches    0x1001C480                      \n\nenumerate disk volumes\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x1001BA30                       \n\nget disk information via IOCTL (2 matches)\nnamespace  host-interaction/hardware/storage\nscope      basic block                      \nmatches    0x10017AD4                       \n           0x1001947F                       \n\nget disk size\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x10017A20                       \n\nget storage device properties\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x1001BE60                       \n\nunmount volume via IOCTL\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x10018DB0                       \n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex\nscope      instruction           \nmatches    0x1001C0C2            \n\ncheck OS version (4 matches)\nnamespace  host-interaction/os/version\nscope      function                   \nmatches    0x10016D10                 \n           0x10019E20                 \n           0x1001A170                 \n           0x1001A2F0                 \n\nget thread local storage value (27 matches)\nnamespace  host-interaction/process\nscope      function                \nmatches    0x10017540              \n           0x1001A3D0              \n           0x1001A400              \n           0x1001A490              \n           0x1001A4D0              \n           0x1001A5A0              \n           0x1001A630              \n           0x1001A6D0              \n           0x1001A760              \n           0x1001A800              \n           0x1001A970              \n           0x1001AA30              \n           0x1001AB90              \n           0x1001AC80              \n           0x1001ADB0              \n           0x1001AEF0              \n           0x1001B030              \n           0x1001B160              \n           0x1001B290              \n           0x1001B3D0              \n           0x1001B510              \n           0x1001B620              \n           0x1001B750              \n           0x1001B890              \n           0x1001C070              \n           0x1001C1B0              \n           0x1001C7D0              \n\nallocate or change RWX memory (13 matches)\nnamespace  host-interaction/process/inject\nscope      basic block                    \nmatches    0x10017600                     \n           0x1001AC80                     \n           0x1001ADB0                     \n           0x1001AEF0                     \n           0x1001B030                     \n           0x1001B160                     \n           0x1001B290                     \n           0x1001B3D0                     \n           0x1001B510                     \n           0x1001B620                     \n           0x1001B750                     \n           0x1001C690                     \n           0x1001C7D0                     \n\nmodify access privileges\nnamespace  host-interaction/process/modify\nscope      instruction                    \nmatches    0x10017498                     \n\nquery or enumerate registry value (3 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x100196A0               \n           0x10019890               \n           0x10019CA0               \n\nset registry value (4 matches)\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x10019550                      \n           0x100196A0                      \n           0x10019890                      \n           0x10019BC0                      \n\ndelete registry value\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x10019890                      \n\ncreate service\nnamespace  host-interaction/service/create\nscope      function                       \nmatches    0x10019F50                     \n\ndelete service\nnamespace  host-interaction/service/delete\nscope      function                       \nmatches    0x10019630                     \n\nget token membership\nnamespace  host-interaction/session\nscope      function                \nmatches    0x10017370              \n\nallocate thread local storage\nnamespace  host-interaction/thread/tls\nscope      function                   \nmatches    0x1001C070                 \n\nset thread local storage value (16 matches)\nnamespace  host-interaction/thread/tls\nscope      function                   \nmatches    0x10017540                 \n           0x1001AB90                 \n           0x1001AC40                 \n           0x1001AC80                 \n           0x1001ADB0                 \n           0x1001AEF0                 \n           0x1001B030                 \n           0x1001B160                 \n           0x1001B290                 \n           0x1001B3D0                 \n           0x1001B510                 \n           0x1001B620                 \n           0x1001B750                 \n           0x1001B890                 \n           0x1001C1B0                 \n           0x1001C7D0                 \n\ndelete drive layout via IOCTL\nnamespace  impact/wipe-disk\nscope      basic block     \nmatches    0x10018E4F      \n\nlink function at runtime on Windows (3 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x1001723D             \n           0x100174F2             \n           0x10018FEE             \n\nexecute shellcode via indirect call (2 matches)\nnamespace  load-code/shellcode\nscope      function           \nmatches    0x1001C690         \n           0x1001C7D0         \n\npersist via Windows service (2 matches)\nnamespace  persistence/service\nscope      function           \nmatches    0x10019550         \n           0x10019BC0         \n\n\n\n","very_verbose":"md5                     f93c8da34f2c03c8ccdc29343fdb4be7                        \nsha1                    8df2856ab19e1f3b476e751efdef95f08bd3a2d7                \nsha256                  77300d435ee41065e1bee369c31908388cb56a8759471d8ade2028c…\npath                    /tmp/sdm_decoded_43pdx2vn/resource_32DCAPI.DLL_105.bin  \ntimestamp               2026-07-10 02:09:58.273542                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x10000000                                              \nrules                   /tmp/_MEImw8kFQ/rules                                   \nfunction count          186                                                     \nlibrary function count  21                                                      \ntotal feature count     14649                                                   \n\nallocate memory (14 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x10017600 in function 0x10017600\n  or:\n    api: VirtualAlloc @ 0x10017617\n\nallocate or change RW memory (library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x1001D1A7 in function 0x1001D010\n  and:\n    or:\n      match: allocate memory @ 0x1001D1A7\n        or:\n          api: VirtualAlloc @ 0x1001D1B5\n    or:\n      number: 0x4 = PAGE_READWRITE @ 0x1001D1A7\n\ncontain loop (61 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x1000284B\n  or:\n    characteristic: loop @ 0x1000284B\n\ncreate or open file (31 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x1001702A\n  or:\n    api: CreateFile @ 0x1001702A\n\ncreate or open registry key (6 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x10019550 in function 0x10019550\n  or:\n    api: RegCreateKey @ 0x10019578\n\ndelay execution (2 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x1000D6F6 in function 0x1000D698\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x1000D6FB\n\nget OS version (4 matches, only showing first match of library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x10016D10\n  or:\n    api: GetVersionEx @ 0x10016D34\n\nget service handle (2 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x10019630\n  or:\n    api: OpenService @ 0x10019657\n\nreference processor manufacturer constants\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      matthew.williams@mandiant.com                                       \nscope       basic block                                                         \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection::Instruction    \n            Testing - CPUID [B0009.034]                                         \nreferences  https://en.wikipedia.org/wiki/CPUID                                 \nbasic block @ 0x10015CD3 in function 0x10015C50\n  and:\n    mnemonic: cmp @ 0x10015CEE\n    optional:\n      mnemonic: cpuid @ 0x10015CDE\n    or:\n      number: 0x7263694D = 'rciM' (Microsoft Hyper-V) @ 0x10015CEE\n\nlog keystrokes via application hook\nnamespace  collection/keylog                                   \nauthor     michael.hunhoff@mandiant.com                        \nscope      basic block                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]   \nmbc        Collection::Keylogging::Application Hook [F0002.001]\nbasic block @ 0x1001C722 in function 0x1001C690\n  and:\n    match: set application hook @ 0x1001C73A, 0x1001C74D\n      or:\n        api: SetWindowsHookEx @ 0x1001C73A\n      or:\n        api: SetWindowsHookEx @ 0x1001C74D\n    or:\n      number: 0x2 = WH_KEYBOARD @ 0x1001C74B\n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32 \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \nmbc        Data::Checksum::CRC32 [C0032.001]\nfunction @ 0x10016AC0\n  or:\n    bytes: 00000000963007772c610eeeba51099919c46d078ff46a7035a563e9a395649e = crc32_tab @ 0x10016ADC, 0x10016AEE, 0x10016B01, 0x10016B14\n\nencode data using XOR (17 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x1000295E in function 0x100028C0\n  and:\n    characteristic: tight loop @ 0x1000295E\n    characteristic: nzxor @ 0x1000299C, 0x100029D8, 0x10002A1E, 0x10002A26, and 756 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x100050F4 in function 0x10005060\n  and:\n    characteristic: tight loop @ 0x100050F4\n    characteristic: nzxor @ 0x1000512C, 0x10005168, 0x100051B2, 0x100051B6, and 768 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1000DFE3 in function 0x1000DF60\n  and:\n    characteristic: tight loop @ 0x1000DFE3\n    characteristic: nzxor @ 0x1000DFFD, 0x1000E00C, 0x1000E016, 0x1000E020, and 11 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1000E140 in function 0x1000DF60\n  and:\n    characteristic: tight loop @ 0x1000E140\n    characteristic: nzxor @ 0x1000E164, 0x1000E17A, 0x1000E18B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1000EAB0 in function 0x1000E1C0\n  and:\n    characteristic: tight loop @ 0x1000EAB0\n    characteristic: nzxor @ 0x1000EAB4, 0x1000EAC1, 0x1000EACE, 0x1000EAD8, and 12 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x10014790 in function 0x10014730\n  and:\n    characteristic: tight loop @ 0x10014790\n    characteristic: nzxor @ 0x100147F2, 0x100147F7, 0x100147FE, 0x10014804, and 4 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x10014840 in function 0x10014730\n  and:\n    characteristic: tight loop @ 0x10014840\n    characteristic: nzxor @ 0x10014880, 0x1001488D, 0x10014898, 0x100148A3, and 92 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x100155F7 in function 0x10015580\n  and:\n    characteristic: tight loop @ 0x100155F7\n    characteristic: nzxor @ 0x100155FF, 0x10015603, 0x10015616, 0x10015618, and 5 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x10015717 in function 0x100156A0\n  and:\n    characteristic: tight loop @ 0x10015717\n    characteristic: nzxor @ 0x1001571F, 0x10015723, 0x10015738, 0x1001573A, and 5 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x10015848 in function 0x100157C0\n  and:\n    characteristic: tight loop @ 0x10015848\n    characteristic: nzxor @ 0x1001584A, 0x1001584F, 0x1001585C, 0x10015860, and 5 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x10015978 in function 0x100158F0\n  and:\n    characteristic: tight loop @ 0x10015978\n    characteristic: nzxor @ 0x1001597A, 0x1001597F, 0x1001598C, 0x10015990, and 5 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x10015A8C in function 0x10015A20\n  and:\n    characteristic: tight loop @ 0x10015A8C\n    characteristic: nzxor @ 0x10015A8E, 0x10015A93, 0x10015AA0, 0x10015AA4, and 5 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x10015B9C in function 0x10015B30\n  and:\n    characteristic: tight loop @ 0x10015B9C\n    characteristic: nzxor @ 0x10015B9E, 0x10015BA3, 0x10015BB0, 0x10015BB4, and 5 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x10016AD0 in function 0x10016AC0\n  and:\n    characteristic: tight loop @ 0x10016AD0\n    characteristic: nzxor @ 0x10016AD7, 0x10016ADC, 0x10016AE9, 0x10016AEE, and 4 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1001CB33 in function 0x1001CB10\n  and:\n    characteristic: tight loop @ 0x1001CB33\n    characteristic: nzxor @ 0x1001CB33\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1001CCE0 in function 0x1001CC80\n  and:\n    characteristic: tight loop @ 0x1001CCE0\n    characteristic: nzxor @ 0x1001CCE0\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1001CF60 in function 0x1001CE00\n  and:\n    characteristic: tight loop @ 0x1001CF60\n    characteristic: nzxor @ 0x1001CF6E, 0x1001CF72, 0x1001CF84, 0x1001CF88\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\ncreate new key via CryptAcquireContext\nnamespace   data-manipulation/encryption                                        \nauthor      chuong.dong@mandiant.com                                            \nscope       basic block                                                         \natt&ck      Defense Evasion::Obfuscated Files or Information [T1027]            \nmbc         Cryptography::Encryption Key [C0028]                                \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/wincrypt/nf-winc…\nbasic block @ 0x1001C76D in function 0x1001C690\n  and:\n    api: CryptAcquireContext @ 0x1001C778\n    or:\n      number: 0x8 = CRYPT_NEWKEYSET @ 0x1001C76D\n\ndecrypt data using AES via x86 extensions\nnamespace  data-manipulation/encryption/aes                                \nauthor     moritz.raabe@mandiant.com                                       \nscope      function                                                        \natt&ck     Defense Evasion::Deobfuscate/Decode Files or Information [T1140]\nmbc        Cryptography::Decrypt Data::AES [C0031.001]                     \nfunction @ 0x1000C1E0\n  or:\n    mnemonic: aesdec = Perform One Round of an AES Decryption Flow @ 0x1000C2ED, 0x1000C2F2, 0x1000C2FC, 0x1000C301, and 22 more...\n    mnemonic: aesdeclast = Perform Last Round of an AES Decryption Flow @ 0x1000C3C5, 0x1000C3CA\n\nencrypt data using AES via x86 extensions (3 matches)\nnamespace  data-manipulation/encryption/aes                                     \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encryption-Standard\n           Algorithm [E1027.m05], Cryptography::Encrypt Data::AES [C0027.001]   \nfunction @ 0x1000BF80\n  or:\n    mnemonic: aesenc = Perform One Round of an AES Encryption Flow @ 0x1000BFC2, 0x1000BFC8, 0x1000BFCE, 0x1000BFD4, and 35 more...\n    mnemonic: aesenclast = Perform Last Round of an AES Encryption Flow @ 0x1000C022, 0x1000C160, 0x1000C165\nfunction @ 0x1000C1E0\n  or:\n    mnemonic: aesenc = Perform One Round of an AES Encryption Flow @ 0x1000C227, 0x1000C22D, 0x1000C233, 0x1000C239, and 9 more...\n    mnemonic: aesenclast = Perform Last Round of an AES Encryption Flow @ 0x1000C287\nfunction @ 0x10015C50\n  or:\n    mnemonic: aesenc = Perform One Round of an AES Encryption Flow @ 0x10015D2A\n\nencrypt data using twofish (7 matches)\nnamespace  data-manipulation/encryption/twofish                                 \nauthor     @_re_fox                                                             \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encryption-Standard\n           Algorithm [E1027.m05], Cryptography::Encrypt Data::Twofish           \n           [C0027.005]                                                          \nbasic block @ 0x1000E20B in function 0x1000E1C0\n  or:\n    bytes: 01020408102040804d9a79f2a91f3e7cf8bd376edcf5a703060c183060c0cdd7e38b5bb621428445\n8a59b22952a4050a142850a00d1a3468d0ed9763c6c1cfd3eb9b7bf6a10f1e3c78f0ad172e5cb83d\n7af4a5070e1c3870e08d57ae112244885dba3972e485478e51a209122448906ddaf9bf3366ccd5e7\n834b9661c2c9dff3ab1b366cd8fdb723468c55aa193264c8ddf7a30b162c58b02d5ab4254a9465ca\nd9ffb32b56ac152a54a81d = EXP_TO_POLY @ 0x1000E215\nbasic block @ 0x1000E424 in function 0x1000E1C0\n  or:\n    bytes: 01020408102040804d9a79f2a91f3e7cf8bd376edcf5a703060c183060c0cdd7e38b5bb621428445\n8a59b22952a4050a142850a00d1a3468d0ed9763c6c1cfd3eb9b7bf6a10f1e3c78f0ad172e5cb83d\n7af4a5070e1c3870e08d57ae112244885dba3972e485478e51a209122448906ddaf9bf3366ccd5e7\n834b9661c2c9dff3ab1b366cd8fdb723468c55aa193264c8ddf7a30b162c58b02d5ab4254a9465ca\nd9ffb32b56ac152a54a81d = EXP_TO_POLY @ 0x1000E42E\nbasic block @ 0x1000E63D in function 0x1000E1C0\n  or:\n    bytes: 01020408102040804d9a79f2a91f3e7cf8bd376edcf5a703060c183060c0cdd7e38b5bb621428445\n8a59b22952a4050a142850a00d1a3468d0ed9763c6c1cfd3eb9b7bf6a10f1e3c78f0ad172e5cb83d\n7af4a5070e1c3870e08d57ae112244885dba3972e485478e51a209122448906ddaf9bf3366ccd5e7\n834b9661c2c9dff3ab1b366cd8fdb723468c55aa193264c8ddf7a30b162c58b02d5ab4254a9465ca\nd9ffb32b56ac152a54a81d = EXP_TO_POLY @ 0x1000E647\nbasic block @ 0x1000E856 in function 0x1000E1C0\n  or:\n    bytes: 01020408102040804d9a79f2a91f3e7cf8bd376edcf5a703060c183060c0cdd7e38b5bb621428445\n8a59b22952a4050a142850a00d1a3468d0ed9763c6c1cfd3eb9b7bf6a10f1e3c78f0ad172e5cb83d\n7af4a5070e1c3870e08d57ae112244885dba3972e485478e51a209122448906ddaf9bf3366ccd5e7\n834b9661c2c9dff3ab1b366cd8fdb723468c55aa193264c8ddf7a30b162c58b02d5ab4254a9465ca\nd9ffb32b56ac152a54a81d = EXP_TO_POLY @ 0x1000E860\nbasic block @ 0x1000EA2F in function 0x1000E1C0\n  or:\n    bytes: a97567f3b3c6e8f404dbfd7ba3fb76c89a4a92d380e6786be445dd7dd1e8384b0dd6c63235d898fd\n1837f771ecf16ce14330750f37f8261bfa8713fa9406483ff25ed0ba8bae305b848a5400dfbc239d\n196d5bc13db1590ef380ae5da2d282d563a0018483072e14d9b551909b2c7ca3a6b2eb73a54cbe54\n16920c74e3366151c0388cb03abdf55a73fc2c6025620b96bb6c4e4289f76b10537c6a28b427f18c\ne113e695bd9c45c7e224f4 = CALC_SB_TBL @ 0x1000EA9E\nbasic block @ 0x1000EAB0 in function 0x1000E1C0\n  or:\n    bytes: a967b3e804fda3769a928078e4ddd1380dc6359818f7ec6c43753726fa139448f2d08b308454df23\n195b3d59f3aea2826301832ed9519b7ca6eba5be160ce361c08c3af5732c250bbb4e896b536ab4f1\ne1e6bd45e2f4b666cc950356d41c1ed7fbc38eb5e9cfbfbaea7739af33c96271817909ad24cdf9d8\ne5c5b94d440886e7a11daaed0670b2d2417ba01131c2279020f660ff965cb1ab9e9c521b5f930aef\n918549ee2d4f8f3b47876d = Q0 @ 0x1000EAC7, 0x1000EAD1, 0x1000EB03, 0x1000EB21, and 2 more...\n    bytes: 75f3c6f4db7bfbc84ad3e66b457de84bd632d8fd3771f1e1300ff81b87fa063f5ebaae5b8a00bc9d\n6dc1b10e805dd2d5a0840714b5902ca3b2734c549274365138b0bd5afc6062966c42f7107c28278c\n13959cc724463b70cae385cb11d093b8a68320ff9f77c3cc036f08bf40e72be2790caa82413aeab9\ne49aa4977eda7a176694a11d3df0deb30b72a71cefd1533e8f33265fec762a498188ee21c41aebd9\nc53999cdad318b011823dd = Q1 @ 0x1000EABA, 0x1000EAEF, 0x1000EAF9, 0x1000EB35, and 2 more...\n    bytes: 7532bcbcf321ececc6432020f4c9b3b3db03dada7b8b0202fb2be2e2c8fa9e9e4aecc9c9d309d4d4\ne66b18186b9f1e1e450e98987d38b2b2e8d2a6a64bb72626d6573c3c328a9393d8ee8282fd985252\n37d47b7b7137bbbbf1975b5be1834747303c24240fe25151f8c6baba1bf34a4a8748bfbffa700d0d\n06b3b0b03fde75755efdd2d2ba207d7dae3166665ba33a3a8a1c595900000000bc93cdcd9de01a1a\n6d2caeaec1ab7f7fb1c72b = MDS1 @ 0x1000EADB\n    bytes: 3939d9a9171790679c9c71b3a6a6d2e807070504525298fd808065a3e4e4df764545089a4b4b0292\ne0e0a0805a5a6678afafdde46a6ab0dd6363bfd12a2a3638e6e6540d202043c6cccc6235f2f2be98\n12121e18ebeb24f7a1a1d7ec4141776c2828bd43bcbc32757b7bd43788889b260d0d70fa4444f913\nfbfbb1947e7e5a4803037af28c8ce4d0b6b6478b24243c30e7e7a5846b6b4154dddd06df6060c523\nfdfd45193a3aa35bc2c268 = MDS2 @ 0x1000EB0D\n    bytes: 32bc75bc21ecf3ec4320c620c9b3f4b303dadbda8b027b022be2fbe2fa9ec89eecc94ac909d4d3d4\n6b18e6189f1e6b1e0e98459838b27db2d2a6e8a6b7264b26573cd63c8a933293ee82d8829852fd52\nd47b377b37bb71bb975bf15b8347e1473c243024e2510f51c6baf8baf34a1b4a48bf87bf700dfa0d\nb3b006b0de753f75fdd25ed2207dba7d3166ae66a33a5b3a1c598a590000000093cdbccde01a9d1a\n2cae6daeab7fc17fc72bb1 = MDS3 @ 0x1000EB3F\n    bytes: d9a939d99067179071b39c71d2e8a6d20504070598fd529865a38065df76e4df089a450802924b02\na080e0a066785a66dde4afddb0dd6ab0bfd163bf36382a36540de65443c620436235cc62be98f2be\n1e18121e24f7eb24d7eca1d7776c4177bd4328bd3275bc32d4377bd49b26889b70fa0d70f91344f9\nb194fbb15a487e5a7af2037ae4d08ce4478bb6473c30243ca584e7a541546b4106dfdd06c52360c5\n4519fd45a35b3aa3683dc2 = MDS4 @ 0x1000EB71\nbasic block @ 0x1000EB84 in function 0x1000E1C0\n  or:\n    bytes: a967b3e804fda3769a928078e4ddd1380dc6359818f7ec6c43753726fa139448f2d08b308454df23\n195b3d59f3aea2826301832ed9519b7ca6eba5be160ce361c08c3af5732c250bbb4e896b536ab4f1\ne1e6bd45e2f4b666cc950356d41c1ed7fbc38eb5e9cfbfbaea7739af33c96271817909ad24cdf9d8\ne5c5b94d440886e7a11daaed0670b2d2417ba01131c2279020f660ff965cb1ab9e9c521b5f930aef\n918549ee2d4f8f3b47876d = Q0 @ 0x1000EB92, 0x1000EBBC, 0x1000EBC9, 0x1000EC12, and 236 more...\n    bytes: 75f3c6f4db7bfbc84ad3e66b457de84bd632d8fd3771f1e1300ff81b87fa063f5ebaae5b8a00bc9d\n6dc1b10e805dd2d5a0840714b5902ca3b2734c549274365138b0bd5afc6062966c42f7107c28278c\n13959cc724463b70cae385cb11d093b8a68320ff9f77c3cc036f08bf40e72be2790caa82413aeab9\ne49aa4977eda7a176694a11d3df0deb30b72a71cefd1533e8f33265fec762a498188ee21c41aebd9\nc53999cdad318b011823dd = Q1 @ 0x1000EB9B, 0x1000EBA8, 0x1000EBD6, 0x1000EBFC, and 236 more...\n    bytes: 7532bcbcf321ececc6432020f4c9b3b3db03dada7b8b0202fb2be2e2c8fa9e9e4aecc9c9d309d4d4\ne66b18186b9f1e1e450e98987d38b2b2e8d2a6a64bb72626d6573c3c328a9393d8ee8282fd985252\n37d47b7b7137bbbbf1975b5be1834747303c24240fe25151f8c6baba1bf34a4a8748bfbffa700d0d\n06b3b0b03fde75755efdd2d2ba207d7dae3166665ba33a3a8a1c595900000000bc93cdcd9de01a1a\n6d2caeaec1ab7f7fb1c72b = MDS1 @ 0x1000EC57, 0x1000ECFB, 0x1000EE26, 0x1000EED0, and 36 more...\n    bytes: 3939d9a9171790679c9c71b3a6a6d2e807070504525298fd808065a3e4e4df764545089a4b4b0292\ne0e0a0805a5a6678afafdde46a6ab0dd6363bfd12a2a3638e6e6540d202043c6cccc6235f2f2be98\n12121e18ebeb24f7a1a1d7ec4141776c2828bd43bcbc32757b7bd43788889b260d0d70fa4444f913\nfbfbb1947e7e5a4803037af28c8ce4d0b6b6478b24243c30e7e7a5846b6b4154dddd06df6060c523\nfdfd45193a3aa35bc2c268 = MDS2 @ 0x1000EC1F, 0x1000ED33, 0x1000EDEE, 0x1000EF08, and 36 more...\n    bytes: 32bc75bc21ecf3ec4320c620c9b3f4b303dadbda8b027b022be2fbe2fa9ec89eecc94ac909d4d3d4\n6b18e6189f1e6b1e0e98459838b27db2d2a6e8a6b7264b26573cd63c8a933293ee82d8829852fd52\nd47b377b37bb71bb975bf15b8347e1473c243024e2510f51c6baf8baf34a1b4a48bf87bf700dfa0d\nb3b006b0de753f75fdd25ed2207dba7d3166ae66a33a5b3a1c598a590000000093cdbccde01a9d1a\n2cae6daeab7fc17fc72bb1 = MDS3 @ 0x1000EBEA, 0x1000ECC4, 0x1000EDB6, 0x1000EE99, and 36 more...\n    bytes: d9a939d99067179071b39c71d2e8a6d20504070598fd529865a38065df76e4df089a450802924b02\na080e0a066785a66dde4afddb0dd6ab0bfd163bf36382a36540de65443c620436235cc62be98f2be\n1e18121e24f7eb24d7eca1d7776c4177bd4328bd3275bc32d4377bd49b26889b70fa0d70f91344f9\nb194fbb15a487e5a7af2037ae4d08ce4478bb6473c30243ca584e7a541546b4106dfdd06c52360c5\n4519fd45a35b3aa3683dc2 = MDS4 @ 0x1000EBE3, 0x1000EC94, 0x1000EDAD, 0x1000EE61, and 36 more...\n\nhash data using SHA256 (4 matches)\nnamespace   data-manipulation/hashing/sha256                                    \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,         \n            william.ballenthin@mandiant.com                                     \nscope       function                                                            \nmbc         Cryptography::Cryptographic Hash::SHA256 [C0029.003]                \nreferences  https://www.rfc-editor.org/rfc/rfc6234                              \nfunction @ 0x100146B0\n  or:\n    and:\n      number: 0x6A09E667 = H(0)0 @ 0x100146C1\n      number: 0xBB67AE85 = H(0)1 @ 0x100146CF\n      number: 0x3C6EF372 = H(0)2 @ 0x100146DD\n      number: 0xA54FF53A = H(0)3 @ 0x100146EB\n      number: 0x510E527F = H(0)4 @ 0x100146F9\n      number: 0x9B05688C = H(0)5 @ 0x10014707\n      number: 0x1F83D9AB = H(0)6 @ 0x10014715\n      number: 0x5BE0CD19 = H(0)7 @ 0x10014723\nfunction @ 0x1001C7D0\n  or:\n    and:\n      number: 0x6A09E667 = H(0)0 @ 0x1001C8D2\n      number: 0xBB67AE85 = H(0)1 @ 0x1001C8E0\n      number: 0x3C6EF372 = H(0)2 @ 0x1001C8EE\n      number: 0xA54FF53A = H(0)3 @ 0x1001C8FC\n      number: 0x510E527F = H(0)4 @ 0x1001C90A\n      number: 0x9B05688C = H(0)5 @ 0x1001C918\n      number: 0x1F83D9AB = H(0)6 @ 0x1001C926\n      number: 0x5BE0CD19 = H(0)7 @ 0x1001C934\nfunction @ 0x1001CB10\n  or:\n    and:\n      number: 0x6A09E667 = H(0)0 @ 0x1001CB50\n      number: 0xBB67AE85 = H(0)1 @ 0x1001CB5E\n      number: 0x3C6EF372 = H(0)2 @ 0x1001CB6C\n      number: 0xA54FF53A = H(0)3 @ 0x1001CB7A\n      number: 0x510E527F = H(0)4 @ 0x1001CB88\n      number: 0x9B05688C = H(0)5 @ 0x1001CB96\n      number: 0x1F83D9AB = H(0)6 @ 0x1001CBA4\n      number: 0x5BE0CD19 = H(0)7 @ 0x1001CBB2\nfunction @ 0x1001CC80\n  or:\n    and:\n      number: 0x6A09E667 = H(0)0 @ 0x1001CCFF\n      number: 0xBB67AE85 = H(0)1 @ 0x1001CD0D\n      number: 0x3C6EF372 = H(0)2 @ 0x1001CD1B\n      number: 0xA54FF53A = H(0)3 @ 0x1001CD29\n      number: 0x510E527F = H(0)4 @ 0x1001CD37\n      number: 0x9B05688C = H(0)5 @ 0x1001CD45\n      number: 0x1F83D9AB = H(0)6 @ 0x1001CD53\n      number: 0x5BE0CD19 = H(0)7 @ 0x1001CD61\n\ngenerate random numbers via WinAPI\nnamespace  data-manipulation/prng                                            \nauthor     michael.hunhoff@mandiant.com, johnk3r                             \nscope      function                                                          \nmbc        Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\nfunction @ 0x1001C690\n  and:\n    or:\n      api: CryptGenRandom @ 0x1001C78D\n\nextract resource via kernel32 functions (4 matches)\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x10018100\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x1001819F, 0x10018205\n        api: LockResource @ 0x100181A6, 0x1001820C\n      optional:\n        or:\n          api: FindResource @ 0x10018177, 0x100181E1\n        api: SizeofResource @ 0x1001818F, 0x100181F5\nfunction @ 0x10018650\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x10018698\n        api: LockResource @ 0x1001869F\n      optional:\n        or:\n          api: FindResource @ 0x10018674\n        api: SizeofResource @ 0x10018688\nfunction @ 0x10018700\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x1001875B, 0x100187C9\n        api: LockResource @ 0x10018762, 0x100187D0\n      optional:\n        or:\n          api: FindResource @ 0x10018737, 0x100187A8\n        api: SizeofResource @ 0x10018751, 0x100187BC\nfunction @ 0x1001C110\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x1001C14F\n        api: LockResource @ 0x1001C156\n      optional:\n        or:\n          api: FindResource @ 0x1001C128\n        api: SizeofResource @ 0x1001C13C\n\ninteract with driver via IOCTL (57 matches)\nnamespace  host-interaction/driver  \nauthor     moritz.raabe@mandiant.com\nscope      instruction              \ninstruction @ 0x10017076\n  or:\n    api: DeviceIoControl @ 0x10017076\ninstruction @ 0x10017596\n  or:\n    api: DeviceIoControl @ 0x10017596\ninstruction @ 0x100178FF\n  or:\n    api: DeviceIoControl @ 0x100178FF\ninstruction @ 0x10017AB9\n  or:\n    api: DeviceIoControl @ 0x10017AB9\ninstruction @ 0x10017AEF\n  or:\n    api: DeviceIoControl @ 0x10017AEF\ninstruction @ 0x10017B4D\n  or:\n    api: DeviceIoControl @ 0x10017B4D\ninstruction @ 0x10017B94\n  or:\n    api: DeviceIoControl @ 0x10017B94\ninstruction @ 0x10017BD4\n  or:\n    api: DeviceIoControl @ 0x10017BD4\ninstruction @ 0x10018E39\n  or:\n    api: DeviceIoControl @ 0x10018E39\ninstruction @ 0x10018E66\n  or:\n    api: DeviceIoControl @ 0x10018E66\ninstruction @ 0x10018EB0\n  or:\n    api: DeviceIoControl @ 0x10018EB0\ninstruction @ 0x10018F8C\n  or:\n    api: DeviceIoControl @ 0x10018F8C\ninstruction @ 0x10018FB3\n  or:\n    api: DeviceIoControl @ 0x10018FB3\ninstruction @ 0x10018FC7\n  or:\n    api: DeviceIoControl @ 0x10018FC7\ninstruction @ 0x10019299\n  or:\n    api: DeviceIoControl @ 0x10019299\ninstruction @ 0x10019450\n  or:\n    api: DeviceIoControl @ 0x10019450\ninstruction @ 0x10019497\n  or:\n    api: DeviceIoControl @ 0x10019497\ninstruction @ 0x1001A3F5\n  or:\n    api: DeviceIoControl @ 0x1001A3F5\ninstruction @ 0x1001A460\n  or:\n    api: DeviceIoControl @ 0x1001A460\ninstruction @ 0x1001A4B8\n  or:\n    api: DeviceIoControl @ 0x1001A4B8\ninstruction @ 0x1001A539\n  or:\n    api: DeviceIoControl @ 0x1001A539\ninstruction @ 0x1001A600\n  or:\n    api: DeviceIoControl @ 0x1001A600\ninstruction @ 0x1001A69B\n  or:\n    api: DeviceIoControl @ 0x1001A69B\ninstruction @ 0x1001A730\n  or:\n    api: DeviceIoControl @ 0x1001A730\ninstruction @ 0x1001A7CB\n  or:\n    api: DeviceIoControl @ 0x1001A7CB\ninstruction @ 0x1001A879\n  or:\n    api: DeviceIoControl @ 0x1001A879\ninstruction @ 0x1001A8C8\n  or:\n    api: DeviceIoControl @ 0x1001A8C8\ninstruction @ 0x1001A9D2\n  or:\n    api: DeviceIoControl @ 0x1001A9D2\ninstruction @ 0x1001AAD6\n  or:\n    api: DeviceIoControl @ 0x1001AAD6\ninstruction @ 0x1001AB32\n  or:\n    api: DeviceIoControl @ 0x1001AB32\ninstruction @ 0x1001ABF3\n  or:\n    api: DeviceIoControl @ 0x1001ABF3\ninstruction @ 0x1001ACF9\n  or:\n    api: DeviceIoControl @ 0x1001ACF9\ninstruction @ 0x1001AD89\n  or:\n    api: DeviceIoControl @ 0x1001AD89\ninstruction @ 0x1001AE29\n  or:\n    api: DeviceIoControl @ 0x1001AE29\ninstruction @ 0x1001AEA9\n  or:\n    api: DeviceIoControl @ 0x1001AEA9\ninstruction @ 0x1001AF69\n  or:\n    api: DeviceIoControl @ 0x1001AF69\ninstruction @ 0x1001B000\n  or:\n    api: DeviceIoControl @ 0x1001B000\ninstruction @ 0x1001B0A9\n  or:\n    api: DeviceIoControl @ 0x1001B0A9\ninstruction @ 0x1001B139\n  or:\n    api: DeviceIoControl @ 0x1001B139\ninstruction @ 0x1001B1D9\n  or:\n    api: DeviceIoControl @ 0x1001B1D9\ninstruction @ 0x1001B262\n  or:\n    api: DeviceIoControl @ 0x1001B262\ninstruction @ 0x1001B309\n  or:\n    api: DeviceIoControl @ 0x1001B309\ninstruction @ 0x1001B3A0\n  or:\n    api: DeviceIoControl @ 0x1001B3A0\ninstruction @ 0x1001B449\n  or:\n    api: DeviceIoControl @ 0x1001B449\ninstruction @ 0x1001B4E0\n  or:\n    api: DeviceIoControl @ 0x1001B4E0\ninstruction @ 0x1001B589\n  or:\n    api: DeviceIoControl @ 0x1001B589\ninstruction @ 0x1001B5EF\n  or:\n    api: DeviceIoControl @ 0x1001B5EF\ninstruction @ 0x1001B699\n  or:\n    api: DeviceIoControl @ 0x1001B699\ninstruction @ 0x1001B70E\n  or:\n    api: DeviceIoControl @ 0x1001B70E\ninstruction @ 0x1001B7C9\n  or:\n    api: DeviceIoControl @ 0x1001B7C9\ninstruction @ 0x1001B861\n  or:\n    api: DeviceIoControl @ 0x1001B861\ninstruction @ 0x1001B8E6\n  or:\n    api: DeviceIoControl @ 0x1001B8E6\ninstruction @ 0x1001BD10\n  or:\n    api: DeviceIoControl @ 0x1001BD10\ninstruction @ 0x1001BDE1\n  or:\n    api: DeviceIoControl @ 0x1001BDE1\ninstruction @ 0x1001BED4\n  or:\n    api: DeviceIoControl @ 0x1001BED4\ninstruction @ 0x1001C23B\n  or:\n    api: DeviceIoControl @ 0x1001C23B\ninstruction @ 0x1001C84A\n  or:\n    api: DeviceIoControl @ 0x1001C84A\n\nget common file path (4 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x10019B40\n  or:\n    api: GetSystemDirectory @ 0x10019B5F\nfunction @ 0x10019D90\n  or:\n    api: GetSystemDirectory @ 0x10019DAF\nfunction @ 0x10019E20\n  or:\n    api: GetSystemDirectory @ 0x10019EAE\nfunction @ 0x10019F50\n  or:\n    api: GetSystemDirectory @ 0x10019F6F\n\ncopy file\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ 0x1001A060\n  or:\n    api: CopyFile @ 0x1001A124\n\ndelete file (3 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x10019E20\n  or:\n    api: DeleteFile @ 0x10019F17\nfunction @ 0x1001A170\n  or:\n    api: DeleteFile @ 0x1001A1D2\nfunction @ 0x1001D010\n  or:\n    api: DeleteFile @ 0x1001D4A5\n\ncheck if file exists\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x10019D90\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x10019E00\n        instruction:\n          and:\n            mnemonic: cmp @ 0x10019E08\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x10019E08\n\nenumerate files on Windows\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ 0x1001CA00\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x1001CA4C\n      or:\n        api: FindNextFile @ 0x1001CAA9\n      optional:\n        api: FindClose @ 0x1001CAB8\n        match: contain loop @ 0x1001CA00\n          or:\n            characteristic: loop @ 0x1001CA00\n            characteristic: tight loop @ 0x1001CAD5, 0x1001CAE8\n\nget file attributes\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x10019DF9 in function 0x10019D90\n  or:\n    api: GetFileAttributes @ 0x10019E00\n\nget file size (4 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x10017270\n  or:\n    api: GetFileSize @ 0x100172A4\nfunction @ 0x10017E60\n  or:\n    api: GetFileSize @ 0x10017EC5\nfunction @ 0x10018AE0\n  or:\n    api: GetFileSize @ 0x10018B92\nfunction @ 0x1001D010\n  or:\n    api: GetFileSizeEx @ 0x1001D113\n\nread file on Windows (8 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x10016D60\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x10016E16\nfunction @ 0x10016E90\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x10016F3E\nfunction @ 0x10017270\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x10017282\n          match: create or open file @ 0x10017288\n            or:\n              api: CreateFile @ 0x10017288\n      or:\n        api: ReadFile @ 0x100172D2\nfunction @ 0x10017670\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x10017722\nfunction @ 0x10017E60\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x10017F73\nfunction @ 0x10018AE0\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x10018B61\n          match: create or open file @ 0x10018B67\n            or:\n              api: CreateFile @ 0x10018B67\n      or:\n        api: ReadFile @ 0x10018C31\nfunction @ 0x1001C7D0\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x1001C88A\n          match: create or open file @ 0x1001C820, 0x1001C890\n            or:\n              api: CreateFile @ 0x1001C820\n            or:\n              api: CreateFile @ 0x1001C890\n      or:\n        api: ReadFile @ 0x1001C93B, 0x1001C960\nfunction @ 0x1001D010\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x1001D0F6\n          match: create or open file @ 0x1001D102, 0x1001D12D\n            or:\n              api: CreateFile @ 0x1001D102\n            or:\n              api: CreateFile @ 0x1001D12D\n      or:\n        api: ReadFile @ 0x1001D369\n\nwrite file on Windows (7 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x10016D60\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x10016E5A, 0x10016E65\nfunction @ 0x10017310\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x10017322\n            number: 0x2 = FILE_WRITE_DATA @ 0x1001731C\n            match: create or open file @ 0x10017328\n              or:\n                api: CreateFile @ 0x10017328\n      or:\n        api: WriteFile @ 0x10017344\nfunction @ 0x10017E60\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            match: create or open file @ 0x10017E9E\n              or:\n                api: CreateFile @ 0x10017E9E\n      or:\n        api: WriteFile @ 0x10018070\nfunction @ 0x10018650\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x100186C5\n            number: 0x2 = FILE_WRITE_DATA @ 0x100186BF\n            match: create or open file @ 0x100186CB\n              or:\n                api: CreateFile @ 0x100186CB\n      or:\n        api: WriteFile @ 0x100186E1\nfunction @ 0x10018700\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x1001899E\n            number: 0x2 = FILE_WRITE_DATA @ 0x10018922, 0x10018930, 0x10018998\n            match: create or open file @ 0x100189A4\n              or:\n                api: CreateFile @ 0x100189A4\n      or:\n        api: WriteFile @ 0x100189BE\nfunction @ 0x10018DB0\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x10018F1F\nfunction @ 0x1001D010\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            match: create or open file @ 0x1001D102\n              or:\n                api: CreateFile @ 0x1001D102\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x1001D240\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x1001D127\n            match: create or open file @ 0x1001D12D\n              or:\n                api: CreateFile @ 0x1001D12D\n      or:\n        api: WriteFile @ 0x1001D2DE, 0x1001D3AD\n\nenumerate gui resources\nnamespace  host-interaction/gui                           \nauthor     johnk3r, anushka.virgaonkar@mandiant.com       \nscope      function                                       \natt&ck     Discovery::Application Window Discovery [T1010]\nfunction @ 0x1001C480\n  or:\n    api: EnumWindows @ 0x1001C638\n\nset application hook (2 matches)\nnamespace  host-interaction/gui        \nauthor     michael.hunhoff@mandiant.com\nscope      instruction                 \ninstruction @ 0x1001C73A\n  or:\n    api: SetWindowsHookEx @ 0x1001C73A\ninstruction @ 0x1001C74D\n  or:\n    api: SetWindowsHookEx @ 0x1001C74D\n\nget graphical window text\nnamespace  host-interaction/gui/window/get-text           \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \nmbc        Discovery::Application Window Discovery [E1010]\nfunction @ 0x1001C3B0\n  or:\n    and:\n      api: GetWindowText @ 0x1001C434\n\nget memory capacity\nnamespace  host-interaction/hardware/memory               \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x1001C480\n  or:\n    api: GlobalMemoryStatusEx @ 0x1001C619\n\nenumerate disk volumes\nnamespace  host-interaction/hardware/storage              \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x1001BA30\n  and:\n    match: contain loop @ 0x1001BA30\n      or:\n        characteristic: loop @ 0x1001BA30\n    or:\n      and:\n        api: FindFirstVolume @ 0x1001BA5A\n        api: FindNextVolume @ 0x1001BACB\n        optional:\n          api: FindVolumeClose @ 0x1001BB13\n\nget disk information via IOCTL (2 matches)\nnamespace   host-interaction/hardware/storage                                   \nauthor      william.ballenthin@mandiant.com                                     \nscope       basic block                                                         \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-…\n            http://www.ioctls.net/                                              \nbasic block @ 0x10017AD4 in function 0x10017A20\n  and:\n    or:\n      match: interact with driver via IOCTL @ 0x10017AEF\n        or:\n          api: DeviceIoControl @ 0x10017AEF\n      characteristic: indirect call @ 0x10017AEF\n    or:\n      number: 0x2D1080 = IOCTL_STORAGE_GET_DEVICE_NUMBER @ 0x10017AE9\nbasic block @ 0x1001947F in function 0x100193A0\n  and:\n    or:\n      match: interact with driver via IOCTL @ 0x10019497\n        or:\n          api: DeviceIoControl @ 0x10019497\n      characteristic: indirect call @ 0x10019497\n    or:\n      number: 0x2D1080 = IOCTL_STORAGE_GET_DEVICE_NUMBER @ 0x10019491\n\nget disk size\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ 0x10017A20\n  or:\n    basic block:\n      and:\n        match: interact with driver via IOCTL @ 0x10017B94\n          or:\n            api: DeviceIoControl @ 0x10017B94\n        number: 0x7405C = IOCTL_DISK_GET_LENGTH_INFO @ 0x10017B87\n\nget storage device properties\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com                                        \nscope       function                                                            \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/winioctl/ni-wini…\nfunction @ 0x1001BE60\n  and:\n    number: 0x2D1400 = IOCTL_STORAGE_QUERY_PROPERTY @ 0x1001BEBA\n    or:\n      match: interact with driver via IOCTL @ 0x1001BED4\n        or:\n          api: DeviceIoControl @ 0x1001BED4\n\nunmount volume via IOCTL\nnamespace   host-interaction/hardware/storage                                   \nauthor      william.ballenthin@mandiant.com                                     \nscope       function                                                            \nreferences  https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-…\nfunction @ 0x10018DB0\n  and:\n    or:\n      match: interact with driver via IOCTL @ 0x10018E39, 0x10018E66, 0x10018EB0, 0x10018F8C, and 2 more...\n        or:\n          api: DeviceIoControl @ 0x10018EB0\n        or:\n          api: DeviceIoControl @ 0x10018FB3\n        or:\n          api: DeviceIoControl @ 0x10018E66\n        or:\n          api: DeviceIoControl @ 0x10018FC7\n        or:\n          api: DeviceIoControl @ 0x10018E39\n        or:\n          api: DeviceIoControl @ 0x10018F8C\n      characteristic: indirect call @ 0x10018EB0, 0x10018F8C, 0x10018FB3, 0x10018FC7, and 1 more...\n    and:\n      number: 0x90018 = FSCTL_LOCK_VOLUME @ 0x10018E33\n      number: 0x90020 = FSCTL_DISMOUNT_VOLUME @ 0x10018FAD\n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex                                               \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           mehunhoff@google.com                                                 \nscope      instruction                                                          \nmbc        Process::Create Mutex [C0042]                                        \ninstruction @ 0x1001C0C2\n  or:\n    api: CreateMutex @ 0x1001C0C2\n\ncheck OS version (4 matches)\nnamespace  host-interaction/os/version                    \nauthor     michael.hunhoff@mandiant.com, johnk3r          \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x10016D10\n  and:\n    match: get OS version @ 0x10016D10\n      or:\n        api: GetVersionEx @ 0x10016D34\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x10016D3A\n            number: 0x6 = Windows Vista / Windows Server 2008 @ 0x10016D3A\nfunction @ 0x10019E20\n  and:\n    match: get OS version @ 0x10019E20\n      or:\n        api: GetVersion @ 0x10019E70\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x10019E76\n            number: 0x6 = Windows Vista / Windows Server 2008 @ 0x10019E76\nfunction @ 0x1001A170\n  and:\n    match: get OS version @ 0x1001A170\n      or:\n        api: GetVersion @ 0x1001A239\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1001A23F\n            number: 0x6 = Windows Vista / Windows Server 2008 @ 0x1001A23F\nfunction @ 0x1001A2F0\n  and:\n    match: get OS version @ 0x1001A2F0\n      or:\n        api: GetVersion @ 0x1001A37F\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1001A385\n            number: 0x6 = Windows Vista / Windows Server 2008 @ 0x1001A385\n\nget thread local storage value (27 matches)\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x10017540\n  and:\n    api: TlsGetValue @ 0x1001754D\nfunction @ 0x1001A3D0\n  and:\n    api: TlsGetValue @ 0x1001A3EE\nfunction @ 0x1001A400\n  and:\n    api: TlsGetValue @ 0x1001A459\nfunction @ 0x1001A490\n  and:\n    api: TlsGetValue @ 0x1001A4B1\nfunction @ 0x1001A4D0\n  and:\n    api: TlsGetValue @ 0x1001A532\nfunction @ 0x1001A5A0\n  and:\n    api: TlsGetValue @ 0x1001A5F9\nfunction @ 0x1001A630\n  and:\n    api: TlsGetValue @ 0x1001A694\nfunction @ 0x1001A6D0\n  and:\n    api: TlsGetValue @ 0x1001A729\nfunction @ 0x1001A760\n  and:\n    api: TlsGetValue @ 0x1001A7C4\nfunction @ 0x1001A800\n  and:\n    api: TlsGetValue @ 0x1001A823\nfunction @ 0x1001A970\n  and:\n    api: TlsGetValue @ 0x1001A9CB\nfunction @ 0x1001AA30\n  and:\n    api: TlsGetValue @ 0x1001AA54\nfunction @ 0x1001AB90\n  and:\n    api: TlsGetValue @ 0x1001AB9B\nfunction @ 0x1001AC80\n  and:\n    api: TlsGetValue @ 0x1001ACB0, 0x1001AD82\nfunction @ 0x1001ADB0\n  and:\n    api: TlsGetValue @ 0x1001ADE0, 0x1001AEA2\nfunction @ 0x1001AEF0\n  and:\n    api: TlsGetValue @ 0x1001AF20, 0x1001AFF9\nfunction @ 0x1001B030\n  and:\n    api: TlsGetValue @ 0x1001B060, 0x1001B132\nfunction @ 0x1001B160\n  and:\n    api: TlsGetValue @ 0x1001B190, 0x1001B25B\nfunction @ 0x1001B290\n  and:\n    api: TlsGetValue @ 0x1001B2C0, 0x1001B399\nfunction @ 0x1001B3D0\n  and:\n    api: TlsGetValue @ 0x1001B400, 0x1001B4D9\nfunction @ 0x1001B510\n  and:\n    api: TlsGetValue @ 0x1001B540, 0x1001B5E8\nfunction @ 0x1001B620\n  and:\n    api: TlsGetValue @ 0x1001B650, 0x1001B707\nfunction @ 0x1001B750\n  and:\n    api: TlsGetValue @ 0x1001B780, 0x1001B85A\nfunction @ 0x1001B890\n  and:\n    api: TlsGetValue @ 0x1001B89D\nfunction @ 0x1001C070\n  and:\n    api: TlsGetValue @ 0x1001C089\nfunction @ 0x1001C1B0\n  and:\n    api: TlsGetValue @ 0x1001C1F3\nfunction @ 0x1001C7D0\n  and:\n    api: TlsGetValue @ 0x1001C802\n\nallocate or change RWX memory (13 matches)\nnamespace  host-interaction/process/inject\nauthor     @mr-tz, mehunhoff@google.com   \nscope      basic block                    \nmbc        Memory::Allocate Memory [C0007]\nbasic block @ 0x10017600 in function 0x10017600\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x10017600\n            or:\n              api: VirtualAlloc @ 0x10017617\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x1001760A\nbasic block @ 0x1001AC80 in function 0x1001AC80\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x1001AC80\n            or:\n              api: VirtualAlloc @ 0x1001AC9D\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x1001AC88\nbasic block @ 0x1001ADB0 in function 0x1001ADB0\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x1001ADB0\n            or:\n              api: VirtualAlloc @ 0x1001ADCD\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x1001ADB8\nbasic block @ 0x1001AEF0 in function 0x1001AEF0\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x1001AEF0\n            or:\n              api: VirtualAlloc @ 0x1001AF0D\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x1001AEF8\nbasic block @ 0x1001B030 in function 0x1001B030\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x1001B030\n            or:\n              api: VirtualAlloc @ 0x1001B04D\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x1001B038\nbasic block @ 0x1001B160 in function 0x1001B160\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x1001B160\n            or:\n              api: VirtualAlloc @ 0x1001B17D\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x1001B168\nbasic block @ 0x1001B290 in function 0x1001B290\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x1001B290\n            or:\n              api: VirtualAlloc @ 0x1001B2AD\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x1001B298\nbasic block @ 0x1001B3D0 in function 0x1001B3D0\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x1001B3D0\n            or:\n              api: VirtualAlloc @ 0x1001B3ED\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x1001B3D8\nbasic block @ 0x1001B510 in function 0x1001B510\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x1001B510\n            or:\n              api: VirtualAlloc @ 0x1001B52D\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x1001B518\nbasic block @ 0x1001B620 in function 0x1001B620\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x1001B620\n            or:\n              api: VirtualAlloc @ 0x1001B63D\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x1001B628\nbasic block @ 0x1001B750 in function 0x1001B750\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x1001B750\n            or:\n              api: VirtualAlloc @ 0x1001B76D\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x1001B758\nbasic block @ 0x1001C690 in function 0x1001C690\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x1001C690\n            or:\n              api: VirtualAlloc @ 0x1001C6C2\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x1001C6AC\nbasic block @ 0x1001C7D0 in function 0x1001C7D0\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x1001C7D0\n            or:\n              api: VirtualAlloc @ 0x1001C7EF\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x1001C7D9\n\nmodify access privileges\nnamespace  host-interaction/process/modify                        \nauthor     moritz.raabe@mandiant.com                              \nscope      instruction                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\ninstruction @ 0x10017498\n  and:\n    api: AdjustTokenPrivileges @ 0x10017498\n\nquery or enumerate registry value (3 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x100196A0\n  and:\n    optional:\n      match: create or open registry key @ 0x100196A0\n        or:\n          api: RegOpenKey @ 0x100196D5\n    or:\n      api: RegQueryValueEx @ 0x1001972F\nfunction @ 0x10019890\n  and:\n    optional:\n      match: create or open registry key @ 0x10019890\n        or:\n          api: RegOpenKey @ 0x100198CD\n    or:\n      api: RegQueryValueEx @ 0x100198F6\nfunction @ 0x10019CA0\n  and:\n    optional:\n      match: create or open registry key @ 0x10019CA0\n        or:\n          api: RegOpenKey @ 0x10019CB7\n    or:\n      api: RegQueryValueEx @ 0x10019CEB, 0x10019D10, 0x10019D38\n\nset registry value (4 matches)\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x10019550\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x10019550, 0x100195A5\n          or:\n            api: RegCreateKey @ 0x10019578\n          or:\n            api: RegCreateKey @ 0x100195B2\n      or:\n        api: RegSetValueEx @ 0x1001959D, 0x100195CD, 0x100195E7\nfunction @ 0x100196A0\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x100196A0\n          or:\n            api: RegOpenKey @ 0x100196D5\n      or:\n        api: RegSetValueEx @ 0x10019845\nfunction @ 0x10019890\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x10019890\n          or:\n            api: RegOpenKey @ 0x100198CD\n      or:\n        api: RegSetValueEx @ 0x10019A38\nfunction @ 0x10019BC0\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x10019BC0\n          or:\n            api: RegCreateKey @ 0x10019BEF\n      or:\n        api: RegSetValueEx @ 0x10019C13, 0x10019C2D, 0x10019C47\n\ndelete registry value\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ 0x10019890\n  and:\n    optional:\n      match: create or open registry key @ 0x10019890\n        or:\n          api: RegOpenKey @ 0x100198CD\n    or:\n      api: RegDeleteValue @ 0x100199D8\n\ncreate service\nnamespace  host-interaction/service/create                                      \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003], Execution::System Services::Service Execution           \n           [T1569.002]                                                          \nfunction @ 0x10019F50\n  and:\n    api: CreateService @ 0x1001A029\n    optional:\n      api: OpenSCManager @ 0x10019FD9\n\ndelete service\nnamespace  host-interaction/service/delete                                      \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003]                                                          \nfunction @ 0x10019630\n  and:\n    api: DeleteService @ 0x10019664\n    optional:\n      match: get service handle @ 0x10019630\n        or:\n          api: OpenService @ 0x10019657\n\nget token membership\nnamespace  host-interaction/session                      \nauthor     michael.hunhoff@mandiant.com                  \nscope      function                                      \natt&ck     Discovery::System Owner/User Discovery [T1033]\nfunction @ 0x10017370\n  and:\n    api: CheckTokenMembership @ 0x100173CF\n    optional:\n      api: AllocateAndInitializeSid @ 0x100173A9\n      api: FreeSid @ 0x100173F3\n\nallocate thread local storage\nnamespace  host-interaction/thread/tls                   \nauthor     michael.hunhoff@mandiant.com                  \nscope      function                                      \nmbc        Process::Allocate Thread Local Storage [C0040]\nfunction @ 0x1001C070\n  or:\n    api: TlsAlloc @ 0x1001C0A3\n\nset thread local storage value (16 matches)\nnamespace  host-interaction/thread/tls                    \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \nmbc        Process::Set Thread Local Storage Value [C0041]\nfunction @ 0x10017540\n  and:\n    api: TlsSetValue @ 0x1001757A\nfunction @ 0x1001AB90\n  and:\n    api: TlsSetValue @ 0x1001ABD2\nfunction @ 0x1001AC40\n  and:\n    api: TlsSetValue @ 0x1001AC63\nfunction @ 0x1001AC80\n  and:\n    api: TlsSetValue @ 0x1001ACDD\nfunction @ 0x1001ADB0\n  and:\n    api: TlsSetValue @ 0x1001AE0D\nfunction @ 0x1001AEF0\n  and:\n    api: TlsSetValue @ 0x1001AF4D\nfunction @ 0x1001B030\n  and:\n    api: TlsSetValue @ 0x1001B08D\nfunction @ 0x1001B160\n  and:\n    api: TlsSetValue @ 0x1001B1BD\nfunction @ 0x1001B290\n  and:\n    api: TlsSetValue @ 0x1001B2ED\nfunction @ 0x1001B3D0\n  and:\n    api: TlsSetValue @ 0x1001B42D\nfunction @ 0x1001B510\n  and:\n    api: TlsSetValue @ 0x1001B56D\nfunction @ 0x1001B620\n  and:\n    api: TlsSetValue @ 0x1001B67D\nfunction @ 0x1001B750\n  and:\n    api: TlsSetValue @ 0x1001B7AD\nfunction @ 0x1001B890\n  and:\n    api: TlsSetValue @ 0x1001B8CA\nfunction @ 0x1001C1B0\n  and:\n    api: TlsSetValue @ 0x1001C21F\nfunction @ 0x1001C7D0\n  and:\n    api: TlsSetValue @ 0x1001C831\n\ndelete drive layout via IOCTL\nnamespace   impact/wipe-disk                                                    \nauthor      william.ballenthin@mandiant.com                                     \nscope       basic block                                                         \natt&ck      Impact::Disk Wipe::Disk Structure Wipe [T1561.002]                  \nmbc         Impact::Disk Wipe [F0014]                                           \nreferences  https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-…\n            http://www.ioctls.net/,                                             \n            https://tyleo.github.io/sharedlib/doc/winapi/winioctl/constant.IOCT…\nbasic block @ 0x10018E4F in function 0x10018DB0\n  and:\n    number: 0x7C100 = IOCTL_DISK_DELETE_DRIVE_LAYOUT @ 0x10018E60\n    or:\n      match: interact with driver via IOCTL @ 0x10018E66\n        or:\n          api: DeviceIoControl @ 0x10018E66\n\nlink function at runtime on Windows (3 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x1001723D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1001723D\ninstruction @ 0x100174F2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x100174F2\ninstruction @ 0x10018FEE\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x10018FEE\n\nexecute shellcode via indirect call (2 matches)\nnamespace  load-code/shellcode            \nauthor     ronnie.salomonsen@mandiant.com \nscope      function                       \nmbc        Memory::Allocate Memory [C0007]\nfunction @ 0x1001C690\n  and:\n    match: allocate or change RWX memory @ 0x1001C690\n      or:\n        basic block:\n          and:\n            or:\n              match: allocate memory @ 0x1001C690\n                or:\n                  api: VirtualAlloc @ 0x1001C6C2\n            or:\n              number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x1001C6AC\n    or:\n      characteristic: indirect call @ 0x1001C728, 0x1001C73A, 0x1001C741, 0x1001C74D, and 2 more...\nfunction @ 0x1001C7D0\n  and:\n    match: allocate or change RWX memory @ 0x1001C7D0\n      or:\n        basic block:\n          and:\n            or:\n              match: allocate memory @ 0x1001C7D0\n                or:\n                  api: VirtualAlloc @ 0x1001C7EF\n            or:\n              number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x1001C7D9\n    or:\n      characteristic: indirect call @ 0x1001C820, 0x1001C890\n\npersist via Windows service (2 matches)\nnamespace  persistence/service                                                  \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003], Execution::System Services::Service Execution           \n           [T1569.002]                                                          \nfunction @ 0x10019550\n  or:\n    and:\n      match: set registry value @ 0x10019550\n        or:\n          and:\n            optional:\n              match: create or open registry key @ 0x10019550, 0x100195A5\n                or:\n                  api: RegCreateKey @ 0x10019578\n                or:\n                  api: RegCreateKey @ 0x100195B2\n            or:\n              api: RegSetValueEx @ 0x1001959D, 0x100195CD, 0x100195E7\n      regex: /System\\\\(ControlSet\\d{3}|CurrentControlSet)\\\\Services/i\n        - \"SYSTEM\\\\CurrentControlSet\\\\Services\\\\dcrypt\\\\Instances\" @ 0x10019565\nfunction @ 0x10019BC0\n  or:\n    and:\n      match: set registry value @ 0x10019BC0\n        or:\n          and:\n            optional:\n              match: create or open registry key @ 0x10019BC0\n                or:\n                  api: RegCreateKey @ 0x10019BEF\n            or:\n              api: RegSetValueEx @ 0x10019C13, 0x10019C2D, 0x10019C47\n      regex: /System\\\\(ControlSet\\d{3}|CurrentControlSet)\\\\Services/i\n        - \"SYSTEM\\\\CurrentControlSet\\\\Services\\\\dcrypt\\\\config\" @ 0x10019BD8\n\n\n\n"},"hashes":{"md5":"f93c8da34f2c03c8ccdc29343fdb4be7","sha1":"8df2856ab19e1f3b476e751efdef95f08bd3a2d7","sha256":"77300d435ee41065e1bee369c31908388cb56a8759471d8ade2028c80950c654"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 186</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 14649</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"resource_32DCAPI.DLL_105.bin\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"f93c8da34f2c03c8ccdc29343fdb4be7\",\n        \"sha256\": \"77300d435ee41065e1bee369c31908388cb56a8759471d8ade2028c\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_allocate_memory__14_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"allocate memory (14 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x10017600\",\n      \"label\": \"Block 0x10017600\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x10017600\"\n    },\n    {\n      \"id\": \"api_VirtualAlloc\",\n      \"label\": \"VirtualAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_contain_loop__61_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (61 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1000284B\",\n      \"label\": \"Function 0x1000284B\",\n      \"type\": \"function\",\n      \"address\": \"0x1000284B\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__31_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (31 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x10019550\",\n      \"label\": \"Block 0x10019550\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x10019550\"\n    },\n    {\n      \"id\": \"api_RegCreateKey\",\n      \"label\": \"RegCreateKey\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1000D6F6\",\n      \"label\": \"Block 0x1000D6F6\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1000D6F6\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_os_version__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"get OS version (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x10016D10\",\n      \"label\": \"Function 0x10016D10\",\n      \"type\": \"function\",\n      \"address\": \"0x10016D10\"\n    },\n    {\n      \"id\": \"api_GetVersionEx\",\n      \"label\": \"GetVersionEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_service_handle__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"get service handle (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x10019630\",\n      \"label\": \"Function 0x10019630\",\n      \"type\": \"function\",\n      \"address\": \"0x10019630\"\n    },\n    {\n      \"id\": \"api_OpenService\",\n      \"label\": \"OpenService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_reference_processor_manufacturer_constants\",\n      \"label\": \"reference processor manufacturer constants\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection::Instruction\",\n        \"Testing - CPUID [B0009.034]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x10015CD3\",\n      \"label\": \"Block 0x10015CD3\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x10015CD3\"\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection::Instruction\",\n        \"Testing - CPUID [B0009.034]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_application_hook\",\n      \"label\": \"log keystrokes via application hook\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Application Hook [F0002.001]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1001C722\",\n      \"label\": \"Block 0x1001C722\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1001C722\"\n    },\n    {\n      \"id\": \"api_SetWindowsHookEx\",\n      \"label\": \"SetWindowsHookEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Application Hook [F0002.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_with_crc32\",\n      \"label\": \"hash data with CRC32\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x10016AC0\",\n      \"label\": \"Function 0x10016AC0\",\n      \"type\": \"function\",\n      \"address\": \"0x10016AC0\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_new_key_via_cryptacquirecontext\",\n      \"label\": \"create new key via CryptAcquireContext\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encryption Key [C0028]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1001C76D\",\n      \"label\": \"Block 0x1001C76D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1001C76D\"\n    },\n    {\n      \"id\": \"api_CryptAcquireContext\",\n      \"label\": \"CryptAcquireContext\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______chuong_dong_mandiant_com\",\n      \"label\": \"author      chuong.dong@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encryption Key [C0028]\"\n      ]\n    },\n    {\n      \"id\": \"cap_decrypt_data_using_aes_via_x86_extensions\",\n      \"label\": \"decrypt data using AES via x86 extensions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Decrypt Data::AES [C0031.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1000C1E0\",\n      \"label\": \"Function 0x1000C1E0\",\n      \"type\": \"function\",\n      \"address\": \"0x1000C1E0\"\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_aes_via_x86_extensions__3_matches_\",\n      \"label\": \"encrypt data using AES via x86 extensions (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encryption-Standard\",\n        \"Algorithm [E1027.m05]\",\n        \"Cryptography::Encrypt Data::AES [C0027.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x10015C50\",\n      \"label\": \"Function 0x10015C50\",\n      \"type\": \"function\",\n      \"address\": \"0x10015C50\"\n    },\n    {\n      \"id\": \"func_0x1000BF80\",\n      \"label\": \"Function 0x1000BF80\",\n      \"type\": \"function\",\n      \"address\": \"0x1000BF80\"\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_twofish__7_matches_\",\n      \"label\": \"encrypt data using twofish (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encryption-Standard\",\n        \"Algorithm [E1027.m05]\",\n        \"Cryptography::Encrypt Data::Twofish\",\n        \"[C0027.005]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1000EAB0\",\n      \"label\": \"Block 0x1000EAB0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1000EAB0\"\n    },\n    {\n      \"id\": \"bb_0x1000E856\",\n      \"label\": \"Block 0x1000E856\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1000E856\"\n    },\n    {\n      \"id\": \"bb_0x1000E424\",\n      \"label\": \"Block 0x1000E424\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1000E424\"\n    },\n    {\n      \"id\": \"bb_0x1000E20B\",\n      \"label\": \"Block 0x1000E20B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1000E20B\"\n    },\n    {\n      \"id\": \"bb_0x1000EA2F\",\n      \"label\": \"Block 0x1000EA2F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1000EA2F\"\n    },\n    {\n      \"id\": \"bb_0x1000EB84\",\n      \"label\": \"Block 0x1000EB84\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1000EB84\"\n    },\n    {\n      \"id\": \"bb_0x1000E63D\",\n      \"label\": \"Block 0x1000E63D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1000E63D\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox\",\n      \"label\": \"author     @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encryption-Standard\",\n        \"Algorithm [E1027.m05]\",\n        \"Cryptography::Encrypt Data::Twofish\",\n        \"[C0027.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_using_sha256__4_matches_\",\n      \"label\": \"hash data using SHA256 (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash::SHA256 [C0029.003]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1001C7D0\",\n      \"label\": \"Function 0x1001C7D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1001C7D0\"\n    },\n    {\n      \"id\": \"func_0x1001CC80\",\n      \"label\": \"Function 0x1001CC80\",\n      \"type\": \"function\",\n      \"address\": \"0x1001CC80\"\n    },\n    {\n      \"id\": \"func_0x100146B0\",\n      \"label\": \"Function 0x100146B0\",\n      \"type\": \"function\",\n      \"address\": \"0x100146B0\"\n    },\n    {\n      \"id\": \"func_0x1001CB10\",\n      \"label\": \"Function 0x1001CB10\",\n      \"type\": \"function\",\n      \"address\": \"0x1001CB10\"\n    },\n    {\n      \"id\": \"cap_william_ballenthin_mandiant_com\",\n      \"label\": \"william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash::SHA256 [C0029.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_via_winapi\",\n      \"label\": \"generate random numbers via WinAPI\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1001C690\",\n      \"label\": \"Function 0x1001C690\",\n      \"type\": \"function\",\n      \"address\": \"0x1001C690\"\n    },\n    {\n      \"id\": \"api_CryptGenRandom\",\n      \"label\": \"CryptGenRandom\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions__4_matches_\",\n      \"label\": \"extract resource via kernel32 functions (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x10018650\",\n      \"label\": \"Function 0x10018650\",\n      \"type\": \"function\",\n      \"address\": \"0x10018650\"\n    },\n    {\n      \"id\": \"func_0x10018100\",\n      \"label\": \"Function 0x10018100\",\n      \"type\": \"function\",\n      \"address\": \"0x10018100\"\n    },\n    {\n      \"id\": \"func_0x1001C110\",\n      \"label\": \"Function 0x1001C110\",\n      \"type\": \"function\",\n      \"address\": \"0x1001C110\"\n    },\n    {\n      \"id\": \"func_0x10018700\",\n      \"label\": \"Function 0x10018700\",\n      \"type\": \"function\",\n      \"address\": \"0x10018700\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_interact_with_driver_via_ioctl__57_matches_\",\n      \"label\": \"interact with driver via IOCTL (57 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_DeviceIoControl\",\n      \"label\": \"DeviceIoControl\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__4_matches_\",\n      \"label\": \"get common file path (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x10019D90\",\n      \"label\": \"Function 0x10019D90\",\n      \"type\": \"function\",\n      \"address\": \"0x10019D90\"\n    },\n    {\n      \"id\": \"func_0x10019E20\",\n      \"label\": \"Function 0x10019E20\",\n      \"type\": \"function\",\n      \"address\": \"0x10019E20\"\n    },\n    {\n      \"id\": \"func_0x10019F50\",\n      \"label\": \"Function 0x10019F50\",\n      \"type\": \"function\",\n      \"address\": \"0x10019F50\"\n    },\n    {\n      \"id\": \"func_0x10019B40\",\n      \"label\": \"Function 0x10019B40\",\n      \"type\": \"function\",\n      \"address\": \"0x10019B40\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_copy_file\",\n      \"label\": \"copy file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1001A060\",\n      \"label\": \"Function 0x1001A060\",\n      \"type\": \"function\",\n      \"address\": \"0x1001A060\"\n    },\n    {\n      \"id\": \"api_CopyFile\",\n      \"label\": \"CopyFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_file__3_matches_\",\n      \"label\": \"delete file (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1001D010\",\n      \"label\": \"Function 0x1001D010\",\n      \"type\": \"function\",\n      \"address\": \"0x1001D010\"\n    },\n    {\n      \"id\": \"func_0x1001A170\",\n      \"label\": \"Function 0x1001A170\",\n      \"type\": \"function\",\n      \"address\": \"0x1001A170\"\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists\",\n      \"label\": \"check if file exists\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_enumerate_files_on_windows\",\n      \"label\": \"enumerate files on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1001CA00\",\n      \"label\": \"Function 0x1001CA00\",\n      \"type\": \"function\",\n      \"address\": \"0x1001CA00\"\n    },\n    {\n      \"id\": \"api_FindClose\",\n      \"label\": \"FindClose\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindNextFile\",\n      \"label\": \"FindNextFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindFirstFile\",\n      \"label\": \"FindFirstFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes\",\n      \"label\": \"get file attributes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x10019DF9\",\n      \"label\": \"Block 0x10019DF9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x10019DF9\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size__4_matches_\",\n      \"label\": \"get file size (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x10017E60\",\n      \"label\": \"Function 0x10017E60\",\n      \"type\": \"function\",\n      \"address\": \"0x10017E60\"\n    },\n    {\n      \"id\": \"func_0x10017270\",\n      \"label\": \"Function 0x10017270\",\n      \"type\": \"function\",\n      \"address\": \"0x10017270\"\n    },\n    {\n      \"id\": \"func_0x10018AE0\",\n      \"label\": \"Function 0x10018AE0\",\n      \"type\": \"function\",\n      \"address\": \"0x10018AE0\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileSizeEx\",\n      \"label\": \"GetFileSizeEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__8_matches_\",\n      \"label\": \"read file on Windows (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x10016D60\",\n      \"label\": \"Function 0x10016D60\",\n      \"type\": \"function\",\n      \"address\": \"0x10016D60\"\n    },\n    {\n      \"id\": \"func_0x10016E90\",\n      \"label\": \"Function 0x10016E90\",\n      \"type\": \"function\",\n      \"address\": \"0x10016E90\"\n    },\n    {\n      \"id\": \"func_0x10017670\",\n      \"label\": \"Function 0x10017670\",\n      \"type\": \"function\",\n      \"address\": \"0x10017670\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__7_matches_\",\n      \"label\": \"write file on Windows (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x10017310\",\n      \"label\": \"Function 0x10017310\",\n      \"type\": \"function\",\n      \"address\": \"0x10017310\"\n    },\n    {\n      \"id\": \"func_0x10018DB0\",\n      \"label\": \"Function 0x10018DB0\",\n      \"type\": \"function\",\n      \"address\": \"0x10018DB0\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_gui_resources\",\n      \"label\": \"enumerate gui resources\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1001C480\",\n      \"label\": \"Function 0x1001C480\",\n      \"type\": \"function\",\n      \"address\": \"0x1001C480\"\n    },\n    {\n      \"id\": \"api_EnumWindows\",\n      \"label\": \"EnumWindows\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     johnk3r, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_application_hook__2_matches_\",\n      \"label\": \"set application hook (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_graphical_window_text\",\n      \"label\": \"get graphical window text\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1001C3B0\",\n      \"label\": \"Function 0x1001C3B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1001C3B0\"\n    },\n    {\n      \"id\": \"api_GetWindowText\",\n      \"label\": \"GetWindowText\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_memory_capacity\",\n      \"label\": \"get memory capacity\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GlobalMemoryStatusEx\",\n      \"label\": \"GlobalMemoryStatusEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_enumerate_disk_volumes\",\n      \"label\": \"enumerate disk volumes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1001BA30\",\n      \"label\": \"Function 0x1001BA30\",\n      \"type\": \"function\",\n      \"address\": \"0x1001BA30\"\n    },\n    {\n      \"id\": \"api_FindVolumeClose\",\n      \"label\": \"FindVolumeClose\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindNextVolume\",\n      \"label\": \"FindNextVolume\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindFirstVolume\",\n      \"label\": \"FindFirstVolume\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_information_via_ioctl__2_matches_\",\n      \"label\": \"get disk information via IOCTL (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x10017AD4\",\n      \"label\": \"Block 0x10017AD4\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x10017AD4\"\n    },\n    {\n      \"id\": \"bb_0x1001947F\",\n      \"label\": \"Block 0x1001947F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1001947F\"\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_disk_size\",\n      \"label\": \"get disk size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x10017A20\",\n      \"label\": \"Function 0x10017A20\",\n      \"type\": \"function\",\n      \"address\": \"0x10017A20\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_storage_device_properties\",\n      \"label\": \"get storage device properties\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1001BE60\",\n      \"label\": \"Function 0x1001BE60\",\n      \"type\": \"function\",\n      \"address\": \"0x1001BE60\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_unmount_volume_via_ioctl\",\n      \"label\": \"unmount volume via IOCTL\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_or_open_mutex_on_windows\",\n      \"label\": \"create or open mutex on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateMutex\",\n      \"label\": \"CreateMutex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_mehunhoff_google_com\",\n      \"label\": \"mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_os_version__4_matches_\",\n      \"label\": \"check OS version (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1001A2F0\",\n      \"label\": \"Function 0x1001A2F0\",\n      \"type\": \"function\",\n      \"address\": \"0x1001A2F0\"\n    },\n    {\n      \"id\": \"api_GetVersion\",\n      \"label\": \"GetVersion\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"label\": \"get thread local storage value (27 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1001AB90\",\n      \"label\": \"Function 0x1001AB90\",\n      \"type\": \"function\",\n      \"address\": \"0x1001AB90\"\n    },\n    {\n      \"id\": \"func_0x1001AEF0\",\n      \"label\": \"Function 0x1001AEF0\",\n      \"type\": \"function\",\n      \"address\": \"0x1001AEF0\"\n    },\n    {\n      \"id\": \"func_0x1001A970\",\n      \"label\": \"Function 0x1001A970\",\n      \"type\": \"function\",\n      \"address\": \"0x1001A970\"\n    },\n    {\n      \"id\": \"func_0x1001B3D0\",\n      \"label\": \"Function 0x1001B3D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1001B3D0\"\n    },\n    {\n      \"id\": \"func_0x1001A400\",\n      \"label\": \"Function 0x1001A400\",\n      \"type\": \"function\",\n      \"address\": \"0x1001A400\"\n    },\n    {\n      \"id\": \"func_0x1001B290\",\n      \"label\": \"Function 0x1001B290\",\n      \"type\": \"function\",\n      \"address\": \"0x1001B290\"\n    },\n    {\n      \"id\": \"func_0x1001C070\",\n      \"label\": \"Function 0x1001C070\",\n      \"type\": \"function\",\n      \"address\": \"0x1001C070\"\n    },\n    {\n      \"id\": \"func_0x1001B750\",\n      \"label\": \"Function 0x1001B750\",\n      \"type\": \"function\",\n      \"address\": \"0x1001B750\"\n    },\n    {\n      \"id\": \"func_0x1001A4D0\",\n      \"label\": \"Function 0x1001A4D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1001A4D0\"\n    },\n    {\n      \"id\": \"func_0x1001A800\",\n      \"label\": \"Function 0x1001A800\",\n      \"type\": \"function\",\n      \"address\": \"0x1001A800\"\n    },\n    {\n      \"id\": \"func_0x1001B160\",\n      \"label\": \"Function 0x1001B160\",\n      \"type\": \"function\",\n      \"address\": \"0x1001B160\"\n    },\n    {\n      \"id\": \"func_0x1001B510\",\n      \"label\": \"Function 0x1001B510\",\n      \"type\": \"function\",\n      \"address\": \"0x1001B510\"\n    },\n    {\n      \"id\": \"func_0x1001A6D0\",\n      \"label\": \"Function 0x1001A6D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1001A6D0\"\n    },\n    {\n      \"id\": \"func_0x1001B030\",\n      \"label\": \"Function 0x1001B030\",\n      \"type\": \"function\",\n      \"address\": \"0x1001B030\"\n    },\n    {\n      \"id\": \"func_0x1001A630\",\n      \"label\": \"Function 0x1001A630\",\n      \"type\": \"function\",\n      \"address\": \"0x1001A630\"\n    },\n    {\n      \"id\": \"func_0x1001ADB0\",\n      \"label\": \"Function 0x1001ADB0\",\n      \"type\": \"function\",\n      \"address\": \"0x1001ADB0\"\n    },\n    {\n      \"id\": \"func_0x1001AA30\",\n      \"label\": \"Function 0x1001AA30\",\n      \"type\": \"function\",\n      \"address\": \"0x1001AA30\"\n    },\n    {\n      \"id\": \"func_0x1001A490\",\n      \"label\": \"Function 0x1001A490\",\n      \"type\": \"function\",\n      \"address\": \"0x1001A490\"\n    },\n    {\n      \"id\": \"func_0x10017540\",\n      \"label\": \"Function 0x10017540\",\n      \"type\": \"function\",\n      \"address\": \"0x10017540\"\n    },\n    {\n      \"id\": \"func_0x1001A760\",\n      \"label\": \"Function 0x1001A760\",\n      \"type\": \"function\",\n      \"address\": \"0x1001A760\"\n    },\n    {\n      \"id\": \"func_0x1001A5A0\",\n      \"label\": \"Function 0x1001A5A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1001A5A0\"\n    },\n    {\n      \"id\": \"func_0x1001B890\",\n      \"label\": \"Function 0x1001B890\",\n      \"type\": \"function\",\n      \"address\": \"0x1001B890\"\n    },\n    {\n      \"id\": \"func_0x1001B620\",\n      \"label\": \"Function 0x1001B620\",\n      \"type\": \"function\",\n      \"address\": \"0x1001B620\"\n    },\n    {\n      \"id\": \"func_0x1001C1B0\",\n      \"label\": \"Function 0x1001C1B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1001C1B0\"\n    },\n    {\n      \"id\": \"func_0x1001AC80\",\n      \"label\": \"Function 0x1001AC80\",\n      \"type\": \"function\",\n      \"address\": \"0x1001AC80\"\n    },\n    {\n      \"id\": \"func_0x1001A3D0\",\n      \"label\": \"Function 0x1001A3D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1001A3D0\"\n    },\n    {\n      \"id\": \"api_TlsGetValue\",\n      \"label\": \"TlsGetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_allocate_or_change_rwx_memory__13_matches_\",\n      \"label\": \"allocate or change RWX memory (13 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1001ADB0\",\n      \"label\": \"Block 0x1001ADB0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1001ADB0\"\n    },\n    {\n      \"id\": \"bb_0x1001C7D0\",\n      \"label\": \"Block 0x1001C7D0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1001C7D0\"\n    },\n    {\n      \"id\": \"bb_0x1001B750\",\n      \"label\": \"Block 0x1001B750\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1001B750\"\n    },\n    {\n      \"id\": \"bb_0x1001B160\",\n      \"label\": \"Block 0x1001B160\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1001B160\"\n    },\n    {\n      \"id\": \"bb_0x1001B620\",\n      \"label\": \"Block 0x1001B620\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1001B620\"\n    },\n    {\n      \"id\": \"bb_0x1001AEF0\",\n      \"label\": \"Block 0x1001AEF0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1001AEF0\"\n    },\n    {\n      \"id\": \"bb_0x1001B510\",\n      \"label\": \"Block 0x1001B510\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1001B510\"\n    },\n    {\n      \"id\": \"bb_0x1001B3D0\",\n      \"label\": \"Block 0x1001B3D0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1001B3D0\"\n    },\n    {\n      \"id\": \"bb_0x1001B030\",\n      \"label\": \"Block 0x1001B030\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1001B030\"\n    },\n    {\n      \"id\": \"bb_0x1001C690\",\n      \"label\": \"Block 0x1001C690\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1001C690\"\n    },\n    {\n      \"id\": \"bb_0x1001AC80\",\n      \"label\": \"Block 0x1001AC80\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1001AC80\"\n    },\n    {\n      \"id\": \"bb_0x1001B290\",\n      \"label\": \"Block 0x1001B290\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1001B290\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"label\": \"author     @mr-tz, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_modify_access_privileges\",\n      \"label\": \"modify access privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"api_AdjustTokenPrivileges\",\n      \"label\": \"AdjustTokenPrivileges\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__3_matches_\",\n      \"label\": \"query or enumerate registry value (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x10019890\",\n      \"label\": \"Function 0x10019890\",\n      \"type\": \"function\",\n      \"address\": \"0x10019890\"\n    },\n    {\n      \"id\": \"func_0x10019CA0\",\n      \"label\": \"Function 0x10019CA0\",\n      \"type\": \"function\",\n      \"address\": \"0x10019CA0\"\n    },\n    {\n      \"id\": \"func_0x100196A0\",\n      \"label\": \"Function 0x100196A0\",\n      \"type\": \"function\",\n      \"address\": \"0x100196A0\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegOpenKey\",\n      \"label\": \"RegOpenKey\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_set_registry_value__4_matches_\",\n      \"label\": \"set registry value (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x10019550\",\n      \"label\": \"Function 0x10019550\",\n      \"type\": \"function\",\n      \"address\": \"0x10019550\"\n    },\n    {\n      \"id\": \"func_0x10019BC0\",\n      \"label\": \"Function 0x10019BC0\",\n      \"type\": \"function\",\n      \"address\": \"0x10019BC0\"\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delete_registry_value\",\n      \"label\": \"delete registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegDeleteValue\",\n      \"label\": \"RegDeleteValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_service\",\n      \"label\": \"create service\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\",\n        \"Execution::System Services::Service Execution\",\n        \"[T1569.002]\"\n      ]\n    },\n    {\n      \"id\": \"api_OpenSCManager\",\n      \"label\": \"OpenSCManager\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateService\",\n      \"label\": \"CreateService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_service\",\n      \"label\": \"delete service\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_DeleteService\",\n      \"label\": \"DeleteService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_token_membership\",\n      \"label\": \"get token membership\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x10017370\",\n      \"label\": \"Function 0x10017370\",\n      \"type\": \"function\",\n      \"address\": \"0x10017370\"\n    },\n    {\n      \"id\": \"api_CheckTokenMembership\",\n      \"label\": \"CheckTokenMembership\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_AllocateAndInitializeSid\",\n      \"label\": \"AllocateAndInitializeSid\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FreeSid\",\n      \"label\": \"FreeSid\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_allocate_thread_local_storage\",\n      \"label\": \"allocate thread local storage\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Allocate Thread Local Storage [C0040]\"\n      ]\n    },\n    {\n      \"id\": \"api_TlsAlloc\",\n      \"label\": \"TlsAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"label\": \"set thread local storage value (16 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Set Thread Local Storage Value [C0041]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1001AC40\",\n      \"label\": \"Function 0x1001AC40\",\n      \"type\": \"function\",\n      \"address\": \"0x1001AC40\"\n    },\n    {\n      \"id\": \"api_TlsSetValue\",\n      \"label\": \"TlsSetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_drive_layout_via_ioctl\",\n      \"label\": \"delete drive layout via IOCTL\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Disk Wipe [F0014]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x10018E4F\",\n      \"label\": \"Block 0x10018E4F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x10018E4F\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__3_matches_\",\n      \"label\": \"link function at runtime on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_execute_shellcode_via_indirect_call__2_matches_\",\n      \"label\": \"execute shellcode via indirect call (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"label\": \"author     ronnie.salomonsen@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_persist_via_windows_service__2_matches_\",\n      \"label\": \"persist via Windows service (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\",\n        \"Execution::System Services::Service Execution\",\n        \"[T1569.002]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_memory__14_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_memory__14_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x10017600\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__61_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__61_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x1000284B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__31_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x10019550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x1000D6F6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_os_version__4_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x10016D10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10016D10\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_service_handle__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_service_handle__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x10019630\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019630\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_processor_manufacturer_constants\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_reference_processor_manufacturer_constants\",\n      \"target\": \"bb_0x10015CD3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______matthew_williams_mandiant_com\",\n      \"target\": \"bb_0x10015CD3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_application_hook\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_application_hook\",\n      \"target\": \"bb_0x1001C722\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x1001C722\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_crc32\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_with_crc32\",\n      \"target\": \"func_0x10016AC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x10016AC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_new_key_via_cryptacquirecontext\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_new_key_via_cryptacquirecontext\",\n      \"target\": \"bb_0x1001C76D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______chuong_dong_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______chuong_dong_mandiant_com\",\n      \"target\": \"bb_0x1001C76D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decrypt_data_using_aes_via_x86_extensions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_decrypt_data_using_aes_via_x86_extensions\",\n      \"target\": \"func_0x1000C1E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1000C1E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_aes_via_x86_extensions__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_aes_via_x86_extensions__3_matches_\",\n      \"target\": \"func_0x10015C50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_aes_via_x86_extensions__3_matches_\",\n      \"target\": \"func_0x1000C1E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_aes_via_x86_extensions__3_matches_\",\n      \"target\": \"func_0x1000BF80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x10015C50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1000C1E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1000BF80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_twofish__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_twofish__7_matches_\",\n      \"target\": \"bb_0x1000EAB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_twofish__7_matches_\",\n      \"target\": \"bb_0x1000E856\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_twofish__7_matches_\",\n      \"target\": \"bb_0x1000E424\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_twofish__7_matches_\",\n      \"target\": \"bb_0x1000E20B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_twofish__7_matches_\",\n      \"target\": \"bb_0x1000EA2F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_twofish__7_matches_\",\n      \"target\": \"bb_0x1000EB84\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_twofish__7_matches_\",\n      \"target\": \"bb_0x1000E63D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox\",\n      \"target\": \"bb_0x1000EAB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox\",\n      \"target\": \"bb_0x1000E856\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox\",\n      \"target\": \"bb_0x1000E424\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox\",\n      \"target\": \"bb_0x1000E20B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox\",\n      \"target\": \"bb_0x1000EA2F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox\",\n      \"target\": \"bb_0x1000EB84\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox\",\n      \"target\": \"bb_0x1000E63D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_sha256__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_sha256__4_matches_\",\n      \"target\": \"func_0x1001C7D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_sha256__4_matches_\",\n      \"target\": \"func_0x1001CC80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_sha256__4_matches_\",\n      \"target\": \"func_0x100146B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_sha256__4_matches_\",\n      \"target\": \"func_0x1001CB10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x1001C7D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x1001CC80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x100146B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x1001CB10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_via_winapi\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_via_winapi\",\n      \"target\": \"func_0x1001C690\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001C690\",\n      \"target\": \"api_CryptGenRandom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x1001C690\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001C690\",\n      \"target\": \"api_CryptGenRandom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__4_matches_\",\n      \"target\": \"func_0x10018650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__4_matches_\",\n      \"target\": \"func_0x10018100\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__4_matches_\",\n      \"target\": \"func_0x1001C110\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions__4_matches_\",\n      \"target\": \"func_0x10018700\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10018650\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018100\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C110\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018700\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018650\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018100\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C110\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018700\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018650\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018100\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C110\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018700\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018650\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018100\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C110\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018700\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x10018650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x10018100\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x1001C110\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x10018700\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10018650\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018100\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C110\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018700\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018650\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018100\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C110\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018700\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018650\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018100\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C110\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018700\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018650\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018100\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C110\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018700\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_interact_with_driver_via_ioctl__57_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__4_matches_\",\n      \"target\": \"func_0x10019D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__4_matches_\",\n      \"target\": \"func_0x10019E20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__4_matches_\",\n      \"target\": \"func_0x10019F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__4_matches_\",\n      \"target\": \"func_0x10019B40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019D90\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019E20\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019F50\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019B40\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10019D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10019E20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10019F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10019B40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019D90\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019E20\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019F50\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019B40\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_copy_file\",\n      \"target\": \"func_0x1001A060\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001A060\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001A060\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001A060\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x1001D010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x10019E20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__3_matches_\",\n      \"target\": \"func_0x1001A170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001D010\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019E20\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A170\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001D010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x10019E20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001A170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001D010\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019E20\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A170\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists\",\n      \"target\": \"func_0x10019D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019D90\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x10019D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019D90\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows\",\n      \"target\": \"func_0x1001CA00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001CA00\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001CA00\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001CA00\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1001CA00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001CA00\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001CA00\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001CA00\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes\",\n      \"target\": \"bb_0x10019DF9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x10019DF9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size__4_matches_\",\n      \"target\": \"func_0x10017E60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__4_matches_\",\n      \"target\": \"func_0x1001D010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__4_matches_\",\n      \"target\": \"func_0x10017270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__4_matches_\",\n      \"target\": \"func_0x10018AE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10017E60\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001D010\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017270\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018AE0\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017E60\",\n      \"target\": \"api_GetFileSizeEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001D010\",\n      \"target\": \"api_GetFileSizeEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017270\",\n      \"target\": \"api_GetFileSizeEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018AE0\",\n      \"target\": \"api_GetFileSizeEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10017E60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1001D010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10017270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10018AE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10017E60\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001D010\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017270\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018AE0\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017E60\",\n      \"target\": \"api_GetFileSizeEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001D010\",\n      \"target\": \"api_GetFileSizeEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017270\",\n      \"target\": \"api_GetFileSizeEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018AE0\",\n      \"target\": \"api_GetFileSizeEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__8_matches_\",\n      \"target\": \"func_0x1001C7D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__8_matches_\",\n      \"target\": \"func_0x10017E60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__8_matches_\",\n      \"target\": \"func_0x10016D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__8_matches_\",\n      \"target\": \"func_0x10016E90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__8_matches_\",\n      \"target\": \"func_0x1001D010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__8_matches_\",\n      \"target\": \"func_0x10017270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__8_matches_\",\n      \"target\": \"func_0x10018AE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__8_matches_\",\n      \"target\": \"func_0x10017670\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001C7D0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017E60\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10016D60\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10016E90\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001D010\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017270\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018AE0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017670\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C7D0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017E60\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10016D60\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10016E90\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001D010\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017270\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018AE0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017670\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1001C7D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10017E60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10016D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10016E90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1001D010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10017270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10018AE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10017670\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001C7D0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017E60\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10016D60\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10016E90\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001D010\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017270\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018AE0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017670\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C7D0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017E60\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10016D60\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10016E90\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001D010\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017270\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018AE0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017670\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x10018650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x10017E60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x10017310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x10016D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x10018DB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x1001D010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x10018700\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10018650\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017E60\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017310\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10016D60\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018DB0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001D010\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018700\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018650\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017E60\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017310\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10016D60\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018DB0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001D010\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018700\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10018650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10017E60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10017310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10016D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10018DB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1001D010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10018700\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10018650\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017E60\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017310\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10016D60\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018DB0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001D010\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018700\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018650\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017E60\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017310\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10016D60\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018DB0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001D010\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10018700\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_gui_resources\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_gui_resources\",\n      \"target\": \"func_0x1001C480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001C480\",\n      \"target\": \"api_EnumWindows\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1001C480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001C480\",\n      \"target\": \"api_EnumWindows\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_application_hook__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_graphical_window_text\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text\",\n      \"target\": \"func_0x1001C3B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001C3B0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1001C3B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001C3B0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_memory_capacity\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_memory_capacity\",\n      \"target\": \"func_0x1001C480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001C480\",\n      \"target\": \"api_GlobalMemoryStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1001C480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001C480\",\n      \"target\": \"api_GlobalMemoryStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_disk_volumes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_disk_volumes\",\n      \"target\": \"func_0x1001BA30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001BA30\",\n      \"target\": \"api_FindVolumeClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001BA30\",\n      \"target\": \"api_FindNextVolume\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001BA30\",\n      \"target\": \"api_FindFirstVolume\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001BA30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001BA30\",\n      \"target\": \"api_FindVolumeClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001BA30\",\n      \"target\": \"api_FindNextVolume\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001BA30\",\n      \"target\": \"api_FindFirstVolume\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information_via_ioctl__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information_via_ioctl__2_matches_\",\n      \"target\": \"bb_0x10017AD4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information_via_ioctl__2_matches_\",\n      \"target\": \"bb_0x1001947F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"bb_0x10017AD4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"bb_0x1001947F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_size\",\n      \"target\": \"func_0x10017A20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10017A20\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10017A20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10017A20\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_storage_device_properties\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_storage_device_properties\",\n      \"target\": \"func_0x1001BE60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001BE60\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001BE60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001BE60\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_unmount_volume_via_ioctl\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_unmount_volume_via_ioctl\",\n      \"target\": \"func_0x10018DB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10018DB0\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x10018DB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10018DB0\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_mutex_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_os_version__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_os_version__4_matches_\",\n      \"target\": \"func_0x10019E20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_os_version__4_matches_\",\n      \"target\": \"func_0x1001A2F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_os_version__4_matches_\",\n      \"target\": \"func_0x1001A170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_os_version__4_matches_\",\n      \"target\": \"func_0x10016D10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019E20\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A2F0\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A170\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10016D10\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019E20\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A2F0\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A170\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10016D10\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x10019E20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x1001A2F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x1001A170\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x10016D10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019E20\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A2F0\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A170\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10016D10\",\n      \"target\": \"api_GetVersion\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019E20\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A2F0\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A170\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10016D10\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001C7D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001AB90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001AEF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001A970\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001B3D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001A400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001B290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001C070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001B750\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001A4D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001A800\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001B160\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001B510\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001A6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001B030\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001A630\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001ADB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001AA30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001A490\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x10017540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001A760\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001A5A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001B890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001B620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001C1B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001AC80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__27_matches_\",\n      \"target\": \"func_0x1001A3D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001C7D0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001AB90\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001AEF0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A970\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B3D0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A400\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B290\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C070\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B750\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A4D0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A800\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B160\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B510\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A6D0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B030\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A630\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001ADB0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001AA30\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A490\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017540\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A760\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A5A0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B890\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B620\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C1B0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001AC80\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A3D0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001C7D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001AB90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001AEF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001A970\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001B3D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001A400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001B290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001C070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001B750\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001A4D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001A800\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001B160\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001B510\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001A6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001B030\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001A630\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001ADB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001AA30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001A490\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x10017540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001A760\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001A5A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001B890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001B620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001C1B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001AC80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001A3D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001C7D0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001AB90\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001AEF0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A970\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B3D0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A400\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B290\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C070\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B750\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A4D0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A800\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B160\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B510\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A6D0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B030\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A630\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001ADB0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001AA30\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A490\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017540\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A760\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A5A0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B890\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B620\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C1B0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001AC80\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001A3D0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_or_change_rwx_memory__13_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__13_matches_\",\n      \"target\": \"bb_0x1001ADB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__13_matches_\",\n      \"target\": \"bb_0x1001C7D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__13_matches_\",\n      \"target\": \"bb_0x1001B750\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__13_matches_\",\n      \"target\": \"bb_0x1001B160\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__13_matches_\",\n      \"target\": \"bb_0x1001B620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__13_matches_\",\n      \"target\": \"bb_0x1001AEF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__13_matches_\",\n      \"target\": \"bb_0x1001B510\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__13_matches_\",\n      \"target\": \"bb_0x10017600\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__13_matches_\",\n      \"target\": \"bb_0x1001B3D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__13_matches_\",\n      \"target\": \"bb_0x1001B030\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__13_matches_\",\n      \"target\": \"bb_0x1001C690\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__13_matches_\",\n      \"target\": \"bb_0x1001AC80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory__13_matches_\",\n      \"target\": \"bb_0x1001B290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x1001ADB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x1001C7D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x1001B750\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x1001B160\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x1001B620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x1001AEF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x1001B510\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x10017600\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x1001B3D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x1001B030\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x1001C690\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x1001AC80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x1001B290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_modify_access_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__3_matches_\",\n      \"target\": \"func_0x10019890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__3_matches_\",\n      \"target\": \"func_0x10019CA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__3_matches_\",\n      \"target\": \"func_0x100196A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019890\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019CA0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x100196A0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019890\",\n      \"target\": \"api_RegOpenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019CA0\",\n      \"target\": \"api_RegOpenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x100196A0\",\n      \"target\": \"api_RegOpenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10019890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10019CA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x100196A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019890\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019CA0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x100196A0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019890\",\n      \"target\": \"api_RegOpenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019CA0\",\n      \"target\": \"api_RegOpenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x100196A0\",\n      \"target\": \"api_RegOpenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__4_matches_\",\n      \"target\": \"func_0x10019890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__4_matches_\",\n      \"target\": \"func_0x10019550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__4_matches_\",\n      \"target\": \"func_0x100196A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__4_matches_\",\n      \"target\": \"func_0x10019BC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019890\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019550\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x100196A0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019BC0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019890\",\n      \"target\": \"api_RegCreateKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019550\",\n      \"target\": \"api_RegCreateKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x100196A0\",\n      \"target\": \"api_RegCreateKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019BC0\",\n      \"target\": \"api_RegCreateKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019890\",\n      \"target\": \"api_RegOpenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019550\",\n      \"target\": \"api_RegOpenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x100196A0\",\n      \"target\": \"api_RegOpenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019BC0\",\n      \"target\": \"api_RegOpenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x10019890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x10019550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x100196A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x10019BC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019890\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019550\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x100196A0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019BC0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019890\",\n      \"target\": \"api_RegCreateKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019550\",\n      \"target\": \"api_RegCreateKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x100196A0\",\n      \"target\": \"api_RegCreateKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019BC0\",\n      \"target\": \"api_RegCreateKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019890\",\n      \"target\": \"api_RegOpenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019550\",\n      \"target\": \"api_RegOpenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x100196A0\",\n      \"target\": \"api_RegOpenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019BC0\",\n      \"target\": \"api_RegOpenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value\",\n      \"target\": \"func_0x10019890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019890\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019890\",\n      \"target\": \"api_RegOpenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x10019890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019890\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019890\",\n      \"target\": \"api_RegOpenKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_service\",\n      \"target\": \"func_0x10019F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019F50\",\n      \"target\": \"api_OpenSCManager\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019F50\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x10019F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019F50\",\n      \"target\": \"api_OpenSCManager\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019F50\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_service\",\n      \"target\": \"func_0x10019630\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019630\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019630\",\n      \"target\": \"api_DeleteService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x10019630\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019630\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019630\",\n      \"target\": \"api_DeleteService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_token_membership\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_token_membership\",\n      \"target\": \"func_0x10017370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10017370\",\n      \"target\": \"api_CheckTokenMembership\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017370\",\n      \"target\": \"api_AllocateAndInitializeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017370\",\n      \"target\": \"api_FreeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x10017370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10017370\",\n      \"target\": \"api_CheckTokenMembership\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017370\",\n      \"target\": \"api_AllocateAndInitializeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017370\",\n      \"target\": \"api_FreeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_thread_local_storage\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_thread_local_storage\",\n      \"target\": \"func_0x1001C070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001C070\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001C070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001C070\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"target\": \"func_0x1001ADB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"target\": \"func_0x1001AC40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"target\": \"func_0x1001C7D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"target\": \"func_0x1001B750\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"target\": \"func_0x1001B160\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"target\": \"func_0x1001B620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"target\": \"func_0x1001AB90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"target\": \"func_0x1001AEF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"target\": \"func_0x1001B510\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"target\": \"func_0x10017540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"target\": \"func_0x1001B3D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"target\": \"func_0x1001B890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"target\": \"func_0x1001B030\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"target\": \"func_0x1001C1B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"target\": \"func_0x1001AC80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value__16_matches_\",\n      \"target\": \"func_0x1001B290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001ADB0\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001AC40\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C7D0\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B750\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B160\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B620\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001AB90\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001AEF0\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B510\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017540\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B3D0\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B890\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B030\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C1B0\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001AC80\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B290\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001ADB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001AC40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001C7D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001B750\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001B160\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001B620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001AB90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001AEF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001B510\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x10017540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001B3D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001B890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001B030\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001C1B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001AC80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1001B290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001ADB0\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001AC40\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C7D0\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B750\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B160\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B620\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001AB90\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001AEF0\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B510\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10017540\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B3D0\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B890\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B030\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C1B0\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001AC80\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001B290\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_drive_layout_via_ioctl\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_drive_layout_via_ioctl\",\n      \"target\": \"bb_0x10018E4F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"bb_0x10018E4F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_execute_shellcode_via_indirect_call__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_execute_shellcode_via_indirect_call__2_matches_\",\n      \"target\": \"func_0x1001C690\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_execute_shellcode_via_indirect_call__2_matches_\",\n      \"target\": \"func_0x1001C7D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001C690\",\n      \"target\": \"api_VirtualAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C7D0\",\n      \"target\": \"api_VirtualAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"target\": \"func_0x1001C690\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"target\": \"func_0x1001C7D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1001C690\",\n      \"target\": \"api_VirtualAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1001C7D0\",\n      \"target\": \"api_VirtualAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_persist_via_windows_service__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_persist_via_windows_service__2_matches_\",\n      \"target\": \"func_0x10019550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_persist_via_windows_service__2_matches_\",\n      \"target\": \"func_0x10019BC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019550\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019BC0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019550\",\n      \"target\": \"api_RegCreateKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019BC0\",\n      \"target\": \"api_RegCreateKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x10019550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x10019BC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x10019550\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019BC0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019550\",\n      \"target\": \"api_RegCreateKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x10019BC0\",\n      \"target\": \"api_RegCreateKey\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-10 02:09:58.273542\",\n    \"total_functions\": \"186\",\n    \"total_features\": \"14649\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-10 02:09:59"}
{"_id":{"$oid":"6a5a2911b3bed57e0e737860"},"sha256":"5a3938aa0350f3bf94c8f12cab8b9b0555648c20176fe9166a91240c4b27fa18","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":true,"path":"/tmp/sdm_capa_yh6rggrj/001_binwalk_ntuser.exe_verbose.txt"},"very_verbose":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\nUnexpected exception raised: <class 'RuntimeError'>. Please run capa in debug mode (-d/--debug) to see the stack trace.\nPlease also report your issue on the capa GitHub page so we can improve the code! (https://github.com/mandiant/capa/issues)\n[PYI-1340394:ERROR] Failed to execute script 'main' due to unhandled exception!\n"}},"outputs":{"normal":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"md5                     5b4695d9482762159ace5248aca22a2f                        \nsha1                    c2a690055cd4c6986e61f34dbcf0fdf1dcf04312                \nsha256                  17a306266041f489ad7511cd29394bb0216eeb54d8353139ef674b3…\npath                    /tmp/sdm_unpack_ysexfpy_/5a3938aa0350f3bf94c8f12cab8b9b…\ntimestamp               2026-07-17 18:37:13.460414                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x10000000                                              \nrules                   /tmp/_MEI4Lo8tQ/rules                                   \nfunction count          666                                                     \nlibrary function count  0                                                       \ntotal feature count     26055                                                   \n\npacked with generic packer\nnamespace  anti-analysis/packer/generic\nscope      function                    \nmatches    0x102B38C0                  \n\npacked with UPX\nnamespace  anti-analysis/packer/upx\nscope      file                    \n\nresolve function by parsing PE exports\nnamespace  load-code/pe\nscope      function    \nmatches    0x102B38C0  \n\n\n\n","very_verbose":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\nUnexpected exception raised: <class 'RuntimeError'>. Please run capa in debug mode (-d/--debug) to see the stack trace.\nPlease also report your issue on the capa GitHub page so we can improve the code! (https://github.com/mandiant/capa/issues)\n[PYI-1340394:ERROR] Failed to execute script 'main' due to unhandled exception!\n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\nUnexpected exception raised: <class 'RuntimeError'>. Please run capa in debug mode (-d/--debug) to see the stack trace.\nPlease also report your issue on the capa GitHub page so we can improve the code! (https://github.com/mandiant/capa/issues)\n[PYI-1340394:ERROR] Failed to execute script 'main' due to unhandled exception!\n"},"hashes":{"md5":"5b4695d9482762159ace5248aca22a2f","sha1":"c2a690055cd4c6986e61f34dbcf0fdf1dcf04312","sha256":"17a306266041f489ad7511cd29394bb0216eeb54d8353139ef674b3d669f7ece"}},"timestamp":"2026-07-17 18:37:29"}
{"_id":{"$oid":"6a5a29b1b3bed57e0e737863"},"sha256":"7163fefbf2f865ef78a2d3d4480532fffb979300d6f0a77b6f3fc5c4b0d2cada","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_ndra8dfg/7163fefbf2f865ef78a2d3d4480532fffb979300d6f0a77b6f3fc5c4b0d2cada-019f703240a17f91b79fc68a59c3e397.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_ndra8dfg/7163fefbf2f865ef78a2d3d4480532fffb979300d6f0a77b6f3fc5c4b0d2cada-019f703240a17f91b79fc68a59c3e397.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_ndra8dfg/7163fefbf2f865ef78a2d3d4480532fffb979300d6f0a77b6f3fc5c4b0d2cada-019f703240a17f91b79fc68a59c3e397.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 2b1e9226d7e1015552a21faca891ec41                                  │\n│ sha1     │ f87fcbe10fa9312048214d4473498ad4f9f331ce                          │\n│ sha256   │ 7163fefbf2f865ef78a2d3d4480532fffb979300d6f0a77b6f3fc5c4b0d2cada  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/7163fefbf2f865ef… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic             ┃ ATT&CK Technique                                 ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION                │ Screen Capture [T1113]                           │\n│ DEFENSE EVASION           │ Obfuscated Files or Information [T1027]          │\n│ EXECUTION                 │ Shared Modules [T1129]                           │\n└───────────────────────────┴──────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Screen Capture::WinAPI [E1113.m01]                    │\n│ DATA                 │ Encode Data::XOR [C0026.002]                          │\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Encoding-Custom      │\n│                      │ Algorithm [E1027.m03]                                 │\n│                      │ Obfuscated Files or Information::Encoding-Standard    │\n│                      │ Algorithm [E1027.m02]                                 │\n│ FILE SYSTEM          │ Writes File [C0052]                                   │\n│ OPERATING SYSTEM     │ Environment Variable::Set Variable [C0034.001]        │\n│ PROCESS              │ Create Thread [C0038]                                 │\n│                      │ Terminate Process [C0018]                             │\n│                      │ Terminate Thread [C0039]                              │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ capture screenshot (2 matches)        │ collection/screenshot                │\n│ encode data using ADD XOR SUB         │ data-manipulation/encoding           │\n│ operations                            │                                      │\n│ encode data using XOR (3 matches)     │ data-manipulation/encoding/xor       │\n│ contains PDB path                     │ executable/pe/pdb                    │\n│ set environment variable              │ host-interaction/environment-variab… │\n│ read raw disk data                    │ host-interaction/file-system         │\n│ write file on Windows                 │ host-interaction/file-system/write   │\n│ terminate process                     │ host-interaction/process/terminate   │\n│ create thread                         │ host-interaction/thread/create       │\n│ terminate thread                      │ host-interaction/thread/terminate    │\n│ link function at runtime on Windows   │ linking/runtime-linking              │\n│ (6 matches)                           │                                      │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     2b1e9226d7e1015552a21faca891ec41                        \nsha1                    f87fcbe10fa9312048214d4473498ad4f9f331ce                \nsha256                  7163fefbf2f865ef78a2d3d4480532fffb979300d6f0a77b6f3fc5c…\npath                    /home/apogean/projects/malware/windows/all_runs/7163fef…\ntimestamp               2026-07-17 20:06:55.475567                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIpZLjfO/rules                                   \nfunction count          195                                                     \nlibrary function count  306                                                     \ntotal feature count     7432                                                    \n\ncapture screenshot (2 matches)\nnamespace  collection/screenshot\nscope      function             \nmatches    0x4015F0             \n           0x4016C0             \n\nencode data using ADD XOR SUB operations\nnamespace    data-manipulation/encoding                                         \ndescription  Data encoding using a sequence of ADD/XOR/SUB (or SUB/XOR/ADD)     \n             operations common for PlugX but also used by other malware         \n             families.                                                          \nscope        function                                                           \nmatches      0x4023A0                                                           \n\nencode data using XOR (3 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x401421                      \n           0x402424                      \n           0x402593                      \n\ncontains PDB path\nnamespace  executable/pe/pdb\nscope      file             \n\nset environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x407FF7                             \n\nread raw disk data\nnamespace  host-interaction/file-system\nscope      file                        \n\nwrite file on Windows\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x401000                          \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x402E00                          \n\ncreate thread\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x402E4C                      \n\nterminate thread\nnamespace  host-interaction/thread/terminate\nscope      basic block                      \nmatches    0x402E4C                         \n\nlink function at runtime on Windows (6 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x403191               \n           0x4031A2               \n           0x4042A4               \n           0x4042A4               \n           0x40811C               \n           0x40811C               \n\n\n\n","very_verbose":"md5                     2b1e9226d7e1015552a21faca891ec41                        \nsha1                    f87fcbe10fa9312048214d4473498ad4f9f331ce                \nsha256                  7163fefbf2f865ef78a2d3d4480532fffb979300d6f0a77b6f3fc5c…\npath                    /home/apogean/projects/malware/windows/all_runs/7163fef…\ntimestamp               2026-07-17 20:07:04.046142                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIpSENA3/rules                                   \nfunction count          195                                                     \nlibrary function count  306                                                     \ntotal feature count     7432                                                    \n\ncontain loop (34 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401150\n  or:\n    characteristic: loop @ 0x401150\n    characteristic: tight loop @ 0x401211\n\ncreate or open file (2 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x401027\n  or:\n    api: CreateFile @ 0x401027\n\ndelay execution (4 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x40155D in function 0x401470\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x4015CF\n\ncapture screenshot (2 matches)\nnamespace  collection/screenshot                                            \nauthor     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\nscope      function                                                         \natt&ck     Collection::Screen Capture [T1113]                               \nmbc        Collection::Screen Capture::WinAPI [E1113.m01]                   \nfunction @ 0x4015F0\n  or:\n    basic block:\n      and:\n        api: BitBlt @ 0x401669\n        characteristic: tight loop @ 0x401615\nfunction @ 0x4016C0\n  or:\n    basic block:\n      and:\n        api: BitBlt @ 0x401760\n        characteristic: tight loop @ 0x401730\n\nencode data using ADD XOR SUB operations\nnamespace    data-manipulation/encoding                                         \nauthor       jakub.jozwiak@mandiant.com                                         \nscope        function                                                           \natt&ck       Defense Evasion::Obfuscated Files or Information [T1027]           \nmbc          Defense Evasion::Obfuscated Files or Information::Encoding-Custom  \n             Algorithm [E1027.m03]                                              \ndescription  Data encoding using a sequence of ADD/XOR/SUB (or SUB/XOR/ADD)     \n             operations common for PlugX but also used by other malware         \n             families.                                                          \nfunction @ 0x4023A0\n  and:\n    basic block:\n      and:\n        characteristic: tight loop @ 0x402424\n        characteristic: nzxor @ 0x40244A\n        count(mnemonic(add)): 1 @ 0x40244C\n        count(mnemonic(sub)): 1 @ 0x40243D\n    count(basic block): 6 or fewer @ 0x4023A0, 0x402424, 0x40245E\n\nencode data using XOR (3 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x401421 in function 0x401360\n  and:\n    characteristic: tight loop @ 0x401421\n    characteristic: nzxor @ 0x401429\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x402424 in function 0x4023A0\n  and:\n    characteristic: tight loop @ 0x402424\n    characteristic: nzxor @ 0x40244A\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x402593 in function 0x402510\n  and:\n    characteristic: tight loop @ 0x402593\n    characteristic: nzxor @ 0x4025A6, 0x4025AD, 0x4025B2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\ncontains PDB path\nnamespace  executable/pe/pdb        \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nregex: /:\\\\.*\\.pdb/\n  - \"C:\\\\Users\\\\ACER\\\\source\\\\repos\\\\salinewin\\\\Release\\\\salinewin.pdb\" @ file+0x1C494\n\nset environment variable\nnamespace  host-interaction/environment-variable                           \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \nmbc        Operating System::Environment Variable::Set Variable [C0034.001]\nfunction @ 0x407FF7\n  or:\n    api: SetEnvironmentVariable @ 0x407EC3\n\nread raw disk data\nnamespace  host-interaction/file-system   \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  string: \"\\\\\\\\.\\\\PhysicalDrive0\" @ file+0x13888\n\nwrite file on Windows\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x401000\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            match: create or open file @ 0x401027\n              or:\n                api: CreateFile @ 0x401027\n      or:\n        api: WriteFile @ 0x40103C\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x402E00\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x402E29, 0x402E46\n\ncreate thread\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x402E4C in function 0x402E00\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x402E5F, 0x402E70, 0x402E8E, 0x402E9F, and 13 more...\n\nterminate thread\nnamespace  host-interaction/thread/terminate                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \nmbc        Process::Terminate Thread [C0039]                                    \nbasic block @ 0x402E4C in function 0x402E00\n  or:\n    api: TerminateThread @ 0x402EC3, 0x402F13, 0x402F6B, 0x402FB3, and 7 more...\n\nlink function at runtime on Windows (6 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x403191\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x403191\ninstruction @ 0x4031A2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4031A2\ninstruction @ 0x4042A4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4042A4\ninstruction @ 0x4042A4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4042A4\ninstruction @ 0x40811C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40811C\ninstruction @ 0x40811C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40811C\n\n\n\n"},"hashes":{"md5":"2b1e9226d7e1015552a21faca891ec41","sha1":"f87fcbe10fa9312048214d4473498ad4f9f331ce","sha256":"7163fefbf2f865ef78a2d3d4480532fffb979300d6f0a77b6f3fc5c4b0d2cada"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 195</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 7432</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"7163fef\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"2b1e9226d7e1015552a21faca891ec41\",\n        \"sha256\": \"7163fefbf2f865ef78a2d3d4480532fffb979300d6f0a77b6f3fc5c\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__34_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (34 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401150\",\n      \"label\": \"Function 0x401150\",\n      \"type\": \"function\",\n      \"address\": \"0x401150\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_delay_execution__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40155D\",\n      \"label\": \"Block 0x40155D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40155D\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_capture_screenshot__2_matches_\",\n      \"label\": \"capture screenshot (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4016C0\",\n      \"label\": \"Function 0x4016C0\",\n      \"type\": \"function\",\n      \"address\": \"0x4016C0\"\n    },\n    {\n      \"id\": \"func_0x4015F0\",\n      \"label\": \"Function 0x4015F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4015F0\"\n    },\n    {\n      \"id\": \"api_BitBlt\",\n      \"label\": \"BitBlt\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encode_data_using_add_xor_sub_operations\",\n      \"label\": \"encode data using ADD XOR SUB operations\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Custom\",\n        \"Algorithm [E1027.m03]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4023A0\",\n      \"label\": \"Function 0x4023A0\",\n      \"type\": \"function\",\n      \"address\": \"0x4023A0\"\n    },\n    {\n      \"id\": \"cap_author_______jakub_jozwiak_mandiant_com\",\n      \"label\": \"author       jakub.jozwiak@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Custom\",\n        \"Algorithm [E1027.m03]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contains_pdb_path\",\n      \"label\": \"contains PDB path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_set_environment_variable\",\n      \"label\": \"set environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable::Set Variable [C0034.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407FF7\",\n      \"label\": \"Function 0x407FF7\",\n      \"type\": \"function\",\n      \"address\": \"0x407FF7\"\n    },\n    {\n      \"id\": \"api_SetEnvironmentVariable\",\n      \"label\": \"SetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable::Set Variable [C0034.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_raw_disk_data\",\n      \"label\": \"read raw disk data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_write_file_on_windows\",\n      \"label\": \"write file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401000\",\n      \"label\": \"Function 0x401000\",\n      \"type\": \"function\",\n      \"address\": \"0x401000\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402E00\",\n      \"label\": \"Function 0x402E00\",\n      \"type\": \"function\",\n      \"address\": \"0x402E00\"\n    },\n    {\n      \"id\": \"api_ExitProcess\",\n      \"label\": \"ExitProcess\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_thread\",\n      \"label\": \"create thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x402E4C\",\n      \"label\": \"Block 0x402E4C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x402E4C\"\n    },\n    {\n      \"id\": \"api_CreateThread\",\n      \"label\": \"CreateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_thread\",\n      \"label\": \"terminate thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Thread [C0039]\"\n      ]\n    },\n    {\n      \"id\": \"api_TerminateThread\",\n      \"label\": \"TerminateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__6_matches_\",\n      \"label\": \"link function at runtime on Windows (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__34_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__34_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401150\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__4_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x40155D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_capture_screenshot__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_capture_screenshot__2_matches_\",\n      \"target\": \"func_0x4016C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_capture_screenshot__2_matches_\",\n      \"target\": \"func_0x4015F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4016C0\",\n      \"target\": \"api_BitBlt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4015F0\",\n      \"target\": \"api_BitBlt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4016C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4015F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4016C0\",\n      \"target\": \"api_BitBlt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4015F0\",\n      \"target\": \"api_BitBlt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encode_data_using_add_xor_sub_operations\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_add_xor_sub_operations\",\n      \"target\": \"func_0x4023A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______jakub_jozwiak_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______jakub_jozwiak_mandiant_com\",\n      \"target\": \"func_0x4023A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contains_pdb_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_environment_variable\",\n      \"target\": \"func_0x407FF7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407FF7\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407FF7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407FF7\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_raw_disk_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x402E00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402E00\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402E00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402E00\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread\",\n      \"target\": \"bb_0x402E4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x402E4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_thread\",\n      \"target\": \"bb_0x402E4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x402E4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-17 20:07:04.046142\",\n    \"total_functions\": \"195\",\n    \"total_features\": \"7432\",\n    \"pdb_path\": \"C:\\\\\\\\Users\\\\\\\\ACER\\\\\\\\source\\\\\\\\repos\\\\\\\\salinewin\\\\\\\\Release\\\\\\\\salinewin.pdb\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-17 20:07:04"}
{"_id":{"$oid":"6a5a2b10b3bed57e0e737864"},"sha256":"40b2b086397a96608915013652e16e3dd9437e71763925dd8324656138648e46","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_2basfas5/com.google.Chrome-019f703016587100a4a695a71555c2ee.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_2basfas5/com.google.Chrome-019f703016587100a4a695a71555c2ee.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_2basfas5/com.google.Chrome-019f703016587100a4a695a71555c2ee.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 75bd50f2b7077d8b22ea51e77028c6b0                                  │\n│ sha1     │ 4534a212afcfc401521f63d89bbde400999ffc71                          │\n│ sha256   │ 40b2b086397a96608915013652e16e3dd9437e71763925dd8324656138648e46  │\n│ analysis │ static                                                            │\n│ os       │ any                                                               │\n│ format   │ dotnet                                                            │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/com.google.Chrom… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic         ┃ ATT&CK Technique                                     ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION       │ Deobfuscate/Decode Files or Information [T1140]      │\n│                       │ File and Directory Permissions Modification [T1222]  │\n│                       │ Hide Artifacts::Hidden Window [T1564.003]            │\n│ DISCOVERY             │ Account Discovery [T1087]                            │\n│                       │ File and Directory Discovery [T1083]                 │\n│                       │ Process Discovery [T1057]                            │\n│                       │ Software Discovery [T1518]                           │\n│                       │ System Information Discovery [T1082]                 │\n│                       │ System Network Configuration Discovery [T1016]       │\n│                       │ System Owner/User Discovery [T1033]                  │\n│ EXECUTION             │ Windows Management Instrumentation [T1047]           │\n└───────────────────────┴──────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective         ┃ MBC Behavior                                         ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ CRYPTOGRAPHY          │ Generate Pseudo-random Sequence::Use API [C0021.003] │\n│ DATA                  │ Decode Data::Base64 [C0053.001]                      │\n│ DISCOVERY             │ File and Directory Discovery [E1083]                 │\n│                       │ System Information Discovery [E1082]                 │\n│ FILE SYSTEM           │ Create Directory [C0046]                             │\n│                       │ Delete File [C0047]                                  │\n│                       │ Read File [C0051]                                    │\n│                       │ Set File Attributes [C0050]                          │\n│                       │ Writes File [C0052]                                  │\n│ PROCESS               │ Create Process [C0017]                               │\n│                       │ Terminate Process [C0018]                            │\n└───────────────────────┴──────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ get MAC address in .NET               │ collection/network                   │\n│ decode data using Base64 in .NET      │ data-manipulation/encoding/base64    │\n│ generate random numbers in .NET (2    │ data-manipulation/prng               │\n│ matches)                              │                                      │\n│ access .NET resource (2 matches)      │ executable/resource                  │\n│ query environment variable (2         │ host-interaction/environment-variab… │\n│ matches)                              │                                      │\n│ check file extension in .NET          │ host-interaction/file-system         │\n│ get common file path (3 matches)      │ host-interaction/file-system         │\n│ create directory                      │ host-interaction/file-system/create  │\n│ delete file                           │ host-interaction/file-system/delete  │\n│ check if directory exists             │ host-interaction/file-system/exists  │\n│ check if file exists (5 matches)      │ host-interaction/file-system/exists  │\n│ get file size                         │ host-interaction/file-system/meta    │\n│ set file attributes (2 matches)       │ host-interaction/file-system/meta    │\n│ read file on Windows                  │ host-interaction/file-system/read    │\n│ write file on Windows                 │ host-interaction/file-system/write   │\n│ hide graphical window                 │ host-interaction/gui/window/hide     │\n│ get disk size                         │ host-interaction/hardware/storage    │\n│ get networking interfaces             │ host-interaction/network/interface   │\n│ get hostname                          │ host-interaction/os/hostname         │\n│ get process image filename (2         │ host-interaction/process             │\n│ matches)                              │                                      │\n│ create a process with modified I/O    │ host-interaction/process/create      │\n│ handles and window                    │                                      │\n│ create process on Windows             │ host-interaction/process/create      │\n│ enumerate processes (2 matches)       │ host-interaction/process/list        │\n│ terminate process                     │ host-interaction/process/terminate   │\n│ get session user name (2 matches)     │ host-interaction/session             │\n│ access WMI data in .NET (2 matches)   │ host-interaction/wmi                 │\n│ unmanaged call                        │ runtime                              │\n│ compiled to the .NET platform         │ runtime/dotnet                       │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     75bd50f2b7077d8b22ea51e77028c6b0                        \nsha1                    4534a212afcfc401521f63d89bbde400999ffc71                \nsha256                  40b2b086397a96608915013652e16e3dd9437e71763925dd8324656…\npath                    /home/apogean/projects/malware/windows/all_runs/com.goo…\ntimestamp               2026-07-17 18:45:59.346498                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIwZ5aqA/rules                                   \nfunction count          127                                                     \nlibrary function count  0                                                       \ntotal feature count     3883                                                    \n\nget MAC address in .NET\nnamespace  collection/network\nscope      function          \nmatches    token(0x600003F)  \n\ndecode data using Base64 in .NET\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    token(0x600006F)                 \n\ngenerate random numbers in .NET (2 matches)\nnamespace  data-manipulation/prng\nscope      function              \nmatches    token(0x600001B)      \n           token(0x6000081)      \n\naccess .NET resource (2 matches)\nnamespace  executable/resource\nscope      function           \nmatches    token(0x6000003)   \n           token(0x6000011)   \n\nquery environment variable (2 matches)\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    token(0x6000042)                     \n           token(0x6000043)                     \n\ncheck file extension in .NET\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x600007D)            \n\nget common file path (3 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x6000044)            \n           token(0x6000046)            \n           token(0x600006C)            \n\ncreate directory\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    token(0x600006C)                   \n\ndelete file\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    token(0x6000074)                   \n\ncheck if directory exists\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x600006C)                   \n\ncheck if file exists (5 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x6000041)                   \n           token(0x6000046)                   \n           token(0x6000074)                   \n           token(0x600007D)                   \n           token(0x600007F)                   \n\nget file size\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    token(0x600007F)                 \n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    token(0x600006C)                 \n           token(0x600007F)                 \n\nread file on Windows\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    token(0x6000046)                 \n\nwrite file on Windows\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    token(0x600007F)                  \n\nhide graphical window\nnamespace  host-interaction/gui/window/hide\nscope      basic block                     \nmatches    token(0x6000019)                \n\nget disk size\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    token(0x6000040)                 \n\nget networking interfaces\nnamespace  host-interaction/network/interface\nscope      function                          \nmatches    token(0x6000046)                  \n\nget hostname\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    token(0x6000043)            \n\nget process image filename (2 matches)\nnamespace  host-interaction/process\nscope      basic block             \nmatches    token(0x6000019)        \n           token(0x6000069)        \n\ncreate a process with modified I/O handles and window\nnamespace  host-interaction/process/create\nscope      function                       \nmatches    token(0x600007D)               \n\ncreate process on Windows\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    token(0x600007D)               \n\nenumerate processes (2 matches)\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    token(0x600003E)             \n           token(0x6000044)             \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    token(0x6000019)                  \n\nget session user name (2 matches)\nnamespace  host-interaction/session\nscope      function                \nmatches    token(0x6000043)        \n           token(0x6000045)        \n\naccess WMI data in .NET (2 matches)\nnamespace  host-interaction/wmi\nscope      function            \nmatches    token(0x6000046)    \n           token(0x6000047)    \n\nunmanaged call\nnamespace    runtime                                                       \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nscope        function                                                      \nmatches      token(0x6000019)                                              \n\ncompiled to the .NET platform\nnamespace  runtime/dotnet\nscope      file          \n\n\n\n","very_verbose":"md5                     75bd50f2b7077d8b22ea51e77028c6b0                        \nsha1                    4534a212afcfc401521f63d89bbde400999ffc71                \nsha256                  40b2b086397a96608915013652e16e3dd9437e71763925dd8324656…\npath                    /home/apogean/projects/malware/windows/all_runs/com.goo…\ntimestamp               2026-07-17 18:46:00.553822                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIzvFkQ7/rules                                   \nfunction count          127                                                     \nlibrary function count  0                                                       \ntotal feature count     3883                                                    \n\nget MAC address in .NET\nnamespace  collection/network                                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           echernofsky@google.com                                               \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nfunction @ token(0x600003F)\n  or:\n    api: System.Net.NetworkInformation.NetworkInterface::GetPhysicalAddress @ token(0x600003F)+0x1B\n\ndecode data using Base64 in .NET\nnamespace  data-manipulation/encoding/base64                               \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \natt&ck     Defense Evasion::Deobfuscate/Decode Files or Information [T1140]\nmbc        Data::Decode Data::Base64 [C0053.001]                           \nfunction @ token(0x600006F)\n  or:\n    api: System.Convert::FromBase64String @ token(0x600006F)+0xA, token(0x600006F)+0x4E\n\ngenerate random numbers in .NET (2 matches)\nnamespace  data-manipulation/prng                                            \nauthor     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com     \nscope      function                                                          \nmbc        Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\nfunction @ token(0x600001B)\n  or:\n    api: System.Random::Next @ token(0x600001B)+0x1D\nfunction @ token(0x6000081)\n  or:\n    api: System.Random::Next @ token(0x6000081)+0x45\n\naccess .NET resource (2 matches)\nnamespace  executable/resource\nauthor     @mr-tz             \nscope      function           \nfunction @ token(0x6000003)\n  and:\n    format: dotnet\n    or:\n      api: System.Reflection.Assembly::GetManifestResourceStream @ token(0x6000003)+0x113\nfunction @ token(0x6000011)\n  and:\n    format: dotnet\n    or:\n      api: System.Resources.ResourceManager::ctor @ token(0x6000011)+0x20\n\nquery environment variable (2 matches)\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ token(0x6000042)\n  or:\n    api: System.Environment::GetEnvironmentVariable @ token(0x6000042)+0xE\nfunction @ token(0x6000043)\n  or:\n    api: System.Environment::GetEnvironmentVariable @ token(0x6000043)+0x96\n\ncheck file extension in .NET\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x600007D)\n  or:\n    api: System.IO.Path::GetExtension @ token(0x600007D)+0x4A\n\nget common file path (3 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ token(0x6000044)\n  or:\n    property/read: System.Environment::SystemDirectory @ token(0x6000044)+0x0\nfunction @ token(0x6000046)\n  or:\n    property/read: System.Environment::SystemDirectory @ token(0x6000046)+0x110\nfunction @ token(0x600006C)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x600006C)+0x2\n\ncreate directory\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ token(0x600006C)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x600006C)+0x8E, token(0x600006C)+0xFE\n\ndelete file\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ token(0x6000074)\n  or:\n    api: System.IO.File::Delete @ token(0x6000074)+0xAE\n\ncheck if directory exists\nnamespace  host-interaction/file-system/exists            \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nfunction @ token(0x600006C)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600006C)+0x86, token(0x600006C)+0xF6\n\ncheck if file exists (5 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ token(0x6000041)\n  or:\n    api: System.IO.File::Exists @ token(0x6000041)+0x21\nfunction @ token(0x6000046)\n  or:\n    api: System.IO.File::Exists @ token(0x6000046)+0x13A\nfunction @ token(0x6000074)\n  or:\n    api: System.IO.File::Exists @ token(0x6000074)+0xA1\nfunction @ token(0x600007D)\n  or:\n    api: System.IO.File::Exists @ token(0x600007D)+0x3F\nfunction @ token(0x600007F)\n  or:\n    api: System.IO.File::Exists @ token(0x600007F)+0x17B\n\nget file size\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ token(0x600007F)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x600007F)+0x18D\n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ token(0x600006C) in function token(0x600006C)\n  or:\n    api: System.IO.File::SetAttributes @ token(0x600006C)+0x96, token(0x600006C)+0x106\nbasic block @ token(0x600007F) in function token(0x600007F)\n  or:\n    api: System.IO.File::SetAttributes @ token(0x600007F)+0x19D\n\nread file on Windows\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ token(0x6000046)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x6000046)+0x142\n\nwrite file on Windows\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ token(0x600007F)\n  or:\n    api: System.IO.File::WriteAllBytes @ token(0x600007F)+0x170\n\nhide graphical window\nnamespace  host-interaction/gui/window/hide                          \nauthor     michael.hunhoff@mandiant.com                              \nscope      basic block                                               \natt&ck     Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\nbasic block @ token(0x6000019) in function token(0x6000019)\n  and:\n    number: 0x0 = SW_HIDE @ token(0x6000019)+0x3F, token(0x6000019)+0x88\n    api: ShowWindow @ token(0x6000019)+0x40, token(0x6000019)+0x89\n\nget disk size\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ token(0x6000040)\n  or:\n    property/read: System.IO.DriveInfo::TotalSize @ token(0x6000040)+0x19\n\nget networking interfaces\nnamespace  host-interaction/network/interface                                   \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Network Configuration Discovery [T1016]            \nfunction @ token(0x6000046)\n  or:\n    and:\n      or:\n        api: System.Net.NetworkInformation.NetworkInterface::GetIPProperties @ token(0x6000046)+0xA5\n      optional:\n        api: System.Net.NetworkInformation.NetworkInterface::GetAllNetworkInterfaces @ token(0x6000046)+0x88\n\nget hostname\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ token(0x6000043)\n  or:\n    property/read: System.Environment::MachineName @ token(0x6000043)+0x0\n\nget process image filename (2 matches)\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ token(0x6000019) in function token(0x6000019)\n  or:\n    and:\n      api: System.Diagnostics.Process::GetCurrentProcess @ token(0x6000019)+0x0\n      property/read: System.Diagnostics.Process::MainModule @ token(0x6000019)+0x5\n      property/read: System.Diagnostics.ProcessModule::FileName @ token(0x6000019)+0xA\nbasic block @ token(0x6000069) in function token(0x6000069)\n  or:\n    and:\n      api: System.Diagnostics.Process::GetCurrentProcess @ token(0x6000069)+0x35\n      property/read: System.Diagnostics.Process::MainModule @ token(0x6000069)+0x3A\n      property/read: System.Diagnostics.ProcessModule::FileName @ token(0x6000069)+0x3F\n\ncreate a process with modified I/O handles and window\nnamespace   host-interaction/process/create                                     \nauthor      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com      \nscope       function                                                            \nmbc         Process::Create Process [C0017]                                     \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/processthreadsap…\nfunction @ token(0x600007D)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600007D)+0xC7, token(0x600007D)+0x1A9, token(0x600007D)+0x279, \ntoken(0x600007D)+0x357\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600007D)+0xC2, token(0x600007D)+0x1A4, token(0x600007D)+0x274, \ntoken(0x600007D)+0x352\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600007D)+0xB4, token(0x600007D)+0x196, token(0x600007D)+0x266\n        property/write: System.Diagnostics.ProcessStartInfo::WorkingDirectory @ token(0x600007D)+0xAD\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600007D)+0xA1, token(0x600007D)+0x16F, token(0x600007D)+0x23F, \ntoken(0x600007D)+0x34B\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600007D)+0x18F, token(0x600007D)+0x25F\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600007D)+0xBB, token(0x600007D)+0x19D, token(0x600007D)+0x26D\n\ncreate process on Windows\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ token(0x600007D) in function token(0x600007D)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600007D)+0xC7, token(0x600007D)+0x1A9, token(0x600007D)+0x279, \ntoken(0x600007D)+0x357\n\nenumerate processes (2 matches)\nnamespace  host-interaction/process/list                                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      function                                                             \natt&ck     Discovery::Process Discovery [T1057], Discovery::Software Discovery  \n           [T1518]                                                              \nfunction @ token(0x600003E)\n  or:\n    api: System.Diagnostics.Process::GetProcesses @ token(0x600003E)+0x0\nfunction @ token(0x6000044)\n  or:\n    api: System.Diagnostics.Process::GetProcesses @ token(0x6000044)+0x60\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ token(0x6000019)\n  or:\n    api: System.Environment::Exit @ token(0x6000019)+0x68\n\nget session user name (2 matches)\nnamespace  host-interaction/session                                             \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope      function                                                             \natt&ck     Discovery::System Owner/User Discovery [T1033], Discovery::Account   \n           Discovery [T1087]                                                    \nfunction @ token(0x6000043)\n  or:\n    property/read: System.Environment::UserName @ token(0x6000043)+0x1A\nfunction @ token(0x6000045)\n  or:\n    property/read: System.Environment::UserName @ token(0x6000045)+0x0\n\naccess WMI data in .NET (2 matches)\nnamespace  host-interaction/wmi                                 \nauthor     michael.hunhoff@mandiant.com                         \nscope      function                                             \natt&ck     Execution::Windows Management Instrumentation [T1047]\nfunction @ token(0x6000046)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000046)+0x13\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000046)+0xA\nfunction @ token(0x6000047)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000047)+0x11, token(0x6000047)+0xD8\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000047)+0xA, token(0x6000047)+0xD1\n\n(internal) .NET file limitation\nnamespace    internal/limitation/dynamic                        \nauthor       @v1bh475u                                          \nscope        file                                               \ndescription  This dynamic analysis trace describes a .NET file. \n                                                                \n             capa rules are not yet tuned for the .NET runtime, \n             so its analysis may be incomplete or misleading.   \n                                                                \nor:\n  format: dotnet\n\nunmanaged call\nnamespace    runtime                                                       \nauthor       michael.hunhoff@mandiant.com                                  \nscope        function                                                      \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nfunction @ token(0x6000019)\n  or:\n    characteristic: unmanaged call @ token(0x6000019)+0x25, token(0x6000019)+0x2B, token(0x6000019)+0x40, \ntoken(0x6000019)+0x61, and 3 more...\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  format: dotnet\n\n\n\n"},"hashes":{"md5":"75bd50f2b7077d8b22ea51e77028c6b0","sha1":"4534a212afcfc401521f63d89bbde400999ffc71","sha256":"40b2b086397a96608915013652e16e3dd9437e71763925dd8324656138648e46"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 127</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 3883</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"com.goo\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"75bd50f2b7077d8b22ea51e77028c6b0\",\n        \"sha256\": \"40b2b086397a96608915013652e16e3dd9437e71763925dd8324656\",\n        \"arch\": \"i386\",\n        \"os\": \"any\",\n        \"format\": \"dotnet\"\n      }\n    },\n    {\n      \"id\": \"cap_get_mac_address_in__net\",\n      \"label\": \"get MAC address in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_System\",\n      \"label\": \"System\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_echernofsky_google_com\",\n      \"label\": \"echernofsky@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_decode_data_using_base64_in__net\",\n      \"label\": \"decode data using Base64 in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decode Data::Base64 [C0053.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decode Data::Base64 [C0053.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_in__net__2_matches_\",\n      \"label\": \"generate random numbers in .NET (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_access__net_resource__2_matches_\",\n      \"label\": \"access .NET resource (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz\",\n      \"label\": \"author     @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_query_environment_variable__2_matches_\",\n      \"label\": \"query environment variable (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_file_extension_in__net\",\n      \"label\": \"check file extension in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__3_matches_\",\n      \"label\": \"get common file path (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory\",\n      \"label\": \"create directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_file\",\n      \"label\": \"delete file\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_directory_exists\",\n      \"label\": \"check if directory exists\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__5_matches_\",\n      \"label\": \"check if file exists (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size\",\n      \"label\": \"get file size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_file_attributes__2_matches_\",\n      \"label\": \"set file attributes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows\",\n      \"label\": \"read file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows\",\n      \"label\": \"write file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hide_graphical_window\",\n      \"label\": \"hide graphical window\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_ShowWindow\",\n      \"label\": \"ShowWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_size\",\n      \"label\": \"get disk size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_networking_interfaces\",\n      \"label\": \"get networking interfaces\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Network Configuration Discovery [T1016]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_hostname\",\n      \"label\": \"get hostname\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_process_image_filename__2_matches_\",\n      \"label\": \"get process image filename (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_a_process_with_modified_i_o_handles_and_window\",\n      \"label\": \"create a process with modified I/O handles and window\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows\",\n      \"label\": \"create process on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_processes__2_matches_\",\n      \"label\": \"enumerate processes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\",\n        \"Discovery::Software Discovery\",\n        \"[T1518]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_session_user_name__2_matches_\",\n      \"label\": \"get session user name (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\",\n        \"Discovery::Account\",\n        \"Discovery [T1087]\"\n      ]\n    },\n    {\n      \"id\": \"cap_access_wmi_data_in__net__2_matches_\",\n      \"label\": \"access WMI data in .NET (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Windows Management Instrumentation [T1047]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal___net_file_limitation\",\n      \"label\": \"(internal) .NET file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author________v1bh475u\",\n      \"label\": \"author       @v1bh475u\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_unmanaged_call\",\n      \"label\": \"unmanaged call\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"label\": \"author       michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compiled_to_the__net_platform\",\n      \"label\": \"compiled to the .NET platform\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_mac_address_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_echernofsky_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decode_data_using_base64_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_in__net__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access__net_resource__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_file_extension_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_directory_exists\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hide_graphical_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_networking_interfaces\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_process_image_filename__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_a_process_with_modified_i_o_handles_and_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_processes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_user_name__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_wmi_data_in__net__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal___net_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________v1bh475u\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_unmanaged_call\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_to_the__net_platform\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-17 18:46:00.553822\",\n    \"total_functions\": \"127\",\n    \"total_features\": \"3883\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-17 18:46:00"}
{"_id":{"$oid":"6a5a37e6b3bed57e0e737868"},"sha256":"33d74b754a992eedc1eb2a0758fd6dfe0e29208b72147fb5c613d66640de086e","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_i7y698an/zlib_offset_0x58c18_6.bin_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_i7y698an/zlib_offset_0x58c18_6.bin_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_i7y698an/zlib_offset_0x58c18_6.bin_very_verbose.txt"}},"outputs":{"normal":"┌───────────┬──────────────────────────────────────────────────────────────────┐\n│ md5       │ 862f820c3251e4ca6fc0ac00e4092239                                 │\n│ sha1      │ ef96d84b253041b090c243594f90938e9a487a9a                         │\n│ sha256    │ 36585912e5eaf83ba9fea0631534f690ccdc2d7ba91537166fe53e56c221e153 │\n│ analysis  │ static                                                           │\n│ os        │ windows                                                          │\n│ format    │ pe                                                               │\n│ arch      │ amd64                                                            │\n│ path      │ /tmp/sdm_decoded_ufky5he7/zlib_offset_0x58c18_6.bin              │\n└───────────┴──────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic                       ┃ ATT&CK Technique                       ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ EXECUTION                           │ Shared Modules [T1129]                 │\n└─────────────────────────────────────┴────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                               ┃ Namespace                         ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ contains PDB path                        │ executable/pe/pdb                 │\n│ parse PE header                          │ load-code/pe                      │\n└──────────────────────────────────────────┴───────────────────────────────────┘\n\n","verbose":"md5                     862f820c3251e4ca6fc0ac00e4092239                        \nsha1                    ef96d84b253041b090c243594f90938e9a487a9a                \nsha256                  36585912e5eaf83ba9fea0631534f690ccdc2d7ba91537166fe53e5…\npath                    /tmp/sdm_decoded_ufky5he7/zlib_offset_0x58c18_6.bin     \ntimestamp               2026-07-17 19:40:37.583692                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x180000000                                             \nrules                   /tmp/_MEITN493a/rules                                   \nfunction count          141                                                     \nlibrary function count  145                                                     \ntotal feature count     10317                                                   \n\ncontains PDB path\nnamespace  executable/pe/pdb\nscope      file             \n\nparse PE header\nnamespace  load-code/pe\nscope      function    \nmatches    0x180010D30 \n\n\n\n","very_verbose":"md5                     862f820c3251e4ca6fc0ac00e4092239                        \nsha1                    ef96d84b253041b090c243594f90938e9a487a9a                \nsha256                  36585912e5eaf83ba9fea0631534f690ccdc2d7ba91537166fe53e5…\npath                    /tmp/sdm_decoded_ufky5he7/zlib_offset_0x58c18_6.bin     \ntimestamp               2026-07-17 19:40:45.466384                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x180000000                                             \nrules                   /tmp/_MEIjmnjrG/rules                                   \nfunction count          141                                                     \nlibrary function count  145                                                     \ntotal feature count     10317                                                   \n\ncontain loop (59 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x180001230\n  or:\n    characteristic: loop @ 0x180001230\n\ncontains PDB path\nnamespace  executable/pe/pdb        \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nregex: /:\\\\.*\\.pdb/\n  - \"D:\\\\a\\\\_work\\\\1\\\\s\\\\binaries\\\\amd64ret\\\\bin\\\\amd64\\\\\\\\vcruntime140.amd64.pdb\" @ file+0x14EDC\n\nparse PE header\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x180010D30\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x180010D35, 0x180010D41, 0x180010D50\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x180010D41\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x180010D30\n\n\n\n"},"hashes":{"md5":"862f820c3251e4ca6fc0ac00e4092239","sha1":"ef96d84b253041b090c243594f90938e9a487a9a","sha256":"36585912e5eaf83ba9fea0631534f690ccdc2d7ba91537166fe53e56c221e153"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 141</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 10317</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"zlib_offset_0x58c18_6.bin\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"862f820c3251e4ca6fc0ac00e4092239\",\n        \"sha256\": \"36585912e5eaf83ba9fea0631534f690ccdc2d7ba91537166fe53e5\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__59_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (59 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x180001230\",\n      \"label\": \"Function 0x180001230\",\n      \"type\": \"function\",\n      \"address\": \"0x180001230\"\n    },\n    {\n      \"id\": \"cap_contains_pdb_path\",\n      \"label\": \"contains PDB path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_parse_pe_header\",\n      \"label\": \"parse PE header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180010D30\",\n      \"label\": \"Function 0x180010D30\",\n      \"type\": \"function\",\n      \"address\": \"0x180010D30\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__59_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__59_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x180001230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contains_pdb_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header\",\n      \"target\": \"func_0x180010D30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x180010D30\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-17 19:40:45.466384\",\n    \"total_functions\": \"141\",\n    \"total_features\": \"10317\",\n    \"pdb_path\": \"D:\\\\\\\\a\\\\\\\\_work\\\\\\\\1\\\\\\\\s\\\\\\\\binaries\\\\\\\\amd64ret\\\\\\\\bin\\\\\\\\amd64\\\\\\\\\\\\\\\\vcruntime140.amd64.pdb\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-17 19:40:46"}
{"_id":{"$oid":"6a5a3cd9b3bed57e0e73786a"},"sha256":"93759d6cfbfdd0d5018f197461a25ac2361bc57c6d8eea5e3ee044bb146f071a","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_icyo_of2/93759d6cfbfdd0d5018f197461a25ac2361bc57c6d8eea5e3ee044bb146f071a-019f7031eea97001b5694560606f6706.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_icyo_of2/93759d6cfbfdd0d5018f197461a25ac2361bc57c6d8eea5e3ee044bb146f071a-019f7031eea97001b5694560606f6706.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_icyo_of2/93759d6cfbfdd0d5018f197461a25ac2361bc57c6d8eea5e3ee044bb146f071a-019f7031eea97001b5694560606f6706.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 5123d3cc830d4acd49dafb1ba472a90e                                  │\n│ sha1     │ 4bc13337342c06f7b156904544be65bc74e5a0b9                          │\n│ sha256   │ 93759d6cfbfdd0d5018f197461a25ac2361bc57c6d8eea5e3ee044bb146f071a  │\n│ analysis │ static                                                            │\n│ os       │ any                                                               │\n│ format   │ dotnet                                                            │\n│ arch     │ amd64                                                             │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/93759d6cfbfdd0d5… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Clipboard Data [T1115]                                │\n│                      │ Data from Information Repositories [T1213]            │\n│                      │ Input Capture::Keylogging [T1056.001]                 │\n│                      │ Screen Capture [T1113]                                │\n│                      │ Video Capture [T1125]                                 │\n│ DEFENSE EVASION      │ Deobfuscate/Decode Files or Information [T1140]       │\n│                      │ File and Directory Permissions Modification [T1222]   │\n│                      │ Indicator Removal::File Deletion [T1070.004]          │\n│                      │ Obfuscated Files or Information [T1027]               │\n│                      │ Reflective Code Loading [T1620]                       │\n│                      │ Virtualization/Sandbox Evasion [T1497]                │\n│                      │ Virtualization/Sandbox Evasion::System Checks         │\n│                      │ [T1497.001]                                           │\n│ DISCOVERY            │ Account Discovery [T1087]                             │\n│                      │ File and Directory Discovery [T1083]                  │\n│                      │ Process Discovery [T1057]                             │\n│                      │ Query Registry [T1012]                                │\n│                      │ Software Discovery [T1518]                            │\n│                      │ System Information Discovery [T1082]                  │\n│                      │ System Location Discovery::System Language Discovery  │\n│                      │ [T1614.001]                                           │\n│                      │ System Network Configuration Discovery [T1016]        │\n│                      │ System Owner/User Discovery [T1033]                   │\n│ EXECUTION            │ Shared Modules [T1129]                                │\n│                      │ Windows Management Instrumentation [T1047]            │\n│ IMPACT               │ Resource Hijacking [T1496]                            │\n│ PERSISTENCE          │ Boot or Logon Autostart Execution::Registry Run Keys  │\n│                      │ / Startup Folder [T1547.001]                          │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Virtual Machine Detection [B0009]                 │\n│ COLLECTION               │ Keylogging::Application Hook [F0002.001]          │\n│                          │ Keylogging::Polling [F0002.002]                   │\n│                          │ Screen Capture::WinAPI [E1113.m01]                │\n│ CRYPTOGRAPHY             │ Cryptographic Hash::MD5 [C0029.001]               │\n│                          │ Decrypt Data [C0031]                              │\n│                          │ Encrypt Data [C0027]                              │\n│                          │ Generate Pseudo-random Sequence::Use API          │\n│                          │ [C0021.003]                                       │\n│ DATA                     │ Decode Data::Base64 [C0053.001]                   │\n│ DEFENSE EVASION          │ Self Deletion::COMSPEC Environment Variable       │\n│                          │ [F0007.001]                                       │\n│ DISCOVERY                │ File and Directory Discovery [E1083]              │\n│                          │ System Information Discovery [E1082]              │\n│ FILE SYSTEM              │ Copy File [C0045]                                 │\n│                          │ Create Directory [C0046]                          │\n│                          │ Delete Directory [C0048]                          │\n│                          │ Delete File [C0047]                               │\n│                          │ Get File Attributes [C0049]                       │\n│                          │ Read File [C0051]                                 │\n│                          │ Set File Attributes [C0050]                       │\n│                          │ Writes File [C0052]                               │\n│ OPERATING SYSTEM         │ Console [C0033]                                   │\n│                          │ Registry::Query Registry Key [C0036.005]          │\n│                          │ Registry::Query Registry Value [C0036.006]        │\n│                          │ Registry::Set Registry Key [C0036.001]            │\n│ PERSISTENCE              │ Registry Run Keys / Startup Folder [F0012]        │\n│ PROCESS                  │ Create Mutex [C0042]                              │\n│                          │ Create Process [C0017]                            │\n│                          │ Create Thread [C0038]                             │\n│                          │ Suspend Thread [C0055]                            │\n│                          │ Terminate Process [C0018]                         │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ self delete (2 matches)               │ anti-analysis/anti-forensic/self-de… │\n│ check for sandbox username or         │ anti-analysis/anti-vm/vm-detection   │\n│ hostname (2 matches)                  │                                      │\n│ reference anti-VM strings             │ anti-analysis/anti-vm/vm-detection   │\n│ reference anti-VM strings targeting   │ anti-analysis/anti-vm/vm-detection   │\n│ VMWare                                │                                      │\n│ reference anti-VM strings targeting   │ anti-analysis/anti-vm/vm-detection   │\n│ VirtualBox                            │                                      │\n│ save image in .NET (2 matches)        │ collection                           │\n│ reference SQL statements              │ collection/database/sql              │\n│ reference WMI statements (5 matches)  │ collection/database/wmi              │\n│ log keystrokes                        │ collection/keylog                    │\n│ log keystrokes via application hook   │ collection/keylog                    │\n│ log keystrokes via polling (2         │ collection/keylog                    │\n│ matches)                              │                                      │\n│ capture screenshot                    │ collection/screenshot                │\n│ capture webcam image                  │ collection/webcam                    │\n│ manipulate network credentials in     │ communication/authentication         │\n│ .NET (3 matches)                      │                                      │\n│ decode data using Base64 in .NET (7   │ data-manipulation/encoding/base64    │\n│ matches)                              │                                      │\n│ encrypt or decrypt data via BCrypt    │ data-manipulation/encryption         │\n│ encrypt data using DPAPI (5 matches)  │ data-manipulation/encryption/dpapi   │\n│ hash data with MD5                    │ data-manipulation/hashing/md5        │\n│ serialize JSON in .NET                │ data-manipulation/json               │\n│ use .NET library Newtonsoft.Json      │ data-manipulation/json               │\n│ generate random numbers in .NET       │ data-manipulation/prng               │\n│ find data using regex in .NET (15     │ data-manipulation/regex              │\n│ matches)                              │                                      │\n│ load XML in .NET (3 matches)          │ data-manipulation/xml                │\n│ access .NET resource (2 matches)      │ executable/resource                  │\n│ embed dependencies as resources using │ executable/resource                  │\n│ Fody/Costura                          │                                      │\n│ clear clipboard data                  │ host-interaction/clipboard           │\n│ read clipboard data                   │ host-interaction/clipboard           │\n│ manipulate console buffer (8 matches) │ host-interaction/console             │\n│ query environment variable            │ host-interaction/environment-variab… │\n│ enumerate drives                      │ host-interaction/file-system         │\n│ generate random filename in .NET (7   │ host-interaction/file-system         │\n│ matches)                              │                                      │\n│ get common file path (8 matches)      │ host-interaction/file-system         │\n│ set current directory                 │ host-interaction/file-system         │\n│ copy file (23 matches)                │ host-interaction/file-system/copy    │\n│ create directory (30 matches)         │ host-interaction/file-system/create  │\n│ delete directory                      │ host-interaction/file-system/delete  │\n│ delete file (17 matches)              │ host-interaction/file-system/delete  │\n│ check if directory exists (46         │ host-interaction/file-system/exists  │\n│ matches)                              │                                      │\n│ check if file exists (37 matches)     │ host-interaction/file-system/exists  │\n│ enumerate files in .NET (24 matches)  │ host-interaction/file-system/files/… │\n│ get file attributes (6 matches)       │ host-interaction/file-system/meta    │\n│ get file size (8 matches)             │ host-interaction/file-system/meta    │\n│ set file attributes (5 matches)       │ host-interaction/file-system/meta    │\n│ read file on Windows (16 matches)     │ host-interaction/file-system/read    │\n│ write file on Windows (35 matches)    │ host-interaction/file-system/write   │\n│ get CPU information                   │ host-interaction/hardware/cpu        │\n│ get keyboard layout                   │ host-interaction/hardware/keyboard   │\n│ get disk information                  │ host-interaction/hardware/storage    │\n│ allocate unmanaged memory in .NET (4  │ host-interaction/memory              │\n│ matches)                              │                                      │\n│ manipulate unmanaged memory in .NET   │ host-interaction/memory              │\n│ (8 matches)                           │                                      │\n│ create or open mutex on Windows       │ host-interaction/mutex               │\n│ get networking interfaces             │ host-interaction/network/interface   │\n│ get OS version in .NET                │ host-interaction/os/version          │\n│ get process image filename            │ host-interaction/process             │\n│ create a process with modified I/O    │ host-interaction/process/create      │\n│ handles and window (3 matches)        │                                      │\n│ create process on Windows (3 matches) │ host-interaction/process/create      │\n│ enumerate processes (4 matches)       │ host-interaction/process/list        │\n│ find process by PID                   │ host-interaction/process/list        │\n│ find process by name                  │ host-interaction/process/list        │\n│ terminate process (3 matches)         │ host-interaction/process/terminate   │\n│ query or enumerate registry key (9    │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ create thread (2 matches)             │ host-interaction/thread/create       │\n│ suspend thread (5 matches)            │ host-interaction/thread/suspend      │\n│ access WMI data in .NET (9 matches)   │ host-interaction/wmi                 │\n│ reference cryptocurrency strings      │ impact/cryptocurrency                │\n│ link function at runtime on Windows   │ linking/runtime-linking              │\n│ (3 matches)                           │                                      │\n│ load .NET assembly (2 matches)        │ load-code/dotnet                     │\n│ persist via Run registry key          │ persistence/registry/run             │\n│ unmanaged call (14 matches)           │ runtime                              │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     5123d3cc830d4acd49dafb1ba472a90e                        \nsha1                    4bc13337342c06f7b156904544be65bc74e5a0b9                \nsha256                  93759d6cfbfdd0d5018f197461a25ac2361bc57c6d8eea5e3ee044b…\npath                    /home/apogean/projects/malware/windows/all_runs/93759d6…\ntimestamp               2026-07-17 20:01:23.118942                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIG3G9dC/rules                                   \nfunction count          784                                                     \nlibrary function count  0                                                       \ntotal feature count     110924                                                  \n\nself delete (2 matches)\nnamespace  anti-analysis/anti-forensic/self-deletion\nscope      function                                 \nmatches    token(0x60000AB)                         \n           token(0x60000AB)                         \n\ncheck for sandbox username or hostname (2 matches)\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      function                          \nmatches    token(0x6000097)                  \n           token(0x6000098)                  \n\nreference anti-VM strings\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nreference anti-VM strings targeting VMWare\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nreference anti-VM strings targeting VirtualBox\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nsave image in .NET (2 matches)\nnamespace  collection      \nscope      function        \nmatches    token(0x60000FE)\n           token(0x600010D)\n\nreference SQL statements\nnamespace  collection/database/sql\nscope      function               \nmatches    token(0x60000FD)       \n\nreference WMI statements (5 matches)\nnamespace  collection/database/wmi\nscope      function               \nmatches    token(0x6000099)       \n           token(0x60000EA)       \n           token(0x60000FD)       \n           token(0x600011A)       \n           token(0x600011B)       \n\nlog keystrokes\nnamespace  collection/keylog\nscope      function         \nmatches    token(0x6000086) \n\nlog keystrokes via application hook\nnamespace  collection/keylog\nscope      basic block      \nmatches    token(0x6000084) \n\nlog keystrokes via polling (2 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    token(0x6000085) \n           token(0x6000086) \n\ncapture screenshot\nnamespace  collection/screenshot\nscope      function             \nmatches    token(0x600010D)     \n\ncapture webcam image\nnamespace  collection/webcam\nscope      function         \nmatches    token(0x60000FE) \n\nmanipulate network credentials in .NET (3 matches)\nnamespace  communication/authentication\nscope      function                    \nmatches    token(0x600003B)            \n           token(0x6000043)            \n           token(0x6000268)            \n\ndecode data using Base64 in .NET (7 matches)\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    token(0x60000BF)                 \n           token(0x60000C7)                 \n           token(0x60000DA)                 \n           token(0x600019C)                 \n           token(0x6000208)                 \n           token(0x600020A)                 \n           token(0x600023A)                 \n\nencrypt or decrypt data via BCrypt\nnamespace  data-manipulation/encryption\nscope      function                    \nmatches    token(0x600021A)            \n\nencrypt data using DPAPI (5 matches)\nnamespace  data-manipulation/encryption/dpapi\nscope      function                          \nmatches    token(0x60000DA)                  \n           token(0x6000143)                  \n           token(0x6000208)                  \n           token(0x600020A)                  \n           token(0x6000239)                  \n\nhash data with MD5\nnamespace  data-manipulation/hashing/md5\nscope      function                     \nmatches    token(0x60000BD)             \n\nserialize JSON in .NET\nnamespace  data-manipulation/json\nscope      function              \nmatches    token(0x60001C2)      \n\nuse .NET library Newtonsoft.Json\nnamespace  data-manipulation/json\nscope      file                  \n\ngenerate random numbers in .NET\nnamespace  data-manipulation/prng\nscope      function              \nmatches    token(0x60000AD)      \n\nfind data using regex in .NET (15 matches)\nnamespace  data-manipulation/regex\nscope      function               \nmatches    token(0x6000030)       \n           token(0x6000049)       \n           token(0x600012D)       \n           token(0x6000132)       \n           token(0x6000141)       \n           token(0x6000145)       \n           token(0x60001A9)       \n           token(0x60001AD)       \n           token(0x60001B0)       \n           token(0x6000231)       \n           token(0x6000233)       \n           token(0x6000236)       \n           token(0x600023A)       \n           token(0x60002EE)       \n           token(0x60002F0)       \n\nload XML in .NET (3 matches)\nnamespace  data-manipulation/xml\nscope      function             \nmatches    token(0x60000C6)     \n           token(0x60000DB)     \n           token(0x600014B)     \n\naccess .NET resource (2 matches)\nnamespace  executable/resource\nscope      function           \nmatches    token(0x6000009)   \n           token(0x600033B)   \n\nembed dependencies as resources using Fody/Costura\nnamespace  executable/resource\nscope      file               \n\nclear clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    token(0x60000FE)          \n\nread clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    token(0x60000FE)          \n\nmanipulate console buffer (8 matches)\nnamespace  host-interaction/console\nscope      function                \nmatches    token(0x600003B)        \n           token(0x6000043)        \n           token(0x60000E8)        \n           token(0x6000128)        \n           token(0x600012B)        \n           token(0x600019C)        \n           token(0x6000268)        \n           token(0x6000336)        \n\nquery environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    token(0x60000E7)                     \n\nenumerate drives\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x60000E5)            \n\ngenerate random filename in .NET (7 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x60001C5)            \n           token(0x60001C8)            \n           token(0x60001C9)            \n           token(0x60001CA)            \n           token(0x60001CB)            \n           token(0x6000335)            \n           token(0x6000336)            \n\nget common file path (8 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x60000C5)            \n           token(0x60000DD)            \n           token(0x60000DF)            \n           token(0x60000E7)            \n           token(0x6000155)            \n           token(0x60001AB)            \n           token(0x600020F)            \n           token(0x600032A)            \n\nset current directory\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x600006A)            \n\ncopy file (23 matches)\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    token(0x60000B9)                 \n           token(0x60000C8)                 \n           token(0x60000DD)                 \n           token(0x60000DF)                 \n           token(0x600013A)                 \n           token(0x6000156)                 \n           token(0x6000158)                 \n           token(0x600015D)                 \n           token(0x600015E)                 \n           token(0x600015F)                 \n           token(0x6000163)                 \n           token(0x6000165)                 \n           token(0x60001A3)                 \n           token(0x60001A8)                 \n           token(0x60001C5)                 \n           token(0x60001C8)                 \n           token(0x60001C9)                 \n           token(0x60001CA)                 \n           token(0x60001CB)                 \n           token(0x60002BC)                 \n           token(0x60002C9)                 \n           token(0x6000335)                 \n           token(0x6000336)                 \n\ncreate directory (30 matches)\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    token(0x6000074)                   \n           token(0x6000091)                   \n           token(0x60000B3)                   \n           token(0x60000CB)                   \n           token(0x60000CE)                   \n           token(0x60000D6)                   \n           token(0x60000D7)                   \n           token(0x60000DB)                   \n           token(0x60000DD)                   \n           token(0x60000DF)                   \n           token(0x600010D)                   \n           token(0x6000128)                   \n           token(0x6000140)                   \n           token(0x600014B)                   \n           token(0x6000156)                   \n           token(0x6000158)                   \n           token(0x600015D)                   \n           token(0x600015F)                   \n           token(0x6000160)                   \n           token(0x6000163)                   \n           token(0x6000165)                   \n           token(0x6000169)                   \n           token(0x600016B)                   \n           token(0x600019E)                   \n           token(0x60001A8)                   \n           token(0x60001BA)                   \n           token(0x60002BC)                   \n           token(0x60002D1)                   \n           token(0x60002E8)                   \n           token(0x6000327)                   \n\ndelete directory\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    token(0x60002BB)                   \n\ndelete file (17 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    token(0x6000021)                   \n           token(0x6000027)                   \n           token(0x6000029)                   \n           token(0x600003D)                   \n           token(0x6000045)                   \n           token(0x6000047)                   \n           token(0x600005B)                   \n           token(0x6000063)                   \n           token(0x6000065)                   \n           token(0x60001C5)                   \n           token(0x60001C8)                   \n           token(0x60001C9)                   \n           token(0x60001CA)                   \n           token(0x60001CB)                   \n           token(0x60002BB)                   \n           token(0x6000335)                   \n           token(0x6000336)                   \n\ncheck if directory exists (46 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x6000027)                   \n           token(0x6000029)                   \n           token(0x6000045)                   \n           token(0x6000047)                   \n           token(0x6000063)                   \n           token(0x6000065)                   \n           token(0x6000074)                   \n           token(0x6000091)                   \n           token(0x60000B3)                   \n           token(0x60000CE)                   \n           token(0x60000D5)                   \n           token(0x60000D6)                   \n           token(0x60000D7)                   \n           token(0x60000DD)                   \n           token(0x60000DF)                   \n           token(0x60000E3)                   \n           token(0x600010D)                   \n           token(0x6000129)                   \n           token(0x600012B)                   \n           token(0x6000137)                   \n           token(0x600013A)                   \n           token(0x600013D)                   \n           token(0x600014A)                   \n           token(0x600014F)                   \n           token(0x6000152)                   \n           token(0x6000156)                   \n           token(0x6000158)                   \n           token(0x600015F)                   \n           token(0x6000160)                   \n           token(0x6000163)                   \n           token(0x6000165)                   \n           token(0x6000168)                   \n           token(0x6000169)                   \n           token(0x600016B)                   \n           token(0x6000182)                   \n           token(0x6000185)                   \n           token(0x600019E)                   \n           token(0x60001A0)                   \n           token(0x60001A4)                   \n           token(0x60001A7)                   \n           token(0x60001A8)                   \n           token(0x60001BA)                   \n           token(0x600026A)                   \n           token(0x60002BC)                   \n           token(0x60002BE)                   \n           token(0x6000327)                   \n\ncheck if file exists (37 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x6000011)                   \n           token(0x6000017)                   \n           token(0x600002F)                   \n           token(0x6000034)                   \n           token(0x600004B)                   \n           token(0x6000051)                   \n           token(0x60000B4)                   \n           token(0x60000B5)                   \n           token(0x60000B7)                   \n           token(0x60000B8)                   \n           token(0x60000B9)                   \n           token(0x60000C9)                   \n           token(0x60000DB)                   \n           token(0x60000DF)                   \n           token(0x600014B)                   \n           token(0x600015F)                   \n           token(0x600016B)                   \n           token(0x6000182)                   \n           token(0x6000185)                   \n           token(0x60001A0)                   \n           token(0x60001A3)                   \n           token(0x60001A7)                   \n           token(0x60001A8)                   \n           token(0x60001B0)                   \n           token(0x60001C5)                   \n           token(0x60001C6)                   \n           token(0x60001C8)                   \n           token(0x60001C9)                   \n           token(0x60001CA)                   \n           token(0x60001CB)                   \n           token(0x6000208)                   \n           token(0x6000236)                   \n           token(0x600023A)                   \n           token(0x60002BB)                   \n           token(0x60002C9)                   \n           token(0x6000335)                   \n           token(0x6000336)                   \n\nenumerate files in .NET (24 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    token(0x60000DB)                       \n           token(0x60000DD)                       \n           token(0x60000DF)                       \n           token(0x60000E3)                       \n           token(0x600012B)                       \n           token(0x6000156)                       \n           token(0x6000158)                       \n           token(0x600015B)                       \n           token(0x600015C)                       \n           token(0x600015D)                       \n           token(0x600015E)                       \n           token(0x600015F)                       \n           token(0x6000163)                       \n           token(0x6000165)                       \n           token(0x600016B)                       \n           token(0x6000182)                       \n           token(0x6000185)                       \n           token(0x60001A0)                       \n           token(0x60001A4)                       \n           token(0x60001A7)                       \n           token(0x600026B)                       \n           token(0x60002BB)                       \n           token(0x60002BC)                       \n           token(0x60002BD)                       \n\nget file attributes (6 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    token(0x60000B4)                 \n           token(0x60000B5)                 \n           token(0x60000B7)                 \n           token(0x600015C)                 \n           token(0x600026B)                 \n           token(0x6000327)                 \n\nget file size (8 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    token(0x6000021)                 \n           token(0x600003D)                 \n           token(0x600005B)                 \n           token(0x6000156)                 \n           token(0x600015C)                 \n           token(0x600015F)                 \n           token(0x600026B)                 \n           token(0x60002C2)                 \n\nset file attributes (5 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    token(0x60000B4)                 \n           token(0x60000B5)                 \n           token(0x60000B6)                 \n           token(0x60000B7)                 \n           token(0x6000327)                 \n\nread file on Windows (16 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    token(0x6000011)                 \n           token(0x6000017)                 \n           token(0x600002F)                 \n           token(0x6000034)                 \n           token(0x600004B)                 \n           token(0x6000051)                 \n           token(0x6000131)                 \n           token(0x60001A9)                 \n           token(0x60001B0)                 \n           token(0x60001C6)                 \n           token(0x6000208)                 \n           token(0x6000236)                 \n           token(0x600023A)                 \n           token(0x6000263)                 \n           token(0x6000273)                 \n           token(0x600032B)                 \n\nwrite file on Windows (35 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    token(0x6000010)                  \n           token(0x6000027)                  \n           token(0x6000029)                  \n           token(0x600002E)                  \n           token(0x6000045)                  \n           token(0x6000047)                  \n           token(0x600004A)                  \n           token(0x6000063)                  \n           token(0x6000065)                  \n           token(0x6000074)                  \n           token(0x60000CB)                  \n           token(0x60000DB)                  \n           token(0x60000E1)                  \n           token(0x60000E5)                  \n           token(0x60000E8)                  \n           token(0x60000EC)                  \n           token(0x6000103)                  \n           token(0x6000104)                  \n           token(0x6000109)                  \n           token(0x6000128)                  \n           token(0x6000140)                  \n           token(0x600014B)                  \n           token(0x600015B)                  \n           token(0x600015C)                  \n           token(0x6000163)                  \n           token(0x6000175)                  \n           token(0x6000176)                  \n           token(0x6000177)                  \n           token(0x6000178)                  \n           token(0x6000179)                  \n           token(0x600017B)                  \n           token(0x600017C)                  \n           token(0x60001C2)                  \n           token(0x60002C8)                  \n           token(0x60002E4)                  \n\nset application hook\nnamespace  host-interaction/gui \nscope      instruction          \nmatches    token(0x6000084)+0x15\n\nget CPU information\nnamespace  host-interaction/hardware/cpu\nscope      function                     \nmatches    token(0x6000114)             \n\nget keyboard layout\nnamespace  host-interaction/hardware/keyboard\nscope      function                          \nmatches    token(0x6000086)                  \n\nget disk information\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    token(0x60000E5)                 \n\nallocate unmanaged memory in .NET (4 matches)\nnamespace  host-interaction/memory\nscope      function               \nmatches    token(0x600019C)       \n           token(0x600021D)       \n           token(0x600022F)       \n           token(0x6000239)       \n\nmanipulate unmanaged memory in .NET (8 matches)\nnamespace  host-interaction/memory\nscope      function               \nmatches    token(0x6000085)       \n           token(0x6000199)       \n           token(0x600019C)       \n           token(0x600021A)       \n           token(0x600021D)       \n           token(0x600022F)       \n           token(0x6000230)       \n           token(0x6000239)       \n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex\nscope      instruction           \nmatches    token(0x60000A9)+0x8  \n\nget networking interfaces\nnamespace  host-interaction/network/interface\nscope      function                          \nmatches    token(0x6000122)                  \n\nget hostname (2 matches)\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    token(0x6000098)            \n           token(0x600010F)            \n\nget OS version in .NET\nnamespace  host-interaction/os/version\nscope      basic block                \nmatches    token(0x60000F9)           \n\nget process image filename\nnamespace  host-interaction/process\nscope      basic block             \nmatches    token(0x60000AF)        \n\ncreate a process with modified I/O handles and window (3 matches)\nnamespace  host-interaction/process/create\nscope      function                       \nmatches    token(0x60000AB)               \n           token(0x600020F)               \n           token(0x6000275)               \n\ncreate process on Windows (3 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    token(0x60000AB)               \n           token(0x600020F)               \n           token(0x6000275)               \n\nenumerate processes (4 matches)\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    token(0x600009A)             \n           token(0x60000E1)             \n           token(0x6000109)             \n           token(0x6000216)             \n\nfind process by PID\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    token(0x600006E)             \n\nfind process by name\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    token(0x6000155)             \n\nterminate process (3 matches)\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    token(0x60000A9)                  \n           token(0x6000216)                  \n           token(0x6000275)                  \n\nquery or enumerate registry key (9 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    token(0x600009D)         \n           token(0x60000B8)         \n           token(0x60000B9)         \n           token(0x60000D7)         \n           token(0x60000F9)         \n           token(0x6000114)         \n           token(0x6000141)         \n           token(0x6000142)         \n           token(0x6000163)         \n\nquery or enumerate registry value (8 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    token(0x600009D)         \n           token(0x60000B8)         \n           token(0x60000B9)         \n           token(0x60000D7)         \n           token(0x60000F9)         \n           token(0x6000114)         \n           token(0x6000142)         \n           token(0x6000163)         \n\nset registry value\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    token(0x60000B9)                \n\nget session user name (4 matches)\nnamespace  host-interaction/session\nscope      function                \nmatches    token(0x600003A)        \n           token(0x6000097)        \n           token(0x600010E)        \n           token(0x6000267)        \n\ncreate thread (2 matches)\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    token(0x600006A)              \n           token(0x600006F)              \n\nsuspend thread (5 matches)\nnamespace  host-interaction/thread/suspend\nscope      basic block                    \nmatches    token(0x600006F)               \n           token(0x6000091)               \n           token(0x60000AB)               \n           token(0x60000AD)               \n           token(0x60000FE)               \n\naccess WMI data in .NET (9 matches)\nnamespace  host-interaction/wmi\nscope      function            \nmatches    token(0x6000099)    \n           token(0x60000EA)    \n           token(0x60000FD)    \n           token(0x600010A)    \n           token(0x6000113)    \n           token(0x6000117)    \n           token(0x600011A)    \n           token(0x600011B)    \n           token(0x600011C)    \n\nreference cryptocurrency strings\nnamespace  impact/cryptocurrency\nscope      file                 \n\nlink function at runtime on Windows (3 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    token(0x6000199)+0x34  \n           token(0x6000199)+0x43  \n           token(0x6000199)+0x53  \n\nload .NET assembly (2 matches)\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x600033E)\n           token(0x600033F)\n\npersist via Run registry key\nnamespace  persistence/registry/run\nscope      function                \nmatches    token(0x60000B9)        \n\nunmanaged call (14 matches)\nnamespace    runtime                                                       \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nscope        function                                                      \nmatches      token(0x600006E)                                              \n             token(0x6000084)                                              \n             token(0x6000085)                                              \n             token(0x6000086)                                              \n             token(0x60000A6)                                              \n             token(0x60000FE)                                              \n             token(0x600010D)                                              \n             token(0x6000199)                                              \n             token(0x600019A)                                              \n             token(0x600021A)                                              \n             token(0x600021C)                                              \n             token(0x600021D)                                              \n             token(0x600021E)                                              \n             token(0x6000239)                                              \n\ncompiled to the .NET platform\nnamespace  runtime/dotnet\nscope      file          \n\n\n\n","very_verbose":"md5                     5123d3cc830d4acd49dafb1ba472a90e                        \nsha1                    4bc13337342c06f7b156904544be65bc74e5a0b9                \nsha256                  93759d6cfbfdd0d5018f197461a25ac2361bc57c6d8eea5e3ee044b…\npath                    /home/apogean/projects/malware/windows/all_runs/93759d6…\ntimestamp               2026-07-17 20:01:52.070287                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIoQuJnE/rules                                   \nfunction count          784                                                     \nlibrary function count  0                                                       \ntotal feature count     110924                                                  \n\ncontain loop (7 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ token(0x60000E3)\n  or:\n    characteristic: recursive call @ token(0x60000E3)\n\ncreate or open registry key (9 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ token(0x600009D) in function token(0x600009D)\n  or:\n    api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600009D)+0x127\n\nself delete (2 matches)\nnamespace  anti-analysis/anti-forensic/self-deletion                            \nauthor     michael.hunhoff@mandiant.com, @mr-tz                                 \nscope      function                                                             \natt&ck     Defense Evasion::Indicator Removal::File Deletion [T1070.004]        \nmbc        Defense Evasion::Self Deletion::COMSPEC Environment Variable         \n           [F0007.001]                                                          \nfunction @ token(0x60000AB)\n  and:\n    optional:\n      regex: /\\s*>\\s*nul\\s*/i\n        - \"timeout /T 2 /NOBREAK > NUL\" @ token(0x60000AB)+0x5C\n    or:\n      string: \"cmd.exe\" @ token(0x60000AB)+0x9A\n      match: host-interaction/process/create @ token(0x60000AB)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x60000AB)+0xC8\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x60000AB)+0xC8\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x60000AB)+0xBC\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x60000AB)+0x9F\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x60000AB)+0xB5\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x60000AB)+0xC3\n    or:\n      regex: /(^|[\\&;\\|]\\s*)del(\\s.*)?/i\n        - \"del /F /Q \\\"\" @ token(0x60000AB)+0x67\nfunction @ token(0x60000AB)\n  and:\n    optional:\n      regex: /\\s*>\\s*nul\\s*/i\n        - \"timeout /T 2 /NOBREAK > NUL\" @ token(0x60000AB)+0x5C\n    or:\n      string: \"cmd.exe\" @ token(0x60000AB)+0x9A\n      match: host-interaction/process/create @ token(0x60000AB)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x60000AB)+0xC8\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x60000AB)+0xC8\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x60000AB)+0xBC\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x60000AB)+0x9F\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x60000AB)+0xB5\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x60000AB)+0xC3\n    or:\n      regex: /(^|[\\&;\\|]\\s*)del(\\s.*)?/i\n        - \"del /F /Q \\\"\" @ token(0x60000AB)+0x67\n\ncheck for sandbox username or hostname (2 matches)\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      @_re_fox, echernofsky@google.com                                    \nscope       function                                                            \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion [T1497]             \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LloydLabs/wsb-detect,                            \n            https://www.esentire.com/blog/unraveling-not-azorult-but-koi-loader…\nfunction @ token(0x6000097)\n  and:\n    or:\n      match: get session user name @ token(0x6000097)\n        or:\n          property/read: System.Environment::UserName @ token(0x6000097)+0x52B\n    or:\n      regex: /Paul\\s?Jones/i\n        - \"Paul Jones\" @ token(0x6000097)+0x364\n      regex: /Harry\\s?Johnson/i\n        - \"Harry Johnson\" @ token(0x6000097)+0x1FC\n      regex: /sal\\.rosenburg/i\n        - \"sal.rosenburg\" @ token(0x6000097)+0x3FD\n      regex: /John\\s?Doe/i\n        - \"John Doe\" @ token(0x6000097)+0x271\n      regex: /HAPUBWS/i\n        - \"HAPUBWS\" @ token(0x6000097)+0x1F3\n      regex: /JOHN(-PC)?/i\n        - \"Harry Johnson\" @ token(0x6000097)+0x1FC\n        - \"John\" @ token(0x6000097)+0x268\n        - \"John Doe\" @ token(0x6000097)+0x271\n      regex: /Johnson/i\n        - \"Harry Johnson\" @ token(0x6000097)+0x1FC\n      regex: /WDAGUtilityAccount/i\n        - \"WDAGUtilityAccount\" @ token(0x6000097)+0x4C3\nfunction @ token(0x6000098)\n  and:\n    or:\n      match: get hostname @ token(0x6000098)\n        or:\n          property/read: System.Environment::MachineName @ token(0x6000098)+0x3FC\n    or:\n      regex: /Paul\\s?Jones/i\n        - \"Paul Jones\" @ token(0x6000098)+0x214\n      regex: /JOHN(-PC)?/i\n        - \"JOHN-PC\" @ token(0x6000098)+0x17B\n\nreference anti-VM strings\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      moritz.raabe@mandiant.com                                           \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/ctxis/CAPE/blob/master/modules/signatures/antivm…\n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /HARDWARE\\\\DESCRIPTION\\\\System\\\\CentralProcessor/i\n    - \"HARDWARE\\\\Description\\\\System\\\\CentralProcessor\\\\0\" @ file+0x6F87A6\n\nreference anti-VM strings targeting VMWare\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com, @johnk3r                              \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /VMWare/i\n    - \"VMware SVGA 3D\" @ file+0x6F3269\n\nreference anti-VM strings targeting VirtualBox\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /VirtualBox/i\n    - \"VirtualBox Graphics Adapter\" @ file+0x6F31D9\n    - \"VirtualBox Graphics Adapter (WDDM)\" @ file+0x6F3211\n\nsave image in .NET (2 matches)\nnamespace  collection                  \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x60000FE)\n  and:\n    api: System.Drawing.Image::Save @ token(0x60000FE)+0xF3\n    optional:\n      class: System.Drawing.Imaging.ImageFormat @ token(0x60000FE)+0xEE\nfunction @ token(0x600010D)\n  and:\n    api: System.Drawing.Image::Save @ token(0x600010D)+0x81\n    optional:\n      class: System.Drawing.Imaging.ImageFormat @ token(0x600010D)+0x7C\n\nreference SQL statements\nnamespace  collection/database/sql                               \nauthor     william.ballenthin@mandiant.com                       \nscope      function                                              \natt&ck     Collection::Data from Information Repositories [T1213]\nfunction @ token(0x60000FD)\n  and:\n    regex: /SELECT.*FROM.*WHERE/\n      - \"SELECT * FROM Win32_PnPEntity WHERE (PNPClass = 'Image' OR PNPClass = \n'Camera')\" @ token(0x60000FD)+0x2\n\nreference WMI statements (5 matches)\nnamespace  collection/database/wmi                               \nauthor     michael.hunhoff@mandiant.com                          \nscope      function                                              \natt&ck     Collection::Data from Information Repositories [T1213]\nfunction @ token(0x6000099)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_VideoController\" @ token(0x6000099)+0x31C\nfunction @ token(0x60000EA)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_Product\" @ token(0x60000EA)+0x6\nfunction @ token(0x60000FD)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_PnPEntity WHERE (PNPClass = 'Image' OR PNPClass = \n'Camera')\" @ token(0x60000FD)+0x2\nfunction @ token(0x600011A)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_Processor\" @ token(0x600011A)+0x5\nfunction @ token(0x600011B)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_VideoController\" @ token(0x600011B)+0x5\n\nlog keystrokes\nnamespace  collection/keylog                                \nauthor     moritz.raabe@mandiant.com                        \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nfunction @ token(0x6000086)\n  or:\n    api: MapVirtualKey @ token(0x6000086)+0x1B\n\nlog keystrokes via application hook\nnamespace  collection/keylog                                   \nauthor     michael.hunhoff@mandiant.com                        \nscope      basic block                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]   \nmbc        Collection::Keylogging::Application Hook [F0002.001]\nbasic block @ token(0x6000084) in function token(0x6000084)\n  and:\n    match: set application hook @ token(0x6000084)+0x15\n      or:\n        api: SetWindowsHookEx @ token(0x6000084)+0x15\n    or:\n      number: 0xD = WH_KEYBOARD_LL @ token(0x6000084)+0x6\n\nlog keystrokes via polling (2 matches)\nnamespace  collection/keylog                                \nauthor     michael.hunhoff@mandiant.com                     \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nmbc        Collection::Keylogging::Polling [F0002.002]      \nfunction @ token(0x6000085)\n  or:\n    api: GetKeyState @ token(0x6000085)+0x2B, token(0x6000085)+0x3F, token(0x6000085)+0x51\nfunction @ token(0x6000086)\n  or:\n    api: GetKeyboardState @ token(0x6000086)+0x12\n\ncapture screenshot\nnamespace  collection/screenshot                                            \nauthor     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\nscope      function                                                         \natt&ck     Collection::Screen Capture [T1113]                               \nmbc        Collection::Screen Capture::WinAPI [E1113.m01]                   \nfunction @ token(0x600010D)\n  or:\n    api: System.Drawing.Graphics::CopyFromScreen @ token(0x600010D)+0x69\n\ncapture webcam image\nnamespace  collection/webcam                \nauthor     johnk3r                          \nscope      function                         \natt&ck     Collection::Video Capture [T1125]\nfunction @ token(0x60000FE)\n  or:\n    and:\n      api: capCreateCaptureWindow @ token(0x60000FE)+0x4E\n      basic block:\n        and:\n          api: SendMessage @ token(0x60000FE)+0x64, token(0x60000FE)+0x76, token(0x60000FE)+0x92, \ntoken(0x60000FE)+0xA4, and 1 more...\n          number: 0x40A = WM_CAP_DRIVER_CONNECT @ token(0x60000FE)+0x5D\n      optional:\n        basic block:\n          and:\n            api: SendMessage @ token(0x60000FE)+0x64, token(0x60000FE)+0x76, token(0x60000FE)+0x92, \ntoken(0x60000FE)+0xA4, and 1 more...\n            number: 0x40B = WM_CAP_DRIVER_DISCONNECT @ token(0x60000FE)+0xAF\n\nmanipulate network credentials in .NET (3 matches)\nnamespace  communication/authentication\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x600003B)\n  and:\n    api: System.Net.NetworkCredential::ctor @ token(0x600003B)+0x6AE\nfunction @ token(0x6000043)\n  and:\n    api: System.Net.NetworkCredential::ctor @ token(0x6000043)+0x6BF\nfunction @ token(0x6000268)\n  and:\n    api: System.Net.NetworkCredential::ctor @ token(0x6000268)+0xCC\n\ndecode data using Base64 in .NET (7 matches)\nnamespace  data-manipulation/encoding/base64                               \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \natt&ck     Defense Evasion::Deobfuscate/Decode Files or Information [T1140]\nmbc        Data::Decode Data::Base64 [C0053.001]                           \nfunction @ token(0x60000BF)\n  or:\n    api: System.Convert::FromBase64String @ token(0x60000BF)+0x2D\nfunction @ token(0x60000C7)\n  or:\n    api: System.Convert::FromBase64String @ token(0x60000C7)+0xDC\nfunction @ token(0x60000DA)\n  or:\n    api: System.Convert::FromBase64String @ token(0x60000DA)+0x1\nfunction @ token(0x600019C)\n  or:\n    api: System.Convert::FromBase64String @ token(0x600019C)+0x7\nfunction @ token(0x6000208)\n  or:\n    api: System.Convert::FromBase64String @ token(0x6000208)+0x46\nfunction @ token(0x600020A)\n  or:\n    api: System.Convert::FromBase64String @ token(0x600020A)+0x6\nfunction @ token(0x600023A)\n  or:\n    api: System.Convert::FromBase64String @ token(0x600023A)+0x133\n\nencrypt or decrypt data via BCrypt\nnamespace  data-manipulation/encryption                                         \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Decrypt Data [C0031], Cryptography::Encrypt Data       \n           [C0027]                                                              \nfunction @ token(0x600021A)\n  and:\n    or:\n      api: BCryptDecrypt @ token(0x600021A)+0x4E, token(0x600021A)+0x8E\n    optional:\n      api: BCryptCloseAlgorithmProvider @ token(0x600021A)+0xD9\n      api: BCryptDestroyKey @ token(0x600021A)+0xCC\n\nencrypt data using DPAPI (5 matches)\nnamespace  data-manipulation/encryption/dpapi                           \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]     \nmbc        Cryptography::Encrypt Data [C0027]                           \nfunction @ token(0x60000DA)\n  or:\n    api: System.Security.Cryptography.ProtectedData::Unprotect @ token(0x60000DA)+0x8\nfunction @ token(0x6000143)\n  or:\n    api: System.Security.Cryptography.ProtectedData::Unprotect @ token(0x6000143)+0x21\nfunction @ token(0x6000208)\n  or:\n    api: System.Security.Cryptography.ProtectedData::Unprotect @ token(0x6000208)+0x84\nfunction @ token(0x600020A)\n  or:\n    api: System.Security.Cryptography.ProtectedData::Unprotect @ token(0x600020A)+0xD\nfunction @ token(0x6000239)\n  or:\n    api: CryptUnprotectData @ token(0x6000239)+0xDD\n\nhash data with MD5\nnamespace   data-manipulation/hashing/md5                                       \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,         \n            michael.hunhoff@mandiant.com                                        \nscope       function                                                            \nmbc         Cryptography::Cryptographic Hash::MD5 [C0029.001]                   \nreferences  https://github.com/rwfpl/rewolf-x86-virtualizer/blob/master/src/tes…\nfunction @ token(0x60000BD)\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Security.Cryptography.MD5::Create @ token(0x60000BD)+0x92\n      optional:\n        api: System.Security.Cryptography.HashAlgorithm::ComputeHash @ token(0x60000BD)+0xAB\n\nserialize JSON in .NET\nnamespace  data-manipulation/json      \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x60001C2)\n  or:\n    api: System.Text.Json.JsonSerializer::Serialize @ token(0x60001C2)+0x10\n\nuse .NET library Newtonsoft.Json\nnamespace   data-manipulation/json                                              \nauthor      @johnk3r                                                            \nscope       file                                                                \nreferences  https://www.welivesecurity.com/2021/04/06/janeleiro-time-traveler-n…\nand:\n  match: compiled to the .NET platform @ global\n    or:\n      format: dotnet\n  string: \"Newtonsoft.Json\" @ file+0x6EB71F\n\ngenerate random numbers in .NET\nnamespace  data-manipulation/prng                                            \nauthor     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com     \nscope      function                                                          \nmbc        Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\nfunction @ token(0x60000AD)\n  or:\n    api: System.Random::Next @ token(0x60000AD)+0xB\n\nfind data using regex in .NET (15 matches)\nnamespace  data-manipulation/regex     \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x6000030)\n  or:\n    api: System.Text.RegularExpressions.Regex::IsMatch @ token(0x6000030)+0x11, token(0x6000030)+0x1E\n    api: System.Text.RegularExpressions.Regex::ctor @ token(0x6000030)+0x5\nfunction @ token(0x6000049)\n  or:\n    api: System.Text.RegularExpressions.Regex::Match @ token(0x6000049)+0x6\nfunction @ token(0x600012D)\n  or:\n    api: System.Text.RegularExpressions.Regex::ctor @ token(0x600012D)+0x5\nfunction @ token(0x6000132)\n  or:\n    api: System.Text.RegularExpressions.Regex::Match @ token(0x6000132)+0x6\nfunction @ token(0x6000141)\n  or:\n    api: System.Text.RegularExpressions.Regex::IsMatch @ token(0x6000141)+0xA7, token(0x6000141)+0xBA\nfunction @ token(0x6000145)\n  or:\n    api: System.Text.RegularExpressions.Regex::ctor @ token(0x6000145)+0x5, token(0x6000145)+0x14\nfunction @ token(0x60001A9)\n  or:\n    api: System.Text.RegularExpressions.Regex::Match @ token(0x60001A9)+0x85, token(0x60001A9)+0x93, token(0x60001A9)+0xA1\n    api: System.Text.RegularExpressions.Regex::Split @ token(0x60001A9)+0x34, token(0x60001A9)+0x40, token(0x60001A9)+0x4C, \ntoken(0x60001A9)+0xD8, and 2 more...\nfunction @ token(0x60001AD)\n  or:\n    api: System.Text.RegularExpressions.Regex::ctor @ token(0x60001AD)+0x5, token(0x60001AD)+0x14, token(0x60001AD)+0x23\nfunction @ token(0x60001B0)\n  or:\n    api: System.Text.RegularExpressions.Regex::Split @ token(0x60001B0)+0x25, token(0x60001B0)+0x31, token(0x60001B0)+0x3D, \ntoken(0x60001B0)+0x8C\nfunction @ token(0x6000231)\n  or:\n    api: System.Text.RegularExpressions.Regex::Split @ token(0x6000231)+0x6, token(0x6000231)+0x12\nfunction @ token(0x6000233)\n  or:\n    api: System.Text.RegularExpressions.Regex::Split @ token(0x6000233)+0x6\nfunction @ token(0x6000236)\n  or:\n    api: System.Text.RegularExpressions.Regex::Split @ token(0x6000236)+0x25, token(0x6000236)+0x31, token(0x6000236)+0x3D, \ntoken(0x6000236)+0x8C\nfunction @ token(0x600023A)\n  or:\n    api: System.Text.RegularExpressions.Regex::Match @ token(0x600023A)+0x111\n    api: System.Text.RegularExpressions.Regex::ctor @ token(0x600023A)+0x10A\nfunction @ token(0x60002EE)\n  or:\n    api: System.Text.RegularExpressions.Regex::IsMatch @ token(0x60002EE)+0x2E\nfunction @ token(0x60002F0)\n  or:\n    api: System.Text.RegularExpressions.Regex::ctor @ token(0x60002F0)+0x10, token(0x60002F0)+0x25, token(0x60002F0)+0x3A, \ntoken(0x60002F0)+0x4F, and 13 more...\n\nload XML in .NET (3 matches)\nnamespace  data-manipulation/xml       \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x60000C6)\n  or:\n    api: System.Xml.XmlDocument::Load @ token(0x60000C6)+0x7\nfunction @ token(0x60000DB)\n  or:\n    api: System.Xml.XmlDocument::Load @ token(0x60000DB)+0x8E\nfunction @ token(0x600014B)\n  or:\n    api: System.Xml.XmlDocument::Load @ token(0x600014B)+0x27\n\naccess .NET resource (2 matches)\nnamespace  executable/resource\nauthor     @mr-tz             \nscope      function           \nfunction @ token(0x6000009)\n  and:\n    format: dotnet\n    or:\n      api: System.Reflection.Assembly::GetManifestResourceStream @ token(0x6000009)+0x6\nfunction @ token(0x600033B)\n  and:\n    format: dotnet\n    or:\n      api: System.Reflection.Assembly::GetManifestResourceStream @ token(0x600033B)+0x15, token(0x600033B)+0x53\n\nembed dependencies as resources using Fody/Costura\nnamespace   executable/resource                                                 \nauthor      @johnk3r, @mr-tz                                                    \nscope       file                                                                \nreferences  https://www.welivesecurity.com/2021/04/06/janeleiro-time-traveler-n…\nand:\n  match: compiled to the .NET platform @ global\n    or:\n      format: dotnet\n  or:\n    namespace: Costura @ global\n    class: Costura.AssemblyLoader @ token(0x20000BE)\n\nclear clipboard data\nnamespace  host-interaction/clipboard        \nauthor     anushka.virgaonkar@mandiant.com   \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ token(0x60000FE)\n  and:\n    api: System.Windows.Forms.Clipboard::Clear @ token(0x60000FE)+0x35, token(0x60000FE)+0xD8\n\nread clipboard data\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Collection::Clipboard Data [T1115]                                  \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ token(0x60000FE)\n  and:\n    or:\n      api: System.Windows.Forms.Clipboard::GetDataObject @ token(0x60000FE)+0xBC\n\nmanipulate console buffer (8 matches)\nnamespace   host-interaction/console                                     \nauthor      william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope       function                                                     \nmbc         Operating System::Console [C0033]                            \nreferences  https://stackoverflow.com/a/15770935/87207                   \nfunction @ token(0x600003B)\n  or:\n    api: System.Console::WriteLine @ token(0x600003B)+0x7AC\nfunction @ token(0x6000043)\n  or:\n    api: System.Console::WriteLine @ token(0x6000043)+0x7BD\nfunction @ token(0x60000E8)\n  or:\n    api: System.Console::WriteLine @ token(0x60000E8)+0x190\nfunction @ token(0x6000128)\n  or:\n    api: System.Console::WriteLine @ token(0x6000128)+0x42\nfunction @ token(0x600012B)\n  or:\n    api: System.Console::WriteLine @ token(0x600012B)+0x128\nfunction @ token(0x600019C)\n  or:\n    api: System.Console::WriteLine @ token(0x600019C)+0x9A\nfunction @ token(0x6000268)\n  or:\n    api: System.Console::WriteLine @ token(0x6000268)+0x1C5\nfunction @ token(0x6000336)\n  or:\n    api: System.Console::WriteLine @ token(0x6000336)+0x56\n\nquery environment variable\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ token(0x60000E7)\n  or:\n    api: System.Environment::GetEnvironmentVariable @ token(0x60000E7)+0x17\n\nenumerate drives\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x60000E5)\n  or:\n    api: System.IO.DriveInfo::GetDrives @ token(0x60000E5)+0x0\n\ngenerate random filename in .NET (7 matches)\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x60001C5)\n  or:\n    api: System.IO.Path::GetTempFileName @ token(0x60001C5)+0x7F\nfunction @ token(0x60001C8)\n  or:\n    api: System.IO.Path::GetTempFileName @ token(0x60001C8)+0x40\nfunction @ token(0x60001C9)\n  or:\n    api: System.IO.Path::GetTempFileName @ token(0x60001C9)+0x40\nfunction @ token(0x60001CA)\n  or:\n    api: System.IO.Path::GetTempFileName @ token(0x60001CA)+0x7F\nfunction @ token(0x60001CB)\n  or:\n    api: System.IO.Path::GetTempFileName @ token(0x60001CB)+0x40\nfunction @ token(0x6000335)\n  or:\n    api: System.IO.Path::GetTempFileName @ token(0x6000335)+0xA\nfunction @ token(0x6000336)\n  or:\n    api: System.IO.Path::GetTempFileName @ token(0x6000336)+0xA\n\nget common file path (8 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ token(0x60000C5)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x60000C5)+0x2\nfunction @ token(0x60000DD)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x60000DD)+0x2\nfunction @ token(0x60000DF)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x60000DF)+0x2\nfunction @ token(0x60000E7)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x60000E7)+0x7\nfunction @ token(0x6000155)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x6000155)+0x2\nfunction @ token(0x60001AB)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x60001AB)+0x2\nfunction @ token(0x600020F)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x600020F)+0x11, token(0x600020F)+0x25, token(0x600020F)+0x6C, \ntoken(0x600020F)+0x80\nfunction @ token(0x600032A)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x600032A)+0xC, token(0x600032A)+0x18\n\nset current directory\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x600006A)\n  or:\n    api: System.IO.Directory::SetCurrentDirectory @ token(0x600006A)+0x14C\n\ncopy file (23 matches)\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ token(0x60000B9)\n  or:\n    api: System.IO.File::Copy @ token(0x60000B9)+0x6F\nfunction @ token(0x60000C8)\n  or:\n    api: System.IO.File::Copy @ token(0x60000C8)+0x15\nfunction @ token(0x60000DD)\n  or:\n    api: System.IO.File::Copy @ token(0x60000DD)+0x68\nfunction @ token(0x60000DF)\n  or:\n    api: System.IO.File::Copy @ token(0x60000DF)+0x94\nfunction @ token(0x600013A)\n  or:\n    api: System.IO.File::Copy @ token(0x600013A)+0xAB\nfunction @ token(0x6000156)\n  or:\n    api: System.IO.FileInfo::CopyTo @ token(0x6000156)+0xC2, token(0x6000156)+0xF8\nfunction @ token(0x6000158)\n  or:\n    api: System.IO.FileInfo::CopyTo @ token(0x6000158)+0xD4\nfunction @ token(0x600015D)\n  or:\n    api: System.IO.File::Copy @ token(0x600015D)+0x48\nfunction @ token(0x600015E)\n  or:\n    api: System.IO.FileInfo::CopyTo @ token(0x600015E)+0x58\nfunction @ token(0x600015F)\n  or:\n    api: System.IO.FileInfo::CopyTo @ token(0x600015F)+0x6D\nfunction @ token(0x6000163)\n  or:\n    api: System.IO.File::Copy @ token(0x6000163)+0x227, token(0x6000163)+0x2BE\nfunction @ token(0x6000165)\n  or:\n    api: System.IO.File::Copy @ token(0x6000165)+0x40\nfunction @ token(0x60001A3)\n  or:\n    api: System.IO.File::Copy @ token(0x60001A3)+0x1A\nfunction @ token(0x60001A8)\n  or:\n    api: System.IO.File::Copy @ token(0x60001A8)+0x58\nfunction @ token(0x60001C5)\n  or:\n    api: System.IO.File::Copy @ token(0x60001C5)+0x8A\nfunction @ token(0x60001C8)\n  or:\n    api: System.IO.File::Copy @ token(0x60001C8)+0x49\nfunction @ token(0x60001C9)\n  or:\n    api: System.IO.File::Copy @ token(0x60001C9)+0x49\nfunction @ token(0x60001CA)\n  or:\n    api: System.IO.File::Copy @ token(0x60001CA)+0x8A\nfunction @ token(0x60001CB)\n  or:\n    api: System.IO.File::Copy @ token(0x60001CB)+0x49\nfunction @ token(0x60002BC)\n  or:\n    api: System.IO.File::Copy @ token(0x60002BC)+0x2D\nfunction @ token(0x60002C9)\n  or:\n    api: System.IO.File::Copy @ token(0x60002C9)+0x26\nfunction @ token(0x6000335)\n  or:\n    api: System.IO.File::Copy @ token(0x6000335)+0x1C\nfunction @ token(0x6000336)\n  or:\n    api: System.IO.File::Copy @ token(0x6000336)+0x1C\n\ncreate directory (30 matches)\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ token(0x6000074)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000074)+0x4A\nfunction @ token(0x6000091)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000091)+0x26\nfunction @ token(0x60000B3)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60000B3)+0x1B\nfunction @ token(0x60000CB)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60000CB)+0x1\nfunction @ token(0x60000CE)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60000CE)+0x37\nfunction @ token(0x60000D6)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60000D6)+0x12\nfunction @ token(0x60000D7)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60000D7)+0x7A\nfunction @ token(0x60000DB)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60000DB)+0x20, token(0x60000DB)+0x80\nfunction @ token(0x60000DD)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60000DD)+0x2E\nfunction @ token(0x60000DF)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60000DF)+0x80\nfunction @ token(0x600010D)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x600010D)+0x15\nfunction @ token(0x6000128)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000128)+0x5\nfunction @ token(0x6000140)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000140)+0x155\nfunction @ token(0x600014B)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x600014B)+0x12F\nfunction @ token(0x6000156)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000156)+0x16\nfunction @ token(0x6000158)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000158)+0x1B, token(0x6000158)+0xBA\nfunction @ token(0x600015D)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x600015D)+0x26\nfunction @ token(0x600015F)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x600015F)+0x27\nfunction @ token(0x6000160)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000160)+0xF\nfunction @ token(0x6000163)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000163)+0x45, token(0x6000163)+0x1EB, token(0x6000163)+0x281\nfunction @ token(0x6000165)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000165)+0x1A\nfunction @ token(0x6000169)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000169)+0xD, token(0x6000169)+0x22\nfunction @ token(0x600016B)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x600016B)+0x14\nfunction @ token(0x600019E)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x600019E)+0x22E\nfunction @ token(0x60001A8)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60001A8)+0x21\nfunction @ token(0x60001BA)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60001BA)+0x32\nfunction @ token(0x60002BC)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60002BC)+0x9\nfunction @ token(0x60002D1)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60002D1)+0x10\nfunction @ token(0x60002E8)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x60002E8)+0x36, token(0x60002E8)+0xCD, token(0x60002E8)+0xDA, \ntoken(0x60002E8)+0xE7\nfunction @ token(0x6000327)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000327)+0x38\n\ndelete directory\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ token(0x60002BB)\n  or:\n    api: System.IO.DirectoryInfo::Delete @ token(0x60002BB)+0x58\n\ndelete file (17 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ token(0x6000021)\n  or:\n    api: System.IO.File::Delete @ token(0x6000021)+0x15E, token(0x6000021)+0x285\nfunction @ token(0x6000027)\n  or:\n    api: System.IO.File::Delete @ token(0x6000027)+0x14A\nfunction @ token(0x6000029)\n  or:\n    api: System.IO.File::Delete @ token(0x6000029)+0x142\nfunction @ token(0x600003D)\n  or:\n    api: System.IO.File::Delete @ token(0x600003D)+0x15E, token(0x600003D)+0x29E\nfunction @ token(0x6000045)\n  or:\n    api: System.IO.File::Delete @ token(0x6000045)+0x14A\nfunction @ token(0x6000047)\n  or:\n    api: System.IO.File::Delete @ token(0x6000047)+0x156\nfunction @ token(0x600005B)\n  or:\n    api: System.IO.File::Delete @ token(0x600005B)+0x15E, token(0x600005B)+0x285\nfunction @ token(0x6000063)\n  or:\n    api: System.IO.File::Delete @ token(0x6000063)+0x14A\nfunction @ token(0x6000065)\n  or:\n    api: System.IO.File::Delete @ token(0x6000065)+0x142\nfunction @ token(0x60001C5)\n  or:\n    api: System.IO.File::Delete @ token(0x60001C5)+0x15F\nfunction @ token(0x60001C8)\n  or:\n    api: System.IO.File::Delete @ token(0x60001C8)+0x141\nfunction @ token(0x60001C9)\n  or:\n    api: System.IO.File::Delete @ token(0x60001C9)+0xEC\nfunction @ token(0x60001CA)\n  or:\n    api: System.IO.File::Delete @ token(0x60001CA)+0x171\nfunction @ token(0x60001CB)\n  or:\n    api: System.IO.File::Delete @ token(0x60001CB)+0x18C\nfunction @ token(0x60002BB)\n  or:\n    api: System.IO.FileSystemInfo::Delete @ token(0x60002BB)+0x47\nfunction @ token(0x6000335)\n  or:\n    api: System.IO.File::Delete @ token(0x6000335)+0x31\nfunction @ token(0x6000336)\n  or:\n    api: System.IO.File::Delete @ token(0x6000336)+0x68\n\ncheck if directory exists (46 matches)\nnamespace  host-interaction/file-system/exists            \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nfunction @ token(0x6000027)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000027)+0x27\nfunction @ token(0x6000029)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000029)+0x27\nfunction @ token(0x6000045)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000045)+0x27\nfunction @ token(0x6000047)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000047)+0x27\nfunction @ token(0x6000063)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000063)+0x27\nfunction @ token(0x6000065)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000065)+0x27\nfunction @ token(0x6000074)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000074)+0x3E\nfunction @ token(0x6000091)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000091)+0x1E\nfunction @ token(0x60000B3)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60000B3)+0x1\nfunction @ token(0x60000CE)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60000CE)+0x5\nfunction @ token(0x60000D5)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60000D5)+0x63\nfunction @ token(0x60000D6)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60000D6)+0x1, token(0x60000D6)+0xA\nfunction @ token(0x60000D7)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60000D7)+0x5D, token(0x60000D7)+0x72\nfunction @ token(0x60000DD)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60000DD)+0x18\nfunction @ token(0x60000DF)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60000DF)+0x13, token(0x60000DF)+0x6B\nfunction @ token(0x60000E3)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60000E3)+0x1\nfunction @ token(0x600010D)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600010D)+0xD\nfunction @ token(0x6000129)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000129)+0x36\nfunction @ token(0x600012B)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600012B)+0x3E\nfunction @ token(0x6000137)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000137)+0x5, token(0x6000137)+0x1E\nfunction @ token(0x600013A)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600013A)+0x5\nfunction @ token(0x600013D)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600013D)+0x5\nfunction @ token(0x600014A)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600014A)+0x11\nfunction @ token(0x600014F)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600014F)+0x5, token(0x600014F)+0x1E\nfunction @ token(0x6000152)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000152)+0x5, token(0x6000152)+0x1E\nfunction @ token(0x6000156)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000156)+0x7\nfunction @ token(0x6000158)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000158)+0x5, token(0x6000158)+0xAD\nfunction @ token(0x600015F)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600015F)+0x1D\nfunction @ token(0x6000160)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000160)+0x5\nfunction @ token(0x6000163)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000163)+0x31, token(0x6000163)+0x1D9, token(0x6000163)+0x26F\nfunction @ token(0x6000165)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000165)+0x5\nfunction @ token(0x6000168)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000168)+0x52\nfunction @ token(0x6000169)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000169)+0x1\nfunction @ token(0x600016B)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600016B)+0x6\nfunction @ token(0x6000182)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000182)+0xD\nfunction @ token(0x6000185)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000185)+0xD\nfunction @ token(0x600019E)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600019E)+0x12D, token(0x600019E)+0x201, token(0x600019E)+0x225\nfunction @ token(0x60001A0)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60001A0)+0xD\nfunction @ token(0x60001A4)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60001A4)+0x1\nfunction @ token(0x60001A7)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60001A7)+0xD\nfunction @ token(0x60001A8)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60001A8)+0x19\nfunction @ token(0x60001BA)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60001BA)+0x6\nfunction @ token(0x600026A)\n  or:\n    api: System.IO.Directory::Exists @ token(0x600026A)+0x33\nfunction @ token(0x60002BC)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60002BC)+0x1\nfunction @ token(0x60002BE)\n  or:\n    api: System.IO.Directory::Exists @ token(0x60002BE)+0x1\nfunction @ token(0x6000327)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000327)+0x24\n\ncheck if file exists (37 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ token(0x6000011)\n  or:\n    api: System.IO.File::Exists @ token(0x6000011)+0x5\nfunction @ token(0x6000017)\n  or:\n    api: System.IO.File::Exists @ token(0x6000017)+0x5\nfunction @ token(0x600002F)\n  or:\n    api: System.IO.File::Exists @ token(0x600002F)+0x5\nfunction @ token(0x6000034)\n  or:\n    api: System.IO.File::Exists @ token(0x6000034)+0x5\nfunction @ token(0x600004B)\n  or:\n    api: System.IO.File::Exists @ token(0x600004B)+0x5\nfunction @ token(0x6000051)\n  or:\n    api: System.IO.File::Exists @ token(0x6000051)+0x5\nfunction @ token(0x60000B4)\n  or:\n    property/read: System.IO.FileSystemInfo::Exists @ token(0x60000B4)+0x8\nfunction @ token(0x60000B5)\n  or:\n    property/read: System.IO.FileSystemInfo::Exists @ token(0x60000B5)+0x8\nfunction @ token(0x60000B7)\n  or:\n    property/read: System.IO.FileSystemInfo::Exists @ token(0x60000B7)+0x25\nfunction @ token(0x60000B8)\n  or:\n    api: System.IO.File::Exists @ token(0x60000B8)+0x28\nfunction @ token(0x60000B9)\n  or:\n    api: System.IO.File::Exists @ token(0x60000B9)+0x52\nfunction @ token(0x60000C9)\n  or:\n    api: System.IO.File::Exists @ token(0x60000C9)+0x15\nfunction @ token(0x60000DB)\n  or:\n    api: System.IO.File::Exists @ token(0x60000DB)+0x65\n    property/read: System.IO.FileSystemInfo::Exists @ token(0x60000DB)+0x16\nfunction @ token(0x60000DF)\n  or:\n    api: System.IO.File::Exists @ token(0x60000DF)+0x4E\nfunction @ token(0x600014B)\n  or:\n    api: System.IO.File::Exists @ token(0x600014B)+0x11\nfunction @ token(0x600015F)\n  or:\n    api: System.IO.File::Exists @ token(0x600015F)+0x62\nfunction @ token(0x600016B)\n  or:\n    api: System.IO.File::Exists @ token(0x600016B)+0x3F\nfunction @ token(0x6000182)\n  or:\n    api: System.IO.File::Exists @ token(0x6000182)+0x2E\nfunction @ token(0x6000185)\n  or:\n    api: System.IO.File::Exists @ token(0x6000185)+0x2E\nfunction @ token(0x60001A0)\n  or:\n    api: System.IO.File::Exists @ token(0x60001A0)+0x2E\nfunction @ token(0x60001A3)\n  or:\n    api: System.IO.File::Exists @ token(0x60001A3)+0x1\nfunction @ token(0x60001A7)\n  or:\n    api: System.IO.File::Exists @ token(0x60001A7)+0x2E\nfunction @ token(0x60001A8)\n  or:\n    api: System.IO.File::Exists @ token(0x60001A8)+0x42\nfunction @ token(0x60001B0)\n  or:\n    api: System.IO.File::Exists @ token(0x60001B0)+0x7\nfunction @ token(0x60001C5)\n  or:\n    api: System.IO.File::Exists @ token(0x60001C5)+0x2E, token(0x60001C5)+0x36\nfunction @ token(0x60001C6)\n  or:\n    api: System.IO.File::Exists @ token(0x60001C6)+0x1D\nfunction @ token(0x60001C8)\n  or:\n    api: System.IO.File::Exists @ token(0x60001C8)+0x1D\nfunction @ token(0x60001C9)\n  or:\n    api: System.IO.File::Exists @ token(0x60001C9)+0x1D\nfunction @ token(0x60001CA)\n  or:\n    api: System.IO.File::Exists @ token(0x60001CA)+0x2E, token(0x60001CA)+0x36\nfunction @ token(0x60001CB)\n  or:\n    api: System.IO.File::Exists @ token(0x60001CB)+0x1D\nfunction @ token(0x6000208)\n  or:\n    api: System.IO.File::Exists @ token(0x6000208)+0x1\nfunction @ token(0x6000236)\n  or:\n    api: System.IO.File::Exists @ token(0x6000236)+0x7\nfunction @ token(0x600023A)\n  or:\n    api: System.IO.File::Exists @ token(0x600023A)+0x76, token(0x600023A)+0xC8\nfunction @ token(0x60002BB)\n  or:\n    property/read: System.IO.FileSystemInfo::Exists @ token(0x60002BB)+0x8\nfunction @ token(0x60002C9)\n  or:\n    api: System.IO.File::Exists @ token(0x60002C9)+0x16\nfunction @ token(0x6000335)\n  or:\n    api: System.IO.File::Exists @ token(0x6000335)+0x1\nfunction @ token(0x6000336)\n  or:\n    api: System.IO.File::Exists @ token(0x6000336)+0x1, token(0x6000336)+0x60\n\nenumerate files in .NET (24 matches)\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ token(0x60000DB)\n  or:\n    api: System.IO.DirectoryInfo::GetDirectories @ token(0x60000DB)+0x2C, token(0x60000DB)+0x3C\nfunction @ token(0x60000DD)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x60000DD)+0x3A\nfunction @ token(0x60000DF)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x60000DF)+0x1D, token(0x60000DF)+0x2D\nfunction @ token(0x60000E3)\n  or:\n    api: System.IO.DirectoryInfo::GetFiles @ token(0x60000E3)+0x85\n    api: System.IO.DirectoryInfo::GetDirectories @ token(0x60000E3)+0x48\nfunction @ token(0x600012B)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x600012B)+0x54\nfunction @ token(0x6000156)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x6000156)+0x23\n    api: System.IO.Directory::GetDirectories @ token(0x6000156)+0x1D\nfunction @ token(0x6000158)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x6000158)+0x4A\nfunction @ token(0x600015B)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x600015B)+0xF\nfunction @ token(0x600015C)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x600015C)+0xF\nfunction @ token(0x600015D)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x600015D)+0xF\nfunction @ token(0x600015E)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x600015E)+0x5\nfunction @ token(0x600015F)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x600015F)+0x2E\nfunction @ token(0x6000163)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x6000163)+0x1F2, token(0x6000163)+0x289\nfunction @ token(0x6000165)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x6000165)+0x25\nfunction @ token(0x600016B)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x600016B)+0x26\nfunction @ token(0x6000182)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x6000182)+0x15\nfunction @ token(0x6000185)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x6000185)+0x15\nfunction @ token(0x60001A0)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x60001A0)+0x15\nfunction @ token(0x60001A4)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x60001A4)+0x11\nfunction @ token(0x60001A7)\n  or:\n    api: System.IO.Directory::GetDirectories @ token(0x60001A7)+0x15\nfunction @ token(0x600026B)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x600026B)+0x1\n    api: System.IO.Directory::GetDirectories @ token(0x600026B)+0x88\nfunction @ token(0x60002BB)\n  or:\n    api: System.IO.DirectoryInfo::GetFiles @ token(0x60002BB)+0x33\n    api: System.IO.DirectoryInfo::GetDirectories @ token(0x60002BB)+0x11\nfunction @ token(0x60002BC)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x60002BC)+0x10\n    api: System.IO.Directory::GetDirectories @ token(0x60002BC)+0x3D\nfunction @ token(0x60002BD)\n  or:\n    api: System.IO.DirectoryInfo::GetFiles @ token(0x60002BD)+0x7\n    api: System.IO.DirectoryInfo::GetDirectories @ token(0x60002BD)+0x31\n\nget file attributes (6 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ token(0x60000B4) in function token(0x60000B4)\n  or:\n    property/read: System.IO.FileSystemInfo::Attributes @ token(0x60000B4)+0x26, token(0x60000B4)+0x47\nbasic block @ token(0x60000B5) in function token(0x60000B5)\n  or:\n    property/read: System.IO.FileSystemInfo::Attributes @ token(0x60000B5)+0x26, token(0x60000B5)+0x47\nbasic block @ token(0x60000B7) in function token(0x60000B7)\n  or:\n    property/read: System.IO.FileSystemInfo::Attributes @ token(0x60000B7)+0x41, token(0x60000B7)+0x60\nbasic block @ token(0x600015C) in function token(0x600015C)\n  or:\n    api: System.IO.File::GetCreationTime @ token(0x600015C)+0x45\nbasic block @ token(0x600026B) in function token(0x600026B)\n  or:\n    api: System.IO.File::GetLastWriteTime @ token(0x600026B)+0x2C\nbasic block @ token(0x6000327) in function token(0x6000327)\n  or:\n    property/read: System.IO.FileSystemInfo::Attributes @ token(0x6000327)+0x51\n\nget file size (8 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ token(0x6000021)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x6000021)+0x32\nfunction @ token(0x600003D)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x600003D)+0x32\nfunction @ token(0x600005B)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x600005B)+0x32\nfunction @ token(0x6000156)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x6000156)+0x98\nfunction @ token(0x600015C)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x600015C)+0x2C\nfunction @ token(0x600015F)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x600015F)+0x44\nfunction @ token(0x600026B)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x600026B)+0x3D\nfunction @ token(0x60002C2)\n  or:\n    property/read: System.IO.FileInfo::Length @ token(0x60002C2)+0x1\n\nset file attributes (5 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ token(0x60000B4) in function token(0x60000B4)\n  or:\n    property/write: System.IO.FileSystemInfo::Attributes @ token(0x60000B4)+0x2D, token(0x60000B4)+0x4F\nbasic block @ token(0x60000B5) in function token(0x60000B5)\n  or:\n    property/write: System.IO.FileSystemInfo::Attributes @ token(0x60000B5)+0x2D, token(0x60000B5)+0x4F\nbasic block @ token(0x60000B6) in function token(0x60000B6)\n  or:\n    api: System.IO.File::SetCreationTime @ token(0x60000B6)+0x42\n    api: System.IO.File::SetLastAccessTime @ token(0x60000B6)+0x50\n    api: System.IO.File::SetLastWriteTime @ token(0x60000B6)+0x49\nbasic block @ token(0x60000B7) in function token(0x60000B7)\n  or:\n    property/write: System.IO.FileSystemInfo::Attributes @ token(0x60000B7)+0x67\nbasic block @ token(0x6000327) in function token(0x6000327)\n  or:\n    property/write: System.IO.FileSystemInfo::Attributes @ token(0x6000327)+0x58\n\nread file on Windows (16 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ token(0x6000011)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x6000011)+0x17\nfunction @ token(0x6000017)\n  or:\n    api: System.IO.File::ReadAllLines @ token(0x6000017)+0x17\nfunction @ token(0x600002F)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x600002F)+0x17\nfunction @ token(0x6000034)\n  or:\n    api: System.IO.File::ReadAllLines @ token(0x6000034)+0x17\nfunction @ token(0x600004B)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x600004B)+0x14\nfunction @ token(0x6000051)\n  or:\n    api: System.IO.File::ReadAllLines @ token(0x6000051)+0x17\nfunction @ token(0x6000131)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x6000131)+0x1\nfunction @ token(0x60001A9)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x60001A9)+0x2A\nfunction @ token(0x60001B0)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x60001B0)+0x1B\nfunction @ token(0x60001C6)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x60001C6)+0x41\nfunction @ token(0x6000208)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x6000208)+0x10\nfunction @ token(0x6000236)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x6000236)+0x1B\nfunction @ token(0x600023A)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x600023A)+0xFD\nfunction @ token(0x6000263)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x6000263)+0x2A\nfunction @ token(0x6000273)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x6000273)+0x2A\nfunction @ token(0x600032B)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x600032B)+0x20\n\nwrite file on Windows (35 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ token(0x6000010)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x6000010)+0x6\nfunction @ token(0x6000027)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000027)+0x1BA\nfunction @ token(0x6000029)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000029)+0x196\nfunction @ token(0x600002E)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x600002E)+0x6\nfunction @ token(0x6000045)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000045)+0x1BA\nfunction @ token(0x6000047)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000047)+0x1AA\nfunction @ token(0x600004A)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x600004A)+0xC\nfunction @ token(0x6000063)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000063)+0x1BA\nfunction @ token(0x6000065)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000065)+0x196\nfunction @ token(0x6000074)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x6000074)+0x55\nfunction @ token(0x60000CB)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x60000CB)+0x3B\nfunction @ token(0x60000DB)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x60000DB)+0x147\nfunction @ token(0x60000E1)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x60000E1)+0x89\nfunction @ token(0x60000E5)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x60000E5)+0x8F\nfunction @ token(0x60000E8)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x60000E8)+0x197\nfunction @ token(0x60000EC)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x60000EC)+0x78\nfunction @ token(0x6000103)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000103)+0x25\nfunction @ token(0x6000104)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000104)+0x68\nfunction @ token(0x6000109)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000109)+0x6C\nfunction @ token(0x6000128)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000128)+0x31\nfunction @ token(0x6000140)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x6000140)+0x171\nfunction @ token(0x600014B)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x600014B)+0x14A\nfunction @ token(0x600015B)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x600015B)+0x9D\nfunction @ token(0x600015C)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x600015C)+0x9D\nfunction @ token(0x6000163)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x6000163)+0x359\n    api: System.IO.File::AppendAllText @ token(0x6000163)+0x18E\nfunction @ token(0x6000175)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000175)+0x18\nfunction @ token(0x6000176)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000176)+0x18\nfunction @ token(0x6000177)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x6000177)+0x9\nfunction @ token(0x6000178)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000178)+0x18\nfunction @ token(0x6000179)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x6000179)+0x32\nfunction @ token(0x600017B)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x600017B)+0x3C\nfunction @ token(0x600017C)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x600017C)+0x18\nfunction @ token(0x60001C2)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x60001C2)+0x15\nfunction @ token(0x60002C8)\n  or:\n    api: System.IO.File::AppendAllText @ token(0x60002C8)+0x3A\nfunction @ token(0x60002E4)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x60002E4)+0x15\n\nset application hook\nnamespace  host-interaction/gui        \nauthor     michael.hunhoff@mandiant.com\nscope      instruction                 \ninstruction @ token(0x6000084)+0x15\n  or:\n    api: SetWindowsHookEx @ token(0x6000084)+0x15\n\nget CPU information\nnamespace  host-interaction/hardware/cpu                  \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com  \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ token(0x6000114)\n  or:\n    and:\n      os: windows\n      match: query or enumerate registry value @ token(0x6000114)\n        and:\n          optional:\n            match: create or open registry key @ token(0x6000114)\n              or:\n                api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000114)+0xA\n          or:\n            api: Microsoft.Win32.RegistryKey::GetValue @ token(0x6000114)+0x1B\n      regex: /Hardware\\\\Description\\\\System\\\\CentralProcessor/i\n        - \"HARDWARE\\\\Description\\\\System\\\\CentralProcessor\\\\0\" @ token(0x6000114)+0x5\n\nget keyboard layout\nnamespace  host-interaction/hardware/keyboard                                   \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Discovery::System Location Discovery::System Language Discovery      \n           [T1614.001]                                                          \nfunction @ token(0x6000086)\n  and:\n    or:\n      api: GetKeyboardLayout @ token(0x6000086)+0x2D\n\nget disk information\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ token(0x60000E5)\n  or:\n    property/read: System.IO.DriveInfo::DriveType @ token(0x60000E5)+0xF\n\nallocate unmanaged memory in .NET (4 matches)\nnamespace  host-interaction/memory     \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x600019C)\n  or:\n    api: System.Runtime.InteropServices.Marshal::AllocHGlobal @ token(0x600019C)+0x10\nfunction @ token(0x600021D)\n  or:\n    api: System.Runtime.InteropServices.Marshal::AllocHGlobal @ token(0x600021D)+0x13\nfunction @ token(0x600022F)\n  or:\n    api: System.Runtime.InteropServices.Marshal::AllocHGlobal @ token(0x600022F)+0x3A, token(0x600022F)+0x6A, token(0x600022F)+0x9A, \ntoken(0x600022F)+0xC7\nfunction @ token(0x6000239)\n  or:\n    api: System.Runtime.InteropServices.Marshal::AllocHGlobal @ token(0x6000239)+0x6B, token(0x6000239)+0xA4\n\nmanipulate unmanaged memory in .NET (8 matches)\nnamespace  host-interaction/memory     \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x6000085)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x6000085)+0x24\nfunction @ token(0x6000199)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x6000199)+0x63, token(0x6000199)+0x7D, token(0x6000199)+0x97\nfunction @ token(0x600019C)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x600019C)+0x10, token(0x600019C)+0x1C, token(0x600019C)+0x83, \ntoken(0x600019C)+0xB2\nfunction @ token(0x600021A)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x600021A)+0xD2\nfunction @ token(0x600021D)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x600021D)+0x13\nfunction @ token(0x600022F)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x600022F)+0x1D, token(0x600022F)+0x3A, token(0x600022F)+0x52, \ntoken(0x600022F)+0x6A, and 4 more...\nfunction @ token(0x6000230)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x6000230)+0x18, token(0x6000230)+0x35, token(0x6000230)+0x52, \ntoken(0x6000230)+0x6F\nfunction @ token(0x6000239)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x6000239)+0x2C, token(0x6000239)+0x6B, token(0x6000239)+0x8A, \ntoken(0x6000239)+0xA4, and 5 more...\n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex                                               \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           mehunhoff@google.com                                                 \nscope      instruction                                                          \nmbc        Process::Create Mutex [C0042]                                        \ninstruction @ token(0x60000A9)+0x8\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Threading.Mutex::ctor @ token(0x60000A9)+0x8\n\nget networking interfaces\nnamespace  host-interaction/network/interface                                   \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Network Configuration Discovery [T1016]            \nfunction @ token(0x6000122)\n  or:\n    and:\n      or:\n        api: System.Net.NetworkInformation.NetworkInterface::GetIPProperties @ token(0x6000122)+0x1\n\nget hostname (2 matches)\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ token(0x6000098)\n  or:\n    property/read: System.Environment::MachineName @ token(0x6000098)+0x3FC\nfunction @ token(0x600010F)\n  or:\n    property/read: System.Environment::MachineName @ token(0x600010F)+0x0\n\nget OS version in .NET\nnamespace  host-interaction/os/version                    \nauthor     michael.hunhoff@mandiant.com                   \nscope      basic block                                    \natt&ck     Discovery::System Information Discovery [T1082]\nbasic block @ token(0x60000F9) in function token(0x60000F9)\n  or:\n    property/read: System.Environment::OSVersion @ token(0x60000F9)+0x4C, token(0x60000F9)+0x5E, token(0x60000F9)+0x70\n    property/read: System.Environment::Is64BitOperatingSystem @ token(0x60000F9)+0x5\n    property/read: System.OperatingSystem::Version @ token(0x60000F9)+0x51, token(0x60000F9)+0x63, token(0x60000F9)+0x75\n\nget process image filename\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ token(0x60000AF) in function token(0x60000AF)\n  or:\n    and:\n      api: System.Diagnostics.Process::GetCurrentProcess @ token(0x60000AF)+0x31\n      property/read: System.Diagnostics.Process::MainModule @ token(0x60000AF)+0x54\n      property/read: System.Diagnostics.ProcessModule::FileName @ token(0x60000AF)+0x73\n\ncreate a process with modified I/O handles and window (3 matches)\nnamespace   host-interaction/process/create                                     \nauthor      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com      \nscope       function                                                            \nmbc         Process::Create Process [C0017]                                     \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/processthreadsap…\nfunction @ token(0x60000AB)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x60000AB)+0xC8\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x60000AB)+0xBC\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x60000AB)+0x9F\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x60000AB)+0xB5\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x60000AB)+0xC3\nfunction @ token(0x600020F)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x600020F)+0x121\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x600020F)+0x10E\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x600020F)+0x11C\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x600020F)+0xEC\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x600020F)+0x107\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x600020F)+0x115\nfunction @ token(0x6000275)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000275)+0x51\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x6000275)+0xE\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000275)+0x1C\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000275)+0x27\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000275)+0x38\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x6000275)+0x15\n        property/write: System.Diagnostics.ProcessStartInfo::RedirectStandardOutput @ token(0x6000275)+0x46\n        property/read: System.Diagnostics.Process::StandardOutput @ token(0x6000275)+0x58\n\ncreate process on Windows (3 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ token(0x60000AB) in function token(0x60000AB)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x60000AB)+0xC8\nbasic block @ token(0x600020F) in function token(0x600020F)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600020F)+0x121\nbasic block @ token(0x6000275) in function token(0x6000275)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000275)+0x51\n\nenumerate processes (4 matches)\nnamespace  host-interaction/process/list                                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      function                                                             \natt&ck     Discovery::Process Discovery [T1057], Discovery::Software Discovery  \n           [T1518]                                                              \nfunction @ token(0x600009A)\n  or:\n    api: System.Diagnostics.Process::GetProcesses @ token(0x600009A)+0x24\nfunction @ token(0x60000E1)\n  or:\n    api: System.Diagnostics.Process::GetProcesses @ token(0x60000E1)+0x0\nfunction @ token(0x6000109)\n  or:\n    api: System.Diagnostics.Process::GetProcesses @ token(0x6000109)+0xC\nfunction @ token(0x6000216)\n  or:\n    api: System.Diagnostics.Process::GetProcesses @ token(0x6000216)+0x57\n\nfind process by PID\nnamespace  host-interaction/process/list                                \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::Process Discovery [T1057]                         \nfunction @ token(0x600006E)\n  and:\n    or:\n      api: System.Diagnostics.Process::GetProcessById @ token(0x600006E)+0xE\n\nfind process by name\nnamespace  host-interaction/process/list       \nauthor     anushka.virgaonkar@mandiant.com     \nscope      function                            \natt&ck     Discovery::Process Discovery [T1057]\nfunction @ token(0x6000155)\n  and:\n    api: System.Diagnostics.Process::GetProcessesByName @ token(0x6000155)+0x17\n\nterminate process (3 matches)\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ token(0x60000A9)\n  or:\n    api: System.Environment::Exit @ token(0x60000A9)+0x16, token(0x60000A9)+0x36\nfunction @ token(0x6000216)\n  or:\n    api: System.Diagnostics.Process::Kill @ token(0x6000216)+0xC2, token(0x6000216)+0x62D\nfunction @ token(0x6000275)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x6000275)+0x73\n\nquery or enumerate registry key (9 matches)\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ token(0x600009D)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600009D)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600009D)+0x127\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600009D)+0x127\nfunction @ token(0x60000B8)\n  and:\n    optional:\n      match: create or open registry key @ token(0x60000B8)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000B8)+0xB\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000B8)+0xB\nfunction @ token(0x60000B9)\n  and:\n    optional:\n      match: create or open registry key @ token(0x60000B9)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000B9)+0x8D\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000B9)+0x8D\nfunction @ token(0x60000D7)\n  and:\n    optional:\n      match: create or open registry key @ token(0x60000D7)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000D7)+0xA, token(0x60000D7)+0x17, token(0x60000D7)+0x2E\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000D7)+0xA, token(0x60000D7)+0x17, token(0x60000D7)+0x2E\nfunction @ token(0x60000F9)\n  and:\n    optional:\n      match: create or open registry key @ token(0x60000F9)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000F9)+0x24\n          api: Microsoft.Win32.RegistryKey::OpenBaseKey @ token(0x60000F9)+0x18\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenBaseKey @ token(0x60000F9)+0x18\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000F9)+0x24\nfunction @ token(0x6000114)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000114)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000114)+0xA\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000114)+0xA\nfunction @ token(0x6000141)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000141)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000141)+0x14B\n    or:\n      api: Microsoft.Win32.RegistryKey::GetSubKeyNames @ token(0x6000141)+0x155\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000141)+0x14B\nfunction @ token(0x6000142)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000142)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000142)+0x9\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000142)+0x9\nfunction @ token(0x6000163)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000163)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000163)+0xA, token(0x6000163)+0x51, token(0x6000163)+0x8F\n    or:\n      api: Microsoft.Win32.RegistryKey::GetSubKeyNames @ token(0x6000163)+0x6C\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000163)+0xA, token(0x6000163)+0x51, token(0x6000163)+0x8F\n\nquery or enumerate registry value (8 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ token(0x600009D)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600009D)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x600009D)+0x127\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x600009D)+0x136\nfunction @ token(0x60000B8)\n  and:\n    optional:\n      match: create or open registry key @ token(0x60000B8)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000B8)+0xB\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x60000B8)+0x1C\nfunction @ token(0x60000B9)\n  and:\n    optional:\n      match: create or open registry key @ token(0x60000B9)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000B9)+0x8D\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x60000B9)+0xA8\nfunction @ token(0x60000D7)\n  and:\n    optional:\n      match: create or open registry key @ token(0x60000D7)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000D7)+0xA, token(0x60000D7)+0x17, token(0x60000D7)+0x2E\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x60000D7)+0x42\nfunction @ token(0x60000F9)\n  and:\n    optional:\n      match: create or open registry key @ token(0x60000F9)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000F9)+0x24\n          api: Microsoft.Win32.RegistryKey::OpenBaseKey @ token(0x60000F9)+0x18\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x60000F9)+0x35\nfunction @ token(0x6000114)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000114)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000114)+0xA\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x6000114)+0x1B\nfunction @ token(0x6000142)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000142)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000142)+0x9\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x6000142)+0x14\nfunction @ token(0x6000163)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000163)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000163)+0xA, token(0x6000163)+0x51, token(0x6000163)+0x8F\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x6000163)+0x25, token(0x6000163)+0xA6, token(0x6000163)+0xCD, \ntoken(0x6000163)+0xEF, and 3 more...\n\nset registry value\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ token(0x60000B9)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x60000B9)\n          or:\n            api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000B9)+0x8D\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x60000B9)+0xC8\n\nget session user name (4 matches)\nnamespace  host-interaction/session                                             \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope      function                                                             \natt&ck     Discovery::System Owner/User Discovery [T1033], Discovery::Account   \n           Discovery [T1087]                                                    \nfunction @ token(0x600003A)\n  or:\n    property/read: System.Environment::UserName @ token(0x600003A)+0x44\nfunction @ token(0x6000097)\n  or:\n    property/read: System.Environment::UserName @ token(0x6000097)+0x52B\nfunction @ token(0x600010E)\n  or:\n    property/read: System.Environment::UserName @ token(0x600010E)+0x0\nfunction @ token(0x6000267)\n  or:\n    property/read: System.Environment::UserName @ token(0x6000267)+0x44\n\ncreate thread (2 matches)\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ token(0x600006A) in function token(0x600006A)\n  or:\n    and:\n      api: System.Threading.Thread::Start @ token(0x600006A)+0x840\nbasic block @ token(0x600006F) in function token(0x600006F)\n  or:\n    and:\n      api: System.Threading.Thread::Start @ token(0x600006F)+0x5\n\nsuspend thread (5 matches)\nnamespace  host-interaction/thread/suspend                    \nauthor     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\nscope      basic block                                        \nmbc        Process::Suspend Thread [C0055]                    \nbasic block @ token(0x600006F) in function token(0x600006F)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x600006F)+0x15\nbasic block @ token(0x6000091) in function token(0x6000091)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000091)+0x31, token(0x6000091)+0x41\nbasic block @ token(0x60000AB) in function token(0x60000AB)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x60000AB)+0xD3\nbasic block @ token(0x60000AD) in function token(0x60000AD)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x60000AD)+0x34\nbasic block @ token(0x60000FE) in function token(0x60000FE)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x60000FE)+0x81\n\naccess WMI data in .NET (9 matches)\nnamespace  host-interaction/wmi                                 \nauthor     michael.hunhoff@mandiant.com                         \nscope      function                                             \natt&ck     Execution::Windows Management Instrumentation [T1047]\nfunction @ token(0x6000099)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000099)+0x328\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000099)+0x321\nfunction @ token(0x60000EA)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x60000EA)+0x10\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x60000EA)+0xB\nfunction @ token(0x60000FD)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x60000FD)+0xE\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x60000FD)+0x7\nfunction @ token(0x600010A)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x600010A)+0x29\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x600010A)+0x24\nfunction @ token(0x6000113)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000113)+0x11\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000113)+0xA\nfunction @ token(0x6000117)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000117)+0x11\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000117)+0xA\nfunction @ token(0x600011A)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x600011A)+0x11\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x600011A)+0xA\nfunction @ token(0x600011B)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x600011B)+0x11\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x600011B)+0xA\nfunction @ token(0x600011C)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x600011C)+0xC\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x600011C)+0x5\n\nreference cryptocurrency strings\nnamespace   impact/cryptocurrency                                               \nauthor      moritz.raabe@mandiant.com                                           \nscope       file                                                                \natt&ck      Impact::Resource Hijacking [T1496]                                  \nreferences  https://github.com/ctxis/CAPE/blob/master/modules/signatures/crypto…\nor:\n  string: \"Bitcoin\" @ file+0x6F729F\n  string: \"Ethereum\" @ file+0x6F7003\n  string: \"Dash\" @ file+0x6F7295\n  string: \"Monero\" @ file+0x6F72AF\n  string: \"Zcash\" @ file+0x6F6F19\n\n(internal) .NET file limitation\nnamespace    internal/limitation/dynamic                        \nauthor       @v1bh475u                                          \nscope        file                                               \ndescription  This dynamic analysis trace describes a .NET file. \n                                                                \n             capa rules are not yet tuned for the .NET runtime, \n             so its analysis may be incomplete or misleading.   \n                                                                \nor:\n  format: dotnet\n\nlink function at runtime on Windows (3 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ token(0x6000199)+0x34\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ token(0x6000199)+0x34\ninstruction @ token(0x6000199)+0x43\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ token(0x6000199)+0x43\ninstruction @ token(0x6000199)+0x53\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ token(0x6000199)+0x53\n\nload .NET assembly (2 matches)\nnamespace  load-code/dotnet                                \nauthor     anushka.virgaonkar@mandiant.com                 \nscope      function                                        \natt&ck     Defense Evasion::Reflective Code Loading [T1620]\nfunction @ token(0x600033E)\n  or:\n    api: System.Reflection.Assembly::Load @ token(0x600033E)+0x78, token(0x600033E)+0x8F\nfunction @ token(0x600033F)\n  or:\n    api: System.Reflection.Assembly::Load @ token(0x600033F)+0xA3\n\npersist via Run registry key\nnamespace  persistence/registry/run                                             \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com                      \nscope      function                                                             \natt&ck     Persistence::Boot or Logon Autostart Execution::Registry Run Keys /  \n           Startup Folder [T1547.001]                                           \nmbc        Persistence::Registry Run Keys / Startup Folder [F0012]              \nfunction @ token(0x60000B9)\n  and:\n    or:\n      match: set registry value @ token(0x60000B9)\n        or:\n          and:\n            optional:\n              match: create or open registry key @ token(0x60000B9)\n                or:\n                  api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000B9)+0x8D\n            or:\n              api: Microsoft.Win32.RegistryKey::SetValue @ token(0x60000B9)+0xC8\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\" @ token(0x60000B9)+0x87\n\nunmanaged call (14 matches)\nnamespace    runtime                                                       \nauthor       michael.hunhoff@mandiant.com                                  \nscope        function                                                      \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nfunction @ token(0x600006E)\n  or:\n    characteristic: unmanaged call @ token(0x600006E)+0x0, token(0x600006E)+0x7\nfunction @ token(0x6000084)\n  or:\n    characteristic: unmanaged call @ token(0x6000084)+0xF, token(0x6000084)+0x15\nfunction @ token(0x6000085)\n  or:\n    characteristic: unmanaged call @ token(0x6000085)+0x2B, token(0x6000085)+0x3F, token(0x6000085)+0x51, \ntoken(0x6000085)+0x94\nfunction @ token(0x6000086)\n  or:\n    characteristic: unmanaged call @ token(0x6000086)+0x12, token(0x6000086)+0x1B, token(0x6000086)+0x21, \ntoken(0x6000086)+0x28, and 2 more...\nfunction @ token(0x60000A6)\n  or:\n    characteristic: unmanaged call @ token(0x60000A6)+0xB\nfunction @ token(0x60000FE)\n  or:\n    characteristic: unmanaged call @ token(0x60000FE)+0x4E, token(0x60000FE)+0x64, token(0x60000FE)+0x76, \ntoken(0x60000FE)+0x92, and 2 more...\nfunction @ token(0x600010D)\n  or:\n    characteristic: unmanaged call @ token(0x600010D)+0x0\nfunction @ token(0x6000199)\n  or:\n    characteristic: unmanaged call @ token(0x6000199)+0xB, token(0x6000199)+0x20, token(0x6000199)+0x34, \ntoken(0x6000199)+0x43, and 1 more...\n    api: System.Runtime.InteropServices.Marshal::GetDelegateForFunctionPointer @ token(0x6000199)+0x63, token(0x6000199)+0x7D, token(0x6000199)+0x97\nfunction @ token(0x600019A)\n  or:\n    characteristic: unmanaged call @ token(0x600019A)+0x10, token(0x600019A)+0x1B\nfunction @ token(0x600021A)\n  or:\n    characteristic: unmanaged call @ token(0x600021A)+0x4E, token(0x600021A)+0x8E, token(0x600021A)+0xCC, \ntoken(0x600021A)+0xD9\nfunction @ token(0x600021C)\n  or:\n    characteristic: unmanaged call @ token(0x600021C)+0x5, token(0x600021C)+0x3B\nfunction @ token(0x600021D)\n  or:\n    characteristic: unmanaged call @ token(0x600021D)+0x59\nfunction @ token(0x600021E)\n  or:\n    characteristic: unmanaged call @ token(0x600021E)+0x9, token(0x600021E)+0x38\nfunction @ token(0x6000239)\n  or:\n    characteristic: unmanaged call @ token(0x6000239)+0xDD\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  format: dotnet\n\n\n\n"},"hashes":{"md5":"5123d3cc830d4acd49dafb1ba472a90e","sha1":"4bc13337342c06f7b156904544be65bc74e5a0b9","sha256":"93759d6cfbfdd0d5018f197461a25ac2361bc57c6d8eea5e3ee044bb146f071a"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 784</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 110924</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"93759d6\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"5123d3cc830d4acd49dafb1ba472a90e\",\n        \"sha256\": \"93759d6cfbfdd0d5018f197461a25ac2361bc57c6d8eea5e3ee044b\",\n        \"arch\": \"amd64\",\n        \"os\": \"any\",\n        \"format\": \"dotnet\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__7_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (7 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_Microsoft\",\n      \"label\": \"Microsoft\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_self_delete__2_matches_\",\n      \"label\": \"self delete (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_System\",\n      \"label\": \"System\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_for_sandbox_username_or_hostname__2_matches_\",\n      \"label\": \"check for sandbox username or hostname (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author________re_fox__echernofsky_google_com\",\n      \"label\": \"author      @_re_fox, echernofsky@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings\",\n      \"label\": \"reference anti-VM strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_vmware\",\n      \"label\": \"reference anti-VM strings targeting VMWare\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com___johnk3r\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, @johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_virtualbox\",\n      \"label\": \"reference anti-VM strings targeting VirtualBox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_save_image_in__net__2_matches_\",\n      \"label\": \"save image in .NET (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_reference_sql_statements\",\n      \"label\": \"reference SQL statements\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_wmi_statements__5_matches_\",\n      \"label\": \"reference WMI statements (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes\",\n      \"label\": \"log keystrokes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_MapVirtualKey\",\n      \"label\": \"MapVirtualKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_application_hook\",\n      \"label\": \"log keystrokes via application hook\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Application Hook [F0002.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_SetWindowsHookEx\",\n      \"label\": \"SetWindowsHookEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"label\": \"log keystrokes via polling (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetKeyboardState\",\n      \"label\": \"GetKeyboardState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetKeyState\",\n      \"label\": \"GetKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_capture_screenshot\",\n      \"label\": \"capture screenshot\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"cap_capture_webcam_image\",\n      \"label\": \"capture webcam image\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Video Capture [T1125]\"\n      ]\n    },\n    {\n      \"id\": \"api_capCreateCaptureWindow\",\n      \"label\": \"capCreateCaptureWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SendMessage\",\n      \"label\": \"SendMessage\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____johnk3r\",\n      \"label\": \"author     johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Video Capture [T1125]\"\n      ]\n    },\n    {\n      \"id\": \"cap_manipulate_network_credentials_in__net__3_matches_\",\n      \"label\": \"manipulate network credentials in .NET (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_decode_data_using_base64_in__net__7_matches_\",\n      \"label\": \"decode data using Base64 in .NET (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decode Data::Base64 [C0053.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_or_decrypt_data_via_bcrypt\",\n      \"label\": \"encrypt or decrypt data via BCrypt\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Decrypt Data [C0031]\",\n        \"Cryptography::Encrypt Data\",\n        \"[C0027]\"\n      ]\n    },\n    {\n      \"id\": \"api_BCryptCloseAlgorithmProvider\",\n      \"label\": \"BCryptCloseAlgorithmProvider\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_BCryptDecrypt\",\n      \"label\": \"BCryptDecrypt\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_BCryptDestroyKey\",\n      \"label\": \"BCryptDestroyKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_dpapi__5_matches_\",\n      \"label\": \"encrypt data using DPAPI (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data [C0027]\"\n      ]\n    },\n    {\n      \"id\": \"api_CryptUnprotectData\",\n      \"label\": \"CryptUnprotectData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data [C0027]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_with_md5\",\n      \"label\": \"hash data with MD5\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash::MD5 [C0029.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash::MD5 [C0029.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_serialize_json_in__net\",\n      \"label\": \"serialize JSON in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_use__net_library_newtonsoft_json\",\n      \"label\": \"use .NET library Newtonsoft.Json\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______johnk3r\",\n      \"label\": \"author      @johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_in__net\",\n      \"label\": \"generate random numbers in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_data_using_regex_in__net__15_matches_\",\n      \"label\": \"find data using regex in .NET (15 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_load_xml_in__net__3_matches_\",\n      \"label\": \"load XML in .NET (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_access__net_resource__2_matches_\",\n      \"label\": \"access .NET resource (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz\",\n      \"label\": \"author     @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_embed_dependencies_as_resources_using_fody_costura\",\n      \"label\": \"embed dependencies as resources using Fody/Costura\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______johnk3r___mr_tz\",\n      \"label\": \"author      @johnk3r, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_clear_clipboard_data\",\n      \"label\": \"clear clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_clipboard_data\",\n      \"label\": \"read clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_manipulate_console_buffer__8_matches_\",\n      \"label\": \"manipulate console buffer (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Console [C0033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Console [C0033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable\",\n      \"label\": \"query environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_drives\",\n      \"label\": \"enumerate drives\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_generate_random_filename_in__net__7_matches_\",\n      \"label\": \"generate random filename in .NET (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__8_matches_\",\n      \"label\": \"get common file path (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_current_directory\",\n      \"label\": \"set current directory\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_copy_file__23_matches_\",\n      \"label\": \"copy file (23 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory__30_matches_\",\n      \"label\": \"create directory (30 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_directory\",\n      \"label\": \"delete directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_file__17_matches_\",\n      \"label\": \"delete file (17 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_directory_exists__46_matches_\",\n      \"label\": \"check if directory exists (46 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__37_matches_\",\n      \"label\": \"check if file exists (37 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_in__net__24_matches_\",\n      \"label\": \"enumerate files in .NET (24 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes__6_matches_\",\n      \"label\": \"get file attributes (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size__8_matches_\",\n      \"label\": \"get file size (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_file_attributes__5_matches_\",\n      \"label\": \"set file attributes (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__16_matches_\",\n      \"label\": \"read file on Windows (16 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__35_matches_\",\n      \"label\": \"write file on Windows (35 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_application_hook\",\n      \"label\": \"set application hook\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_cpu_information\",\n      \"label\": \"get CPU information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_keyboard_layout\",\n      \"label\": \"get keyboard layout\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery::System Language Discovery\",\n        \"[T1614.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetKeyboardLayout\",\n      \"label\": \"GetKeyboardLayout\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_information\",\n      \"label\": \"get disk information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_allocate_unmanaged_memory_in__net__4_matches_\",\n      \"label\": \"allocate unmanaged memory in .NET (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_manipulate_unmanaged_memory_in__net__8_matches_\",\n      \"label\": \"manipulate unmanaged memory in .NET (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_or_open_mutex_on_windows\",\n      \"label\": \"create or open mutex on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_mehunhoff_google_com\",\n      \"label\": \"mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_networking_interfaces\",\n      \"label\": \"get networking interfaces\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Network Configuration Discovery [T1016]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_hostname__2_matches_\",\n      \"label\": \"get hostname (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_os_version_in__net\",\n      \"label\": \"get OS version in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_process_image_filename\",\n      \"label\": \"get process image filename\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_a_process_with_modified_i_o_handles_and_window__3_matches_\",\n      \"label\": \"create a process with modified I/O handles and window (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__3_matches_\",\n      \"label\": \"create process on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_processes__4_matches_\",\n      \"label\": \"enumerate processes (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\",\n        \"Discovery::Software Discovery\",\n        \"[T1518]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_process_by_pid\",\n      \"label\": \"find process by PID\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_process_by_name\",\n      \"label\": \"find process by name\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process__3_matches_\",\n      \"label\": \"terminate process (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key__9_matches_\",\n      \"label\": \"query or enumerate registry key (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__8_matches_\",\n      \"label\": \"query or enumerate registry value (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_registry_value\",\n      \"label\": \"set registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_session_user_name__4_matches_\",\n      \"label\": \"get session user name (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\",\n        \"Discovery::Account\",\n        \"Discovery [T1087]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_thread__2_matches_\",\n      \"label\": \"create thread (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_suspend_thread__5_matches_\",\n      \"label\": \"suspend thread (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Suspend Thread [C0055]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Suspend Thread [C0055]\"\n      ]\n    },\n    {\n      \"id\": \"cap_access_wmi_data_in__net__9_matches_\",\n      \"label\": \"access WMI data in .NET (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Windows Management Instrumentation [T1047]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_cryptocurrency_strings\",\n      \"label\": \"reference cryptocurrency strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Resource Hijacking [T1496]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal___net_file_limitation\",\n      \"label\": \"(internal) .NET file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author________v1bh475u\",\n      \"label\": \"author       @v1bh475u\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__3_matches_\",\n      \"label\": \"link function at runtime on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_load__net_assembly__2_matches_\",\n      \"label\": \"load .NET assembly (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_persist_via_run_registry_key\",\n      \"label\": \"persist via Run registry key\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Registry Run Keys / Startup Folder [F0012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_unmanaged_call__14_matches_\",\n      \"label\": \"unmanaged call (14 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"label\": \"author       michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compiled_to_the__net_platform\",\n      \"label\": \"compiled to the .NET platform\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__7_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_self_delete__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_sandbox_username_or_hostname__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________re_fox__echernofsky_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_vmware\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com___johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_virtualbox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_save_image_in__net__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_sql_statements\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_wmi_statements__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_application_hook\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_capture_screenshot\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_capture_webcam_image\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_manipulate_network_credentials_in__net__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decode_data_using_base64_in__net__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_or_decrypt_data_via_bcrypt\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_dpapi__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_md5\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_serialize_json_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_use__net_library_newtonsoft_json\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_data_using_regex_in__net__15_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_load_xml_in__net__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access__net_resource__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_embed_dependencies_as_resources_using_fody_costura\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______johnk3r___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_clear_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_manipulate_console_buffer__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_drives\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_filename_in__net__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_current_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file__23_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory__30_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__17_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_directory_exists__46_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__37_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_in__net__24_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__16_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__35_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_application_hook\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_cpu_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_keyboard_layout\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_unmanaged_memory_in__net__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_manipulate_unmanaged_memory_in__net__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_mutex_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_networking_interfaces\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_process_image_filename\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_a_process_with_modified_i_o_handles_and_window__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_processes__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_process_by_pid\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_process_by_name\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_user_name__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_suspend_thread__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_wmi_data_in__net__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_cryptocurrency_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal___net_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________v1bh475u\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_load__net_assembly__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_persist_via_run_registry_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_unmanaged_call__14_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_to_the__net_platform\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-17 20:01:52.070287\",\n    \"total_functions\": \"784\",\n    \"total_features\": \"110924\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-17 20:01:53"}
{"_id":{"$oid":"6a5a412db3bed57e0e73786f"},"sha256":"54c8c1fa5c44506bb1feb7c8657ef6b761b0e1d1e4a8dbe2b52eea5a89296562","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_frc1i_2u/54c8c1fa5c44506bb1feb7c8657ef6b761b0e1d1e4a8dbe2b52eea5a89296562-019f7057928a7bc29354572b9a052788.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_frc1i_2u/54c8c1fa5c44506bb1feb7c8657ef6b761b0e1d1e4a8dbe2b52eea5a89296562-019f7057928a7bc29354572b9a052788.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_frc1i_2u/54c8c1fa5c44506bb1feb7c8657ef6b761b0e1d1e4a8dbe2b52eea5a89296562-019f7057928a7bc29354572b9a052788.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ dbdc539ce2276d056e3da79e5b556cba                                  │\n│ sha1     │ be359a25b1ed3d17fb2aad16d8d6c81fcda6a319                          │\n│ sha256   │ 54c8c1fa5c44506bb1feb7c8657ef6b761b0e1d1e4a8dbe2b52eea5a89296562  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ amd64                                                             │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/54c8c1fa5c44506b… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic             ┃ ATT&CK Technique                                 ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION           │ Obfuscated Files or Information [T1027]          │\n│ EXECUTION                 │ Shared Modules [T1129]                           │\n└───────────────────────────┴──────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ CRYPTOGRAPHY         │ Encrypt Data::AES [C0027.001]                         │\n│                      │ Encrypt Data::RC4 [C0027.009]                         │\n│                      │ Generate Pseudo-random Sequence::RC4 PRGA [C0021.004] │\n│ DATA                 │ Check String [C0019]                                  │\n│                      │ Encode Data::Base64 [C0026.001]                       │\n│                      │ Encode Data::XOR [C0026.002]                          │\n│                      │ Non-Cryptographic Hash::FNV [C0030.005]               │\n│                      │ Non-Cryptographic Hash::MurmurHash [C0030.001]        │\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Encoding-Standard    │\n│                      │ Algorithm [E1027.m02]                                 │\n│                      │ Obfuscated Files or Information::Encryption-Standard  │\n│                      │ Algorithm [E1027.m05]                                 │\n│ DISCOVERY            │ Analysis Tool Discovery::Process detection            │\n│                      │ [B0013.001]                                           │\n│                      │ Code Discovery::Enumerate PE Sections [B0046.001]     │\n│ PROCESS              │ Allocate Thread Local Storage [C0040]                 │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ reference analysis tools strings      │ anti-analysis                        │\n│ compiled with Go                      │ compiler/go                          │\n│ encode data using Base64 (3 matches)  │ data-manipulation/encoding/base64    │\n│ reference Base64 string               │ data-manipulation/encoding/base64    │\n│ encode data using XOR                 │ data-manipulation/encoding/xor       │\n│ encrypt data using AES via x86        │ data-manipulation/encryption/aes     │\n│ extensions (4 matches)                │                                      │\n│ encrypt data using RC4 PRGA           │ data-manipulation/encryption/rc4     │\n│ encrypt data using Salsa20 or ChaCha  │ data-manipulation/encryption/salsa20 │\n│ hash data using fnv (21 matches)      │ data-manipulation/hashing/fnv        │\n│ hash data using murmur3 (5 matches)   │ data-manipulation/hashing/murmur     │\n│ allocate thread local storage         │ host-interaction/thread/tls          │\n│ get kernel32 base address (5 matches) │ linking/runtime-linking              │\n│ enumerate PE sections                 │ load-code/pe                         │\n│ parse PE header                       │ load-code/pe                         │\n│ resolve function by parsing PE        │ load-code/pe                         │\n│ exports (4 matches)                   │                                      │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     dbdc539ce2276d056e3da79e5b556cba                        \nsha1                    be359a25b1ed3d17fb2aad16d8d6c81fcda6a319                \nsha256                  54c8c1fa5c44506bb1feb7c8657ef6b761b0e1d1e4a8dbe2b52eea5…\npath                    /home/apogean/projects/malware/windows/all_runs/54c8c1f…\ntimestamp               2026-07-17 20:18:30.339535                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x140000000                                             \nrules                   /tmp/_MEI0qxNcK/rules                                   \nfunction count          2457                                                    \nlibrary function count  6                                                       \ntotal feature count     193432                                                  \n\nreference analysis tools strings\nnamespace  anti-analysis\nscope      file         \n\ncompiled with Go\nnamespace  compiler/go\nscope      file       \n\nencode data using Base64 (3 matches)\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    0x14004D480                      \n           0x1400891A0                      \n           0x14008E9A0                      \n\nreference Base64 string\nnamespace  data-manipulation/encoding/base64\nscope      file                             \n\nencode data using XOR\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x14000A90D                   \n\nencrypt data using AES via x86 extensions (4 matches)\nnamespace  data-manipulation/encryption/aes\nscope      function                        \nmatches    0x140074160                     \n           0x140074180                     \n           0x1400741A0                     \n           0x1400741E0                     \n\nencrypt data using RC4 PRGA\nnamespace  data-manipulation/encryption/rc4\nscope      function                        \nmatches    0x140058600                     \n\nencrypt data using Salsa20 or ChaCha\nnamespace  data-manipulation/encryption/salsa20\nscope      function                            \nmatches    0x14000A820                         \n\nhash data using fnv (21 matches)\nnamespace    data-manipulation/hashing/fnv                                      \ndescription  can be any Fowler-Noll-Vo (FNV) hash variant, including FNV-1,     \n             FNV-1a, FNV-0                                                      \nscope        function                                                           \nmatches      0x140096380                                                        \n             0x14009B480                                                        \n             0x14009B4DF                                                        \n             0x14009B4FD                                                        \n             0x14009B517                                                        \n             0x14009B537                                                        \n             0x14009B557                                                        \n             0x14009B577                                                        \n             0x14009B595                                                        \n             0x14009B5B7                                                        \n             0x14009B5D8                                                        \n             0x14009B5F3                                                        \n             0x14009B613                                                        \n             0x14009B637                                                        \n             0x14009B653                                                        \n             0x14009B673                                                        \n             0x14009B693                                                        \n             0x14009B6B7                                                        \n             0x14009B6D7                                                        \n             0x14009B705                                                        \n             0x14009BD20                                                        \n\nhash data using murmur3 (5 matches)\nnamespace  data-manipulation/hashing/murmur\nscope      function                        \nmatches    0x140024540                     \n           0x140024D20                     \n           0x14002D2A0                     \n           0x14002D980                     \n           0x140036600                     \n\nallocate thread local storage\nnamespace  host-interaction/thread/tls\nscope      function                   \nmatches    0x140075FC0                \n\naccess PEB ldr_data (22 matches)\nnamespace  linking/runtime-linking\nscope      basic block            \nmatches    0x140012DEB            \n           0x14001A0AA            \n           0x14001A26A            \n           0x14001C65C            \n           0x140027325            \n           0x14003482E            \n           0x140034F0C            \n           0x1400373C0            \n           0x140039433            \n           0x140039E20            \n           0x14004A625            \n           0x140051C89            \n           0x14006587B            \n           0x14006D67D            \n           0x14007114A            \n           0x1400758A0            \n           0x1400758A0            \n           0x1400758A0            \n           0x1400758A0            \n           0x140075B60            \n           0x1400817EA            \n           0x1400856B8            \n\nget kernel32 base address (5 matches)\nnamespace  linking/runtime-linking\nscope      basic block            \nmatches    0x1400758A0            \n           0x1400758A0            \n           0x1400758A0            \n           0x1400758A0            \n           0x140075B60            \n\nenumerate PE sections\nnamespace  load-code/pe\nscope      function    \nmatches    0x14006F0E0 \n\nparse PE header\nnamespace  load-code/pe\nscope      function    \nmatches    0x1400ED6C0 \n\nresolve function by parsing PE exports (4 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x14005E900 \n           0x1400CF320 \n           0x1400D75A0 \n           0x1400ED6C0 \n\n\n\n","very_verbose":"md5                     dbdc539ce2276d056e3da79e5b556cba                        \nsha1                    be359a25b1ed3d17fb2aad16d8d6c81fcda6a319                \nsha256                  54c8c1fa5c44506bb1feb7c8657ef6b761b0e1d1e4a8dbe2b52eea5…\npath                    /home/apogean/projects/malware/windows/all_runs/54c8c1f…\ntimestamp               2026-07-17 20:20:16.268124                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x140000000                                             \nrules                   /tmp/_MEII2HH50/rules                                   \nfunction count          2457                                                    \nlibrary function count  6                                                       \ntotal feature count     193432                                                  \n\nPEB access (46 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Debugger Detection::Process Environment   \n            Block [B0001.019]                                                   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nbasic block @ 0x14000D0A6 in function 0x14000CF80\n  or:\n    and:\n      arch: amd64\n      characteristic: gs access @ 0x14000D0B6\n      or:\n        offset: 0x60 @ 0x14000D0D2\n\ncontain loop (990 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x140001240\n  or:\n    characteristic: loop @ 0x140001240\n\nget OS version (library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x140070720\n  or:\n    and:\n      match: PEB access @ 0x140070D2E, 0x140070FD4\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x14007103E\n            or:\n              offset: 0x60 @ 0x140070FD4\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x140070DF4\n            or:\n              offset: 0x60 @ 0x140070D56, 0x140070D94\n      or:\n        and:\n          arch: amd64\n          or:\n            offset: 0x118 = PEB->OSMajorVersion @ 0x140070B78, 0x140070BA0\n            offset: 0x120 = PEB->OSBuildNumber @ 0x140070B88\n\nreference analysis tools strings\nnamespace   anti-analysis                                                       \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \nmbc         Discovery::Analysis Tool Discovery::Process detection [B0013.001]   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /procexp(\\.exe)?/i\n    - \"internal/syscall/windows/registry.procExpandEnvironmentStringsW\" @ file+0x29035F\n\ncompiled with Go\nnamespace  compiler/go                 \nauthor     michael.hunhoff@mandiant.com\nscope      file                        \nor:\n  regex: /\\bgo1\\.\\d/\n    - \"go1.25.4\" @ file+0x176C60, file+0x254A21\n  substring: runtime.main\n    - \"pacer: assist ratio=workbuf is not emptybad use of bucket.mpbad use of \nbucket.bpruntime: double waitpreempt off reason: forcegc: phase errorgopark: bad\ng statusgo of nil func valuesemaRoot rotateRightreflect.makeFuncStubtrace: out \nof memorywirep: already in \ngoreflect.Value.IsZeroGetAdaptersAddressesNtSetInformationFileRtlIsDosDeviceName\n_UGetProcessMemoryInfobcryptprimitives.dllhttplaxcontentlengthx509usefallbackroo\ntsuabfrnpwkxumtmfcusvuolink has been severedpackage not installedblock device \nrequiredstate not recoverableread-only file systemstale NFS file \nhandleReadDirectoryChangesWNetGetJoinInformationafter top-level valuein string \nescape codeunsupported \noperationreflect.Value.Complex186264514923095703125931322574615478515625Morocco \nStandard TimeNamibia Standard TimeAlaskan Standard TimeCentral Standard \nTimePacific Standard TimeEastern Standard TimeSE Asia Standard TimeArabian \nStandard TimeMagadan Standard TimeMyanmar Standard TimeYakutsk Standard \nTimeBelarus Standard TimeRussian Standard TimeRomance Standard TimeSaratov \nStandard TimeNorfolk Standard Timenegative shift \namountdataindependenttimingsystem goroutine wait/gc/heap/allocs:bytesruntime: \nwork.nwait=  previous allocCount=, levelBits = runtime: searchIdx = profiler \nhash bucketsdefer on system stackpanic on system stackasync stack too \nlargestartm: m is spinningstartlockedm: m has pfindrunnable: wrong ppreempt at \nunknown pcreleasep: invalid argcheckdead: runnable gruntime: newstack at \nruntime: newstack sp=runtime: confused by  pcHeader.textStart= timer data \ncorruption of unexported methodunexpected value stepreflect.Value.Pointerbad \ntype in compare: \nAdjustTokenPrivilegesLookupPrivilegeValueWNetUserGetLocalGroupsGetProfilesDirect\noryWconcurrent map writesargument list too longaddress already in usenetwork is \nunreachablecannot allocate memoryprotocol not availableprotocol not \nsupportedremote address \nchangedConvertSidToStringSidWConvertStringSidToSidWCreateIoCompletionPortGetEnvi\nronmentStringsWGetTimeZoneInformationreflectlite.Value.Type465661287307739257812\n5Sao Tome Standard TimeAleutian Standard TimeParaguay Standard TimeMountain \nStandard TimeAtlantic Standard TimePakistan Standard TimeSakhalin Standard \nTimeGeorgian Standard TimeCaucasus Standard TimeTasmania Standard TimeDateline \nStandard TimeHawaiian Standard Timeinteger divide by zeroCountPagesInUse \n(test)ReadMetricsSlow (test)trace reader (blocked)trace goroutine statusGC weak \nto strong waitchan receive (durable)send on closed channelcall not at safe \npointgetenv before env initinterface conversion: freeIndex is not \nvalids.freeindex > s.nelemsbad sweepgen in refillspan has no free \nspace/gc/scan/globals:bytes/gc/heap/frees:objectsruntime: work.nwait = \nruntime:scanstack: gp=scanstack - bad statusheadTailIndex overflowruntime.main \nnot on m0set_crosscall2 missingbad g->status in readywirep: invalid p \nstateassembly checks failedstack not a power of 2minpc or maxpc \ninvalidcompileCallback: type syscall: n > len(args)non-Go function at \npc=unexpected method \nstepRtlLookupFunctionEntryNtQueryInformationFileCreateEnvironmentBlockWSAGetOver\nlappedResult%SystemRoot%\\\\system32\\\\exit hook invoked exit=== Inventory \nSnapshot:device or resource busyinterrupted system callno space left on \ndeviceoperation not supportedoperation not \npermittedCertGetCertificateChainFreeEnvironmentStringsWGetEnvironmentVariableWGe\ntSystemTimeAsFileTimeSetEnvironmentVariableWunexpected map key type<invalid \nreflect.Value>23283064365386962890625E. Africa Standard TimeTocantins Standard \nTimeArgentina Standard TimeVenezuela Standard TimeGreenland Standard TimeSri \nLanka Standard TimeWest Bank Standard TimeQyzylorda Standard TimeSingapore \nStandard TimeWest Asia Standard TimeGreenwich Standard TimeLord Howe Standard \nTimeAstrakhan Standard TimeW. Europe Standard TimeE. Europe Standard \nTimeVolgograd Standard TimeMauritius Standard TimeMarquesas Standard Time\\\" not \nfound in registryindex out of range [%x]ReadMemStatsSlow (test)chan receive (nil\nchan)garbage collection scanmakechan: bad alignmentclose of closed channelunlock\nof unlocked lock) must be a power of 2\" @ file+0x138C18\n    - \"runtime.main\" @ file+0x1BF522, file+0x281F9B\n    - \"runtime.main.func1\" @ file+0x1C368C, file+0x284C42\n    - \"runtime.main.func2\" @ file+0x1BF553, file+0x281FA8\n    - \"runtime.mainPC\" @ file+0x2918ED\n    - \"runtime.mainStarted\" @ file+0x28EF70\n    - \"runtime.main_init_done\" @ file+0x28EF59\n  substring: main.main\n    - \"main.main\" @ file+0x1CFDCC, file+0x28D857\n  substring: runtime.gcWork\n    - \"*runtime.gcWork\" @ file+0x10CBEB\n    - \"type:.eq.runtime.gcWork\" @ file+0x1C5AAC, file+0x286FD9\n\nencode data using Base64 (3 matches)\nnamespace  data-manipulation/encoding/base64                                    \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::Base64 [C0026.001]         \nfunction @ 0x14004D480\n  or:\n    and:\n      mnemonic: shl @ 0x14004D52B, 0x14004D57A\n      mnemonic: shr @ 0x14004D505, 0x14004D54D, 0x14004D5C2\n      number: 0x3F = modulo 64 @ 0x14004D5D7\n      or:\n        number: 0x3D = '=' @ 0x14004D5C2\n      match: contain loop @ 0x14004D480\n        or:\n          characteristic: loop @ 0x14004D480\n          characteristic: tight loop @ 0x14004D492\nfunction @ 0x1400891A0\n  or:\n    and:\n      mnemonic: shl @ 0x1400891CD, 0x140089209, 0x140089210, 0x14008924E, and 3 more...\n      mnemonic: shr @ 0x140089227, 0x140089258, 0x14008932E, 0x14008960B, and 2 more...\n      number: 0x3F = modulo 64 @ 0x1400894A1, 0x14008955B, 0x140089647\n      or:\n        number: 0x3D = '=' @ 0x140089251\n      match: contain loop @ 0x1400891A0\n        or:\n          characteristic: loop @ 0x1400891A0\n      optional:\n        number: 0x2 @ 0x140089209, 0x14008948A, 0x1400894CF\n        number: 0x3 @ 0x1400892E2, 0x1400892EE, 0x1400894A8, 0x140089516, and 5 more...\n        number: 0x4 @ 0x14008933F, 0x1400895E5, 0x140089695, 0x1400896F4, and 1 more...\n        number: 0x6 @ 0x1400895C0, 0x1400895FC\n        number: 0xF @ 0x140089200, 0x140089713, 0x140089789\nfunction @ 0x14008E9A0\n  or:\n    and:\n      mnemonic: shl @ 0x14008EC0F, 0x14008ECF2, 0x14008EE06\n      mnemonic: shr @ 0x14008EFA2, 0x14008F059, 0x14008F0D0, 0x14008F16B\n      number: 0x3F = modulo 64 @ 0x14008EA80, 0x14008EAA0, 0x14008EC13, 0x14008ECF6, and 3 more...\n      or:\n        number: 0x3D = '=' @ 0x14008EFA2, 0x14008F059\n      match: contain loop @ 0x14008E9A0\n        or:\n          characteristic: loop @ 0x14008E9A0\n      optional:\n        number: 0x2 @ 0x14008EFB0, 0x14008EFDE, 0x14008F067, 0x14008F09A\n        number: 0x3 @ 0x14008ECF2, 0x14008EF8B, 0x14008EFAC, 0x14008F042, and 3 more...\n        number: 0x4 @ 0x14008EC0F, 0x14008EE06\n\nreference Base64 string\nnamespace  data-manipulation/encoding/base64                                \nauthor     moritz.raabe@mandiant.com                                        \nscope      file                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]         \nmbc        Data::Encode Data::Base64 [C0026.001], Data::Check String [C0019]\nregex: /ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/\n  - \"runtime.SetFinalizer: first argument was allocated into an \narenacompileCallback: expected function with one uintptr-sized resultattempted \nto trace stack of a goroutine this thread does not \nownABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/ABCDEFGHIJKLM\nNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_user arena chunk size is not \na multiple of the physical page sizeruntime: function marked with #cgo \nnocallback called back into Goruntime.SetFinalizer: pointer not at beginning of \nallocated blockcasGToWaitingForSuspendG with non-isWaitingForSuspendG wait \nreasonreflect: reflect.Value.UnsafePointer on an invalid notinheap pointerAfter \nthe assault %d enemies remain and total incoming damage was %d\" @ file+0x141598\n\nencode data using XOR\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x14000A90D in function 0x14000A820\n  and:\n    characteristic: tight loop @ 0x14000A90D\n    characteristic: nzxor @ 0x14000A911, 0x14000A927, 0x14000A931, 0x14000A946, and 60 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nencrypt data using AES via x86 extensions (4 matches)\nnamespace  data-manipulation/encryption/aes                                     \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encryption-Standard\n           Algorithm [E1027.m05], Cryptography::Encrypt Data::AES [C0027.001]   \nfunction @ 0x140074160\n  or:\n    mnemonic: aesenc = Perform One Round of an AES Encryption Flow @ 0x14007139B, 0x1400713F9, 0x1400713FE, 0x140071403, and 101 more...\nfunction @ 0x140074180\n  or:\n    mnemonic: aesenc = Perform One Round of an AES Encryption Flow @ 0x14007139B, 0x1400713F9, 0x1400713FE, 0x140071403, and 101 more...\nfunction @ 0x1400741A0\n  or:\n    mnemonic: aesenc = Perform One Round of an AES Encryption Flow @ 0x1400741B4, 0x1400741BD, 0x1400741C6\nfunction @ 0x1400741E0\n  or:\n    mnemonic: aesenc = Perform One Round of an AES Encryption Flow @ 0x1400741F5, 0x1400741FE, 0x140074207\n\nencrypt data using RC4 PRGA\nnamespace  data-manipulation/encryption/rc4                                     \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Encrypt Data::RC4 [C0027.009], Cryptography::Generate  \n           Pseudo-random Sequence::RC4 PRGA [C0021.004]                         \nfunction @ 0x140058600\n  and:\n    match: contain loop @ 0x140058600\n      or:\n        characteristic: loop @ 0x140058600\n    count(characteristic(nzxor)): 1 @ 0x140058658\n    count(characteristic(calls from)): 4 or fewer @ 0x140074640, 0x140074700\n    count(basic block): between 4 and 50 @ 0x140058600, 0x140058616, 0x14005861D, 0x140058625, and 24 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x140058616, 0x140058689, 0x1400586E5, 0x14005873C\n\nencrypt data using Salsa20 or ChaCha\nnamespace   data-manipulation/encryption/salsa20                    \nauthor      moritz.raabe@mandiant.com                               \nscope       function                                                \natt&ck      Defense Evasion::Obfuscated Files or Information [T1027]\nreferences  http://cr.yp.to/snuffle/ecrypt.c                        \nfunction @ 0x14000A820\n  or: = part of key setup\n    and:\n      number: 0x61707865 = \"apxe\" @ 0x14000A828\n      number: 0x3320646E = \"3 dn\" @ 0x14000A837\n      number: 0x79622D32 = \"yb-2\" @ 0x14000A846\n      number: 0x6B206574 = \"k et\" @ 0x14000A855\n\nhash data using fnv (21 matches)\nnamespace    data-manipulation/hashing/fnv                                      \nauthor       moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com  \nscope        function                                                           \nmbc          Data::Non-Cryptographic Hash::FNV [C0030.005]                      \nreferences   https://en.wikipedia.org/wiki/Fowler%E2%80%93Noll%E2%80%93Vo_hash_…\n             http://isthe.com/chongo/tech/comp/fnv/,                            \n             https://create.stephan-brumme.com/fnv-hash/                        \ndescription  can be any Fowler-Noll-Vo (FNV) hash variant, including FNV-1,     \n             FNV-1a, FNV-0                                                      \nfunction @ 0x140096380\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009652D\n        or:\n          mnemonic: imul @ 0x140096527\n    or:\n      number: 0x1000193 = FNV prime @ 0x140096527\n    optional:\n      characteristic: loop @ 0x140096380\nfunction @ 0x14009B480\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B\n    optional:\n      characteristic: loop @ 0x14009B480\n      number: 0xCBF29CE484222325 = FNV_offset_basis, unused by FNV-0 @ 0x14009B497\nfunction @ 0x14009B4DF\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009BB70\n        or:\n          mnemonic: imul @ 0x14009BB7D\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B, 0x14009BB56, 0x14009BB73\n    optional:\n      characteristic: loop @ 0x14009B4DF\nfunction @ 0x14009B4FD\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009BB0D\n        or:\n          mnemonic: imul @ 0x14009BB1A\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B, 0x14009BB10, 0x14009BB2B\n    optional:\n      characteristic: loop @ 0x14009B4FD\nfunction @ 0x14009B517\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n      and:\n        characteristic: nzxor @ 0x14009BAE9\n        or:\n          mnemonic: imul @ 0x14009BAF6\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B, 0x14009BACE, 0x14009BAEC\n    optional:\n      characteristic: loop @ 0x14009B517\nfunction @ 0x14009B537\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009BA9D\n        or:\n          mnemonic: imul @ 0x14009BAAA\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B, 0x14009BA83, 0x14009BAA0\n    optional:\n      characteristic: loop @ 0x14009B537\nfunction @ 0x14009B557\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n      and:\n        characteristic: nzxor @ 0x14009BA52\n        or:\n          mnemonic: imul @ 0x14009BA5F\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B, 0x14009BA38, 0x14009BA55\n    optional:\n      characteristic: loop @ 0x14009B557\nfunction @ 0x14009B577\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n      and:\n        characteristic: nzxor @ 0x14009BA0A\n        or:\n          mnemonic: imul @ 0x14009BA17\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B, 0x14009B9ED, 0x14009BA0D\n    optional:\n      characteristic: loop @ 0x14009B577\nfunction @ 0x14009B595\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n      and:\n        characteristic: nzxor @ 0x14009B9B3\n        or:\n          mnemonic: imul @ 0x14009B9C0\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B, 0x14009B999, 0x14009B9B6\n    optional:\n      characteristic: loop @ 0x14009B595\nfunction @ 0x14009B5B7\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n      and:\n        characteristic: nzxor @ 0x14009B959\n        or:\n          mnemonic: imul @ 0x14009B966\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B, 0x14009B95C, 0x14009B972\n    optional:\n      characteristic: loop @ 0x14009B5B7\nfunction @ 0x14009B5D8\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n      and:\n        characteristic: nzxor @ 0x14009B920\n        or:\n          mnemonic: imul @ 0x14009B92D\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B, 0x14009B923, 0x14009B93E\n    optional:\n      characteristic: loop @ 0x14009B5D8\nfunction @ 0x14009B5F3\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009B8E6\n        or:\n          mnemonic: imul @ 0x14009B8F3\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B, 0x14009B8E9, 0x14009B906\n    optional:\n      characteristic: loop @ 0x14009B5F3\nfunction @ 0x14009B613\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009B8C0\n        or:\n          mnemonic: imul @ 0x14009B8CD\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B, 0x14009B8A6, 0x14009B8C3\n    optional:\n      characteristic: loop @ 0x14009B613\nfunction @ 0x14009B637\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n      and:\n        characteristic: nzxor @ 0x14009B861\n        or:\n          mnemonic: imul @ 0x14009B86E\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B, 0x14009B864, 0x14009B87F\n    optional:\n      characteristic: loop @ 0x14009B637\nfunction @ 0x14009B653\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n      and:\n        characteristic: nzxor @ 0x14009B829\n        or:\n          mnemonic: imul @ 0x14009B836\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B, 0x14009B82C, 0x14009B847\n    optional:\n      characteristic: loop @ 0x14009B653\nfunction @ 0x14009B673\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n      and:\n        characteristic: nzxor @ 0x14009B7F1\n        or:\n          mnemonic: imul @ 0x14009B7FE\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B, 0x14009B7F4, 0x14009B80E\n    optional:\n      characteristic: loop @ 0x14009B673\nfunction @ 0x14009B693\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009B7BD\n        or:\n          mnemonic: imul @ 0x14009B7CB\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B, 0x14009B7C1, 0x14009B7D7\n    optional:\n      characteristic: loop @ 0x14009B693\nfunction @ 0x14009B6B7\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B77E, 0x14009B79B\n    optional:\n      characteristic: loop @ 0x14009B6B7\nfunction @ 0x14009B6D7\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n      and:\n        characteristic: nzxor @ 0x14009B6E9\n        or:\n          mnemonic: imul @ 0x14009B6F7\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B6ED, 0x14009B77E, 0x14009B79B\n    optional:\n      characteristic: loop @ 0x14009B6D7\nfunction @ 0x14009B705\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009B798\n        or:\n          mnemonic: imul @ 0x14009B7A5\n      and:\n        characteristic: nzxor @ 0x14009B73B\n        or:\n          mnemonic: imul @ 0x14009B748\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009B718, 0x14009B73E, 0x14009B77E, 0x14009B79B\n    optional:\n      characteristic: loop @ 0x14009B705\nfunction @ 0x14009BD20\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14009BD7F\n        or:\n          mnemonic: imul @ 0x14009BD8C\n    or:\n      number: 0x100000001B3 = FNV prime @ 0x14009BD82\n    optional:\n      characteristic: loop @ 0x14009BD20\n      number: 0xCBF29CE484222325 = FNV_offset_basis, unused by FNV-0 @ 0x14009BD51\n\nhash data using murmur3 (5 matches)\nnamespace   data-manipulation/hashing/murmur                                    \nauthor      william.ballenthin@mandiant.com                                     \nscope       function                                                            \nmbc         Data::Non-Cryptographic Hash::MurmurHash [C0030.001]                \nreferences  https://github.com/aappleby/smhasher/blob/master/src/MurmurHash3.cpp\nfunction @ 0x140024540\n  or:\n    basic block:\n      and: = hash >> 16; hash >> 13; hash >> 16\n        instruction:\n          and:\n            mnemonic: shr @ 0x14002462B\n            number: 0x10 @ 0x14002462B\n        instruction:\n          and:\n            mnemonic: shr @ 0x14002463C\n            number: 0xD @ 0x14002463C\n        count(mnemonic(shr)): 3 @ 0x140024617, 0x14002462B, 0x14002463C\nfunction @ 0x140024D20\n  or:\n    basic block:\n      and: = hash >> 16; hash >> 13; hash >> 16\n        instruction:\n          and:\n            mnemonic: shr @ 0x140024DBE\n            number: 0x10 @ 0x140024DBE\n        instruction:\n          and:\n            mnemonic: shr @ 0x140024DCD\n            number: 0xD @ 0x140024DCD\n        count(mnemonic(shr)): 3 @ 0x140024DAB, 0x140024DBE, 0x140024DCD\nfunction @ 0x14002D2A0\n  or:\n    basic block:\n      and: = hash >> 16; hash >> 13; hash >> 16\n        instruction:\n          and:\n            mnemonic: shr @ 0x14002D4BD\n            number: 0x10 @ 0x14002D4BD\n        instruction:\n          and:\n            mnemonic: shr @ 0x14002D4CF\n            number: 0xD @ 0x14002D4CF\n        count(mnemonic(shr)): 3 @ 0x14002D4AB, 0x14002D4BD, 0x14002D4CF\nfunction @ 0x14002D980\n  or:\n    basic block:\n      and: = hash >> 16; hash >> 13; hash >> 16\n        instruction:\n          and:\n            mnemonic: shr @ 0x14002DA30\n            number: 0x10 @ 0x14002DA30\n        instruction:\n          and:\n            mnemonic: shr @ 0x14002DA42\n            number: 0xD @ 0x14002DA42\n        count(mnemonic(shr)): 3 @ 0x14002DA1D, 0x14002DA30, 0x14002DA42\nfunction @ 0x140036600\n  or:\n    basic block:\n      and: = hash >> 16; hash >> 13; hash >> 16\n        instruction:\n          and:\n            mnemonic: shr @ 0x14003677A\n            number: 0x10 @ 0x14003677A\n        instruction:\n          and:\n            mnemonic: shr @ 0x14003678B\n            number: 0xD @ 0x14003678B\n        count(mnemonic(shr)): 3 @ 0x140036765, 0x14003677A, 0x14003678B\n\nallocate thread local storage\nnamespace  host-interaction/thread/tls                   \nauthor     michael.hunhoff@mandiant.com                  \nscope      function                                      \nmbc        Process::Allocate Thread Local Storage [C0040]\nfunction @ 0x140075FC0\n  or:\n    api: TlsAlloc @ 0x140075FDB\n\naccess PEB ldr_data (22 matches)\nnamespace   linking/runtime-linking                                             \nauthor      moritz.raabe@mandiant.com                                           \nscope       basic block                                                         \natt&ck      Execution::Shared Modules [T1129]                                   \nreferences  https://www.geoffchappell.com/studies/windows/km/ntoskrnl/inc/api/n…\n            https://github.com/d35ha/CallObfuscator/blob/5834aff9ff4511f1408ae4…\nbasic block @ 0x140012DEB in function 0x140012BA0\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x140012DEB\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x140012E00\n            or:\n              offset: 0x60 @ 0x140012E2C\n      offset: 0x18 = PEB.LDR_DATA @ 0x140012DEB, 0x140012E31\n      or: = resolve a module list\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x140012E0C, 0x140012E1B, 0x140012E40\nbasic block @ 0x14001A0AA in function 0x14001A0A0\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x14001A0AA\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x14001A0EA\n            or:\n              offset: 0x60 @ 0x14001A0B7\n      offset: 0x18 = PEB.LDR_DATA @ 0x14001A0D1\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x14001A0CC\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x14001A0F1\nbasic block @ 0x14001A26A in function 0x14001A260\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x14001A26A\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x14001A2B3\n            or:\n              offset: 0x60 @ 0x14001A272, 0x14001A2BA\n      offset: 0x18 = PEB.LDR_DATA @ 0x14001A291\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x14001A28C\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x14001A29A\nbasic block @ 0x14001C65C in function 0x14001C280\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x14001C65C\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x14001C6B0\n            or:\n              offset: 0x60 @ 0x14001C6C7\n      offset: 0x18 = PEB.LDR_DATA @ 0x14001C66C, 0x14001C683, 0x14001C6D5\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x14001C67E\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x14001C68D\nbasic block @ 0x140027325 in function 0x1400272C0\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x140027325\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x140027372\n            or:\n              offset: 0x60 @ 0x14002734F\n      offset: 0x18 = PEB.LDR_DATA @ 0x14002732C, 0x140027359\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x140027331\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x140027336\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x140027345\nbasic block @ 0x14003482E in function 0x140034800\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x14003482E\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400348A0\n            or:\n              offset: 0x60 @ 0x14003482E, 0x140034847, 0x1400348AC\n      offset: 0x18 = PEB.LDR_DATA @ 0x140034853, 0x140034887\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x14003483E, 0x14003486F, 0x1400348A7, 0x1400348B1\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x14003485D\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x14003486A\nbasic block @ 0x140034F0C in function 0x140034EA0\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x140034F0C\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x140034F70\n            or:\n              offset: 0x60 @ 0x140034F4D\n      offset: 0x18 = PEB.LDR_DATA @ 0x140034F11, 0x140034F2A, 0x140034F57\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x140034F0C\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x140034F2F\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x140034F52\nbasic block @ 0x1400373C0 in function 0x140037280\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400373C0\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x140037418\n            or:\n              offset: 0x60 @ 0x1400373D6, 0x1400373DB\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400373EE\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400373E9\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x1400373F3\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x1400373FF\nbasic block @ 0x140039433 in function 0x140039220\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x140039433\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x14003948A\n            or:\n              offset: 0x60 @ 0x14003944B\n      offset: 0x18 = PEB.LDR_DATA @ 0x140039471\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x14003946C\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x140039491\nbasic block @ 0x140039E20 in function 0x140039E20\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x140039E20\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x140039E38, 0x140039E6A\n            or:\n              offset: 0x60 @ 0x140039E28, 0x140039E76\n      offset: 0x18 = PEB.LDR_DATA @ 0x140039E5A\n      or: = resolve a module list\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x140039E4E\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x140039E3F\nbasic block @ 0x14004A625 in function 0x14004A460\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x14004A625\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x14004A653, 0x14004A690\n            or:\n              offset: 0x60 @ 0x14004A625\n      offset: 0x18 = PEB.LDR_DATA @ 0x14004A66F\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x14004A66A, 0x14004A674\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x14004A630, 0x14004A63A\nbasic block @ 0x140051C89 in function 0x140051BE0\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x140051C89\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x140051CF1\n            or:\n              offset: 0x60 @ 0x140051C95\n      offset: 0x18 = PEB.LDR_DATA @ 0x140051CBB\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x140051CB6\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x140051CC0\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x140051CCA\nbasic block @ 0x14006587B in function 0x140065840\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x14006587B\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400658C8\n            or:\n              offset: 0x60 @ 0x140065896\n      offset: 0x18 = PEB.LDR_DATA @ 0x14006587B, 0x1400658CF\n      or: = resolve a module list\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x140065887, 0x1400658AF\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x14006589B\nbasic block @ 0x14006D67D in function 0x14006D5E0\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x14006D67D\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x14006D6BF\n            or:\n              offset: 0x60 @ 0x14006D697\n      offset: 0x18 = PEB.LDR_DATA @ 0x14006D68D\n      or: = resolve a module list\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x14006D6C6\nbasic block @ 0x14007114A in function 0x140071140\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x14007114A\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400711DD\n            or:\n              offset: 0x60 @ 0x14007118F\n      offset: 0x18 = PEB.LDR_DATA @ 0x14007116B, 0x140071194\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x140071165, 0x14007118A, 0x1400711C4\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x140071199\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x1400711AB\nbasic block @ 0x1400758A0 in function 0x140075B40\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400758A0\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x14007592E\n            or:\n              offset: 0x60 @ 0x1400758DE\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400758BB\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400758B6\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x1400758C0\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x1400758CA\nbasic block @ 0x1400758A0 in function 0x140075B40\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400758A0\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x14007592E\n            or:\n              offset: 0x60 @ 0x1400758DE\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400758BB\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400758B6\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x1400758C0\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x1400758CA\nbasic block @ 0x1400758A0 in function 0x140075B40\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400758A0\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x14007592E\n            or:\n              offset: 0x60 @ 0x1400758DE\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400758BB\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400758B6\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x1400758C0\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x1400758CA\nbasic block @ 0x1400758A0 in function 0x140075B40\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400758A0\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x14007592E\n            or:\n              offset: 0x60 @ 0x1400758DE\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400758BB\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400758B6\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x1400758C0\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x1400758CA\nbasic block @ 0x140075B60 in function 0x140075B60\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x140075B60\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x140075BEB\n            or:\n              offset: 0x60 @ 0x140075BA2\n      offset: 0x18 = PEB.LDR_DATA @ 0x140075B7F\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x140075B7A\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x140075B84\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x140075B8E\nbasic block @ 0x1400817EA in function 0x1400817E0\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400817EA\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x14008181A\n            or:\n              offset: 0x60 @ 0x1400817F7\n      offset: 0x18 = PEB.LDR_DATA @ 0x140081821\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x140081805\nbasic block @ 0x1400856B8 in function 0x140085460\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400856B8\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x140085718\n            or:\n              offset: 0x60 @ 0x1400856B8\n      offset: 0x18 = PEB.LDR_DATA @ 0x140085703\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400856FE\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x14008571F\n\nget kernel32 base address (5 matches)\nnamespace   linking/runtime-linking                                             \nauthor      moritz.raabe@mandiant.com                                           \nscope       basic block                                                         \natt&ck      Execution::Shared Modules [T1129]                                   \nreferences  https://idafchev.github.io/exploit/2017/09/26/writing_windows_shell…\n            https://www.geoffchappell.com/studies/windows/win32/ntdll/structs/l…\nbasic block @ 0x1400758A0 in function 0x140075B40\n  and:\n    match: access PEB ldr_data @ 0x1400758A0\n      or:\n        and: = x64\n          arch: amd64\n          match: PEB access @ 0x1400758A0\n            or:\n              and:\n                arch: amd64\n                characteristic: gs access @ 0x14007592E\n                or:\n                  offset: 0x60 @ 0x1400758DE\n          offset: 0x18 = PEB.LDR_DATA @ 0x1400758BB\n          or: = resolve a module list\n            offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400758B6\n            offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x1400758C0\n            offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x1400758CA\n    count(offset): 2 @ 0x1400758AD, 0x14007592E\n    or:\n      and:\n        arch: amd64\n        offset: 0x30 = LDR_DATA_TABLE_ENTRY.DllBase @ 0x1400758CA\nbasic block @ 0x1400758A0 in function 0x140075B40\n  and:\n    match: access PEB ldr_data @ 0x1400758A0\n      or:\n        and: = x64\n          arch: amd64\n          match: PEB access @ 0x1400758A0\n            or:\n              and:\n                arch: amd64\n                characteristic: gs access @ 0x14007592E\n                or:\n                  offset: 0x60 @ 0x1400758DE\n          offset: 0x18 = PEB.LDR_DATA @ 0x1400758BB\n          or: = resolve a module list\n            offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400758B6\n            offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x1400758C0\n            offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x1400758CA\n    count(offset): 2 @ 0x1400758AD, 0x14007592E\n    or:\n      and:\n        arch: amd64\n        offset: 0x30 = LDR_DATA_TABLE_ENTRY.DllBase @ 0x1400758CA\nbasic block @ 0x1400758A0 in function 0x140075B40\n  and:\n    match: access PEB ldr_data @ 0x1400758A0\n      or:\n        and: = x64\n          arch: amd64\n          match: PEB access @ 0x1400758A0\n            or:\n              and:\n                arch: amd64\n                characteristic: gs access @ 0x14007592E\n                or:\n                  offset: 0x60 @ 0x1400758DE\n          offset: 0x18 = PEB.LDR_DATA @ 0x1400758BB\n          or: = resolve a module list\n            offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400758B6\n            offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x1400758C0\n            offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x1400758CA\n    count(offset): 2 @ 0x1400758AD, 0x14007592E\n    or:\n      and:\n        arch: amd64\n        offset: 0x30 = LDR_DATA_TABLE_ENTRY.DllBase @ 0x1400758CA\nbasic block @ 0x1400758A0 in function 0x140075B40\n  and:\n    match: access PEB ldr_data @ 0x1400758A0\n      or:\n        and: = x64\n          arch: amd64\n          match: PEB access @ 0x1400758A0\n            or:\n              and:\n                arch: amd64\n                characteristic: gs access @ 0x14007592E\n                or:\n                  offset: 0x60 @ 0x1400758DE\n          offset: 0x18 = PEB.LDR_DATA @ 0x1400758BB\n          or: = resolve a module list\n            offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400758B6\n            offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x1400758C0\n            offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x1400758CA\n    count(offset): 2 @ 0x1400758AD, 0x14007592E\n    or:\n      and:\n        arch: amd64\n        offset: 0x30 = LDR_DATA_TABLE_ENTRY.DllBase @ 0x1400758CA\nbasic block @ 0x140075B60 in function 0x140075B60\n  and:\n    match: access PEB ldr_data @ 0x140075B60\n      or:\n        and: = x64\n          arch: amd64\n          match: PEB access @ 0x140075B60\n            or:\n              and:\n                arch: amd64\n                characteristic: gs access @ 0x140075BEB\n                or:\n                  offset: 0x60 @ 0x140075BA2\n          offset: 0x18 = PEB.LDR_DATA @ 0x140075B7F\n          or: = resolve a module list\n            offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x140075B7A\n            offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x140075B84\n            offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x140075B8E\n    count(offset): 2 @ 0x140075B71, 0x140075BEB\n    or:\n      and:\n        arch: amd64\n        offset: 0x30 = LDR_DATA_TABLE_ENTRY.DllBase @ 0x140075B8E\n\nenumerate PE sections\nnamespace   load-code/pe                                                        \nauthor      @Ana06, @mr-tz                                                      \nscope       function                                                            \nmbc         Discovery::Code Discovery::Enumerate PE Sections [B0046.001]        \nreferences  https://0x00sec.org/t/reflective-dll-injection/3080,                \n            https://www.ired.team/offensive-security/code-injection-process-inj…\nfunction @ 0x14006F0E0\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x14006F76D\n        or:\n          mnemonic: movzx @ 0x14006F76D\n    basic block:\n      or:\n        and: = (DWORD)dll_raw + dos_header->e_lfanew + sizeof(IMAGE_NT_HEADERS) + \nsizeof(IMAGE_SECTION_HEADER) * i\n          number: 0x28 = sizeof(IMAGE_SECTION_HEADER) @ 0x14006F421\n          or:\n            and:\n              arch: amd64\n              operand[1].offset: 0x108 = sizeof(IMAGE_NT_HEADERS64) @ 0x14006F419\n    count(basic block): 3 or more @ 0x14006F0E0, 0x14006F0F2, 0x14006F10F, 0x14006F119, and 47 more...\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x14006F1A9\n      operand[1].offset: 0x10 = IMAGE_SECTION_HEADER.SizeOfRawData @ 0x14006F0E8\n\nparse PE header\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x1400ED6C0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1400ED6D0, 0x1400ED6ED, 0x1400EDA02, 0x1400EDDD2, and 101 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x1400F06E0\n        and:\n          number: 0x50 @ 0x1400ED835, 0x1400EE7FC, 0x1400EF7FC, 0x1400F0815, and 7 more...\n          number: 0x45 @ 0x1400EDF7D, 0x1400EEF49, 0x1400EFF3B, 0x1400F0F49, and 7 more...\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x1400EE6D0\n      optional:\n        and:\n          operand[1].offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x1400EF6B1\n          or:\n            and:\n              arch: amd64\n              operand[1].offset: 0x50 = IMAGE_NT_HEADERS64.OptionalHeader.SizeOfImage @ 0x1400EF9BB, 0x1400EFA00, 0x1400F474A, 0x1400F494A\n              operand[1].offset: 0x30 = IMAGE_NT_HEADERS64.OptionalHeader.ImageBase @ 0x1400F4739, 0x1400F475C, 0x1400F495C, 0x1400F5125, and 1 more...\n\nresolve function by parsing PE exports (4 matches)\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x14005E900\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x14005E900\n      mnemonic: movzx @ 0x14005E996, 0x14005EA15, 0x14005EA72, 0x14005EB55, and 9 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x14005E9D1, 0x14005EA1D, 0x14005EECB, 0x14005EF7A\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x14005E9D6, 0x14005EA89, 0x14005EEC2, 0x14005EFD5\n      3 or more:\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x14005EB89\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x14005F155, 0x14005F16E\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x14005F150, 0x14005F169\nfunction @ 0x1400CF320\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x1400CF320\n      mnemonic: movzx @ 0x1400CF641, 0x1400D3F7B, 0x1400D4ACC, 0x1400D6489, and 3 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x1400CF355, 0x1400CF635, 0x1400D0351, 0x1400D074C, and 1 more...\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x1400D0616, 0x1400D06C1, 0x1400D06ED, 0x1400D073D\n      3 or more:\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x1400D7546\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x1400D7542\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x1400D753D\nfunction @ 0x1400D75A0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x1400D75A0\n      mnemonic: movzx @ 0x1400D78D7, 0x1400D977F, 0x1400D9BB4, 0x1400DAA55, and 7 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x1400DA9DC, 0x1400DAA30\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x1400DAFBF, 0x1400DAFFC, 0x1400DC893, 0x1400DC8D1\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x1400DA9FF\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x1400DDE68\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x1400DDE64\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x1400DDE5F\nfunction @ 0x1400ED6C0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x1400ED6C0\n      mnemonic: movzx @ 0x1400F3714, 0x1400F46E8, 0x1400F68E7, 0x1400F6902, and 3 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x1400EF6B1\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x1400EF125, 0x1400EF1A7\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x1400F3691, 0x1400F3719, 0x1400F68E7, 0x1400F6902, and 1 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x1400F4753, 0x1400F4953\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x1400F6906, 0x1400F6B0D\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x1400F6917, 0x1400F692C, 0x1400F6B1F, 0x1400F6B47, and 1 more...\n\n\n\n"},"hashes":{"md5":"dbdc539ce2276d056e3da79e5b556cba","sha1":"be359a25b1ed3d17fb2aad16d8d6c81fcda6a319","sha256":"54c8c1fa5c44506bb1feb7c8657ef6b761b0e1d1e4a8dbe2b52eea5a89296562"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 2457</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 193432</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"54c8c1f\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"dbdc539ce2276d056e3da79e5b556cba\",\n        \"sha256\": \"54c8c1fa5c44506bb1feb7c8657ef6b761b0e1d1e4a8dbe2b52eea5\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_peb_access__46_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"PEB access (46 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Process Environment\",\n        \"Block [B0001.019]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x14000D0A6\",\n      \"label\": \"Block 0x14000D0A6\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14000D0A6\"\n    },\n    {\n      \"id\": \"cap_contain_loop__990_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (990 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x140001240\",\n      \"label\": \"Function 0x140001240\",\n      \"type\": \"function\",\n      \"address\": \"0x140001240\"\n    },\n    {\n      \"id\": \"cap_reference_analysis_tools_strings\",\n      \"label\": \"reference analysis tools strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_compiled_with_go\",\n      \"label\": \"compiled with Go\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_encode_data_using_base64__3_matches_\",\n      \"label\": \"encode data using Base64 (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14008E9A0\",\n      \"label\": \"Function 0x14008E9A0\",\n      \"type\": \"function\",\n      \"address\": \"0x14008E9A0\"\n    },\n    {\n      \"id\": \"func_0x14004D480\",\n      \"label\": \"Function 0x14004D480\",\n      \"type\": \"function\",\n      \"address\": \"0x14004D480\"\n    },\n    {\n      \"id\": \"func_0x1400891A0\",\n      \"label\": \"Function 0x1400891A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400891A0\"\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_base64_string\",\n      \"label\": \"reference Base64 string\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Encode Data::Base64 [C0026.001]\",\n        \"Data::Check String [C0019]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Encode Data::Base64 [C0026.001]\",\n        \"Data::Check String [C0019]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_aes_via_x86_extensions__4_matches_\",\n      \"label\": \"encrypt data using AES via x86 extensions (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encryption-Standard\",\n        \"Algorithm [E1027.m05]\",\n        \"Cryptography::Encrypt Data::AES [C0027.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400741A0\",\n      \"label\": \"Function 0x1400741A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400741A0\"\n    },\n    {\n      \"id\": \"func_0x140074180\",\n      \"label\": \"Function 0x140074180\",\n      \"type\": \"function\",\n      \"address\": \"0x140074180\"\n    },\n    {\n      \"id\": \"func_0x1400741E0\",\n      \"label\": \"Function 0x1400741E0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400741E0\"\n    },\n    {\n      \"id\": \"func_0x140074160\",\n      \"label\": \"Function 0x140074160\",\n      \"type\": \"function\",\n      \"address\": \"0x140074160\"\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_rc4_prga\",\n      \"label\": \"encrypt data using RC4 PRGA\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data::RC4 [C0027.009]\",\n        \"Cryptography::Generate\",\n        \"Pseudo-random Sequence::RC4 PRGA [C0021.004]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140058600\",\n      \"label\": \"Function 0x140058600\",\n      \"type\": \"function\",\n      \"address\": \"0x140058600\"\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_salsa20_or_chacha\",\n      \"label\": \"encrypt data using Salsa20 or ChaCha\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information [T1027]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14000A820\",\n      \"label\": \"Function 0x14000A820\",\n      \"type\": \"function\",\n      \"address\": \"0x14000A820\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information [T1027]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"label\": \"hash data using fnv (21 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::FNV [C0030.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14009B613\",\n      \"label\": \"Function 0x14009B613\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B613\"\n    },\n    {\n      \"id\": \"func_0x14009B517\",\n      \"label\": \"Function 0x14009B517\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B517\"\n    },\n    {\n      \"id\": \"func_0x14009B4FD\",\n      \"label\": \"Function 0x14009B4FD\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B4FD\"\n    },\n    {\n      \"id\": \"func_0x14009B480\",\n      \"label\": \"Function 0x14009B480\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B480\"\n    },\n    {\n      \"id\": \"func_0x14009B6B7\",\n      \"label\": \"Function 0x14009B6B7\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B6B7\"\n    },\n    {\n      \"id\": \"func_0x14009B705\",\n      \"label\": \"Function 0x14009B705\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B705\"\n    },\n    {\n      \"id\": \"func_0x14009B5B7\",\n      \"label\": \"Function 0x14009B5B7\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B5B7\"\n    },\n    {\n      \"id\": \"func_0x14009B557\",\n      \"label\": \"Function 0x14009B557\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B557\"\n    },\n    {\n      \"id\": \"func_0x14009B4DF\",\n      \"label\": \"Function 0x14009B4DF\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B4DF\"\n    },\n    {\n      \"id\": \"func_0x14009B673\",\n      \"label\": \"Function 0x14009B673\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B673\"\n    },\n    {\n      \"id\": \"func_0x14009B6D7\",\n      \"label\": \"Function 0x14009B6D7\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B6D7\"\n    },\n    {\n      \"id\": \"func_0x14009B637\",\n      \"label\": \"Function 0x14009B637\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B637\"\n    },\n    {\n      \"id\": \"func_0x14009B537\",\n      \"label\": \"Function 0x14009B537\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B537\"\n    },\n    {\n      \"id\": \"func_0x14009B577\",\n      \"label\": \"Function 0x14009B577\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B577\"\n    },\n    {\n      \"id\": \"func_0x14009B693\",\n      \"label\": \"Function 0x14009B693\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B693\"\n    },\n    {\n      \"id\": \"func_0x14009B595\",\n      \"label\": \"Function 0x14009B595\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B595\"\n    },\n    {\n      \"id\": \"func_0x14009B653\",\n      \"label\": \"Function 0x14009B653\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B653\"\n    },\n    {\n      \"id\": \"func_0x140096380\",\n      \"label\": \"Function 0x140096380\",\n      \"type\": \"function\",\n      \"address\": \"0x140096380\"\n    },\n    {\n      \"id\": \"func_0x14009B5D8\",\n      \"label\": \"Function 0x14009B5D8\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B5D8\"\n    },\n    {\n      \"id\": \"func_0x14009B5F3\",\n      \"label\": \"Function 0x14009B5F3\",\n      \"type\": \"function\",\n      \"address\": \"0x14009B5F3\"\n    },\n    {\n      \"id\": \"func_0x14009BD20\",\n      \"label\": \"Function 0x14009BD20\",\n      \"type\": \"function\",\n      \"address\": \"0x14009BD20\"\n    },\n    {\n      \"id\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author       moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::FNV [C0030.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_using_murmur3__5_matches_\",\n      \"label\": \"hash data using murmur3 (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::MurmurHash [C0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14002D980\",\n      \"label\": \"Function 0x14002D980\",\n      \"type\": \"function\",\n      \"address\": \"0x14002D980\"\n    },\n    {\n      \"id\": \"func_0x14002D2A0\",\n      \"label\": \"Function 0x14002D2A0\",\n      \"type\": \"function\",\n      \"address\": \"0x14002D2A0\"\n    },\n    {\n      \"id\": \"func_0x140024540\",\n      \"label\": \"Function 0x140024540\",\n      \"type\": \"function\",\n      \"address\": \"0x140024540\"\n    },\n    {\n      \"id\": \"func_0x140036600\",\n      \"label\": \"Function 0x140036600\",\n      \"type\": \"function\",\n      \"address\": \"0x140036600\"\n    },\n    {\n      \"id\": \"func_0x140024D20\",\n      \"label\": \"Function 0x140024D20\",\n      \"type\": \"function\",\n      \"address\": \"0x140024D20\"\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::MurmurHash [C0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_allocate_thread_local_storage\",\n      \"label\": \"allocate thread local storage\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Allocate Thread Local Storage [C0040]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140075FC0\",\n      \"label\": \"Function 0x140075FC0\",\n      \"type\": \"function\",\n      \"address\": \"0x140075FC0\"\n    },\n    {\n      \"id\": \"api_TlsAlloc\",\n      \"label\": \"TlsAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"label\": \"access PEB ldr_data (22 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1400817EA\",\n      \"label\": \"Block 0x1400817EA\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400817EA\"\n    },\n    {\n      \"id\": \"bb_0x14001A26A\",\n      \"label\": \"Block 0x14001A26A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14001A26A\"\n    },\n    {\n      \"id\": \"bb_0x140027325\",\n      \"label\": \"Block 0x140027325\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140027325\"\n    },\n    {\n      \"id\": \"bb_0x1400373C0\",\n      \"label\": \"Block 0x1400373C0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400373C0\"\n    },\n    {\n      \"id\": \"bb_0x14001A0AA\",\n      \"label\": \"Block 0x14001A0AA\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14001A0AA\"\n    },\n    {\n      \"id\": \"bb_0x140075B60\",\n      \"label\": \"Block 0x140075B60\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140075B60\"\n    },\n    {\n      \"id\": \"bb_0x140034F0C\",\n      \"label\": \"Block 0x140034F0C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140034F0C\"\n    },\n    {\n      \"id\": \"bb_0x14003482E\",\n      \"label\": \"Block 0x14003482E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14003482E\"\n    },\n    {\n      \"id\": \"bb_0x14006D67D\",\n      \"label\": \"Block 0x14006D67D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14006D67D\"\n    },\n    {\n      \"id\": \"bb_0x14007114A\",\n      \"label\": \"Block 0x14007114A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14007114A\"\n    },\n    {\n      \"id\": \"bb_0x14001C65C\",\n      \"label\": \"Block 0x14001C65C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14001C65C\"\n    },\n    {\n      \"id\": \"bb_0x1400758A0\",\n      \"label\": \"Block 0x1400758A0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400758A0\"\n    },\n    {\n      \"id\": \"bb_0x14006587B\",\n      \"label\": \"Block 0x14006587B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14006587B\"\n    },\n    {\n      \"id\": \"bb_0x140012DEB\",\n      \"label\": \"Block 0x140012DEB\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140012DEB\"\n    },\n    {\n      \"id\": \"bb_0x140039E20\",\n      \"label\": \"Block 0x140039E20\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140039E20\"\n    },\n    {\n      \"id\": \"bb_0x140039433\",\n      \"label\": \"Block 0x140039433\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140039433\"\n    },\n    {\n      \"id\": \"bb_0x14004A625\",\n      \"label\": \"Block 0x14004A625\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14004A625\"\n    },\n    {\n      \"id\": \"bb_0x1400856B8\",\n      \"label\": \"Block 0x1400856B8\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400856B8\"\n    },\n    {\n      \"id\": \"bb_0x140051C89\",\n      \"label\": \"Block 0x140051C89\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140051C89\"\n    },\n    {\n      \"id\": \"cap_get_kernel32_base_address__5_matches_\",\n      \"label\": \"get kernel32 base address (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_pe_sections\",\n      \"label\": \"enumerate PE sections\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14006F0E0\",\n      \"label\": \"Function 0x14006F0E0\",\n      \"type\": \"function\",\n      \"address\": \"0x14006F0E0\"\n    },\n    {\n      \"id\": \"cap_author_______ana06___mr_tz\",\n      \"label\": \"author      @Ana06, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header\",\n      \"label\": \"parse PE header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400ED6C0\",\n      \"label\": \"Function 0x1400ED6C0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400ED6C0\"\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports__4_matches_\",\n      \"label\": \"resolve function by parsing PE exports (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1400CF320\",\n      \"label\": \"Function 0x1400CF320\",\n      \"type\": \"function\",\n      \"address\": \"0x1400CF320\"\n    },\n    {\n      \"id\": \"func_0x1400D75A0\",\n      \"label\": \"Function 0x1400D75A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D75A0\"\n    },\n    {\n      \"id\": \"func_0x14005E900\",\n      \"label\": \"Function 0x14005E900\",\n      \"type\": \"function\",\n      \"address\": \"0x14005E900\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_peb_access__46_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_peb_access__46_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x14000D0A6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__990_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__990_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x140001240\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_analysis_tools_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_with_go\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encode_data_using_base64__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__3_matches_\",\n      \"target\": \"func_0x14008E9A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__3_matches_\",\n      \"target\": \"func_0x14004D480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__3_matches_\",\n      \"target\": \"func_0x1400891A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14008E9A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14004D480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400891A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_base64_string\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_aes_via_x86_extensions__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_aes_via_x86_extensions__4_matches_\",\n      \"target\": \"func_0x1400741A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_aes_via_x86_extensions__4_matches_\",\n      \"target\": \"func_0x140074180\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_aes_via_x86_extensions__4_matches_\",\n      \"target\": \"func_0x1400741E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_aes_via_x86_extensions__4_matches_\",\n      \"target\": \"func_0x140074160\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400741A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140074180\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400741E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140074160\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_rc4_prga\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga\",\n      \"target\": \"func_0x140058600\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140058600\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_salsa20_or_chacha\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_salsa20_or_chacha\",\n      \"target\": \"func_0x14000A820\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x14000A820\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B613\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B517\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B4FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B6B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B705\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B5B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B557\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B4DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B673\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B6D7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B637\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B537\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B577\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B693\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B595\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B653\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x140096380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B5D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009B5F3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__21_matches_\",\n      \"target\": \"func_0x14009BD20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B613\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B517\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B4FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B6B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B705\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B5B7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B557\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B4DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B673\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B6D7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B637\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B537\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B577\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B693\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B595\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B653\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140096380\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B5D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009B5F3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14009BD20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_murmur3__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_murmur3__5_matches_\",\n      \"target\": \"func_0x14002D980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_murmur3__5_matches_\",\n      \"target\": \"func_0x14002D2A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_murmur3__5_matches_\",\n      \"target\": \"func_0x140024540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_murmur3__5_matches_\",\n      \"target\": \"func_0x140036600\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_murmur3__5_matches_\",\n      \"target\": \"func_0x140024D20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x14002D980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x14002D2A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x140024540\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x140036600\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x140024D20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_thread_local_storage\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_thread_local_storage\",\n      \"target\": \"func_0x140075FC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140075FC0\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140075FC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140075FC0\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x1400817EA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x14001A26A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x140027325\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x1400373C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x14001A0AA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x140075B60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x140034F0C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x14003482E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x14006D67D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x14007114A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x14001C65C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x1400758A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x14006587B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x140012DEB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x140039E20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x140039433\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x14004A625\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x1400856B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x140051C89\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1400817EA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x14001A26A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x140027325\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1400373C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x14001A0AA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x140075B60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x140034F0C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x14003482E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x14006D67D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x14007114A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x14001C65C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1400758A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x14006587B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x140012DEB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x140039E20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x140039433\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x14004A625\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1400856B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x140051C89\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_kernel32_base_address__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_kernel32_base_address__5_matches_\",\n      \"target\": \"bb_0x140075B60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_kernel32_base_address__5_matches_\",\n      \"target\": \"bb_0x1400758A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x140075B60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1400758A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_pe_sections\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections\",\n      \"target\": \"func_0x14006F0E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______ana06___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x14006F0E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header\",\n      \"target\": \"func_0x1400ED6C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400ED6C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__4_matches_\",\n      \"target\": \"func_0x1400CF320\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__4_matches_\",\n      \"target\": \"func_0x1400ED6C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__4_matches_\",\n      \"target\": \"func_0x1400D75A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__4_matches_\",\n      \"target\": \"func_0x14005E900\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x1400CF320\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x1400ED6C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x1400D75A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x14005E900\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-17 20:20:16.268124\",\n    \"total_functions\": \"2457\",\n    \"total_features\": \"193432\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-17 20:20:21"}
{"_id":{"$oid":"6a5a4261b3bed57e0e737872"},"sha256":"ccdc3e99b62d1b0b4b86a74896c1c1a45ee9a43bba9264fad162eb0116c49033","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_znnacaxv/ccdc3e99b62d1b0b4b86a74896c1c1a45ee9a43bba9264fad162eb0116c49033-019f7059ab947ff1b8cbf407d223a0d8.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_znnacaxv/ccdc3e99b62d1b0b4b86a74896c1c1a45ee9a43bba9264fad162eb0116c49033-019f7059ab947ff1b8cbf407d223a0d8.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_znnacaxv/ccdc3e99b62d1b0b4b86a74896c1c1a45ee9a43bba9264fad162eb0116c49033-019f7059ab947ff1b8cbf407d223a0d8.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ e19293ba06f288b511cb5697b3c2c195                                  │\n│ sha1     │ 10214a6b85cc071194553f5939cd3a0a5bf3d1a3                          │\n│ sha256   │ ccdc3e99b62d1b0b4b86a74896c1c1a45ee9a43bba9264fad162eb0116c49033  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ amd64                                                             │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/ccdc3e99b62d1b0b… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION      │ Obfuscated Files or Information [T1027]               │\n│                      │ Obfuscated Files or Information::Indicator Removal    │\n│                      │ from Tools [T1027.005]                                │\n│ DISCOVERY            │ File and Directory Discovery [T1083]                  │\n│                      │ System Information Discovery [T1082]                  │\n│ EXECUTION            │ Shared Modules [T1129]                                │\n│ PRIVILEGE ESCALATION │ Access Token Manipulation [T1134]                     │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Debugger Detection::Timing/Delay Check            │\n│                          │ QueryPerformanceCounter [B0001.033]               │\n│ ANTI-STATIC ANALYSIS     │ Executable Code Obfuscation::Argument Obfuscation │\n│                          │ [B0032.020]                                       │\n│                          │ Executable Code Obfuscation::Stack Strings        │\n│                          │ [B0032.017]                                       │\n│ CRYPTOGRAPHY             │ Cryptographic Hash::SHA1 [C0029.002]              │\n│                          │ Generate Pseudo-random Sequence::Use API          │\n│                          │ [C0021.003]                                       │\n│ DATA                     │ Encode Data::Base64 [C0026.001]                   │\n│                          │ Encode Data::XOR [C0026.002]                      │\n│                          │ Non-Cryptographic Hash::FNV [C0030.005]           │\n│                          │ Non-Cryptographic Hash::MurmurHash [C0030.001]    │\n│ DEFENSE EVASION          │ Obfuscated Files or                               │\n│                          │ Information::Encoding-Standard Algorithm          │\n│                          │ [E1027.m02]                                       │\n│ DISCOVERY                │ Code Discovery::Enumerate PE Sections [B0046.001] │\n│                          │ File and Directory Discovery [E1083]              │\n│                          │ File and Directory Discovery::Log File            │\n│                          │ [E1083.m01]                                       │\n│                          │ System Information Discovery [E1082]              │\n│ FILE SYSTEM              │ Create Directory [C0046]                          │\n│                          │ Get File Attributes [C0049]                       │\n│                          │ Read File [C0051]                                 │\n│                          │ Writes File [C0052]                               │\n│ OPERATING SYSTEM         │ Registry::Set Registry Key [C0036.001]            │\n│ PROCESS                  │ Create Process [C0017]                            │\n│                          │ Create Thread [C0038]                             │\n│                          │ Resume Thread [C0054]                             │\n│                          │ Suspend Thread [C0055]                            │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ check for time delay via              │ anti-analysis/anti-debugging/debugg… │\n│ QueryPerformanceCounter (2 matches)   │                                      │\n│ contain obfuscated stackstrings (3    │ anti-analysis/obfuscation/string/st… │\n│ matches)                              │                                      │\n│ decode data using Base64 via dword    │ data-manipulation/encoding/base64    │\n│ translation table                     │                                      │\n│ encode data using XOR (16 matches)    │ data-manipulation/encoding/xor       │\n│ hash data using fnv (2 matches)       │ data-manipulation/hashing/fnv        │\n│ hash data using murmur3 (3 matches)   │ data-manipulation/hashing/murmur     │\n│ hash data using SHA1                  │ data-manipulation/hashing/sha1       │\n│ generate random numbers via WinAPI    │ data-manipulation/prng               │\n│ query environment variable (5         │ host-interaction/environment-variab… │\n│ matches)                              │                                      │\n│ get common file path                  │ host-interaction/file-system         │\n│ create directory                      │ host-interaction/file-system/create  │\n│ get file attributes                   │ host-interaction/file-system/meta    │\n│ get file size (2 matches)             │ host-interaction/file-system/meta    │\n│ read file on Windows                  │ host-interaction/file-system/read    │\n│ write file on Windows (4 matches)     │ host-interaction/file-system/write   │\n│ get number of processors (18 matches) │ host-interaction/hardware/cpu        │\n│ get memory capacity (2 matches)       │ host-interaction/hardware/memory     │\n│ access the Windows event log          │ host-interaction/log/winevt/access   │\n│ get system information on Windows     │ host-interaction/os/info             │\n│ create process on Windows             │ host-interaction/process/create      │\n│ modify access privileges              │ host-interaction/process/modify      │\n│ set registry value                    │ host-interaction/registry/create     │\n│ create thread (3 matches)             │ host-interaction/thread/create       │\n│ resume thread (4 matches)             │ host-interaction/thread/resume       │\n│ suspend thread (2 matches)            │ host-interaction/thread/suspend      │\n│ access PEB ldr_data (22 matches)      │ linking/runtime-linking              │\n│ link function at runtime on Windows   │ linking/runtime-linking              │\n│ (12 matches)                          │                                      │\n│ enumerate PE sections (5 matches)     │ load-code/pe                         │\n│ parse PE header (3 matches)           │ load-code/pe                         │\n│ resolve function by parsing PE        │ load-code/pe                         │\n│ exports (2 matches)                   │                                      │\n│ compiled with .NET AoT                │ runtime/dotnet                       │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     e19293ba06f288b511cb5697b3c2c195                        \nsha1                    10214a6b85cc071194553f5939cd3a0a5bf3d1a3                \nsha256                  ccdc3e99b62d1b0b4b86a74896c1c1a45ee9a43bba9264fad162eb0…\npath                    /home/apogean/projects/malware/windows/all_runs/ccdc3e9…\ntimestamp               2026-07-17 20:24:08.000718                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x140000000                                             \nrules                   /tmp/_MEImaJHtr/rules                                   \nfunction count          3945                                                    \nlibrary function count  125                                                     \ntotal feature count     207955                                                  \n\ncheck for time delay via QueryPerformanceCounter (2 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    0x14002E7A0                                    \n           0x140085F80                                    \n\ncontain obfuscated stackstrings (3 matches)\nnamespace  anti-analysis/obfuscation/string/stackstring\nscope      basic block                                 \nmatches    0x140003BDB                                 \n           0x140014C3A                                 \n           0x140014D1D                                 \n\ndecode data using Base64 via dword translation table\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    0x14001E080                      \n\nencode data using XOR (16 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x14000AAEA                   \n           0x140020E6A                   \n           0x1400189C7                   \n           0x140018C36                   \n           0x140020E6A                   \n           0x140020E6A                   \n           0x140020E6A                   \n           0x140020E6A                   \n           0x140020E6A                   \n           0x140020E6A                   \n           0x140020E6A                   \n           0x1400189C7                   \n           0x140020E6A                   \n           0x14004A7A0                   \n           0x140020E6A                   \n           0x1400189C7                   \n\nhash data using fnv (2 matches)\nnamespace    data-manipulation/hashing/fnv                                      \ndescription  can be any Fowler-Noll-Vo (FNV) hash variant, including FNV-1,     \n             FNV-1a, FNV-0                                                      \nscope        function                                                           \nmatches      0x140012A60                                                        \n             0x140012E20                                                        \n\nhash data using murmur3 (3 matches)\nnamespace  data-manipulation/hashing/murmur\nscope      function                        \nmatches    0x140020680                     \n           0x14006DDC0                     \n           0x14006F740                     \n\nhash data using SHA1\nnamespace  data-manipulation/hashing/sha1\nscope      function                      \nmatches    0x140026FA0                   \n\ngenerate random numbers via WinAPI\nnamespace  data-manipulation/prng\nscope      function              \nmatches    0x140014E20           \n\nquery environment variable (5 matches)\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x1400072E0                          \n           0x140017470                          \n           0x140017B60                          \n           0x1400489A0                          \n           0x140082C10                          \n\nget common file path\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x140017A00                 \n\ncreate directory\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x1400072E0                        \n\nget file attributes\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x14000E023                      \n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x1400092E0                      \n           0x140009400                      \n\nread file on Windows\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x140009400                      \n\nwrite file on Windows (4 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x140009400                       \n           0x14000DE00                       \n           0x140048530                       \n           0x1400818F0                       \n\nget number of processors (18 matches)\nnamespace  host-interaction/hardware/cpu\nscope      function                     \nmatches    0x1400CFBB0                  \n           0x1400D00A0                  \n           0x1400D01A0                  \n           0x1400D1400                  \n           0x1400D16D0                  \n           0x1400D1BC0                  \n           0x1400D2320                  \n           0x1400D2500                  \n           0x1400D2620                  \n           0x1400D2810                  \n           0x1400D2BE0                  \n           0x1400D31F0                  \n           0x1400D3A80                  \n           0x1400D3D00                  \n           0x1400D4450                  \n           0x1400D4D10                  \n           0x1400D58E0                  \n           0x1400D5C00                  \n\nget memory capacity (2 matches)\nnamespace  host-interaction/hardware/memory\nscope      function                        \nmatches    0x140087120                     \n           0x1400874F0                     \n\naccess the Windows event log\nnamespace  host-interaction/log/winevt/access\nscope      function                          \nmatches    0x140049020                       \n\nget system information on Windows\nnamespace  host-interaction/os/info\nscope      function                \nmatches    0x140087750             \n\ncreate process on Windows\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x14000E153                    \n\nmodify access privileges\nnamespace  host-interaction/process/modify\nscope      instruction                    \nmatches    0x140087BDC                    \n\nset registry value\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x140009AD0                     \n\ncreate thread (3 matches)\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x140047FD0                   \n           0x1400819B0                   \n           0x1400819F0                   \n\nresume thread (4 matches)\nnamespace  host-interaction/thread/resume\nscope      basic block                   \nmatches    0x140048140                   \n           0x140081769                   \n           0x140081769                   \n           0x140081A25                   \n\nsuspend thread (2 matches)\nnamespace  host-interaction/thread/suspend\nscope      basic block                    \nmatches    0x140081718                    \n           0x140081718                    \n\naccess PEB ldr_data (22 matches)\nnamespace  linking/runtime-linking\nscope      basic block            \nmatches    0x140082D90            \n           0x140079140            \n           0x140079360            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n           0x1400D2741            \n\nlink function at runtime on Windows (12 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x140014D85            \n           0x1400476BB            \n           0x1400476F0            \n           0x140047866            \n           0x140081581            \n           0x14008165B            \n           0x1400816A3            \n           0x14007C691            \n           0x1400811D8            \n           0x140081581            \n           0x14008165B            \n           0x1400816A3            \n\nenumerate PE sections (5 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x14000ABC0 \n           0x14001EFE0 \n           0x14001F520 \n           0x14006CD60 \n           0x1400D9E90 \n\nparse PE header (3 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x14000ABC0 \n           0x1400D6A2C \n           0x1400D9F30 \n\nresolve function by parsing PE exports (2 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x14000AB20 \n           0x14000ABC0 \n\ncompiled with .NET AoT\nnamespace    runtime/dotnet                                     \ndescription  compiled using .NET Ahead-of-Time (AoT) compilation\nscope        file                                               \n\n\n\n","very_verbose":"md5                     e19293ba06f288b511cb5697b3c2c195                        \nsha1                    10214a6b85cc071194553f5939cd3a0a5bf3d1a3                \nsha256                  ccdc3e99b62d1b0b4b86a74896c1c1a45ee9a43bba9264fad162eb0…\npath                    /home/apogean/projects/malware/windows/all_runs/ccdc3e9…\ntimestamp               2026-07-17 20:25:25.201121                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x140000000                                             \nrules                   /tmp/_MEIxaQ823/rules                                   \nfunction count          3945                                                    \nlibrary function count  125                                                     \ntotal feature count     207955                                                  \n\nPEB access (30 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Debugger Detection::Process Environment   \n            Block [B0001.019]                                                   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nbasic block @ 0x14002D680 in function 0x14002D680\n  or:\n    and:\n      arch: amd64\n      characteristic: gs access @ 0x14002D69B\n      or:\n        offset: 0x60 @ 0x14002D68E\n\nallocate memory (13 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x14004DFC0 in function 0x14004DFC0\n  or:\n    api: VirtualAlloc @ 0x14004E01E\n\nallocate or change RW memory (12 matches, only showing first match of library \nrule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x14004DFC0 in function 0x14004DFC0\n  and:\n    or:\n      match: allocate memory @ 0x14004DFC0\n        or:\n          api: VirtualAlloc @ 0x14004E01E\n    or:\n      number: 0x4 = PAGE_READWRITE @ 0x14004DFFB\n\nchange memory protection (library rule)\nauthor  @mr-tz                                  \nscope   basic block                             \nmbc     Memory::Change Memory Protection [C0008]\nbasic block @ 0x140081A90 in function 0x140081A90\n  or:\n    api: VirtualProtect @ 0x140081A99\n\ncontain loop (980 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x140002080\n  or:\n    characteristic: loop @ 0x140002080\n\ncreate or open file (4 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x14000935B\n  or:\n    api: CreateFile @ 0x14000935B\n\ncreate or open registry key (library rule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x140009B40 in function 0x140009AD0\n  or:\n    api: RegCreateKeyEx @ 0x140009BB5\n\ndelay execution (15 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x14002B3F5 in function 0x14002B340\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x14002B40F\n\nget OS version (4 matches, only showing first match of library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x140077350\n  or:\n    api: VerifyVersionInfo @ 0x140081642\n    api: VerSetConditionMask @ 0x1400815F7, 0x140081608, 0x140081619\n\ncheck for time delay via QueryPerformanceCounter (2 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection                      \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check     \n           QueryPerformanceCounter [B0001.033]                                  \nfunction @ 0x14002E7A0\n  and:\n    count(api(QueryPerformanceCounter)): 2 or more @ 0x14002E816, 0x14002E843, 0x14002E8B4, 0x14002E8E1\nfunction @ 0x140085F80\n  and:\n    count(api(QueryPerformanceCounter)): 2 or more @ 0x140085FC7, 0x140086023\n\ncontain obfuscated stackstrings (3 matches)\nnamespace  anti-analysis/obfuscation/string/stackstring                         \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information::Indicator Removal  \n           from Tools [T1027.005]                                               \nmbc        Anti-Static Analysis::Executable Code Obfuscation::Argument          \n           Obfuscation [B0032.020], Anti-Static Analysis::Executable Code       \n           Obfuscation::Stack Strings [B0032.017]                               \nbasic block @ 0x140003BDB in function 0x140003680\n  characteristic: stack string @ 0x140003BDB\nbasic block @ 0x140014C3A in function 0x140014BF0\n  characteristic: stack string @ 0x140014C3A\nbasic block @ 0x140014D1D in function 0x140014BF0\n  characteristic: stack string @ 0x140014D1D\n\ndecode data using Base64 via dword translation table\nnamespace  data-manipulation/encoding/base64                                    \nauthor     gilbert.elliot@mandiant.com, sara.rincon@mandiant.com                \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::Base64 [C0026.001]         \nfunction @ 0x14001E080\n  and:\n    mnemonic: shl @ 0x14001E0D1, 0x14001E117, 0x14001E12E, 0x14001E13C, and 4 more...\n    match: contain loop @ 0x14001E080\n      or:\n        characteristic: loop @ 0x14001E080\n    number: 0x2 @ 0x14001E0B7, 0x14001E0D1, 0x14001E252\n    number: 0x3 @ 0x14001E172, 0x14001E295\n    number: 0x4 @ 0x14001E175, 0x14001E298\n    number: 0x6 @ 0x14001E13C, 0x14001E224, 0x14001E269\n    or:\n      mnemonic: sar @ 0x14001E0B7, 0x14001E15C, 0x14001E166, 0x14001E20E, and 4 more...\n      mnemonic: shr @ 0x14001E0CC\n    or:\n      number: 0x3D @ 0x14001E1F0, 0x14001E1F6\n    or:\n      bytes: ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff\nffffff3effffff3f3435363738393a3b3c3dffffffffffffff000102030405060708090a0b0c0d0e\n0f10111213141516171819ffffffffffff1a1b1c1d1e1f202122232425262728292a2b2c2d2e2f30\n313233ffffffffff = hardcoded base64 translation table @ 0x14001E0AE\n\nencode data using XOR (16 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x14000AAEA in function 0x14000AAE0\n  and:\n    characteristic: tight loop @ 0x14000AAEA\n    characteristic: nzxor @ 0x14000AAF1, 0x14000AB01\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1400189C7 in function 0x14004C9C0\n  and:\n    characteristic: tight loop @ 0x1400189C7\n    characteristic: nzxor @ 0x1400189D4, 0x1400189E1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1400189C7 in function 0x14004C9C0\n  and:\n    characteristic: tight loop @ 0x1400189C7\n    characteristic: nzxor @ 0x1400189D4, 0x1400189E1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1400189C7 in function 0x14004C9C0\n  and:\n    characteristic: tight loop @ 0x1400189C7\n    characteristic: nzxor @ 0x1400189D4, 0x1400189E1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x140018C36 in function 0x140018B60\n  and:\n    characteristic: tight loop @ 0x140018C36\n    characteristic: nzxor @ 0x140018C49, 0x140018C5B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x140020E6A in function 0x14004C950\n  and:\n    characteristic: tight loop @ 0x140020E6A\n    characteristic: nzxor @ 0x140020E71, 0x140020E7F, 0x140020E93, 0x140020EA1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x140020E6A in function 0x14004C950\n  and:\n    characteristic: tight loop @ 0x140020E6A\n    characteristic: nzxor @ 0x140020E71, 0x140020E7F, 0x140020E93, 0x140020EA1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x140020E6A in function 0x14004C950\n  and:\n    characteristic: tight loop @ 0x140020E6A\n    characteristic: nzxor @ 0x140020E71, 0x140020E7F, 0x140020E93, 0x140020EA1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x140020E6A in function 0x14004C950\n  and:\n    characteristic: tight loop @ 0x140020E6A\n    characteristic: nzxor @ 0x140020E71, 0x140020E7F, 0x140020E93, 0x140020EA1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x140020E6A in function 0x14004C950\n  and:\n    characteristic: tight loop @ 0x140020E6A\n    characteristic: nzxor @ 0x140020E71, 0x140020E7F, 0x140020E93, 0x140020EA1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x140020E6A in function 0x14004C950\n  and:\n    characteristic: tight loop @ 0x140020E6A\n    characteristic: nzxor @ 0x140020E71, 0x140020E7F, 0x140020E93, 0x140020EA1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x140020E6A in function 0x14004C950\n  and:\n    characteristic: tight loop @ 0x140020E6A\n    characteristic: nzxor @ 0x140020E71, 0x140020E7F, 0x140020E93, 0x140020EA1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x140020E6A in function 0x14004C950\n  and:\n    characteristic: tight loop @ 0x140020E6A\n    characteristic: nzxor @ 0x140020E71, 0x140020E7F, 0x140020E93, 0x140020EA1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x140020E6A in function 0x14004C950\n  and:\n    characteristic: tight loop @ 0x140020E6A\n    characteristic: nzxor @ 0x140020E71, 0x140020E7F, 0x140020E93, 0x140020EA1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x140020E6A in function 0x14004C950\n  and:\n    characteristic: tight loop @ 0x140020E6A\n    characteristic: nzxor @ 0x140020E71, 0x140020E7F, 0x140020E93, 0x140020EA1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x14004A7A0 in function 0x14004A7A0\n  and:\n    characteristic: tight loop @ 0x14004A7A0\n    characteristic: nzxor @ 0x14004A7B7, 0x14004A7BA, 0x14004A7C9, 0x14004A7CC, and 1 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nhash data using fnv (2 matches)\nnamespace    data-manipulation/hashing/fnv                                      \nauthor       moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com  \nscope        function                                                           \nmbc          Data::Non-Cryptographic Hash::FNV [C0030.005]                      \nreferences   https://en.wikipedia.org/wiki/Fowler%E2%80%93Noll%E2%80%93Vo_hash_…\n             http://isthe.com/chongo/tech/comp/fnv/,                            \n             https://create.stephan-brumme.com/fnv-hash/                        \ndescription  can be any Fowler-Noll-Vo (FNV) hash variant, including FNV-1,     \n             FNV-1a, FNV-0                                                      \nfunction @ 0x140012A60\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x140012B2D\n        or:\n          mnemonic: imul @ 0x140012B30\n      and:\n        characteristic: nzxor @ 0x140012ACE\n        or:\n          mnemonic: imul @ 0x140012AD1\n    or:\n      number: 0x1000193 = FNV prime @ 0x140012AD1, 0x140012B30\n    optional:\n      characteristic: loop @ 0x140012A60\n      number: 0x811C9DC5 = FNV_offset_basis, unused by FNV-0 @ 0x140012A9E, 0x140012AFC\nfunction @ 0x140012E20\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x14001311E\n        or:\n          mnemonic: imul @ 0x140013121\n    or:\n      number: 0x1000193 = FNV prime @ 0x140013121\n    optional:\n      characteristic: loop @ 0x140012E20\n      number: 0x811C9DC5 = FNV_offset_basis, unused by FNV-0 @ 0x1400130E1\n\nhash data using murmur3 (3 matches)\nnamespace   data-manipulation/hashing/murmur                                    \nauthor      william.ballenthin@mandiant.com                                     \nscope       function                                                            \nmbc         Data::Non-Cryptographic Hash::MurmurHash [C0030.001]                \nreferences  https://github.com/aappleby/smhasher/blob/master/src/MurmurHash3.cpp\nfunction @ 0x140020680\n  or:\n    basic block:\n      and: = hash >> 16; hash >> 13; hash >> 16\n        instruction:\n          and:\n            mnemonic: shr @ 0x140020733\n            number: 0x10 @ 0x140020733\n        instruction:\n          and:\n            mnemonic: shr @ 0x140020726\n            number: 0xD @ 0x140020726\n        count(mnemonic(shr)): 3 @ 0x140020719, 0x140020726, 0x140020733\n        optional:\n          count(characteristic(nzxor)): 3 or more @ 0x14002071C, 0x140020729, 0x140020736\nfunction @ 0x14006DDC0\n  or:\n    basic block:\n      and: = hash >> 16; hash >> 13; hash >> 16\n        instruction:\n          and:\n            mnemonic: shr @ 0x14006DE1E\n            number: 0x10 @ 0x14006DE1E\n        instruction:\n          and:\n            mnemonic: shr @ 0x14006DE11\n            number: 0xD @ 0x14006DE11\n        count(mnemonic(shr)): 3 @ 0x14006DE04, 0x14006DE11, 0x14006DE1E\n        optional:\n          count(characteristic(nzxor)): 3 or more @ 0x14006DE07, 0x14006DE14, 0x14006DE21\nfunction @ 0x14006F740\n  or:\n    basic block:\n      and: = hash >> 16; hash >> 13; hash >> 16\n        instruction:\n          and:\n            mnemonic: shr @ 0x14006F7AC\n            number: 0x10 @ 0x14006F7AC\n        instruction:\n          and:\n            mnemonic: shr @ 0x14006F79F\n            number: 0xD @ 0x14006F79F\n        count(mnemonic(shr)): 3 @ 0x14006F792, 0x14006F79F, 0x14006F7AC\n        optional:\n          count(characteristic(nzxor)): 3 or more @ 0x14006F795, 0x14006F7A2, 0x14006F7AF\n\nhash data using SHA1\nnamespace  data-manipulation/hashing/sha1                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           william.ballenthin@mandiant.com                                      \nscope      function                                                             \nmbc        Cryptography::Cryptographic Hash::SHA1 [C0029.002]                   \nfunction @ 0x140026FA0\n  or:\n    and: = Magic initialization constants used in SHA1\n      number: 0x67452301 = A, also used in MD5, RIPEMD-128, RIPEMD-160, RIPEMD-256, and RIPEMD-320 @ 0x140026FDC\n      number: 0xEFCDAB89 = B, also used in MD5, RIPEMD-128, RIPEMD-160, RIPEMD-256, and RIPEMD-320 @ 0x140026FEF\n      number: 0x98BADCFE = C, also used in MD5, RIPEMD-128, RIPEMD-160, RIPEMD-256, and RIPEMD-320 @ 0x140027002\n      number: 0x10325476 = D, also used in MD5, RIPEMD-128, RIPEMD-160, RIPEMD-256, and RIPEMD-320 @ 0x140027015\n      number: 0xC3D2E1F0 = likely SHA1 but also used in RIPEMD-160 and RIPEMD-320 @ 0x140027028\n\ngenerate random numbers via WinAPI\nnamespace  data-manipulation/prng                                            \nauthor     michael.hunhoff@mandiant.com, johnk3r                             \nscope      function                                                          \nmbc        Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\nfunction @ 0x140014E20\n  and:\n    or:\n      api: BCryptGenRandom @ 0x140014E6F\n\nquery environment variable (5 matches)\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x1400072E0\n  or:\n    api: GetEnvironmentVariable @ 0x1400075A2\nfunction @ 0x140017470\n  or:\n    api: GetEnvironmentVariable @ 0x140017C5F\nfunction @ 0x140017B60\n  or:\n    api: GetEnvironmentVariable @ 0x140017C5F\nfunction @ 0x1400489A0\n  or:\n    api: GetEnvironmentVariable @ 0x140048A10\nfunction @ 0x140082C10\n  or:\n    api: GetEnvironmentVariable @ 0x140082C56\n\nget common file path\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x140017A00\n  or:\n    api: GetSystemDirectory @ 0x140017ABE\n\ncreate directory\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x1400072E0\n  or:\n    api: CreateDirectory @ 0x14000773C\n\nget file attributes\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x14000E023 in function 0x14000DFF0\n  or:\n    api: GetFileAttributes @ 0x14000E03E\n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x1400092E0\n  or:\n    api: GetFileSize @ 0x140009396\nfunction @ 0x140009400\n  or:\n    api: GetFileSize @ 0x14000959F\n\nread file on Windows\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x140009400\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x140009460\n          match: create or open file @ 0x1400094A9, 0x140009547\n            or:\n              api: CreateFile @ 0x1400094A9\n            or:\n              api: CreateFile @ 0x140009547\n      or:\n        api: ReadFile @ 0x140009659\n\nwrite file on Windows (4 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x140009400\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            match: create or open file @ 0x1400094A9\n              or:\n                api: CreateFile @ 0x1400094A9\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x140009501\n            number: 0x2 = FILE_WRITE_DATA @ 0x1400094E3\n            match: create or open file @ 0x140009547\n              or:\n                api: CreateFile @ 0x140009547\n      or:\n        api: WriteFile @ 0x1400096E4\nfunction @ 0x14000DE00\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x14000DEA3\nfunction @ 0x140048530\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x1400485A6\nfunction @ 0x1400818F0\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x140081927\n\nget number of processors (18 matches)\nnamespace   host-interaction/hardware/cpu                                       \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/bed03d2f849d9060c6…\nfunction @ 0x1400CFBB0\n  or:\n    and:\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC\nfunction @ 0x1400D00A0\n  or:\n    and:\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC\nfunction @ 0x1400D01A0\n  or:\n    and:\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC\nfunction @ 0x1400D1400\n  or:\n    and:\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC\nfunction @ 0x1400D16D0\n  or:\n    and:\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC\nfunction @ 0x1400D1BC0\n  or:\n    and:\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC\nfunction @ 0x1400D2320\n  or:\n    and:\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC\nfunction @ 0x1400D2500\n  or:\n    and:\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC\nfunction @ 0x1400D2620\n  or:\n    and:\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC\nfunction @ 0x1400D2810\n  or:\n    and:\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC\nfunction @ 0x1400D2BE0\n  or:\n    and:\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC\nfunction @ 0x1400D31F0\n  or:\n    and:\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC\nfunction @ 0x1400D3A80\n  or:\n    and:\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC\nfunction @ 0x1400D3D00\n  or:\n    and:\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC\nfunction @ 0x1400D4450\n  or:\n    and:\n      match: PEB access @ 0x1400D2741, 0x1400D2759\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC, 0x1400D5CC5\nfunction @ 0x1400D4D10\n  or:\n    and:\n      match: PEB access @ 0x1400D2741, 0x1400D2759\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC, 0x1400D5CC5\nfunction @ 0x1400D58E0\n  or:\n    and:\n      match: PEB access @ 0x1400D2741, 0x1400D2759\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC, 0x1400D5CC5\nfunction @ 0x1400D5C00\n  or:\n    and:\n      match: PEB access @ 0x1400D2741, 0x1400D2759\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      or:\n        and:\n          arch: amd64\n          number: 0xB8 = PEB->NumberOfProcessors @ 0x1400D39FC, 0x1400D5CC5\n\nget memory capacity (2 matches)\nnamespace  host-interaction/hardware/memory               \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x140087120\n  or:\n    api: GlobalMemoryStatusEx @ 0x14008721E\nfunction @ 0x1400874F0\n  or:\n    api: GlobalMemoryStatusEx @ 0x140087510\n\naccess the Windows event log\nnamespace  host-interaction/log/winevt/access                           \nauthor     moritz.raabe@mandiant.com                                    \nscope      function                                                     \nmbc        Discovery::File and Directory Discovery::Log File [E1083.m01]\nfunction @ 0x140049020\n  or:\n    api: ReportEvent @ 0x1400490DD\n\nget system information on Windows\nnamespace  host-interaction/os/info                       \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com  \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x140087750\n  and:\n    os: windows\n    or:\n      api: GetSystemInfo @ 0x14008775F\n\ncreate process on Windows\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x14000E153 in function 0x14000E0C0\n  or:\n    api: CreateProcess @ 0x14000E1DC\n\nmodify access privileges\nnamespace  host-interaction/process/modify                        \nauthor     moritz.raabe@mandiant.com                              \nscope      instruction                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\ninstruction @ 0x140087BDC\n  and:\n    api: AdjustTokenPrivileges @ 0x140087BDC\n\nset registry value\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x140009AD0\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x140009B40\n          or:\n            api: RegCreateKeyEx @ 0x140009BB5\n      or:\n        api: RegSetValueEx @ 0x140009DEC\n\ncreate thread (3 matches)\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x140047FD0 in function 0x140047FD0\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x14004807C\nbasic block @ 0x1400819B0 in function 0x1400819B0\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x1400819C9\nbasic block @ 0x1400819F0 in function 0x1400819F0\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x140081A11\n\nresume thread (4 matches)\nnamespace  host-interaction/thread/resume                     \nauthor     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\nscope      basic block                                        \nmbc        Process::Resume Thread [C0054]                     \nbasic block @ 0x140048140 in function 0x140048140\n  or:\n    api: ResumeThread @ 0x14004818D\nbasic block @ 0x140081769 in function 0x140081520\n  or:\n    api: ResumeThread @ 0x14008176C\nbasic block @ 0x140081769 in function 0x140081520\n  or:\n    api: ResumeThread @ 0x14008176C\nbasic block @ 0x140081A25 in function 0x1400819F0\n  or:\n    api: ResumeThread @ 0x140081A36\n\nsuspend thread (2 matches)\nnamespace  host-interaction/thread/suspend                    \nauthor     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\nscope      basic block                                        \nmbc        Process::Suspend Thread [C0055]                    \nbasic block @ 0x140081718 in function 0x140081520\n  or:\n    api: SuspendThread @ 0x14008171B\nbasic block @ 0x140081718 in function 0x140081520\n  or:\n    api: SuspendThread @ 0x14008171B\n\naccess PEB ldr_data (22 matches)\nnamespace   linking/runtime-linking                                             \nauthor      moritz.raabe@mandiant.com                                           \nscope       basic block                                                         \natt&ck      Execution::Shared Modules [T1129]                                   \nreferences  https://www.geoffchappell.com/studies/windows/km/ntoskrnl/inc/api/n…\n            https://github.com/d35ha/CallObfuscator/blob/5834aff9ff4511f1408ae4…\nbasic block @ 0x140079140 in function 0x140079140\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x140079140\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400791C9\n            or:\n              offset: 0x60 @ 0x14007916D, 0x14007921D\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400791FA\n      or: = resolve a module list\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x140079153, 0x140079201\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x140079159, 0x14007920F\nbasic block @ 0x140079360 in function 0x140079360\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x140079360\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400793D9\n            or:\n              offset: 0x60 @ 0x14007938D, 0x14007941E, 0x1400794C1, 0x140079555\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400793FB, 0x14007949E\n      or: = resolve a module list\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x140079373, 0x140079402, 0x1400794A5, 0x14007953B\n        offset: 0x30 = PEB.LDR_DATA.InInitializationOrderModuleList @ 0x140079379, 0x140079410, 0x1400794B3, 0x140079541\nbasic block @ 0x140082D90 in function 0x140078300\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x140082D90\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x140082D90\n            or:\n              offset: 0x60 @ 0x140082D9C\n      offset: 0x18 = PEB.LDR_DATA @ 0x140082DA0\n      or: = resolve a module list\n        offset: 0x20 = PEB.LDR_DATA.InMemoryOrderModuleList @ 0x140082DA4\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\nbasic block @ 0x1400D2741 in function 0x1400D5C00\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1400D2741\n        or:\n          and:\n            arch: amd64\n            characteristic: gs access @ 0x1400D2771\n            or:\n              offset: 0x60 @ 0x1400D2765\n      offset: 0x18 = PEB.LDR_DATA @ 0x1400D274A\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1400D2745\n\nlink function at runtime on Windows (12 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x140014D85\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x140014D85\ninstruction @ 0x1400476BB\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400476BB\ninstruction @ 0x1400476F0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400476F0\ninstruction @ 0x140047866\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x140047866\ninstruction @ 0x14007C691\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x14007C691\ninstruction @ 0x1400811D8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400811D8\ninstruction @ 0x140081581\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x140081581\ninstruction @ 0x140081581\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x140081581\ninstruction @ 0x14008165B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x14008165B\ninstruction @ 0x14008165B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x14008165B\ninstruction @ 0x1400816A3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400816A3\ninstruction @ 0x1400816A3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400816A3\n\nenumerate PE sections (5 matches)\nnamespace   load-code/pe                                                        \nauthor      @Ana06, @mr-tz                                                      \nscope       function                                                            \nmbc         Discovery::Code Discovery::Enumerate PE Sections [B0046.001]        \nreferences  https://0x00sec.org/t/reflective-dll-injection/3080,                \n            https://www.ired.team/offensive-security/code-injection-process-inj…\nfunction @ 0x14000ABC0\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x14000AEDB\n        or:\n          mnemonic: movzx @ 0x14000AEDB\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x14000AEFD\n              or:\n                mnemonic: movzx @ 0x14000AEFD\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x14000AEF0\n    count(basic block): 3 or more @ 0x14000ABC0, 0x14000ABFC, 0x14000AC1A, 0x14000AC3E, and 221 more...\n    optional:\n      offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x14000AE6A, 0x14000AF3C\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x14000ACEA, 0x14000AD69, 0x14000ADD2, 0x14000AFC9, and 28 more...\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x14000AEFD, 0x14000C177\n      operand[1].offset: 0x10 = IMAGE_SECTION_HEADER.SizeOfRawData @ 0x14000AE5A, 0x14000B412, 0x14000BA04, 0x14000BC9A, and 3 more...\nfunction @ 0x14001EFE0\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x14001F0CD\n        or:\n          mnemonic: movzx @ 0x14001F0CD\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x14001F19E\n              or:\n                mnemonic: movzx @ 0x14001F19E\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x14001F158\n    count(basic block): 3 or more @ 0x14001EFE0, 0x14001EFFB, 0x14001F005, 0x14001F010, and 9 more...\n    optional:\n      offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x14001F3CA\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x14001F031, 0x14001F380\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x14001F19E\nfunction @ 0x14001F520\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x14001F5DE\n        or:\n          mnemonic: movzx @ 0x14001F5DE\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x14001F670\n              or:\n                mnemonic: movzx @ 0x14001F670\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x14001F754\n    count(basic block): 3 or more @ 0x14001F520, 0x14001F538, 0x14001F9FF, 0x14001FA15, and 1 more...\n    optional:\n      offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x14001F9B4\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x14001F538, 0x14001F8CC\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x14001F670\n      operand[1].offset: 0x10 = IMAGE_SECTION_HEADER.SizeOfRawData @ 0x14001F6BC\nfunction @ 0x14006CD60\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x14006CF20\n        or:\n          mnemonic: movzx @ 0x14006CF20\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x14006CE23\n              or:\n                mnemonic: movzx @ 0x14006CE23\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x14006CDC0\n    count(basic block): 3 or more @ 0x14006CD60, 0x14006CD6E, 0x14006CD91, 0x14006CDB6, and 19 more...\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x14006CED7\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x14006CE23\n      operand[1].offset: 0x10 = IMAGE_SECTION_HEADER.SizeOfRawData @ 0x14006CE09, 0x14006CE7C\nfunction @ 0x1400D9E90\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x1400D9E9F\n        or:\n          mnemonic: movzx @ 0x1400D9E9F\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x1400D9E9A\n              or:\n                mnemonic: movzx @ 0x1400D9E9A\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x1400D9EA4\n    count(basic block): 3 or more @ 0x1400D9E90, 0x1400D9EB0, 0x1400D9EB9, 0x1400D9EC4, and 2 more...\n    optional:\n      offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x1400D9E90\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x1400D9EB0\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x1400D9E9A\n\nparse PE header (3 matches)\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x14000ABC0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x14000AC3E, 0x14000AC5D, 0x14000AC65, 0x14000ACAB, and 121 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x14000AEB7\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x14000AE93\n      optional:\n        and:\n          operand[1].offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x14000AE6A, 0x14000AF3C\n          or:\n            and:\n              arch: amd64\n              operand[1].offset: 0x50 = IMAGE_NT_HEADERS64.OptionalHeader.SizeOfImage @ 0x14000ABD3, 0x14000B7E6, 0x14000C76E, 0x14000C8C4, and 2 more...\n              operand[1].offset: 0x30 = IMAGE_NT_HEADERS64.OptionalHeader.ImageBase @ 0x14000AC14, 0x14000C009, 0x14000D7A1\nfunction @ 0x1400D6A2C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1400D6A42, 0x1400D6A4B, 0x1400D6A59, 0x1400D6A60, and 1 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x1400D6A4B\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x1400D6A3D\nfunction @ 0x1400D9F30\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1400D9F35, 0x1400D9F41, 0x1400D9F50\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x1400D9F41\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x1400D9F30\n\nresolve function by parsing PE exports (2 matches)\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x14000AB20\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x14000AB20\n      mnemonic: movzx @ 0x14000AB93\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x14000AB38\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x14000AB3C\n      3 or more:\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x14000AB4F\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x14000AB49\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x14000AB46\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x14000AB56\nfunction @ 0x14000ABC0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x14000ABC0\n      mnemonic: movzx @ 0x14000AE6A, 0x14000AE6F, 0x14000AE7B, 0x14000AE87, and 6 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x14000AE6A, 0x14000AF3C\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x14000C2FA\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x14000AEFD, 0x14000C177\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x14000AE1C, 0x14000B431, 0x14000B7F5, 0x14000B805, and 16 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x14000AE11, 0x14000AEA8, 0x14000AEF0, 0x14000AF1E, and 3 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x14000AF0D, 0x14000C64B\n\ncompiled with .NET AoT\nnamespace    runtime/dotnet                                                     \nauthor       still@teamt5.org                                                   \nscope        file                                                               \nreferences   https://learn.microsoft.com/en-us/dotnet/core/deploying/native-aot/\ndescription  compiled using .NET Ahead-of-Time (AoT) compilation                \nand:\n  substring: .NETCoreApp,Version=\n    - \"rMr0.NETCoreApp,Version=v9.0\" @ file+0xDACCF\n  2 or more:\n    substring: https://aka.ms/nativeaot-compatibilit\n      - \"'{0}' is missing native code or metadata. This can happen for code that is not \ncompatible with trimming or AOT. Inspect and fix trimming and AOT related \nwarnings that were generated when the app was published. For more information \nsee https://aka.ms/nativeaot-compatibilit\" @ file+0x162543\n      - \"'{0}' is missing structure marshalling data. This can happen for code that is \nnot compatible with AOT. Inspect and fix AOT related warnings that were \ngenerated when the app was published. For more information see \nhttps://aka.ms/nativeaot-compatibilit\" @ file+0x16276D\n    substring: removed by the AOT compiler\n      - \"The body of this instance method was removed by the AOT compiler. This can \nhappen if the owning type was not seen as allocated by the AOT compiler\" @ file+0x16F969\n      - \"The body of this method was removed by the AOT compiler because it's not \ncallable\" @ file+0x16FA96\n\n\n\n"},"hashes":{"md5":"e19293ba06f288b511cb5697b3c2c195","sha1":"10214a6b85cc071194553f5939cd3a0a5bf3d1a3","sha256":"ccdc3e99b62d1b0b4b86a74896c1c1a45ee9a43bba9264fad162eb0116c49033"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 3945</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 207955</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"ccdc3e9\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"e19293ba06f288b511cb5697b3c2c195\",\n        \"sha256\": \"ccdc3e99b62d1b0b4b86a74896c1c1a45ee9a43bba9264fad162eb0\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_peb_access__30_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"PEB access (30 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Process Environment\",\n        \"Block [B0001.019]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x14002D680\",\n      \"label\": \"Block 0x14002D680\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14002D680\"\n    },\n    {\n      \"id\": \"cap_allocate_memory__13_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"allocate memory (13 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x14004DFC0\",\n      \"label\": \"Block 0x14004DFC0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14004DFC0\"\n    },\n    {\n      \"id\": \"api_VirtualAlloc\",\n      \"label\": \"VirtualAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_loop__980_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (980 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x140002080\",\n      \"label\": \"Function 0x140002080\",\n      \"type\": \"function\",\n      \"address\": \"0x140002080\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_delay_execution__15_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (15 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x14002B3F5\",\n      \"label\": \"Block 0x14002B3F5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14002B3F5\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_os_version__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"get OS version (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x140077350\",\n      \"label\": \"Function 0x140077350\",\n      \"type\": \"function\",\n      \"address\": \"0x140077350\"\n    },\n    {\n      \"id\": \"api_VerifyVersionInfo\",\n      \"label\": \"VerifyVersionInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_VerSetConditionMask\",\n      \"label\": \"VerSetConditionMask\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_check_for_time_delay_via_queryperformancecounter__2_matches_\",\n      \"label\": \"check for time delay via QueryPerformanceCounter (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"QueryPerformanceCounter [B0001.033]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140085F80\",\n      \"label\": \"Function 0x140085F80\",\n      \"type\": \"function\",\n      \"address\": \"0x140085F80\"\n    },\n    {\n      \"id\": \"func_0x14002E7A0\",\n      \"label\": \"Function 0x14002E7A0\",\n      \"type\": \"function\",\n      \"address\": \"0x14002E7A0\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"QueryPerformanceCounter [B0001.033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_obfuscated_stackstrings__3_matches_\",\n      \"label\": \"contain obfuscated stackstrings (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x140003BDB\",\n      \"label\": \"Block 0x140003BDB\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140003BDB\"\n    },\n    {\n      \"id\": \"bb_0x140014C3A\",\n      \"label\": \"Block 0x140014C3A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140014C3A\"\n    },\n    {\n      \"id\": \"bb_0x140014D1D\",\n      \"label\": \"Block 0x140014D1D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140014D1D\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_decode_data_using_base64_via_dword_translation_table\",\n      \"label\": \"decode data using Base64 via dword translation table\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14001E080\",\n      \"label\": \"Function 0x14001E080\",\n      \"type\": \"function\",\n      \"address\": \"0x14001E080\"\n    },\n    {\n      \"id\": \"cap_author_____gilbert_elliot_mandiant_com__sara_rincon_mandiant_com\",\n      \"label\": \"author     gilbert.elliot@mandiant.com, sara.rincon@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_using_fnv__2_matches_\",\n      \"label\": \"hash data using fnv (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::FNV [C0030.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140012E20\",\n      \"label\": \"Function 0x140012E20\",\n      \"type\": \"function\",\n      \"address\": \"0x140012E20\"\n    },\n    {\n      \"id\": \"func_0x140012A60\",\n      \"label\": \"Function 0x140012A60\",\n      \"type\": \"function\",\n      \"address\": \"0x140012A60\"\n    },\n    {\n      \"id\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author       moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::FNV [C0030.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_using_murmur3__3_matches_\",\n      \"label\": \"hash data using murmur3 (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::MurmurHash [C0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14006F740\",\n      \"label\": \"Function 0x14006F740\",\n      \"type\": \"function\",\n      \"address\": \"0x14006F740\"\n    },\n    {\n      \"id\": \"func_0x140020680\",\n      \"label\": \"Function 0x140020680\",\n      \"type\": \"function\",\n      \"address\": \"0x140020680\"\n    },\n    {\n      \"id\": \"func_0x14006DDC0\",\n      \"label\": \"Function 0x14006DDC0\",\n      \"type\": \"function\",\n      \"address\": \"0x14006DDC0\"\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::MurmurHash [C0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_using_sha1\",\n      \"label\": \"hash data using SHA1\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash::SHA1 [C0029.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140026FA0\",\n      \"label\": \"Function 0x140026FA0\",\n      \"type\": \"function\",\n      \"address\": \"0x140026FA0\"\n    },\n    {\n      \"id\": \"cap_william_ballenthin_mandiant_com\",\n      \"label\": \"william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash::SHA1 [C0029.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_via_winapi\",\n      \"label\": \"generate random numbers via WinAPI\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140014E20\",\n      \"label\": \"Function 0x140014E20\",\n      \"type\": \"function\",\n      \"address\": \"0x140014E20\"\n    },\n    {\n      \"id\": \"api_BCryptGenRandom\",\n      \"label\": \"BCryptGenRandom\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable__5_matches_\",\n      \"label\": \"query environment variable (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400072E0\",\n      \"label\": \"Function 0x1400072E0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400072E0\"\n    },\n    {\n      \"id\": \"func_0x1400489A0\",\n      \"label\": \"Function 0x1400489A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400489A0\"\n    },\n    {\n      \"id\": \"func_0x140017B60\",\n      \"label\": \"Function 0x140017B60\",\n      \"type\": \"function\",\n      \"address\": \"0x140017B60\"\n    },\n    {\n      \"id\": \"func_0x140017470\",\n      \"label\": \"Function 0x140017470\",\n      \"type\": \"function\",\n      \"address\": \"0x140017470\"\n    },\n    {\n      \"id\": \"func_0x140082C10\",\n      \"label\": \"Function 0x140082C10\",\n      \"type\": \"function\",\n      \"address\": \"0x140082C10\"\n    },\n    {\n      \"id\": \"api_GetEnvironmentVariable\",\n      \"label\": \"GetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path\",\n      \"label\": \"get common file path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140017A00\",\n      \"label\": \"Function 0x140017A00\",\n      \"type\": \"function\",\n      \"address\": \"0x140017A00\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory\",\n      \"label\": \"create directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes\",\n      \"label\": \"get file attributes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x14000E023\",\n      \"label\": \"Block 0x14000E023\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14000E023\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size__2_matches_\",\n      \"label\": \"get file size (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140009400\",\n      \"label\": \"Function 0x140009400\",\n      \"type\": \"function\",\n      \"address\": \"0x140009400\"\n    },\n    {\n      \"id\": \"func_0x1400092E0\",\n      \"label\": \"Function 0x1400092E0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400092E0\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_file_on_windows\",\n      \"label\": \"read file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__4_matches_\",\n      \"label\": \"write file on Windows (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14000DE00\",\n      \"label\": \"Function 0x14000DE00\",\n      \"type\": \"function\",\n      \"address\": \"0x14000DE00\"\n    },\n    {\n      \"id\": \"func_0x140048530\",\n      \"label\": \"Function 0x140048530\",\n      \"type\": \"function\",\n      \"address\": \"0x140048530\"\n    },\n    {\n      \"id\": \"func_0x1400818F0\",\n      \"label\": \"Function 0x1400818F0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400818F0\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_number_of_processors__18_matches_\",\n      \"label\": \"get number of processors (18 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400D00A0\",\n      \"label\": \"Function 0x1400D00A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D00A0\"\n    },\n    {\n      \"id\": \"func_0x1400D58E0\",\n      \"label\": \"Function 0x1400D58E0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D58E0\"\n    },\n    {\n      \"id\": \"func_0x1400D4450\",\n      \"label\": \"Function 0x1400D4450\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D4450\"\n    },\n    {\n      \"id\": \"func_0x1400D16D0\",\n      \"label\": \"Function 0x1400D16D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D16D0\"\n    },\n    {\n      \"id\": \"func_0x1400D1BC0\",\n      \"label\": \"Function 0x1400D1BC0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D1BC0\"\n    },\n    {\n      \"id\": \"func_0x1400D31F0\",\n      \"label\": \"Function 0x1400D31F0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D31F0\"\n    },\n    {\n      \"id\": \"func_0x1400D3A80\",\n      \"label\": \"Function 0x1400D3A80\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D3A80\"\n    },\n    {\n      \"id\": \"func_0x1400D2320\",\n      \"label\": \"Function 0x1400D2320\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D2320\"\n    },\n    {\n      \"id\": \"func_0x1400D1400\",\n      \"label\": \"Function 0x1400D1400\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D1400\"\n    },\n    {\n      \"id\": \"func_0x1400D2620\",\n      \"label\": \"Function 0x1400D2620\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D2620\"\n    },\n    {\n      \"id\": \"func_0x1400D2810\",\n      \"label\": \"Function 0x1400D2810\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D2810\"\n    },\n    {\n      \"id\": \"func_0x1400D2500\",\n      \"label\": \"Function 0x1400D2500\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D2500\"\n    },\n    {\n      \"id\": \"func_0x1400D3D00\",\n      \"label\": \"Function 0x1400D3D00\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D3D00\"\n    },\n    {\n      \"id\": \"func_0x1400D4D10\",\n      \"label\": \"Function 0x1400D4D10\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D4D10\"\n    },\n    {\n      \"id\": \"func_0x1400D2BE0\",\n      \"label\": \"Function 0x1400D2BE0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D2BE0\"\n    },\n    {\n      \"id\": \"func_0x1400CFBB0\",\n      \"label\": \"Function 0x1400CFBB0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400CFBB0\"\n    },\n    {\n      \"id\": \"func_0x1400D01A0\",\n      \"label\": \"Function 0x1400D01A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D01A0\"\n    },\n    {\n      \"id\": \"func_0x1400D5C00\",\n      \"label\": \"Function 0x1400D5C00\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D5C00\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_memory_capacity__2_matches_\",\n      \"label\": \"get memory capacity (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400874F0\",\n      \"label\": \"Function 0x1400874F0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400874F0\"\n    },\n    {\n      \"id\": \"func_0x140087120\",\n      \"label\": \"Function 0x140087120\",\n      \"type\": \"function\",\n      \"address\": \"0x140087120\"\n    },\n    {\n      \"id\": \"api_GlobalMemoryStatusEx\",\n      \"label\": \"GlobalMemoryStatusEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_access_the_windows_event_log\",\n      \"label\": \"access the Windows event log\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery::Log File [E1083.m01]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140049020\",\n      \"label\": \"Function 0x140049020\",\n      \"type\": \"function\",\n      \"address\": \"0x140049020\"\n    },\n    {\n      \"id\": \"api_ReportEvent\",\n      \"label\": \"ReportEvent\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_system_information_on_windows\",\n      \"label\": \"get system information on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140087750\",\n      \"label\": \"Function 0x140087750\",\n      \"type\": \"function\",\n      \"address\": \"0x140087750\"\n    },\n    {\n      \"id\": \"api_GetSystemInfo\",\n      \"label\": \"GetSystemInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows\",\n      \"label\": \"create process on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x14000E153\",\n      \"label\": \"Block 0x14000E153\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14000E153\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_modify_access_privileges\",\n      \"label\": \"modify access privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"api_AdjustTokenPrivileges\",\n      \"label\": \"AdjustTokenPrivileges\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value\",\n      \"label\": \"set registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140009AD0\",\n      \"label\": \"Function 0x140009AD0\",\n      \"type\": \"function\",\n      \"address\": \"0x140009AD0\"\n    },\n    {\n      \"id\": \"api_RegCreateKeyEx\",\n      \"label\": \"RegCreateKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_create_thread__3_matches_\",\n      \"label\": \"create thread (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x140047FD0\",\n      \"label\": \"Block 0x140047FD0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140047FD0\"\n    },\n    {\n      \"id\": \"bb_0x1400819F0\",\n      \"label\": \"Block 0x1400819F0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400819F0\"\n    },\n    {\n      \"id\": \"bb_0x1400819B0\",\n      \"label\": \"Block 0x1400819B0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400819B0\"\n    },\n    {\n      \"id\": \"api_CreateThread\",\n      \"label\": \"CreateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_resume_thread__4_matches_\",\n      \"label\": \"resume thread (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Resume Thread [C0054]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x140048140\",\n      \"label\": \"Block 0x140048140\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140048140\"\n    },\n    {\n      \"id\": \"bb_0x140081A25\",\n      \"label\": \"Block 0x140081A25\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140081A25\"\n    },\n    {\n      \"id\": \"bb_0x140081769\",\n      \"label\": \"Block 0x140081769\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140081769\"\n    },\n    {\n      \"id\": \"api_ResumeThread\",\n      \"label\": \"ResumeThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Resume Thread [C0054]\"\n      ]\n    },\n    {\n      \"id\": \"cap_suspend_thread__2_matches_\",\n      \"label\": \"suspend thread (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Suspend Thread [C0055]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x140081718\",\n      \"label\": \"Block 0x140081718\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140081718\"\n    },\n    {\n      \"id\": \"api_SuspendThread\",\n      \"label\": \"SuspendThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"label\": \"access PEB ldr_data (22 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x140079140\",\n      \"label\": \"Block 0x140079140\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140079140\"\n    },\n    {\n      \"id\": \"bb_0x140079360\",\n      \"label\": \"Block 0x140079360\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140079360\"\n    },\n    {\n      \"id\": \"bb_0x140082D90\",\n      \"label\": \"Block 0x140082D90\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140082D90\"\n    },\n    {\n      \"id\": \"bb_0x1400D2741\",\n      \"label\": \"Block 0x1400D2741\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400D2741\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__12_matches_\",\n      \"label\": \"link function at runtime on Windows (12 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_pe_sections__5_matches_\",\n      \"label\": \"enumerate PE sections (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400D9E90\",\n      \"label\": \"Function 0x1400D9E90\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D9E90\"\n    },\n    {\n      \"id\": \"func_0x14000ABC0\",\n      \"label\": \"Function 0x14000ABC0\",\n      \"type\": \"function\",\n      \"address\": \"0x14000ABC0\"\n    },\n    {\n      \"id\": \"func_0x14001EFE0\",\n      \"label\": \"Function 0x14001EFE0\",\n      \"type\": \"function\",\n      \"address\": \"0x14001EFE0\"\n    },\n    {\n      \"id\": \"func_0x14006CD60\",\n      \"label\": \"Function 0x14006CD60\",\n      \"type\": \"function\",\n      \"address\": \"0x14006CD60\"\n    },\n    {\n      \"id\": \"func_0x14001F520\",\n      \"label\": \"Function 0x14001F520\",\n      \"type\": \"function\",\n      \"address\": \"0x14001F520\"\n    },\n    {\n      \"id\": \"cap_author_______ana06___mr_tz\",\n      \"label\": \"author      @Ana06, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header__3_matches_\",\n      \"label\": \"parse PE header (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400D9F30\",\n      \"label\": \"Function 0x1400D9F30\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D9F30\"\n    },\n    {\n      \"id\": \"func_0x1400D6A2C\",\n      \"label\": \"Function 0x1400D6A2C\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D6A2C\"\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports__2_matches_\",\n      \"label\": \"resolve function by parsing PE exports (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x14000AB20\",\n      \"label\": \"Function 0x14000AB20\",\n      \"type\": \"function\",\n      \"address\": \"0x14000AB20\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compiled_with__net_aot\",\n      \"label\": \"compiled with .NET AoT\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______still_teamt5_org\",\n      \"label\": \"author       still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_peb_access__30_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_peb_access__30_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x14002D680\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_memory__13_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_memory__13_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x14004DFC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x14004DFC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__980_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__980_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x140002080\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__15_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__15_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x14002B3F5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_os_version__4_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x140077350\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140077350\",\n      \"target\": \"api_VerifyVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140077350\",\n      \"target\": \"api_VerSetConditionMask\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_time_delay_via_queryperformancecounter__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_queryperformancecounter__2_matches_\",\n      \"target\": \"func_0x140085F80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_queryperformancecounter__2_matches_\",\n      \"target\": \"func_0x14002E7A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140085F80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14002E7A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_obfuscated_stackstrings__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__3_matches_\",\n      \"target\": \"bb_0x140003BDB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__3_matches_\",\n      \"target\": \"bb_0x140014C3A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__3_matches_\",\n      \"target\": \"bb_0x140014D1D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x140003BDB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x140014C3A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x140014D1D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decode_data_using_base64_via_dword_translation_table\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_decode_data_using_base64_via_dword_translation_table\",\n      \"target\": \"func_0x14001E080\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____gilbert_elliot_mandiant_com__sara_rincon_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____gilbert_elliot_mandiant_com__sara_rincon_mandiant_com\",\n      \"target\": \"func_0x14001E080\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_fnv__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__2_matches_\",\n      \"target\": \"func_0x140012E20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv__2_matches_\",\n      \"target\": \"func_0x140012A60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140012E20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140012A60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_murmur3__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_murmur3__3_matches_\",\n      \"target\": \"func_0x14006F740\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_murmur3__3_matches_\",\n      \"target\": \"func_0x140020680\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_murmur3__3_matches_\",\n      \"target\": \"func_0x14006DDC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x14006F740\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x140020680\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x14006DDC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_sha1\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_sha1\",\n      \"target\": \"func_0x140026FA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x140026FA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_via_winapi\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_via_winapi\",\n      \"target\": \"func_0x140014E20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140014E20\",\n      \"target\": \"api_BCryptGenRandom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x140014E20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140014E20\",\n      \"target\": \"api_BCryptGenRandom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__5_matches_\",\n      \"target\": \"func_0x1400072E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__5_matches_\",\n      \"target\": \"func_0x1400489A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__5_matches_\",\n      \"target\": \"func_0x140017B60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__5_matches_\",\n      \"target\": \"func_0x140017470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__5_matches_\",\n      \"target\": \"func_0x140082C10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400072E0\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400489A0\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140017B60\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140017470\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140082C10\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x1400072E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x1400489A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x140017B60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x140017470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x140082C10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400072E0\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400489A0\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140017B60\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140017470\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140082C10\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path\",\n      \"target\": \"func_0x140017A00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140017A00\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140017A00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140017A00\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory\",\n      \"target\": \"func_0x1400072E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400072E0\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400072E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400072E0\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes\",\n      \"target\": \"bb_0x14000E023\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x14000E023\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x140009400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x1400092E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140009400\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400092E0\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140009400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400092E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140009400\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400092E0\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows\",\n      \"target\": \"func_0x140009400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140009400\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009400\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140009400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140009400\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009400\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__4_matches_\",\n      \"target\": \"func_0x14000DE00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__4_matches_\",\n      \"target\": \"func_0x140048530\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__4_matches_\",\n      \"target\": \"func_0x140009400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__4_matches_\",\n      \"target\": \"func_0x1400818F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000DE00\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140048530\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009400\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400818F0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000DE00\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140048530\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009400\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400818F0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x14000DE00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140048530\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140009400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400818F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14000DE00\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140048530\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009400\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400818F0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14000DE00\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140048530\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009400\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400818F0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_number_of_processors__18_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D00A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D58E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D4450\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D16D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D1BC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D31F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D3A80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D2320\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D1400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D2620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D2810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D2500\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D3D00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D4D10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D2BE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400CFBB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D01A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors__18_matches_\",\n      \"target\": \"func_0x1400D5C00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D00A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D58E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D4450\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D16D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D1BC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D31F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D3A80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D2320\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D1400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D2620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D2810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D2500\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D3D00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D4D10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D2BE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400CFBB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D01A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D5C00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_memory_capacity__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_memory_capacity__2_matches_\",\n      \"target\": \"func_0x1400874F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_memory_capacity__2_matches_\",\n      \"target\": \"func_0x140087120\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400874F0\",\n      \"target\": \"api_GlobalMemoryStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140087120\",\n      \"target\": \"api_GlobalMemoryStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400874F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140087120\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400874F0\",\n      \"target\": \"api_GlobalMemoryStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140087120\",\n      \"target\": \"api_GlobalMemoryStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_the_windows_event_log\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_access_the_windows_event_log\",\n      \"target\": \"func_0x140049020\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140049020\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140049020\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140049020\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_system_information_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_system_information_on_windows\",\n      \"target\": \"func_0x140087750\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140087750\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x140087750\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140087750\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows\",\n      \"target\": \"bb_0x14000E153\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x14000E153\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_modify_access_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value\",\n      \"target\": \"func_0x140009AD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140009AD0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009AD0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140009AD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140009AD0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140009AD0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread__3_matches_\",\n      \"target\": \"bb_0x140047FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__3_matches_\",\n      \"target\": \"bb_0x1400819F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__3_matches_\",\n      \"target\": \"bb_0x1400819B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x140047FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x1400819F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x1400819B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resume_thread__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resume_thread__4_matches_\",\n      \"target\": \"bb_0x140048140\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resume_thread__4_matches_\",\n      \"target\": \"bb_0x140081A25\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resume_thread__4_matches_\",\n      \"target\": \"bb_0x140081769\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x140048140\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x140081A25\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x140081769\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_suspend_thread__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_suspend_thread__2_matches_\",\n      \"target\": \"bb_0x140081718\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x140081718\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x140079140\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x140079360\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x140082D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__22_matches_\",\n      \"target\": \"bb_0x1400D2741\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x140079140\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x140079360\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x140082D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1400D2741\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__12_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_pe_sections__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__5_matches_\",\n      \"target\": \"func_0x1400D9E90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__5_matches_\",\n      \"target\": \"func_0x14000ABC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__5_matches_\",\n      \"target\": \"func_0x14001EFE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__5_matches_\",\n      \"target\": \"func_0x14006CD60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__5_matches_\",\n      \"target\": \"func_0x14001F520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______ana06___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x1400D9E90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x14000ABC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x14001EFE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x14006CD60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x14001F520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__3_matches_\",\n      \"target\": \"func_0x1400D9F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__3_matches_\",\n      \"target\": \"func_0x14000ABC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__3_matches_\",\n      \"target\": \"func_0x1400D6A2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400D9F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x14000ABC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400D6A2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__2_matches_\",\n      \"target\": \"func_0x14000AB20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__2_matches_\",\n      \"target\": \"func_0x14000ABC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x14000AB20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x14000ABC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_with__net_aot\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-17 20:25:25.201121\",\n    \"total_functions\": \"3945\",\n    \"total_features\": \"207955\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-17 20:25:29"}
{"_id":{"$oid":"6a5b46f7b3bed57e0e737875"},"sha256":"282ed357bde9bd0910eae7c7f373f2657989dd67adb44efd713f8d35eac003a3","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":true,"path":"/tmp/sdm_capa_jlntgbju/Lf4hTq89oy-019f748179807fa0927ba9e5bbce012a.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_jlntgbju/Lf4hTq89oy-019f748179807fa0927ba9e5bbce012a.exe_very_verbose.txt"}},"outputs":{"normal":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"md5                     8321c2999f517b47ac8238b6d5f79f6b                        \nsha1                    70efe3d256d085be8e3be4f1064f56ece4f93d85                \nsha256                  282ed357bde9bd0910eae7c7f373f2657989dd67adb44efd713f8d3…\npath                    /home/apogean/projects/malware/windows/all_runs/Lf4hTq8…\ntimestamp               2026-07-18 14:56:25.783269                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIHUhhmy/rules                                   \nfunction count          4                                                       \nlibrary function count  0                                                       \ntotal feature count     52787                                                   \n\npacked with Themida\nnamespace  anti-analysis/packer/themida\nscope      file                        \n\ndecompress data using aPLib\nnamespace    data-manipulation/compression                  \ndescription  detects decompression function of library aPLib\nscope        function                                       \nmatches      0xC02268                                       \n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls\nscope      file                     \n\n\n\n","very_verbose":"md5                     8321c2999f517b47ac8238b6d5f79f6b                        \nsha1                    70efe3d256d085be8e3be4f1064f56ece4f93d85                \nsha256                  282ed357bde9bd0910eae7c7f373f2657989dd67adb44efd713f8d3…\npath                    /home/apogean/projects/malware/windows/all_runs/Lf4hTq8…\ntimestamp               2026-07-18 14:57:18.845913                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIJFM9n1/rules                                   \nfunction count          4                                                       \nlibrary function count  0                                                       \ntotal feature count     52787                                                   \n\ncontain loop (3 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x472A47\n  or:\n    characteristic: loop @ 0x472A47\n\npacked with Themida\nnamespace   anti-analysis/packer/themida                                        \nauthor      william.ballenthin@mandiant.com                                     \nscope       file                                                                \natt&ck      Defense Evasion::Obfuscated Files or Information::Software Packing  \n            [T1027.002]                                                         \nmbc         Anti-Static Analysis::Software Packing::Themida [F0001.011]         \nreferences  https://www.hexacorn.com/blog/2016/12/15/pe-section-names-re-visite…\nor:\n  section: .themida @ 0x7B6000\n  count(section(        )): 2 or more @ 0x401000, 0x652000, 0x6CB000, 0x798000, and 1 more...\n\ndecompress data using aPLib\nnamespace    data-manipulation/compression                                      \nauthor       @r3c0nst (Frank Boldewin), moritz.raabe@mandiant.com,              \n             cdong49@gatech.edu, still@teamt5.org                               \nscope        function                                                           \nmbc          Data::Decompress Data::aPLib [C0025.003]                           \nreferences   https://ibsensoftware.com/files/aPLib-1.1.1.zip                    \ndescription  detects decompression function of library aPLib                    \nfunction @ 0xC02268\n  and: = aP_depack\n    match: contain loop @ 0xC02268\n      or:\n        characteristic: loop @ 0xC02268\n    instruction:\n      and:\n        mnemonic: cmp @ 0xC0235C\n        or:\n          number: 0x7D00 @ 0xC0235C\n    instruction:\n      and:\n        mnemonic: cmp @ 0xC02378\n        or:\n          number: 0x7F @ 0xC02378\n    instruction:\n      and:\n        mnemonic: shl @ 0xC02339\n        number: 0x8 @ 0xC02339\n    instruction:\n      and:\n        mnemonic: shr @ 0xC02392\n        number: 0x1 @ 0xC02392\n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls   \nauthor     michael.hunhoff@mandiant.com\nscope      file                        \nsection: .tls @ 0x7B5000\n\n(internal) packer file limitation\nnamespace    internal/limitation/static                                         \nauthor       william.ballenthin@mandiant.com                                    \nscope        file                                                               \ndescription  This sample appears to be packed.                                  \n                                                                                \n             Packed samples have often been obfuscated to hide their logic.     \n             capa cannot handle obfuscation well using static analysis. This    \n             means the results may be misleading or incomplete.                 \n             If possible, you should try to unpack this input file before       \n             analyzing it with capa.                                            \n             Alternatively, run the sample in a supported sandbox and invoke    \n             capa against the report to obtain dynamic analysis results.        \n                                                                                \nor:\n  match: anti-analysis/packer @ global\n    or:\n      section: .themida @ 0x7B6000\n      count(section(        )): 2 or more @ 0x401000, 0x652000, 0x6CB000, 0x798000, and 1 more...\n\n\n\n"},"hashes":{"md5":"8321c2999f517b47ac8238b6d5f79f6b","sha1":"70efe3d256d085be8e3be4f1064f56ece4f93d85","sha256":"282ed357bde9bd0910eae7c7f373f2657989dd67adb44efd713f8d35eac003a3"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 4</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 52787</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"Lf4hTq8\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"8321c2999f517b47ac8238b6d5f79f6b\",\n        \"sha256\": \"282ed357bde9bd0910eae7c7f373f2657989dd67adb44efd713f8d3\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__3_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (3 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x472A47\",\n      \"label\": \"Function 0x472A47\",\n      \"type\": \"function\",\n      \"address\": \"0x472A47\"\n    },\n    {\n      \"id\": \"cap_packed_with_themida\",\n      \"label\": \"packed with Themida\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Software Packing::Themida [F0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Software Packing::Themida [F0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_decompress_data_using_aplib\",\n      \"label\": \"decompress data using aPLib\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decompress Data::aPLib [C0025.003]\"\n      ]\n    },\n    {\n      \"id\": \"func_0xC02268\",\n      \"label\": \"Function 0xC02268\",\n      \"type\": \"function\",\n      \"address\": \"0xC02268\"\n    },\n    {\n      \"id\": \"cap_cdong49_gatech_edu__still_teamt5_org\",\n      \"label\": \"cdong49@gatech.edu, still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decompress Data::aPLib [C0025.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"label\": \"contain a thread local storage (.tls) section\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap__internal__packer_file_limitation\",\n      \"label\": \"(internal) packer file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__3_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__3_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x472A47\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_packed_with_themida\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decompress_data_using_aplib\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_decompress_data_using_aplib\",\n      \"target\": \"func_0xC02268\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_cdong49_gatech_edu__still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_cdong49_gatech_edu__still_teamt5_org\",\n      \"target\": \"func_0xC02268\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal__packer_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-18 14:57:18.845913\",\n    \"total_functions\": \"4\",\n    \"total_features\": \"52787\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-18 14:57:19"}
{"_id":{"$oid":"6a5b549cb3bed57e0e737879"},"sha256":"59325c2ad72a1cea4c72822ff917f128909ad0d149d404585fcfcf8b46368c69","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":true,"path":"/tmp/sdm_capa_v96qu4yj/ZKm9GeoUlo-019f74acd1537701bc8d0496bbb37230.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_v96qu4yj/ZKm9GeoUlo-019f74acd1537701bc8d0496bbb37230.exe_very_verbose.txt"}},"outputs":{"normal":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"md5                     5502790712c2ea2789655cc537ebf09d                        \nsha1                    fdc028e7618e05e025e1b5b9e686e8156ca8e50c                \nsha256                  59325c2ad72a1cea4c72822ff917f128909ad0d149d404585fcfcf8…\npath                    /home/apogean/projects/malware/windows/all_runs/ZKm9Geo…\ntimestamp               2026-07-18 15:54:21.915898                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x140000000                                             \nrules                   /tmp/_MEIJZU0hP/rules                                   \nfunction count          2                                                       \nlibrary function count  0                                                       \ntotal feature count     101409                                                  \n\npacked with Themida\nnamespace  anti-analysis/packer/themida\nscope      file                        \n\ndecompress data using aPLib\nnamespace    data-manipulation/compression                  \ndescription  detects decompression function of library aPLib\nscope        function                                       \nmatches      0x140C94210                                    \n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls\nscope      file                     \n\n\n\n","very_verbose":"md5                     5502790712c2ea2789655cc537ebf09d                        \nsha1                    fdc028e7618e05e025e1b5b9e686e8156ca8e50c                \nsha256                  59325c2ad72a1cea4c72822ff917f128909ad0d149d404585fcfcf8…\npath                    /home/apogean/projects/malware/windows/all_runs/ZKm9Geo…\ntimestamp               2026-07-18 15:55:31.478760                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x140000000                                             \nrules                   /tmp/_MEIvElngX/rules                                   \nfunction count          2                                                       \nlibrary function count  0                                                       \ntotal feature count     101409                                                  \n\ncontain loop (library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x140C94210\n  or:\n    characteristic: loop @ 0x140C94210\n\npacked with Themida\nnamespace   anti-analysis/packer/themida                                        \nauthor      william.ballenthin@mandiant.com                                     \nscope       file                                                                \natt&ck      Defense Evasion::Obfuscated Files or Information::Software Packing  \n            [T1027.002]                                                         \nmbc         Anti-Static Analysis::Software Packing::Themida [F0001.011]         \nreferences  https://www.hexacorn.com/blog/2016/12/15/pe-section-names-re-visite…\nor:\n  section: .themida @ 0x14071C000\n  count(section(        )): 2 or more @ 0x140001000, 0x140012000, 0x140015000, 0x140714000, and 4 more...\n\ndecompress data using aPLib\nnamespace    data-manipulation/compression                                      \nauthor       @r3c0nst (Frank Boldewin), moritz.raabe@mandiant.com,              \n             cdong49@gatech.edu, still@teamt5.org                               \nscope        function                                                           \nmbc          Data::Decompress Data::aPLib [C0025.003]                           \nreferences   https://ibsensoftware.com/files/aPLib-1.1.1.zip                    \ndescription  detects decompression function of library aPLib                    \nfunction @ 0x140C94210\n  and: = aP_depack\n    match: contain loop @ 0x140C94210\n      or:\n        characteristic: loop @ 0x140C94210\n    instruction:\n      and:\n        mnemonic: cmp @ 0x140C9432F\n        or:\n          number: 0x7D00 @ 0x140C9432F\n    instruction:\n      and:\n        mnemonic: cmp @ 0x140C9434E\n        or:\n          number: 0x7F @ 0x140C9434E\n    instruction:\n      and:\n        mnemonic: shl @ 0x140C94306\n        number: 0x8 @ 0x140C94306\n    instruction:\n      and:\n        mnemonic: shr @ 0x140C9436C\n        number: 0x1 @ 0x140C9436C\n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls   \nauthor     michael.hunhoff@mandiant.com\nscope      file                        \nsection: .tls @ 0x14071A000\n\n(internal) packer file limitation\nnamespace    internal/limitation/static                                         \nauthor       william.ballenthin@mandiant.com                                    \nscope        file                                                               \ndescription  This sample appears to be packed.                                  \n                                                                                \n             Packed samples have often been obfuscated to hide their logic.     \n             capa cannot handle obfuscation well using static analysis. This    \n             means the results may be misleading or incomplete.                 \n             If possible, you should try to unpack this input file before       \n             analyzing it with capa.                                            \n             Alternatively, run the sample in a supported sandbox and invoke    \n             capa against the report to obtain dynamic analysis results.        \n                                                                                \nor:\n  match: anti-analysis/packer @ global\n    or:\n      section: .themida @ 0x14071C000\n      count(section(        )): 2 or more @ 0x140001000, 0x140012000, 0x140015000, 0x140714000, and 4 more...\n\n\n\n"},"hashes":{"md5":"5502790712c2ea2789655cc537ebf09d","sha1":"fdc028e7618e05e025e1b5b9e686e8156ca8e50c","sha256":"59325c2ad72a1cea4c72822ff917f128909ad0d149d404585fcfcf8b46368c69"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 2</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 101409</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"ZKm9Geo\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"5502790712c2ea2789655cc537ebf09d\",\n        \"sha256\": \"59325c2ad72a1cea4c72822ff917f128909ad0d149d404585fcfcf8\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_packed_with_themida\",\n      \"label\": \"packed with Themida\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Software Packing::Themida [F0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Software Packing::Themida [F0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_decompress_data_using_aplib\",\n      \"label\": \"decompress data using aPLib\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decompress Data::aPLib [C0025.003]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140C94210\",\n      \"label\": \"Function 0x140C94210\",\n      \"type\": \"function\",\n      \"address\": \"0x140C94210\"\n    },\n    {\n      \"id\": \"cap_cdong49_gatech_edu__still_teamt5_org\",\n      \"label\": \"cdong49@gatech.edu, still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decompress Data::aPLib [C0025.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"label\": \"contain a thread local storage (.tls) section\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap__internal__packer_file_limitation\",\n      \"label\": \"(internal) packer file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_packed_with_themida\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decompress_data_using_aplib\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_decompress_data_using_aplib\",\n      \"target\": \"func_0x140C94210\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_cdong49_gatech_edu__still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_cdong49_gatech_edu__still_teamt5_org\",\n      \"target\": \"func_0x140C94210\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal__packer_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-18 15:55:31.478760\",\n    \"total_functions\": \"2\",\n    \"total_features\": \"101409\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-18 15:55:32"}
{"_id":{"$oid":"6a5b5b7db3bed57e0e73787c"},"sha256":"7df9619f4ebfbfae75755efb99f044815ecfb17a8077fe90b300da86fc9e49e7","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"6497fadf53f16529a9833256bfef4e5a","sha1":"b0164153e0d3c576c7944794705a0f82f70b695b","sha256":"7df9619f4ebfbfae75755efb99f044815ecfb17a8077fe90b300da86fc9e49e7"}},"timestamp":"2026-07-18 16:24:53"}
{"_id":{"$oid":"6a5b5d45b3bed57e0e73787e"},"sha256":"3fc1ee3e8ba9718c4c2de7ad73bf362911ea5463f380c189edff62e853b78af1","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: PowerPC                                                  \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"WARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: PowerPC                                                  \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"WARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: PowerPC                                                  \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: PowerPC                                                  \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: PowerPC                                                  \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: PowerPC                                                  \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: PowerPC                                                  \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: PowerPC                                                  \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: PowerPC                                                  \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"edd42ea3cfec3e66dc513f690d1a65ab","sha1":"7cec24bd8c6d9e79ca94c61cee4b102ab3c22948","sha256":"08ac1a0e15f169191786a2352f88b5ea527685a6dbaa15a58d4ebd62a5d8566f"}},"timestamp":"2026-07-18 16:32:29"}
{"_id":{"$oid":"6a5b5f6bb3bed57e0e737880"},"sha256":"840626f21fed3a7ef96f53a7ee2ebc04599ab21d937edba74b9988cd8358f26d","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"WARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"WARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.features.extractors.elffile: unsupported            elffile.py:179\n         architecture: MIPS                                                     \nERROR    capa:                                                    helpers.py:338\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:339\n         architecture.                                                          \nERROR    capa:                                                    helpers.py:340\nERROR    capa:  capa currently only supports analyzing x86 (32-   helpers.py:341\n         and 64-bit).                                                           \nERROR    capa:                                                    helpers.py:342\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"1262a2f24447836a0720bbcdaea98fd7","sha1":"db2e7d6d469d35a0850eed1f472125be91aafb0d","sha256":"840626f21fed3a7ef96f53a7ee2ebc04599ab21d937edba74b9988cd8358f26d"}},"timestamp":"2026-07-18 16:41:39"}
{"_id":{"$oid":"6a5b61d4b3bed57e0e737883"},"sha256":"24af760d399116385ac44f329e586a1e67e8a7c1d4f873b06863bb4bf5e4395e","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \nERROR    capa:                                                    helpers.py:329\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:330\n         OS.                                                                    \nERROR    capa:                                                    helpers.py:331\nERROR    capa:  capa currently only analyzes executables for some helpers.py:332\n         operating systems                                                      \nERROR    capa:  (including Windows, Linux, and Android).          helpers.py:333\nERROR    capa:                                                    helpers.py:334\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \nERROR    capa:                                                    helpers.py:329\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:330\n         OS.                                                                    \nERROR    capa:                                                    helpers.py:331\nERROR    capa:  capa currently only analyzes executables for some helpers.py:332\n         operating systems                                                      \nERROR    capa:  (including Windows, Linux, and Android).          helpers.py:333\nERROR    capa:                                                    helpers.py:334\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \nERROR    capa:                                                    helpers.py:329\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:330\n         OS.                                                                    \nERROR    capa:                                                    helpers.py:331\nERROR    capa:  capa currently only analyzes executables for some helpers.py:332\n         operating systems                                                      \nERROR    capa:  (including Windows, Linux, and Android).          helpers.py:333\nERROR    capa:                                                    helpers.py:334\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \nERROR    capa:                                                    helpers.py:329\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:330\n         OS.                                                                    \nERROR    capa:                                                    helpers.py:331\nERROR    capa:  capa currently only analyzes executables for some helpers.py:332\n         operating systems                                                      \nERROR    capa:  (including Windows, Linux, and Android).          helpers.py:333\nERROR    capa:                                                    helpers.py:334\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \nERROR    capa:                                                    helpers.py:329\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:330\n         OS.                                                                    \nERROR    capa:                                                    helpers.py:331\nERROR    capa:  capa currently only analyzes executables for some helpers.py:332\n         operating systems                                                      \nERROR    capa:  (including Windows, Linux, and Android).          helpers.py:333\nERROR    capa:                                                    helpers.py:334\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \nERROR    capa:                                                    helpers.py:329\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to target a supported  helpers.py:330\n         OS.                                                                    \nERROR    capa:                                                    helpers.py:331\nERROR    capa:  capa currently only analyzes executables for some helpers.py:332\n         operating systems                                                      \nERROR    capa:  (including Windows, Linux, and Android).          helpers.py:333\nERROR    capa:                                                    helpers.py:334\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"f16371851863e755e4ba11f169c39dca","sha1":"2933e930281d0225a62ceacc0483abf221308382","sha256":"24af760d399116385ac44f329e586a1e67e8a7c1d4f873b06863bb4bf5e4395e"}},"timestamp":"2026-07-18 16:51:56"}
{"_id":{"$oid":"6a5b6d6fb3bed57e0e737888"},"sha256":"f36047d7ce108d834458cb5c21c26238f52883b8c56d7bfa7760cbd3bab7c4bf","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":true,"path":"/tmp/sdm_capa_hi7e_w_e/002_binwalk_F_Exe1.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_hi7e_w_e/002_binwalk_F_Exe1.exe_very_verbose.txt"}},"outputs":{"normal":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"md5                     28827bb745df0e8f5ab4d809eba41ac0                        \nsha1                    cfc0552b45b3f66969aa1eaffceb4c12e7636323                \nsha256                  0855861fc39342ca8009838782c39351be5da43e60809aa13322f11…\npath                    /tmp/sdm_unpack_hbslvgtp/test-019f74f969c67b708ae412d02…\ntimestamp               2026-07-18 17:39:50.646929                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIx6Q0kz/rules                                   \nfunction count          104                                                     \nlibrary function count  0                                                       \ntotal feature count     259193                                                  \n\nreference analysis tools strings\nnamespace  anti-analysis\nscope      file         \n\ncheck for time delay via GetTickCount\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    0x403314                                       \n\nreference anti-VM strings\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nreference anti-VM strings targeting VirtualBox\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nreference anti-VM strings targeting Xen\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\ncapture webcam image\nnamespace  collection/webcam\nscope      function         \nmatches    0x404FAB         \n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32\nscope      function                        \nmatches    0x406AA0                        \n\nreference Base64 string\nnamespace  data-manipulation/encoding/base64\nscope      file                             \n\nencode data using XOR (2 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x406AB1                      \n           0x406AEA                      \n\npackaged as a NSIS installer\nnamespace  executable/installer/nsis\nscope      file                     \n\ncontains PDB path\nnamespace  executable/pe/pdb\nscope      file             \n\ncontain an embedded PE file\nnamespace  executable/subfile/pe\nscope      file                 \n\naccept command line arguments\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x40358D            \n\nopen clipboard\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x405783                  \n\nwrite clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x405783                  \n\nquery environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x401434                             \n\nset environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x40358D                             \n\nget common file path (4 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x40358D                    \n           0x4060DE                    \n           0x4065FC                    \n           0x406943                    \n\nget file system object information\nnamespace  host-interaction/file-system\nscope      basic block                 \nmatches    0x4036C3                    \n\nset current directory (2 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x401434                    \n           0x40358D                    \n\ncopy file (2 matches)\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    0x401434                         \n           0x40358D                         \n\ncreate directory (2 matches)\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x405B13                           \n           0x405B6D                           \n\ndelete directory\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x405C83                           \n\ndelete file (4 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x401434                           \n           0x40358D                           \n           0x405C83                           \n           0x405CCB                           \n\ncheck if file exists (3 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x403C91                           \n           0x405F96                           \n           0x40608A                           \n\nenumerate files on Windows (2 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x401434                               \n           0x405CCB                               \n\nenumerate files recursively\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x405CCB                               \n\nget file attributes (6 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x401643                         \n           0x403A4B                         \n           0x403DAF                         \n           0x405FF9                         \n           0x40608A                         \n           0x4060AF                         \n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x4030A9                         \n           0x406205                         \n\nset file attributes (3 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x4015C8                         \n           0x405CBC                         \n           0x40609C                         \n\nmove file (2 matches)\nnamespace  host-interaction/file-system/move\nscope      function                         \nmatches    0x401434                         \n           0x40637F                         \n\nread .ini file\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x401434                         \n\nread file on Windows (2 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x401434                         \n           0x406132                         \n\nwrite file on Windows\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x406161                          \n\nfind graphical window\nnamespace  host-interaction/gui/window/find\nscope      instruction                     \nmatches    0x401D29                        \n\nget graphical window text\nnamespace  host-interaction/gui/window/get-text\nscope      function                            \nmatches    0x405783                            \n\nget disk size\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x404A2F                         \n\nshutdown system\nnamespace  host-interaction/os\nscope      function           \nmatches    0x40358D           \n\ncheck OS version\nnamespace  host-interaction/os/version\nscope      function                   \nmatches    0x40358D                   \n\ncreate process on Windows (2 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x405BA2                       \n           0x405BE5                       \n\nmodify access privileges\nnamespace  host-interaction/process/modify\nscope      instruction                    \nmatches    0x403B69                       \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x40358D                          \n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x401434                 \n           0x402ED5                 \n\nquery or enumerate registry value (3 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x401434                 \n           0x402ED5                 \n           0x40648D                 \n\nset registry value\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x401434                        \n\ndelete registry key\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x402ED5                        \n\ndelete registry value\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x401434                        \n\ncreate thread\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x405936                      \n\nlink function at runtime on Windows (2 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x4069E0               \n           0x406A50               \n\nlinked against CPP standard library\nnamespace  linking/static\nscope      file          \n\nlinked against Crypto++\nnamespace  linking/static/cryptopp\nscope      file                   \n\nlinked against CPP JSON library\nnamespace  linking/static/jsoncpp\nscope      file                  \n\nlinked against libcurl\nnamespace  linking/static/libcurl\nscope      file                  \n\nlinked against OpenSSL\nnamespace  linking/static/openssl\nscope      file                  \n\nlinked against CppSQLite3\nnamespace  linking/static/sqlite3\nscope      file                  \n\nlinked against SQLCipher\nnamespace    linking/static/sqlite3                                             \ndescription  SQLCipher is a standalone fork of SQLite that adds 256 bit AES     \n             encryption of database files and other security features.          \nscope        file                                                               \n\nlinked against sqlite3\nnamespace  linking/static/sqlite3\nscope      file                  \n\nlinked against wolfSSL\nnamespace  linking/static/wolfssl\nscope      file                  \n\nlinked against XZip\nnamespace  linking/static/xzip\nscope      file               \n\nlinked against ZLIB\nnamespace  linking/static/zlib\nscope      file               \n\ncreate shortcut via IShellLink\nnamespace  persistence\nscope      function   \nmatches    0x401434   \n\n\n\n","very_verbose":"md5                     28827bb745df0e8f5ab4d809eba41ac0                        \nsha1                    cfc0552b45b3f66969aa1eaffceb4c12e7636323                \nsha256                  0855861fc39342ca8009838782c39351be5da43e60809aa13322f11…\npath                    /tmp/sdm_unpack_hbslvgtp/test-019f74f969c67b708ae412d02…\ntimestamp               2026-07-18 17:41:26.373955                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEISKo03I/rules                                   \nfunction count          104                                                     \nlibrary function count  0                                                       \ntotal feature count     259193                                                  \n\ncalculate modulo 256 via x86 assembly (library rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x406AEF\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x406AEF\n    or:\n      number: 0xFF @ 0x406AEF\n\ncontain loop (38 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401000\n  or:\n    characteristic: loop @ 0x401000\n\ncreate or open file (library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x4060D5\n  or:\n    api: CreateFile @ 0x4060D5\n\ncreate or open registry key (2 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x406444 in function 0x40642C\n  or:\n    api: RegOpenKeyEx @ 0x406450\n\ndelay execution (4 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x4014E9 in function 0x401434\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x4014EA\n\nget OS version (library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x40358D\n  or:\n    api: GetVersionEx @ 0x4035DB, 0x4035EE\n\nreference analysis tools strings\nnamespace   anti-analysis                                                       \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \nmbc         Discovery::Analysis Tool Discovery::Process detection [B0013.001]   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /(?<!\\w)ida?(\\.exe)?$/i\n    - \"$IDAT\" @ file+0x1E9BFC3\n    - \",IDAT\" @ file+0xB62492\n    - \"IDAT\" @ file+0xAD2BD2, file+0xAD4BDE, file+0xAD6BEA, file+0xAD8BF6, and 8 more...\n    - \"v^IdA\" @ file+0x1A811D\n\ncheck for time delay via GetTickCount\nnamespace  anti-analysis/anti-debugging/debugger-detection                      \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check     \n           GetTickCount [B0001.032]                                             \nfunction @ 0x403314\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x403432\n        mnemonic: cmp @ 0x403435\n      and:\n        mnemonic: sub @ 0x4034FF\n        mnemonic: cmp @ 0x403502\n    count(api(GetTickCount)): 2 or more @ 0x40337E, 0x403425\n\nreference anti-VM strings\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      moritz.raabe@mandiant.com                                           \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/ctxis/CAPE/blob/master/modules/signatures/antivm…\n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /HARDWARE\\\\DESCRIPTION\\\\System\\\\CentralProcessor/i\n    - \"HKEY_LOCAL_MACHINE\\\\HARDWARE\\\\DESCRIPTION\\\\System\\\\CentralProcessor\\\\0\" @ file+0x26AD968\n\nreference anti-VM strings targeting VirtualBox\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /VBOX/i\n    - \"$?staticMetaObject@QVBoxLayout@kso_qt@@2UQMetaObject@2@B\" @ file+0x1BF8143, file+0x295CD73\n    - \".?AVQVBoxLayout@kso_qt@@\" @ file+0x1C56D9C, file+0x29B4020\n    - \"??0QVBoxLayout@kso_qt@@QAE@PAVQWidget@1@@Z\" @ file+0x1BF02E6, file+0x294C8D8\n    - \"??0QVBoxLayout@kso_qt@@QAE@XZ\" @ file+0x1BF1CDC, file+0x294E938\n    - \"??1QVBoxLayout@kso_qt@@UAE@XZ\" @ file+0x1BF0314, file+0x294C906\n    - \"?metaObject@QVBoxLayout@kso_qt@@UBEPBUQMetaObject@2@XZ\" @ file+0x1BF0B42, file+0x294CD68\n    - \"?qt_metacall@QVBoxLayout@kso_qt@@UAEHW4Call@QMetaObject@2@HPAPAX@Z\" @ file+0x1BF0E9E, file+0x294CF08\n    - \"?qt_metacast@QVBoxLayout@kso_qt@@UAEPAXPBD@Z\" @ file+0x1BF0EE4, file+0x294CF4E\n\nreference anti-VM strings targeting Xen\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /^Xen/i\n    - \"xeNX\" @ file+0x213CC1\n\ncapture webcam image\nnamespace  collection/webcam                \nauthor     johnk3r                          \nscope      function                         \natt&ck     Collection::Video Capture [T1125]\nfunction @ 0x404FAB\n  or:\n    basic block:\n      and:\n        api: SendMessage @ 0x405302\n        number: 0x419 = WM_CAP_FILE_SAVEDIB @ 0x4052FA\n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32 \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \nmbc        Data::Checksum::CRC32 [C0032.001]\nfunction @ 0x406AA0\n  or:\n    and:\n      number: 0x1 = bits in a byte @ 0x406AB3, 0x406AC0\n      instruction:\n        and:\n          operand[1].number: 0x1 @ 0x406AB3\n          or:\n            mnemonic: and @ 0x406AB3\n      instruction:\n        and:\n          mnemonic: shr @ 0x406AC0\n          number: 0x1 @ 0x406AC0\n      characteristic: nzxor @ 0x406AC2, 0x406AF5, 0x406B01\n      operand[1].number: 0xEDB88320 @ 0x406ABA\n\nreference Base64 string\nnamespace  data-manipulation/encoding/base64                                \nauthor     moritz.raabe@mandiant.com                                        \nscope      file                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]         \nmbc        Data::Encode Data::Base64 [C0026.001], Data::Check String [C0019]\nregex: /ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/\n  - \"!function(t,n){var r,e;\\\"object\\\"==typeof exports&&\\\"undefined\\\"!=typeof \nmodule?module.exports=n():\\\"function\\\"==typeof \ndefine&&define.amd?define(n):(r=t.Base64,(e=n()).noConflict=function(){return \nt.Base64=r,e},t.Meteor&&(Base64=e),t.Base64=e)}(\\\"undefined\\\"!=typeof \nself?self:\\\"undefined\\\"!=typeof window?window:\\\"undefined\\\"!=typeof \nglobal?global:this,(function(){\\\"use strict\\\";var \nt,n=\\\"3.7.7\\\",r=n,e=\\\"function\\\"==typeof Buffer,o=\\\"function\\\"==typeof \nTextDecoder?new TextDecoder:void 0,u=\\\"function\\\"==typeof TextEncoder?new \nTextEncoder:void \n0,i=Array.prototype.slice.call(\\\"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstu\nvwxyz0123456789+/=\\\"),f=(t={},i.forEach((function(n,r){return \nt=r})),t),c=/^(?:[A-Za-z\\\\d+\\\\/]{4})*?(?:[A-Za-z\\\\d+\\\\/]{2}(?:==)?|[A-Za-z\\\\d+\\\\\n/]{3}=?)?$/,a=String.fromCharCode.bind(String),d=\\\"function\\\"==typeof \nUint8Array.from?Uint8Array.from.bind(Uint8Array):function(t){return new \nUint8Array(Array.prototype.slice.call(t,0))},s=function(t){return \nt.replace(/=/g,\\\"\\\").replace(/[+\\\\/]/g,(function(t){return\\\"+\\\"==t?\\\"-\\\":\\\"_\\\"})\n)},l=function(t){return \nt.replace(/[^A-Za-z0-9\\\\+\\\\/]/g,\\\"\\\")},h=function(t){for(var \nn,r,e,o,u=\\\"\\\",f=t.length%3,c=0;c<t.length;){if((r=t.charCodeAt(c++))>255||(e=t.\ncharCodeAt(c++))>255||(o=t.charCodeAt(c++))>255)throw new TypeError(\\\"invalid \ncharacter found\\\");u+=i[(n=r<<16|e<<8|o)>>18&63]+i+i+i[63&n]}return \nf?u.slice(0,f-3)+\\\"===\\\".substring(f):u},p=\\\"function\\\"==typeof \nbtoa?function(t){return btoa(t)}:e?function(t){return \nBuffer.from(t,\\\"binary\\\").toString(\\\"base64\\\")}:h,y=e?function(t){return \nBuffer.from(t).toString(\\\"base64\\\")}:function(t){for(var \nn=[],r=0,e=t.length;r<e;r+=4096)n.push(a.apply(null,t.subarray(r,r+4096)));retur\nn p(n.join(\\\"\\\"))},A=function(t,n){return void \n0===n&&(n=!1),n?s(y(t)):y(t)},b=function(t){if(t.length<2)return(n=t.charCodeAt(\n0))<128?t:n<2048?a(192|n>>>6)+a(128|63&n):a(224|n>>>12&15)+a(128|n>>>6&63)+a(128\n|63&n);var n=65536+1024*(t.charCodeAt(0)-55296)+(t.charCodeAt(1)-56320);return \na(240|n>>>18&7)+a(128|n>>>12&63)+a(128|n>>>6&63)+a(128|63&n)},g=/[\\\\uD800-\\\\uDBF\nF][\\\\uDC00-\\\\uDFFFF]|[^\\\\x00-\\\\x7F]/g,B=function(t){return \nt.replace(g,b)},x=e?function(t){return \nBuffer.from(t,\\\"utf8\\\").toString(\\\"base64\\\")}:u?function(t){return \ny(u.encode(t))}:function(t){return p(B(t))},C=function(t,n){return void \n0===n&&(n=!1),n?s(x(t)):x(t)},m=function(t){return \nC(t,!0)},v=/[\\\\xC0-\\\\xDF][\\\\x80-\\\\xBF]|[\\\\xE0-\\\\xEF][\\\\x80-\\\\xBF]{2}|[\\\\xF0-\\\\xF\n7][\\\\x80-\\\\xBF]{3}/g,U=function(t){switch(t.length){case 4:var \nn=((7&t.charCodeAt(0))<<18|(63&t.charCodeAt(1))<<12|(63&t.charCodeAt(2))<<6|63&t\n.charCodeAt(3))-65536;return a(55296+(n>>>10))+a(56320+(1023&n));case 3:return \na((15&t.charCodeAt(0))<<12|(63&t.charCodeAt(1))<<6|63&t.charCodeAt(2));default:r\neturn a((31&t.charCodeAt(0))<<6|63&t.charCodeAt(1))}},F=function(t){return \nt.replace(v,U)},w=function(t){if(t=t.replace(/\\\\s+/g,\\\"\\\"),!c.test(t))throw new \nTypeError(\\\"malformed base64.\\\");t+=\\\"==\\\".slice(2-(3&t.length));for(var \nn,r,e,o=\\\"\\\",u=0;u<t.length;)n=f<<18|f<<12|(r=f)<<6|(e=f),o+=64===r?a(n>>16&255)\n:64===e?a(n>>16&255,n>>8&255):a(n>>16&255,n>>8&255,255&n);return \no},S=\\\"function\\\"==typeof atob?function(t){return \natob(l(t))}:e?function(t){return \nBuffer.from(t,\\\"base64\\\").toString(\\\"binary\\\")}:w,E=e?function(t){return \nd(Buffer.from(t,\\\"base64\\\"))}:function(t){return \nd(S(t).split(\\\"\\\").map((function(t){return \nt.charCodeAt(0)})))},D=function(t){return E(z(t))},R=e?function(t){return \nBuffer.from(t,\\\"base64\\\").toString(\\\"utf8\\\")}:o?function(t){return \no.decode(E(t))}:function(t){return F(S(t))},z=function(t){return \nl(t.replace(/[-_]/g,(function(t){return\\\"-\\\"==t?\\\"+\\\":\\\"/\\\"})))},T=function(t){r\neturn \nR(z(t))},Z=function(t){return{value:t,enumerable:!1,writable:!0,configurable:!0}\n},j=function(){var t=function(t,n){return \nObject.defineProperty(String.prototype,t,Z(n))};t(\\\"fromBase64\\\",(function(){ret\nurn T(this)})),t(\\\"toBase64\\\",(function(t){return \nC(this,t)})),t(\\\"toBase64URI\\\",(function(){return \nC(this,!0)})),t(\\\"toBase64URL\\\",(function(){return \nC(this,!0)})),t(\\\"toUint8Array\\\",(function(){return D(this)}))},I=function(){var\nt=function(t,n){return \nObject.defineProperty(Uint8Array.prototype,t,Z(n))};t(\\\"toBase64\\\",(function(t){\nreturn A(this,t)})),t(\\\"toBase64URI\\\",(function(){return \nA(this,!0)})),t(\\\"toBase64URL\\\",(function(){return \nA(this,!0)}))},O={version:n,VERSION:r,atob:S,atobPolyfill:w,btoa:p,btoaPolyfill:\nh,fromBase64:T,toBase64:C,encode:C,encodeURI:m,encodeURL:m,utob:B,btou:F,decode:\nT,isValid:function(t){if(\\\"string\\\"!=typeof t)return!1;var \nn=t.replace(/\\\\s+/g,\\\"\\\").replace(/={0,2}$/,\\\"\\\");return!/[^\\\\s0-9a-zA-Z\\\\+/]/.t\nest(n)||!/[^\\\\s0-9a-zA-Z\\\\-_]/.test(n)},fromUint8Array:A,toUint8Array:D,extendSt\nring:j,extendUint8Array:I,extendBuiltins:function(){j(),I()},Base64:{}};return \nObject.keys(O).forEach((function(t){return O.Base64=O})),O}));\" @ file+0xA02D16\n  - \"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/\" @ file+0x8321A9, file+0x8A4219, file+0xA8A052, file+0xEE9A68, and 7 more...\n  - \"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=\" @ file+0xEEF990, file+0xF7DF88\n  - \"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_\" @ file+0xEEF9D8, file+0xF66BF8, file+0x27568D8\n\nencode data using XOR (2 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x406AB1 in function 0x406AA0\n  and:\n    characteristic: tight loop @ 0x406AB1\n    characteristic: nzxor @ 0x406AC2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x406AEA in function 0x406AA0\n  and:\n    characteristic: tight loop @ 0x406AEA\n    characteristic: nzxor @ 0x406AF5, 0x406B01\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\npackaged as a NSIS installer\nnamespace   executable/installer/nsis            \nauthor      moritz.raabe@mandiant.com            \nscope       file                                 \nreferences  https://nsis.sourceforge.io/Main_Page\nor:\n  substring: http://nsis.sf.net\n    - \"http://nsis.sf.net/NSIS_Error\" @ file+0x85AC\n\ncontains PDB path\nnamespace  executable/pe/pdb        \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nregex: /:\\\\.*\\.pdb/\n  - \"C:\\\\buildworker\\\\steam_rel_client_win32\\\\build\\\\src\\\\thirdparty\\\\vulkandriverqu\nery\\\\Release\\\\vulkandriverquery.pdb\" @ file+0x56969F\n  - \"D:\\\\qci_workspace\\\\root-workspaces\\\\__qci-pipeline-11000227-1\\\\build_project\\\\W\nindows\\\\Win64\\\\Release\\\\WCDB.pdb\" @ file+0x8C3DAD\n  - \"E:\\\\landun\\\\pinyin_agent\\\\workspace\\\\p-f93f0d74ed8a49278e11882bf2562c5a\\\\src\\\\b\nin\\\\Release_Win32\\\\PinyinUp.pdb\" @ file+0xFAD968\n  - \"H:\\\\pub_13f32\\\\rc_bugfix_master_\\\\Build\\\\Release\\\\WPSOffice\\\\office6\\\\addons\\\\k\ncefpreload\\\\kpromecefpreload.pdb\" @ file+0xB19788\n  - \"H:\\\\pub_13f32\\\\rc_bugfix_master_\\\\Build\\\\Release\\\\WPSOffice\\\\office6\\\\addons\\\\k\nhyperion\\\\khyperion.pdb\" @ file+0x1AEAB80\n  - \"H:\\\\pub_13f32\\\\rc_bugfix_master_\\\\Build\\\\Release\\\\WPSOffice\\\\office6\\\\addons\\\\k\nyunhook\\\\kyunhook.pdb\" @ file+0xA9EB1E\n  - \"H:\\\\pub_13f32\\\\rc_bugfix_master_\\\\Build\\\\Release\\\\WPSOffice\\\\office6\\\\kccservic\ne.pdb\" @ file+0x1F3B4EF\n  - \"H:\\\\pub_13f32\\\\rc_bugfix_master_\\\\Build\\\\Release\\\\WPSOffice\\\\office6\\\\ksolite.p\ndb\" @ file+0x27937A8\n  - \"H:\\\\pub_13f32\\\\rc_bugfix_master_\\\\Build\\\\Release\\\\WPSOffice\\\\office6\\\\wppoutlin\ne.pdb\" @ file+0x53C56E\n  - \"d:\\\\work\\\\Bin\\\\Release\\\\P2PUpdaterDll.pdb\" @ file+0x10802F0\n\ncontain an embedded PE file\nnamespace  executable/subfile/pe                        \nauthor     moritz.raabe@mandiant.com                    \nscope      file                                         \nmbc        Execution::Install Additional Program [B0023]\nor:\n  count(characteristic(embedded pe)): 1 or more @ file+0x22B6A, file+0x11016A, file+0x5340EE, file+0x546FBF, and 10 more...\n\naccept command line arguments\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x40358D\n  or:\n    api: GetCommandLine @ 0x4036FF\n\nopen clipboard\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ 0x405783\n  and:\n    api: OpenClipboard @ 0x405AA5\n    optional:\n      api: CloseClipboard @ 0x405B06\n\nwrite clipboard data\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \nmbc         Impact::Clipboard Modification [E1510]                              \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ 0x405783\n  and:\n    optional:\n      match: open clipboard @ 0x405783\n        and:\n          api: OpenClipboard @ 0x405AA5\n          optional:\n            api: CloseClipboard @ 0x405B06\n      api: EmptyClipboard @ 0x405AAB\n    or:\n      api: SetClipboardData @ 0x405B00\n\nquery environment variable\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x401434\n  or:\n    api: ExpandEnvironmentStrings @ 0x401A6F\n\nset environment variable\nnamespace  host-interaction/environment-variable                           \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \nmbc        Operating System::Environment Variable::Set Variable [C0034.001]\nfunction @ 0x40358D\n  or:\n    api: SetEnvironmentVariable @ 0x4038C7, 0x4038CF\n\nget common file path (4 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x40358D\n  or:\n    api: GetTempPath @ 0x403870, 0x4038AE\n    api: GetWindowsDirectory @ 0x403881\nfunction @ 0x4060DE\n  or:\n    api: GetTempFileName @ 0x406117\nfunction @ 0x4065FC\n  or:\n    api: GetSystemDirectory @ 0x40671E\n    api: GetWindowsDirectory @ 0x406734\nfunction @ 0x406943\n  or:\n    api: GetSystemDirectory @ 0x40695A\n\nget file system object information\nnamespace  host-interaction/file-system                   \nauthor     michael.hunhoff@mandiant.com                   \nscope      basic block                                    \natt&ck     Discovery::File and Directory Discovery [T1083]\nbasic block @ 0x4036C3 in function 0x40358D\n  or:\n    api: SHGetFileInfo @ 0x4036EA\n\nset current directory (2 matches)\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x401434\n  or:\n    api: SetCurrentDirectory @ 0x401679\nfunction @ 0x40358D\n  or:\n    api: SetCurrentDirectory @ 0x403A86\n\ncopy file (2 matches)\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ 0x401434\n  or:\n    basic block:\n      and:\n        number: 0x2 = FO_COPY @ 0x402364\n        or:\n          api: SHFileOperation @ 0x40239F\nfunction @ 0x40358D\n  or:\n    api: CopyFile @ 0x403A9C\n\ncreate directory (2 matches)\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x405B13\n  or:\n    api: CreateDirectory @ 0x405B55\nfunction @ 0x405B6D\n  or:\n    api: CreateDirectory @ 0x405B73\n\ndelete directory\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ 0x405C83\n  or:\n    api: RemoveDirectory @ 0x405C9E\n\ndelete file (4 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x401434\n  or:\n    api: DeleteFile @ 0x402A74\nfunction @ 0x40358D\n  or:\n    api: DeleteFile @ 0x4038E3, 0x403A58\nfunction @ 0x405C83\n  or:\n    api: DeleteFile @ 0x405CA6\nfunction @ 0x405CCB\n  or:\n    api: DeleteFile @ 0x405CF4\n\ncheck if file exists (3 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x403C91\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x403DB0\n        instruction:\n          and:\n            mnemonic: cmp @ 0x403DB6\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x403DB6\nfunction @ 0x405F96\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x405FFF\n        instruction:\n          and:\n            mnemonic: cmp @ 0x406007\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x406007\nfunction @ 0x40608A\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x40608F\n        instruction:\n          and:\n            mnemonic: cmp @ 0x406097\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x406097\n\nenumerate files on Windows (2 matches)\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ 0x401434\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x402946\n      or:\n        api: FindNextFile @ 0x40291E\n      optional:\n        api: FindClose @ 0x4028FF\n        match: contain loop @ 0x401434\n          or:\n            characteristic: loop @ 0x401434\nfunction @ 0x405CCB\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x405D75\n      or:\n        api: FindNextFile @ 0x405E15\n      optional:\n        api: FindClose @ 0x405E24\n        match: contain loop @ 0x405CCB\n          or:\n            characteristic: loop @ 0x405CCB\n            characteristic: recursive call @ 0x405CCB\n\nenumerate files recursively\nnamespace  host-interaction/file-system/files/list        \nauthor     @_re_fox, anushka.virgaonkar@mandiant.com      \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nmbc        Discovery::File and Directory Discovery [E1083]\nfunction @ 0x405CCB\n  and:\n    characteristic: recursive call @ 0x405CCB\n    or:\n      match: enumerate files on Windows @ 0x405CCB\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x405D75\n            or:\n              api: FindNextFile @ 0x405E15\n            optional:\n              api: FindClose @ 0x405E24\n              match: contain loop @ 0x405CCB\n                or:\n                  characteristic: loop @ 0x405CCB\n                  characteristic: recursive call @ 0x405CCB\n\nget file attributes (6 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x401643 in function 0x401434\n  or:\n    api: GetFileAttributes @ 0x401646\nbasic block @ 0x403A4B in function 0x40358D\n  or:\n    api: GetFileAttributes @ 0x403A4C\nbasic block @ 0x403DAF in function 0x403C91\n  or:\n    api: GetFileAttributes @ 0x403DB0\nbasic block @ 0x405FF9 in function 0x405F96\n  or:\n    api: GetFileAttributes @ 0x405FFF\nbasic block @ 0x40608A in function 0x40608A\n  or:\n    api: GetFileAttributes @ 0x40608F\nbasic block @ 0x4060AF in function 0x4060AF\n  or:\n    api: GetFileAttributes @ 0x4060B3\n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x4030A9\n  or:\n    api: GetFileSize @ 0x403143\nfunction @ 0x406205\n  or:\n    api: GetFileSize @ 0x4062BF\n\nset file attributes (3 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ 0x4015C8 in function 0x401434\n  or:\n    api: SetFileAttributes @ 0x4015D3\nbasic block @ 0x405CBC in function 0x405C83\n  or:\n    api: SetFileAttributes @ 0x405CBE\nbasic block @ 0x40609C in function 0x40608A\n  or:\n    api: SetFileAttributes @ 0x4060A3\n\nmove file (2 matches)\nnamespace  host-interaction/file-system/move                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Move File [C0063]                         \nfunction @ 0x401434\n  or:\n    api: MoveFile @ 0x4016C2\nfunction @ 0x40637F\n  or:\n    api: MoveFileEx @ 0x406389\n\nread .ini file\nnamespace  host-interaction/file-system/read     \nauthor     @_re_fox, michael.hunhoff@mandiant.com\nscope      function                              \nmbc        File System::Read File [C0051]        \nfunction @ 0x401434\n  and:\n    optional:\n      api: GetFullPathName @ 0x40170E\n    or:\n      api: GetPrivateProfileString @ 0x402451\n\nread file on Windows (2 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x401434\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x402784\nfunction @ 0x406132\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x406146\n\nwrite file on Windows\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x406161\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x406175\n\nfind graphical window\nnamespace  host-interaction/gui/window/find               \nauthor     moritz.raabe@mandiant.com                      \nscope      instruction                                    \natt&ck     Discovery::Application Window Discovery [T1010]\ninstruction @ 0x401D29\n  or:\n    api: FindWindowEx @ 0x401D29\n\nget graphical window text\nnamespace  host-interaction/gui/window/get-text           \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \nmbc        Discovery::Application Window Discovery [E1010]\nfunction @ 0x405783\n  or:\n    and:\n      or:\n        basic block:\n          and:\n            number: 0xD = WM_GETTEXT @ 0x405ADE\n            api: SendMessage @ 0x405AD5\n\nget disk size\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ 0x404A2F\n  or:\n    api: GetDiskFreeSpace @ 0x404C77\n\nshutdown system\nnamespace  host-interaction/os                   \nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \natt&ck     Impact::System Shutdown/Reboot [T1529]\nfunction @ 0x40358D\n  or:\n    api: ExitWindowsEx @ 0x403B8E\n\ncheck OS version\nnamespace  host-interaction/os/version                    \nauthor     michael.hunhoff@mandiant.com, johnk3r          \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x40358D\n  and:\n    match: get OS version @ 0x40358D\n      or:\n        api: GetVersionEx @ 0x4035DB, 0x4035EE\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x403619\n            number: 0xA = Windows Server 2016 / Windows Server 2019 / Windows 10 @ 0x403619\n        optional:\n          instruction:\n            and:\n              mnemonic: cmp @ 0x403691\n              number: 0x0 @ 0x403691\n            and:\n              mnemonic: cmp @ 0x403A33\n              number: 0x0 @ 0x403A33\n\ncreate process on Windows (2 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x405BA2 in function 0x405BA2\n  or:\n    api: CreateProcess @ 0x405BCB\nbasic block @ 0x405BE5 in function 0x405BE5\n  or:\n    api: ShellExecuteEx @ 0x405BF4\n\nmodify access privileges\nnamespace  host-interaction/process/modify                        \nauthor     moritz.raabe@mandiant.com                              \nscope      instruction                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\ninstruction @ 0x403B69\n  and:\n    api: AdjustTokenPrivileges @ 0x403B69\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x40358D\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x403B07, 0x403BB1\n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ 0x401434\n  and:\n    or:\n      api: RegEnumKey @ 0x4025FD\nfunction @ 0x402ED5\n  and:\n    or:\n      api: RegEnumKey @ 0x402F75\n\nquery or enumerate registry value (3 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x401434\n  and:\n    or:\n      api: RegEnumValue @ 0x402610\n      api: RegQueryValueEx @ 0x402587\nfunction @ 0x402ED5\n  and:\n    or:\n      api: RegEnumValue @ 0x402F29\nfunction @ 0x40648D\n  and:\n    or:\n      api: RegQueryValueEx @ 0x4064D3\n\nset registry value\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x401434\n  or:\n    and:\n      or:\n        api: RegSetValueEx @ 0x402541\n\ndelete registry key\nnamespace  host-interaction/registry/delete                                \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\nscope      function                                                        \natt&ck     Defense Evasion::Modify Registry [T1112]                        \nmbc        Operating System::Registry::Delete Registry Key [C0036.002]     \nfunction @ 0x402ED5\n  and:\n    or:\n      api: RegDeleteKey @ 0x402F95\n\ndelete registry value\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ 0x401434\n  and:\n    or:\n      api: RegDeleteValue @ 0x402482\n\ncreate thread\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x405936 in function 0x405783\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x405951\n\n(internal) installer file limitation\nnamespace    internal/limitation/static                                         \nauthor       william.ballenthin@mandiant.com                                    \nscope        file                                                               \ndescription  This sample appears to be an installer.                            \n                                                                                \n             capa cannot handle installers well. This means the results may be  \n             misleading or incomplete.                                          \n             You should try to understand the install mechanism and analyze     \n             created files with capa.                                           \n                                                                                \nor:\n  match: executable/installer @ global\n    or:\n      substring: http://nsis.sf.net\n        - \"http://nsis.sf.net/NSIS_Error\" @ file+0x85AC\n\nlink function at runtime on Windows (2 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x4069E0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4069E0\ninstruction @ 0x406A50\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x406A50\n\nlinked against CPP standard library\nnamespace   linking/static                                                      \nauthor      @mr-tz                                                              \nscope       file                                                                \nreferences  https://en.wikipedia.org/wiki/P._J._Plauger,                        \n            https://www.dinkumware.com/                                         \nor:\n  string: \"Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL \nRIGHTS RESERVED.\" @ file+0x1088E98\n\nlinked against Crypto++\nnamespace  linking/static/cryptopp             \nauthor     moritz.raabe@mandiant.com           \nscope      file                                \nmbc        Cryptography::Crypto Library [C0059]\nor:\n  string: \"Cryptographic algorithms are disabled after a power-up self test failed.\" @ file+0x1F34E2B, file+0x2755660\n  string: \": this object requires an IV\" @ file+0x1F34E77, file+0x27556AC\n  string: \"BER decode error\" @ file+0x1F3577B, file+0x2756220\n  string: \".?AVException@CryptoPP@@\" @ file+0x1F484D7, file+0x29AF95C\n  string: \"StreamTransformationFilter: PKCS_PADDING cannot be used with \" @ file+0x1F3544B, file+0x2755F48\n\nlinked against CPP JSON library\nnamespace   linking/static/jsoncpp                        \nauthor      @mr-tz                                        \nscope       file                                          \nreferences  https://github.com/open-source-parsers/jsoncpp\nor:\n  string: \"Exceeded stackLimit in readValue().\" @ file+0xA908B6, file+0x275975C\n  string: \"Missing ',' or '}' in object declaration\" @ file+0xA90942, file+0x27597E8\n  string: \"Extra non-whitespace after JSON value.\" @ file+0xA90B5E\n\nlinked against libcurl\nnamespace  linking/static/libcurl   \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nor:\n  substring: CLIENT libcurl\n    - \"CLIENT libcurl 8.2.0-DEV\" @ file+0xEF1A68, file+0xEF1AD4, file+0xEF1B04\n\nlinked against OpenSSL\nnamespace  linking/static/openssl                                       \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope      file                                                         \nmbc        Cryptography::Crypto Library [C0059]                         \nor:\n  string: \"DSA-SHA1-old\" @ file+0x853141, file+0xF04D30\n  string: \"OpenSSL DH Method\" @ file+0x861AD1, file+0xF0CFB4\n\nlinked against CppSQLite3\nnamespace  linking/static/sqlite3\nauthor     still@teamt5.org      \nscope      file                  \nand:\n  substring: CppSQLite3DB\n    - \".?AVCppSQLite3DB@@\" @ file+0x29C7AE8\n  substring: CppSQLite3Query\n    - \".?AVCppSQLite3Query@@\" @ file+0x29C7AA4\n    - \"??0KDBQuery@ksolite@@QAE@ABVCppSQLite3Query@@@Z\" @ file+0x287441C\n\nlinked against SQLCipher\nnamespace    linking/static/sqlite3                                             \nauthor       wballenthin@google.com                                             \nscope        file                                                               \nreferences   https://www.zetetic.net/sqlcipher/,                                \n             https://github.com/sqlcipher/sqlcipher                             \ndescription  SQLCipher is a standalone fork of SQLite that adds 256 bit AES     \n             encryption of database files and other security features.          \nor:\n  3 or more:\n    string: \"hexkey\" @ file+0x82FEC1, file+0xF10DAC\n    string: \"hexrekey\" @ file+0x8340E1\n    string: \"cipher\" @ file+0x82CB19, file+0xF10DA4\n    string: \"rekey_cipher\" @ file+0x830229\n    string: \"kdf_iter\" @ file+0x82CDE9\n    string: \"rekey_kdf_iter\" @ file+0x8302B9\n\nlinked against sqlite3\nnamespace  linking/static/sqlite3\nauthor     still@teamt5.org      \nscope      file                  \nor:\n  3 or more:\n    string: \"database corruption\" @ file+0x82FF09\n    string: \"SQLite format 3\" @ file+0x8267B9, file+0x8306F9, file+0x832199\n    string: \"sqlite3_extension_init\" @ file+0x831FD9\n    substring: UPSERT not implemented for virtual table\n      - \"UPSERT not implemented for virtual table \\\"%s\\\"\" @ file+0x839F69\n    substring: sqlite3_get_table()\n      - \"sqlite3_get_table() called with two or more incompatible queries\" @ file+0x839CE9\n    substring: qualified table names are not allowed on\n      - \"qualified table names are not allowed on INSERT, UPDATE, and DELETE statements \nwithin triggers\" @ file+0x840E89\n\nlinked against wolfSSL\nnamespace   linking/static/wolfssl                                              \nauthor      jakub.jozwiak@mandiant.com                                          \nscope       file                                                                \nmbc         Cryptography::Crypto Library [C0059]                                \nreferences  https://www.wolfssl.com/,                                           \n            https://github.com/wolfSSL/wolfssl/blob/2841b5c93b87311dadcf2278151…\nor:\n  3 or more:\n    substring: server finished\n      - \"server finished\" @ file+0xF4A4F0\n    substring: client finished\n      - \"client finished\" @ file+0xF4A4E0\n    substring: DOWNGRD\n      - \"DOWNGRD\" @ file+0xF4D460, file+0xF4D468\n\nlinked against XZip\nnamespace   linking/static/xzip                                                 \nauthor      moritz.raabe@mandiant.com                                           \nscope       file                                                                \nmbc         Data::Compression Library [C0060]                                   \nreferences  https://github.com/ValveSoftware/source-sdk-2013/blob/master/sp/src…\nor:\n  string: \"ct_init: dist != 256\" @ file+0xA91352\n  string: \"ct_init: 256+dist != 512\" @ file+0xA9136A\n  string: \"inconsistent bit counts\" @ file+0xA91386\n  string: \"bad pack level\" @ file+0xA91442\n\nlinked against ZLIB\nnamespace  linking/static/zlib              \nauthor     william.ballenthin@mandiant.com  \nscope      file                             \nmbc        Data::Compression Library [C0060]\nor:\n  regex: /deflate .* Copyright/\n    - \" deflate 1.2.13 Copyright 1995-2022 Jean-loup Gailly and Mark Adler \" @ file+0xF57460\n    - \" deflate 1.3.1 Copyright 1995-2024 Jean-loup Gailly and Mark Adler \" @ file+0x2759A50\n  regex: /inflate .* Copyright/\n    - \" inflate 1.2.13 Copyright 1995-2022 Mark Adler \" @ file+0xF57330\n    - \" inflate 1.3.1 Copyright 1995-2024 Mark Adler \" @ file+0x275D948\n\ncreate shortcut via IShellLink\nnamespace   persistence                                                         \nauthor      matthew.williams@mandiant.com                                       \nscope       function                                                            \natt&ck      Persistence::Boot or Logon Autostart Execution::Shortcut            \n            Modification [T1547.009]                                            \nreferences  https://docs.microsoft.com/en-us/windows/win32/shell/links#creating…\nfunction @ 0x401434\n  and:\n    offset: 0x50 = psl->SetPath @ 0x402288\n    offset: 0x18 = ppf->Save @ 0x402040, 0x4022F7, 0x402AB9, 0x402AED\n    api: CoCreateInstance @ 0x402255\n    bytes: 0114020000000000c000000000000046 = CLSID_ShellLink @ 0x402250\n    bytes: 0b01000000000000c000000000000046 = IID_IPersistFile @ 0x40226A\n    or:\n      bytes: f914020000000000c000000000000046 = IID_IShellLinkW @ 0x402248\n\n\n\n"},"hashes":{"md5":"28827bb745df0e8f5ab4d809eba41ac0","sha1":"cfc0552b45b3f66969aa1eaffceb4c12e7636323","sha256":"0855861fc39342ca8009838782c39351be5da43e60809aa13322f11cd95d59ad"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 104</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 259193</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"test-019f74f969c67b708ae412d02\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"28827bb745df0e8f5ab4d809eba41ac0\",\n        \"sha256\": \"0855861fc39342ca8009838782c39351be5da43e60809aa13322f11\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__38_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (38 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401000\",\n      \"label\": \"Function 0x401000\",\n      \"type\": \"function\",\n      \"address\": \"0x401000\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x406444\",\n      \"label\": \"Block 0x406444\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x406444\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4014E9\",\n      \"label\": \"Block 0x4014E9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4014E9\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_reference_analysis_tools_strings\",\n      \"label\": \"reference analysis tools strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_for_time_delay_via_gettickcount\",\n      \"label\": \"check for time delay via GetTickCount\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"GetTickCount [B0001.032]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x403314\",\n      \"label\": \"Function 0x403314\",\n      \"type\": \"function\",\n      \"address\": \"0x403314\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"GetTickCount [B0001.032]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings\",\n      \"label\": \"reference anti-VM strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_virtualbox\",\n      \"label\": \"reference anti-VM strings targeting VirtualBox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"label\": \"reference anti-VM strings targeting Xen\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_capture_webcam_image\",\n      \"label\": \"capture webcam image\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Video Capture [T1125]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404FAB\",\n      \"label\": \"Function 0x404FAB\",\n      \"type\": \"function\",\n      \"address\": \"0x404FAB\"\n    },\n    {\n      \"id\": \"api_SendMessage\",\n      \"label\": \"SendMessage\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____johnk3r\",\n      \"label\": \"author     johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Video Capture [T1125]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_with_crc32\",\n      \"label\": \"hash data with CRC32\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x406AA0\",\n      \"label\": \"Function 0x406AA0\",\n      \"type\": \"function\",\n      \"address\": \"0x406AA0\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_base64_string\",\n      \"label\": \"reference Base64 string\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Encode Data::Base64 [C0026.001]\",\n        \"Data::Check String [C0019]\"\n      ]\n    },\n    {\n      \"id\": \"cap_packaged_as_a_nsis_installer\",\n      \"label\": \"packaged as a NSIS installer\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_contains_pdb_path\",\n      \"label\": \"contains PDB path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_contain_an_embedded_pe_file\",\n      \"label\": \"contain an embedded PE file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments\",\n      \"label\": \"accept command line arguments\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40358D\",\n      \"label\": \"Function 0x40358D\",\n      \"type\": \"function\",\n      \"address\": \"0x40358D\"\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_open_clipboard\",\n      \"label\": \"open clipboard\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405783\",\n      \"label\": \"Function 0x405783\",\n      \"type\": \"function\",\n      \"address\": \"0x405783\"\n    },\n    {\n      \"id\": \"api_CloseClipboard\",\n      \"label\": \"CloseClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_OpenClipboard\",\n      \"label\": \"OpenClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_write_clipboard_data\",\n      \"label\": \"write clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"api_EmptyClipboard\",\n      \"label\": \"EmptyClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SetClipboardData\",\n      \"label\": \"SetClipboardData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable\",\n      \"label\": \"query environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401434\",\n      \"label\": \"Function 0x401434\",\n      \"type\": \"function\",\n      \"address\": \"0x401434\"\n    },\n    {\n      \"id\": \"api_ExpandEnvironmentStrings\",\n      \"label\": \"ExpandEnvironmentStrings\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_environment_variable\",\n      \"label\": \"set environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable::Set Variable [C0034.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_SetEnvironmentVariable\",\n      \"label\": \"SetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__4_matches_\",\n      \"label\": \"get common file path (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4065FC\",\n      \"label\": \"Function 0x4065FC\",\n      \"type\": \"function\",\n      \"address\": \"0x4065FC\"\n    },\n    {\n      \"id\": \"func_0x406943\",\n      \"label\": \"Function 0x406943\",\n      \"type\": \"function\",\n      \"address\": \"0x406943\"\n    },\n    {\n      \"id\": \"func_0x4060DE\",\n      \"label\": \"Function 0x4060DE\",\n      \"type\": \"function\",\n      \"address\": \"0x4060DE\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempFileName\",\n      \"label\": \"GetTempFileName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_system_object_information\",\n      \"label\": \"get file system object information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4036C3\",\n      \"label\": \"Block 0x4036C3\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4036C3\"\n    },\n    {\n      \"id\": \"api_SHGetFileInfo\",\n      \"label\": \"SHGetFileInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_current_directory__2_matches_\",\n      \"label\": \"set current directory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_SetCurrentDirectory\",\n      \"label\": \"SetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_copy_file__2_matches_\",\n      \"label\": \"copy file (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"api_SHFileOperation\",\n      \"label\": \"SHFileOperation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CopyFile\",\n      \"label\": \"CopyFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory__2_matches_\",\n      \"label\": \"create directory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405B6D\",\n      \"label\": \"Function 0x405B6D\",\n      \"type\": \"function\",\n      \"address\": \"0x405B6D\"\n    },\n    {\n      \"id\": \"func_0x405B13\",\n      \"label\": \"Function 0x405B13\",\n      \"type\": \"function\",\n      \"address\": \"0x405B13\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_delete_directory\",\n      \"label\": \"delete directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405C83\",\n      \"label\": \"Function 0x405C83\",\n      \"type\": \"function\",\n      \"address\": \"0x405C83\"\n    },\n    {\n      \"id\": \"api_RemoveDirectory\",\n      \"label\": \"RemoveDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_file__4_matches_\",\n      \"label\": \"delete file (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405CCB\",\n      \"label\": \"Function 0x405CCB\",\n      \"type\": \"function\",\n      \"address\": \"0x405CCB\"\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__3_matches_\",\n      \"label\": \"check if file exists (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405F96\",\n      \"label\": \"Function 0x405F96\",\n      \"type\": \"function\",\n      \"address\": \"0x405F96\"\n    },\n    {\n      \"id\": \"func_0x40608A\",\n      \"label\": \"Function 0x40608A\",\n      \"type\": \"function\",\n      \"address\": \"0x40608A\"\n    },\n    {\n      \"id\": \"func_0x403C91\",\n      \"label\": \"Function 0x403C91\",\n      \"type\": \"function\",\n      \"address\": \"0x403C91\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"label\": \"enumerate files on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindFirstFile\",\n      \"label\": \"FindFirstFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindNextFile\",\n      \"label\": \"FindNextFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindClose\",\n      \"label\": \"FindClose\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_recursively\",\n      \"label\": \"enumerate files recursively\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     @_re_fox, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes__6_matches_\",\n      \"label\": \"get file attributes (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4060AF\",\n      \"label\": \"Block 0x4060AF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4060AF\"\n    },\n    {\n      \"id\": \"bb_0x40608A\",\n      \"label\": \"Block 0x40608A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40608A\"\n    },\n    {\n      \"id\": \"bb_0x403A4B\",\n      \"label\": \"Block 0x403A4B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x403A4B\"\n    },\n    {\n      \"id\": \"bb_0x405FF9\",\n      \"label\": \"Block 0x405FF9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x405FF9\"\n    },\n    {\n      \"id\": \"bb_0x401643\",\n      \"label\": \"Block 0x401643\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401643\"\n    },\n    {\n      \"id\": \"bb_0x403DAF\",\n      \"label\": \"Block 0x403DAF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x403DAF\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size__2_matches_\",\n      \"label\": \"get file size (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x406205\",\n      \"label\": \"Function 0x406205\",\n      \"type\": \"function\",\n      \"address\": \"0x406205\"\n    },\n    {\n      \"id\": \"func_0x4030A9\",\n      \"label\": \"Function 0x4030A9\",\n      \"type\": \"function\",\n      \"address\": \"0x4030A9\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_file_attributes__3_matches_\",\n      \"label\": \"set file attributes (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x405CBC\",\n      \"label\": \"Block 0x405CBC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x405CBC\"\n    },\n    {\n      \"id\": \"bb_0x4015C8\",\n      \"label\": \"Block 0x4015C8\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4015C8\"\n    },\n    {\n      \"id\": \"bb_0x40609C\",\n      \"label\": \"Block 0x40609C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40609C\"\n    },\n    {\n      \"id\": \"api_SetFileAttributes\",\n      \"label\": \"SetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_move_file__2_matches_\",\n      \"label\": \"move file (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40637F\",\n      \"label\": \"Function 0x40637F\",\n      \"type\": \"function\",\n      \"address\": \"0x40637F\"\n    },\n    {\n      \"id\": \"api_MoveFileEx\",\n      \"label\": \"MoveFileEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_MoveFile\",\n      \"label\": \"MoveFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read__ini_file\",\n      \"label\": \"read .ini file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetPrivateProfileString\",\n      \"label\": \"GetPrivateProfileString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFullPathName\",\n      \"label\": \"GetFullPathName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__2_matches_\",\n      \"label\": \"read file on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x406132\",\n      \"label\": \"Function 0x406132\",\n      \"type\": \"function\",\n      \"address\": \"0x406132\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_write_file_on_windows\",\n      \"label\": \"write file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x406161\",\n      \"label\": \"Function 0x406161\",\n      \"type\": \"function\",\n      \"address\": \"0x406161\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_graphical_window\",\n      \"label\": \"find graphical window\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindWindowEx\",\n      \"label\": \"FindWindowEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_graphical_window_text\",\n      \"label\": \"get graphical window text\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_disk_size\",\n      \"label\": \"get disk size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404A2F\",\n      \"label\": \"Function 0x404A2F\",\n      \"type\": \"function\",\n      \"address\": \"0x404A2F\"\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpace\",\n      \"label\": \"GetDiskFreeSpace\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_shutdown_system\",\n      \"label\": \"shutdown system\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::System Shutdown/Reboot [T1529]\"\n      ]\n    },\n    {\n      \"id\": \"api_ExitWindowsEx\",\n      \"label\": \"ExitWindowsEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_check_os_version\",\n      \"label\": \"check OS version\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetVersionEx\",\n      \"label\": \"GetVersionEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__2_matches_\",\n      \"label\": \"create process on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x405BE5\",\n      \"label\": \"Block 0x405BE5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x405BE5\"\n    },\n    {\n      \"id\": \"bb_0x405BA2\",\n      \"label\": \"Block 0x405BA2\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x405BA2\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_ShellExecuteEx\",\n      \"label\": \"ShellExecuteEx\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_modify_access_privileges\",\n      \"label\": \"modify access privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"api_AdjustTokenPrivileges\",\n      \"label\": \"AdjustTokenPrivileges\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"api_ExitProcess\",\n      \"label\": \"ExitProcess\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"label\": \"query or enumerate registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402ED5\",\n      \"label\": \"Function 0x402ED5\",\n      \"type\": \"function\",\n      \"address\": \"0x402ED5\"\n    },\n    {\n      \"id\": \"api_RegEnumKey\",\n      \"label\": \"RegEnumKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__3_matches_\",\n      \"label\": \"query or enumerate registry value (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40648D\",\n      \"label\": \"Function 0x40648D\",\n      \"type\": \"function\",\n      \"address\": \"0x40648D\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegEnumValue\",\n      \"label\": \"RegEnumValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value\",\n      \"label\": \"set registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delete_registry_key\",\n      \"label\": \"delete registry key\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegDeleteKey\",\n      \"label\": \"RegDeleteKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_value\",\n      \"label\": \"delete registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegDeleteValue\",\n      \"label\": \"RegDeleteValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_thread\",\n      \"label\": \"create thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x405936\",\n      \"label\": \"Block 0x405936\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x405936\"\n    },\n    {\n      \"id\": \"api_CreateThread\",\n      \"label\": \"CreateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal__installer_file_limitation\",\n      \"label\": \"(internal) installer file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__2_matches_\",\n      \"label\": \"link function at runtime on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_linked_against_cpp_standard_library\",\n      \"label\": \"linked against CPP standard library\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______mr_tz\",\n      \"label\": \"author      @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_linked_against_crypto__\",\n      \"label\": \"linked against Crypto++\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Crypto Library [C0059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_linked_against_cpp_json_library\",\n      \"label\": \"linked against CPP JSON library\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_linked_against_libcurl\",\n      \"label\": \"linked against libcurl\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_linked_against_openssl\",\n      \"label\": \"linked against OpenSSL\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Crypto Library [C0059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Crypto Library [C0059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_linked_against_cppsqlite3\",\n      \"label\": \"linked against CppSQLite3\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____still_teamt5_org\",\n      \"label\": \"author     still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_linked_against_sqlcipher\",\n      \"label\": \"linked against SQLCipher\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______wballenthin_google_com\",\n      \"label\": \"author       wballenthin@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_linked_against_sqlite3\",\n      \"label\": \"linked against sqlite3\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_linked_against_wolfssl\",\n      \"label\": \"linked against wolfSSL\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Crypto Library [C0059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______jakub_jozwiak_mandiant_com\",\n      \"label\": \"author      jakub.jozwiak@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Crypto Library [C0059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_linked_against_xzip\",\n      \"label\": \"linked against XZip\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Compression Library [C0060]\"\n      ]\n    },\n    {\n      \"id\": \"cap_linked_against_zlib\",\n      \"label\": \"linked against ZLIB\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Compression Library [C0060]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Compression Library [C0060]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_shortcut_via_ishelllink\",\n      \"label\": \"create shortcut via IShellLink\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    },\n    {\n      \"id\": \"api_CoCreateInstance\",\n      \"label\": \"CoCreateInstance\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__38_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__38_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x406444\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__4_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x4014E9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_analysis_tools_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_time_delay_via_gettickcount\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount\",\n      \"target\": \"func_0x403314\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403314\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_virtualbox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_capture_webcam_image\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_capture_webcam_image\",\n      \"target\": \"func_0x404FAB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404FAB\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____johnk3r\",\n      \"target\": \"func_0x404FAB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404FAB\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_crc32\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_with_crc32\",\n      \"target\": \"func_0x406AA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x406AA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_base64_string\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_packaged_as_a_nsis_installer\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contains_pdb_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_an_embedded_pe_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_clipboard\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_clipboard\",\n      \"target\": \"func_0x405783\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405783\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405783\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405783\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405783\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405783\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_clipboard_data\",\n      \"target\": \"func_0x405783\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405783\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405783\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405783\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405783\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405783\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405783\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405783\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405783\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405783\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_environment_variable\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__4_matches_\",\n      \"target\": \"func_0x4065FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__4_matches_\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__4_matches_\",\n      \"target\": \"func_0x406943\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__4_matches_\",\n      \"target\": \"func_0x4060DE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4065FC\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406943\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4060DE\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4065FC\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406943\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4060DE\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4065FC\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406943\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4060DE\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4065FC\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406943\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4060DE\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4065FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406943\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4060DE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4065FC\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406943\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4060DE\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4065FC\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406943\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4060DE\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4065FC\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406943\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4060DE\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4065FC\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406943\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4060DE\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_system_object_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_system_object_information\",\n      \"target\": \"bb_0x4036C3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4036C3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_current_directory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__2_matches_\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__2_matches_\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_copy_file__2_matches_\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_copy_file__2_matches_\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory__2_matches_\",\n      \"target\": \"func_0x405B6D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__2_matches_\",\n      \"target\": \"func_0x405B13\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405B6D\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405B13\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405B6D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405B13\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405B6D\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405B13\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_directory\",\n      \"target\": \"func_0x405C83\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405C83\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405C83\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405C83\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__4_matches_\",\n      \"target\": \"func_0x405C83\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__4_matches_\",\n      \"target\": \"func_0x405CCB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__4_matches_\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__4_matches_\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405C83\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405CCB\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405C83\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405CCB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405C83\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405CCB\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x405F96\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x40608A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x403C91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405F96\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40608A\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403C91\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405F96\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40608A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403C91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405F96\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40608A\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403C91\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"target\": \"func_0x405CCB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__2_matches_\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405CCB\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405CCB\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405CCB\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405CCB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405CCB\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405CCB\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405CCB\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_recursively\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively\",\n      \"target\": \"func_0x405CCB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405CCB\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405CCB\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405CCB\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405CCB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405CCB\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405CCB\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405CCB\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x4060AF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x40608A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x403A4B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x405FF9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x401643\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x403DAF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4060AF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40608A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x403A4B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x405FF9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x401643\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x403DAF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x406205\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x4030A9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406205\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4030A9\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406205\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4030A9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406205\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4030A9\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__3_matches_\",\n      \"target\": \"bb_0x405CBC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__3_matches_\",\n      \"target\": \"bb_0x4015C8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__3_matches_\",\n      \"target\": \"bb_0x40609C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x405CBC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4015C8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40609C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_move_file__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_move_file__2_matches_\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__2_matches_\",\n      \"target\": \"func_0x40637F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40637F\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40637F\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40637F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40637F\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40637F\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read__ini_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read__ini_file\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_GetFullPathName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_GetFullPathName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__2_matches_\",\n      \"target\": \"func_0x406132\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__2_matches_\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406132\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406132\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406132\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows\",\n      \"target\": \"func_0x406161\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406161\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406161\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406161\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_graphical_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_graphical_window_text\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text\",\n      \"target\": \"func_0x405783\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405783\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x405783\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405783\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_size\",\n      \"target\": \"func_0x404A2F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404A2F\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x404A2F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404A2F\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_shutdown_system\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_shutdown_system\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_os_version\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_os_version\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__2_matches_\",\n      \"target\": \"bb_0x405BE5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__2_matches_\",\n      \"target\": \"bb_0x405BA2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x405BE5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x405BA2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_modify_access_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40358D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40358D\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"target\": \"func_0x402ED5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402ED5\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x402ED5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402ED5\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__3_matches_\",\n      \"target\": \"func_0x40648D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__3_matches_\",\n      \"target\": \"func_0x402ED5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__3_matches_\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40648D\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402ED5\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40648D\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402ED5\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40648D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402ED5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40648D\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402ED5\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40648D\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402ED5\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key\",\n      \"target\": \"func_0x402ED5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402ED5\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x402ED5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402ED5\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread\",\n      \"target\": \"bb_0x405936\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x405936\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal__installer_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_cpp_standard_library\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_crypto__\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_cpp_json_library\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_libcurl\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_openssl\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_cppsqlite3\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_sqlcipher\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______wballenthin_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_sqlite3\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_wolfssl\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______jakub_jozwiak_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_xzip\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_zlib\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_shortcut_via_ishelllink\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_shortcut_via_ishelllink\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______matthew_williams_mandiant_com\",\n      \"target\": \"func_0x401434\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401434\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-18 17:41:26.373955\",\n    \"total_functions\": \"104\",\n    \"total_features\": \"259193\",\n    \"pdb_path\": \"C:\\\\\\\\buildworker\\\\\\\\steam_rel_client_win32\\\\\\\\build\\\\\\\\src\\\\\\\\thirdparty\\\\\\\\vulkandriverqu\\nery\\\\\\\\Release\\\\\\\\vulkandriverquery.pdb\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-18 17:41:27"}
{"_id":{"$oid":"6a5b79d9b3bed57e0e737889"},"sha256":"2158f554787de6bc29c709e9f99fc7700ef55e6b46a2386a9b2722414d022a38","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"b4aae42b3973517333bdcfdf68abb865","sha1":"c82d009a889f7505025230a6f108e5ccd66d2ac4","sha256":"2158f554787de6bc29c709e9f99fc7700ef55e6b46a2386a9b2722414d022a38"}},"timestamp":"2026-07-18 18:34:25"}
{"_id":{"$oid":"6a5c6ce3b3bed57e0e73788d"},"sha256":"5fc07750ace241e22a7d63a5d5aff50815e975aa0084c285ccc7c514c58c09df","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_lwqffrtu/5fc07750ace241e22a7d63a5d5aff50815e975aa0084c285ccc7c514c58c09df-019f78fe518c72709650852969b4a5c3.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_lwqffrtu/5fc07750ace241e22a7d63a5d5aff50815e975aa0084c285ccc7c514c58c09df-019f78fe518c72709650852969b4a5c3.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_lwqffrtu/5fc07750ace241e22a7d63a5d5aff50815e975aa0084c285ccc7c514c58c09df-019f78fe518c72709650852969b4a5c3.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 174ad172303b51111727aea63e9bdc0a                                  │\n│ sha1     │ 94cec0c0823f19023c283e73a4b7486113e02f22                          │\n│ sha256   │ 5fc07750ace241e22a7d63a5d5aff50815e975aa0084c285ccc7c514c58c09df  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ amd64                                                             │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/5fc07750ace241e2… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic                       ┃ ATT&CK Technique                       ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ EXECUTION                           │ Shared Modules [T1129]                 │\n└─────────────────────────────────────┴────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective                ┃ MBC Behavior                                  ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DATA                         │ Compression Library [C0060]                   │\n│ EXECUTION                    │ Install Additional Program [B0023]            │\n│ FILE SYSTEM                  │ Writes File [C0052]                           │\n│ PROCESS                      │ Create Process [C0017]                        │\n│                              │ Terminate Process [C0018]                     │\n└──────────────────────────────┴───────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                              ┃ Namespace                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ extract resource via kernel32 functions │ executable/resource                │\n│ contain an embedded PE file             │ executable/subfile/pe              │\n│ write file on Windows                   │ host-interaction/file-system/write │\n│ create process on Windows               │ host-interaction/process/create    │\n│ terminate process                       │ host-interaction/process/terminate │\n│ link function at runtime on Windows (5  │ linking/runtime-linking            │\n│ matches)                                │                                    │\n│ link many functions at runtime          │ linking/runtime-linking            │\n│ linked against ZLIB                     │ linking/static/zlib                │\n└─────────────────────────────────────────┴────────────────────────────────────┘\n\n","verbose":"md5                     174ad172303b51111727aea63e9bdc0a                        \nsha1                    94cec0c0823f19023c283e73a4b7486113e02f22                \nsha256                  5fc07750ace241e22a7d63a5d5aff50815e975aa0084c285ccc7c51…\npath                    /home/apogean/projects/malware/windows/all_runs/5fc0775…\ntimestamp               2026-07-19 11:51:03.087379                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x180000000                                             \nrules                   /tmp/_MEInkiQHz/rules                                   \nfunction count          29                                                      \nlibrary function count  170                                                     \ntotal feature count     43645                                                   \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x180001014        \n\ncontain an embedded PE file\nnamespace  executable/subfile/pe\nscope      file                 \n\nwrite file on Windows\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x180001014                       \n\ncreate process on Windows\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x1800010F8                    \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x180007DAF                       \n\nlink function at runtime on Windows (5 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x180007F31            \n           0x180007F5A            \n           0x180007F7A            \n           0x180007F9A            \n           0x180007FC2            \n\nlink many functions at runtime\nnamespace  linking/runtime-linking\nscope      function               \nmatches    0x180007ED0            \n\nlinked against ZLIB\nnamespace  linking/static/zlib\nscope      file               \n\n\n\n","very_verbose":"md5                     174ad172303b51111727aea63e9bdc0a                        \nsha1                    94cec0c0823f19023c283e73a4b7486113e02f22                \nsha256                  5fc07750ace241e22a7d63a5d5aff50815e975aa0084c285ccc7c51…\npath                    /home/apogean/projects/malware/windows/all_runs/5fc0775…\ntimestamp               2026-07-19 11:51:22.867281                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x180000000                                             \nrules                   /tmp/_MEISpnkGe/rules                                   \nfunction count          29                                                      \nlibrary function count  170                                                     \ntotal feature count     43645                                                   \n\ncontain loop (4 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x1800018FC\n  or:\n    characteristic: loop @ 0x1800018FC\n\ncreate or open file (library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x1800010AF\n  or:\n    api: CreateFile @ 0x1800010AF\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x180001014\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x180001055\n        api: LockResource @ 0x180001063\n      optional:\n        or:\n          api: FindResource @ 0x180001036\n        api: SizeofResource @ 0x18000107B\n\ncontain an embedded PE file\nnamespace  executable/subfile/pe                        \nauthor     moritz.raabe@mandiant.com                    \nscope      file                                         \nmbc        Execution::Install Additional Program [B0023]\nor:\n  count(characteristic(embedded pe)): 1 or more @ file+0xC8A8, file+0x178C8, file+0x1B928, file+0x3E94C\n\nwrite file on Windows\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x180001014\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x18000109D\n            number: 0x2 = FILE_WRITE_DATA @ 0x18000108D\n            match: create or open file @ 0x1800010AF\n              or:\n                api: CreateFile @ 0x1800010AF\n      or:\n        api: WriteFile @ 0x1800010D3\n\ncreate process on Windows\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x1800010F8 in function 0x1800010F8\n  or:\n    api: CreateProcess @ 0x180001178\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x180007DAF\n  or:\n    and:\n      or:\n        api: TerminateProcess @ 0x180007E44\n\nlink function at runtime on Windows (5 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x180007F31\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x180007F31\ninstruction @ 0x180007F5A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x180007F5A\ninstruction @ 0x180007F7A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x180007F7A\ninstruction @ 0x180007F9A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x180007F9A\ninstruction @ 0x180007FC2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x180007FC2\n\nlink many functions at runtime\nnamespace  linking/runtime-linking                      \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com\nscope      function                                     \natt&ck     Execution::Shared Modules [T1129]            \nfunction @ 0x180007ED0\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x180007F31, 0x180007F5A, 0x180007F7A, 0x180007F9A, and 1 more...\n\nlinked against ZLIB\nnamespace  linking/static/zlib              \nauthor     william.ballenthin@mandiant.com  \nscope      file                             \nmbc        Data::Compression Library [C0060]\nor:\n  regex: /inflate .* Copyright/\n    - \" inflate 1.1.3 Copyright 1995-1998 Mark Adler \" @ file+0x4B788\n\n\n\n"},"hashes":{"md5":"174ad172303b51111727aea63e9bdc0a","sha1":"94cec0c0823f19023c283e73a4b7486113e02f22","sha256":"5fc07750ace241e22a7d63a5d5aff50815e975aa0084c285ccc7c514c58c09df"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 29</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 43645</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"5fc0775\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"174ad172303b51111727aea63e9bdc0a\",\n        \"sha256\": \"5fc07750ace241e22a7d63a5d5aff50815e975aa0084c285ccc7c51\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1800018FC\",\n      \"label\": \"Function 0x1800018FC\",\n      \"type\": \"function\",\n      \"address\": \"0x1800018FC\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x180001014\",\n      \"label\": \"Function 0x180001014\",\n      \"type\": \"function\",\n      \"address\": \"0x180001014\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_contain_an_embedded_pe_file\",\n      \"label\": \"contain an embedded PE file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows\",\n      \"label\": \"write file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows\",\n      \"label\": \"create process on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1800010F8\",\n      \"label\": \"Block 0x1800010F8\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1800010F8\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180007DAF\",\n      \"label\": \"Function 0x180007DAF\",\n      \"type\": \"function\",\n      \"address\": \"0x180007DAF\"\n    },\n    {\n      \"id\": \"api_TerminateProcess\",\n      \"label\": \"TerminateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__5_matches_\",\n      \"label\": \"link function at runtime on Windows (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_many_functions_at_runtime\",\n      \"label\": \"link many functions at runtime\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180007ED0\",\n      \"label\": \"Function 0x180007ED0\",\n      \"type\": \"function\",\n      \"address\": \"0x180007ED0\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_linked_against_zlib\",\n      \"label\": \"linked against ZLIB\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Compression Library [C0060]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__4_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x1800018FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x180001014\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x180001014\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_an_embedded_pe_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows\",\n      \"target\": \"func_0x180001014\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x180001014\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows\",\n      \"target\": \"bb_0x1800010F8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1800010F8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x180007DAF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180007DAF\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x180007DAF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180007DAF\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_many_functions_at_runtime\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime\",\n      \"target\": \"func_0x180007ED0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x180007ED0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_linked_against_zlib\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-19 11:51:22.867281\",\n    \"total_functions\": \"29\",\n    \"total_features\": \"43645\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-19 11:51:23"}
{"_id":{"$oid":"6a5c7715b3bed57e0e737890"},"sha256":"19ee106f5490826e09271022d24b27a0586a48c5c9db4a55a63320bafcbb8342","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_cqy68hdx/19ee106f5490826e09271022d24b27a0586a48c5c9db4a55a63320bafcbb8342-019f7901f0467b93b982cba84d4dbea2.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_cqy68hdx/19ee106f5490826e09271022d24b27a0586a48c5c9db4a55a63320bafcbb8342-019f7901f0467b93b982cba84d4dbea2.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_cqy68hdx/19ee106f5490826e09271022d24b27a0586a48c5c9db4a55a63320bafcbb8342-019f7901f0467b93b982cba84d4dbea2.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 5dd58790c78d382d696cdfbca55f832d                                  │\n│ sha1     │ 67d86cf4d4c8a064647dc468c18344541affdaea                          │\n│ sha256   │ 19ee106f5490826e09271022d24b27a0586a48c5c9db4a55a63320bafcbb8342  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ amd64                                                             │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/19ee106f5490826e… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION      │ Obfuscated Files or Information [T1027]               │\n│                      │ Obfuscated Files or Information::Indicator Removal    │\n│                      │ from Tools [T1027.005]                                │\n│                      │ Process Injection::Thread Execution Hijacking         │\n│                      │ [T1055.003]                                           │\n│                      │ Reflective Code Loading [T1620]                       │\n│ DISCOVERY            │ Application Window Discovery [T1010]                  │\n│                      │ System Information Discovery [T1082]                  │\n│                      │ System Location Discovery [T1614]                     │\n│                      │ System Location Discovery::System Language Discovery  │\n│                      │ [T1614.001]                                           │\n│ EXECUTION            │ Command and Scripting Interpreter [T1059]             │\n│                      │ Shared Modules [T1129]                                │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-STATIC ANALYSIS │ Executable Code Obfuscation::Argument Obfuscation     │\n│                      │ [B0032.020]                                           │\n│                      │ Executable Code Obfuscation::Stack Strings            │\n│                      │ [B0032.017]                                           │\n│ COMMUNICATION        │ HTTP Communication::Read Header [C0002.014]           │\n│ CRYPTOGRAPHY         │ Encrypt Data::RC4 [C0027.009]                         │\n│                      │ Encryption Key::RC4 KSA [C0028.002]                   │\n│                      │ Generate Pseudo-random Sequence::RC4 PRGA [C0021.004] │\n│ DATA                 │ Checksum::CRC32 [C0032.001]                           │\n│                      │ Encode Data::XOR [C0026.002]                          │\n│                      │ Non-Cryptographic Hash::djb2 [C0030.006]              │\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Encoding-Standard    │\n│                      │ Algorithm [E1027.m02]                                 │\n│ DISCOVERY            │ System Information Discovery [E1082]                  │\n│ EXECUTION            │ Command and Scripting Interpreter [E1059]             │\n│ FILE SYSTEM          │ Copy File [C0045]                                     │\n│                      │ Create Directory [C0046]                              │\n│ PROCESS              │ Create Mutex [C0042]                                  │\n│                      │ Create Thread [C0038]                                 │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                           ┃ Namespace                             ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ contain obfuscated stackstrings      │ anti-analysis/obfuscation/string/sta… │\n│ get geographical location            │ collection                            │\n│ check HTTP status code (3 matches)   │ communication/http/client             │\n│ hash data with CRC32                 │ data-manipulation/checksum/crc32      │\n│ encode data using XOR (10 matches)   │ data-manipulation/encoding/xor        │\n│ encrypt data using RC4 KSA           │ data-manipulation/encryption/rc4      │\n│ encrypt data using RC4 PRGA (2       │ data-manipulation/encryption/rc4      │\n│ matches)                             │                                       │\n│ encrypt data using Salsa20 or ChaCha │ data-manipulation/encryption/salsa20  │\n│ hash data using djb2                 │ data-manipulation/hashing/djb2        │\n│ accept command line arguments        │ host-interaction/cli                  │\n│ set current directory                │ host-interaction/file-system          │\n│ copy file                            │ host-interaction/file-system/copy     │\n│ create directory                     │ host-interaction/file-system/create   │\n│ enumerate gui resources              │ host-interaction/gui                  │\n│ get disk information                 │ host-interaction/hardware/storage     │\n│ create or open mutex on Windows (2   │ host-interaction/mutex                │\n│ matches)                             │                                       │\n│ check OS version                     │ host-interaction/os/version           │\n│ inject thread                        │ host-interaction/process/inject       │\n│ link function at runtime on Windows  │ linking/runtime-linking               │\n│ (77 matches)                         │                                       │\n│ link many functions at runtime (5    │ linking/runtime-linking               │\n│ matches)                             │                                       │\n│ parse PE header (5 matches)          │ load-code/pe                          │\n│ resolve function by parsing PE       │ load-code/pe                          │\n│ exports (6 matches)                  │                                       │\n│ identify system language via API     │ targeting/language                    │\n└──────────────────────────────────────┴───────────────────────────────────────┘\n\n","verbose":"md5                     5dd58790c78d382d696cdfbca55f832d                        \nsha1                    67d86cf4d4c8a064647dc468c18344541affdaea                \nsha256                  19ee106f5490826e09271022d24b27a0586a48c5c9db4a55a63320b…\npath                    /home/apogean/projects/malware/windows/all_runs/19ee106…\ntimestamp               2026-07-19 12:34:39.849260                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIdbhnMG/rules                                   \nfunction count          270                                                     \nlibrary function count  1                                                       \ntotal feature count     26644                                                   \n\ncontain obfuscated stackstrings\nnamespace  anti-analysis/obfuscation/string/stackstring\nscope      basic block                                 \nmatches    0x406CBB                                    \n\nget geographical location\nnamespace  collection\nscope      function  \nmatches    0x424650  \n\ncheck HTTP status code (3 matches)\nnamespace  communication/http/client\nscope      function                 \nmatches    0x40E370                 \n           0x418370                 \n           0x4188E0                 \n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32\nscope      function                        \nmatches    0x423F30                        \n\nencode data using XOR (10 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x402FA1                      \n           0x40F11B                      \n           0x419136                      \n           0x41916C                      \n           0x4191E1                      \n           0x4192F3                      \n           0x41F9BA                      \n           0x423F6D                      \n           0x423FD0                      \n           0x4242D3                      \n\nencrypt data using RC4 KSA\nnamespace  data-manipulation/encryption/rc4\nscope      function                        \nmatches    0x411D60                        \n\nencrypt data using RC4 PRGA (2 matches)\nnamespace  data-manipulation/encryption/rc4\nscope      function                        \nmatches    0x411D60                        \n           0x4145D0                        \n\nencrypt data using Salsa20 or ChaCha\nnamespace  data-manipulation/encryption/salsa20\nscope      function                            \nmatches    0x424030                            \n\nhash data using djb2\nnamespace  data-manipulation/hashing/djb2\nscope      function                      \nmatches    0x408B10                      \n\naccept command line arguments\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x424650            \n\nset current directory\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x424650                    \n\ncopy file\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    0x424650                         \n\ncreate directory\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x424650                           \n\nenumerate gui resources\nnamespace  host-interaction/gui\nscope      function            \nmatches    0x424650            \n\nget disk information\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x424650                         \n\ncreate or open mutex on Windows (2 matches)\nnamespace  host-interaction/mutex\nscope      instruction           \nmatches    0x4247E7              \n           0x4248E6              \n\ncheck OS version\nnamespace  host-interaction/os/version\nscope      function                   \nmatches    0x424650                   \n\ninject thread\nnamespace  host-interaction/process/inject\nscope      function                       \nmatches    0x4188E0                       \n\ncreate thread\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x41A329                      \n\nlink function at runtime on Windows (77 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x4121C0               \n           0x4121E6               \n           0x41220C               \n           0x412232               \n           0x412258               \n           0x41227E               \n           0x4122A4               \n           0x4122C3               \n           0x4122E2               \n           0x412301               \n           0x412402               \n           0x412428               \n           0x41244E               \n           0x412474               \n           0x41249A               \n           0x4124C0               \n           0x4124E6               \n           0x41250C               \n           0x412532               \n           0x412558               \n           0x41257E               \n           0x412697               \n           0x412790               \n           0x4127B2               \n           0x4127D4               \n           0x4127F2               \n           0x412814               \n           0x412836               \n           0x412858               \n           0x41287A               \n           0x412895               \n           0x4128B7               \n           0x4128D9               \n           0x4128FB               \n           0x41291D               \n           0x412938               \n           0x41295A               \n           0x41297C               \n           0x41299E               \n           0x4129C0               \n           0x4129E2               \n           0x412A04               \n           0x412A26               \n           0x412A48               \n           0x412A88               \n           0x412AAA               \n           0x412ACC               \n           0x412AF3               \n           0x412B15               \n           0x412B37               \n           0x412B59               \n           0x41F770               \n           0x41F796               \n           0x41F7BC               \n           0x41F831               \n           0x41F857               \n           0x41F87D               \n           0x41F8A3               \n           0x41F8C9               \n           0x41F8EF               \n           0x41F915               \n           0x41F9DF               \n           0x41FC47               \n           0x41FC6D               \n           0x41FC93               \n           0x41FCB9               \n           0x41FCDF               \n           0x41FD05               \n           0x41FD2B               \n           0x41FDC9               \n           0x41FDEF               \n           0x425641               \n           0x42566B               \n           0x425695               \n           0x4256BF               \n           0x4256E9               \n           0x425713               \n\nlink many functions at runtime (5 matches)\nnamespace  linking/runtime-linking\nscope      function               \nmatches    0x412160               \n           0x412370               \n           0x4126D0               \n           0x41F700               \n           0x424650               \n\nparse PE header (5 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x406BB0    \n           0x407160    \n           0x407230    \n           0x4188E0    \n           0x424650    \n\nresolve function by parsing PE exports (6 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x406BB0    \n           0x407160    \n           0x407230    \n           0x407580    \n           0x407BF0    \n           0x4188E0    \n\nidentify system language via API\nnamespace  targeting/language\nscope      function          \nmatches    0x40F500          \n\n\n\n","very_verbose":"md5                     5dd58790c78d382d696cdfbca55f832d                        \nsha1                    67d86cf4d4c8a064647dc468c18344541affdaea                \nsha256                  19ee106f5490826e09271022d24b27a0586a48c5c9db4a55a63320b…\npath                    /home/apogean/projects/malware/windows/all_runs/19ee106…\ntimestamp               2026-07-19 12:34:52.386637                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIw6XcU9/rules                                   \nfunction count          270                                                     \nlibrary function count  1                                                       \ntotal feature count     26644                                                   \n\nPEB access (2 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Debugger Detection::Process Environment   \n            Block [B0001.019]                                                   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nbasic block @ 0x41016C in function 0x40F500\n  or:\n    characteristic: peb access @ 0x41017A\n\nallocate memory (library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x419BAF in function 0x4188E0\n  or:\n    api: VirtualAllocEx @ 0x419BC9\n\nallocate or change RW memory (library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x419BAF in function 0x4188E0\n  and:\n    or:\n      match: allocate memory @ 0x419BAF\n        or:\n          api: VirtualAllocEx @ 0x419BC9\n    or:\n      number: 0x4 = PAGE_READWRITE @ 0x419BAF\n\nchange memory protection (library rule)\nauthor  @mr-tz                                  \nscope   basic block                             \nmbc     Memory::Change Memory Protection [C0008]\nbasic block @ 0x41A144 in function 0x4188E0\n  or:\n    api: VirtualProtectEx @ 0x41A159\n\ncontain loop (221 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401000\n  or:\n    characteristic: loop @ 0x401000\n\ndelay execution (2 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x417D7D in function 0x417D60\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x417D84\n\nget OS version (library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x424650\n  or:\n    and:\n      match: PEB access @ 0x424650\n        or:\n          characteristic: peb access @ 0x424663\n      or:\n        and:\n          arch: amd64\n          or:\n            offset: 0x118 = PEB->OSMajorVersion @ 0x425946\n            offset: 0x120 = PEB->OSBuildNumber @ 0x4259AF\n\nwrite process memory (library rule)\nauthor  moritz.raabe@mandiant.com                 \nscope   instruction                               \natt&ck  Defense Evasion::Process Injection [T1055]\ninstruction @ 0x41A08C\n  or:\n    api: WriteProcessMemory @ 0x41A08C\n\ncontain obfuscated stackstrings\nnamespace  anti-analysis/obfuscation/string/stackstring                         \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information::Indicator Removal  \n           from Tools [T1027.005]                                               \nmbc        Anti-Static Analysis::Executable Code Obfuscation::Argument          \n           Obfuscation [B0032.020], Anti-Static Analysis::Executable Code       \n           Obfuscation::Stack Strings [B0032.017]                               \nbasic block @ 0x406CBB in function 0x406BB0\n  characteristic: stack string @ 0x406CBB\n\nget geographical location\nnamespace  collection                                  \nauthor     moritz.raabe, michael.hunhoff@mandiant.com  \nscope      function                                    \natt&ck     Discovery::System Location Discovery [T1614]\nfunction @ 0x424650\n  or:\n    api: GetLocaleInfo @ 0x42489E\n\ncheck HTTP status code (3 matches)\nnamespace  communication/http/client                                 \nauthor     @mr-tz                                                    \nscope      function                                                  \nmbc        Communication::HTTP Communication::Read Header [C0002.014]\nfunction @ 0x40E370\n  and:\n    os: windows\n    instruction:\n      and:\n        or:\n          mnemonic: cmp @ 0x40E5B3\n        or:\n          number: 0x193 = Forbidden @ 0x40E5B3\n    or:\n      number: 0x20000013 = HTTP_QUERY_FLAG_NUMBER | HTTP_QUERY_STATUS_CODE @ 0x40E595\n      number: 0x13 = HTTP_QUERY_STATUS_CODE @ 0x40F12A\nfunction @ 0x418370\n  and:\n    os: windows\n    instruction:\n      and:\n        or:\n          mnemonic: cmp @ 0x418793\n        or:\n          number: 0xC8 = OK @ 0x418793\n    or:\n      number: 0x20000013 = HTTP_QUERY_FLAG_NUMBER | HTTP_QUERY_STATUS_CODE @ 0x418763\nfunction @ 0x4188E0\n  and:\n    os: windows\n    instruction:\n      and:\n        or:\n          mnemonic: cmp @ 0x419042\n        or:\n          number: 0xC8 = OK @ 0x419042\n    or:\n      number: 0x20000013 = HTTP_QUERY_FLAG_NUMBER | HTTP_QUERY_STATUS_CODE @ 0x419017\n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32 \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \nmbc        Data::Checksum::CRC32 [C0032.001]\nfunction @ 0x423F30\n  or:\n    and:\n      number: 0x1 = bits in a byte @ 0x423F4D, 0x423F70, 0x423F75\n      instruction:\n        and:\n          operand[1].number: 0x1 @ 0x423F70\n          or:\n            mnemonic: and @ 0x423F70\n      instruction:\n        and:\n          mnemonic: shr @ 0x423F75\n          number: 0x1 @ 0x423F75\n      characteristic: nzxor @ 0x423F7D, 0x423FD3, 0x423FE0\n      operand[1].number: 0xEDB88320 @ 0x423F78\n\nencode data using XOR (10 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x402FA1 in function 0x401C80\n  and:\n    characteristic: tight loop @ 0x402FA1\n    characteristic: nzxor @ 0x402FB0\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x40F11B in function 0x40E370\n  and:\n    characteristic: tight loop @ 0x40F11B\n    characteristic: nzxor @ 0x40F11F\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x419136 in function 0x4188E0\n  and:\n    characteristic: tight loop @ 0x419136\n    characteristic: nzxor @ 0x419158, 0x41915D\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x41916C in function 0x4188E0\n  and:\n    characteristic: tight loop @ 0x41916C\n    characteristic: nzxor @ 0x419170\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4191E1 in function 0x4188E0\n  and:\n    characteristic: tight loop @ 0x4191E1\n    characteristic: nzxor @ 0x4191EA\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4192F3 in function 0x4188E0\n  and:\n    characteristic: tight loop @ 0x4192F3\n    characteristic: nzxor @ 0x4192F8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x41F9BA in function 0x41F700\n  and:\n    characteristic: tight loop @ 0x41F9BA\n    characteristic: nzxor @ 0x41F9BE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x423F6D in function 0x423F30\n  and:\n    characteristic: tight loop @ 0x423F6D\n    characteristic: nzxor @ 0x423F7D\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x423FD0 in function 0x423F30\n  and:\n    characteristic: tight loop @ 0x423FD0\n    characteristic: nzxor @ 0x423FD3, 0x423FE0\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4242D3 in function 0x424030\n  and:\n    characteristic: tight loop @ 0x4242D3\n    characteristic: nzxor @ 0x4242DC, 0x4242DE, 0x4242E0, 0x4242F1, and 28 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nencrypt data using RC4 KSA\nnamespace  data-manipulation/encryption/rc4                                     \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Encrypt Data::RC4 [C0027.009], Cryptography::Encryption\n           Key::RC4 KSA [C0028.002]                                             \nfunction @ 0x411D60\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x411DB3\n          or:\n            number: 0x100 @ 0x411DBA\n        and: = initialize S\n          characteristic: tight loop @ 0x411DCB\n          or:\n            number: 0x100 @ 0x411DFF\n      or: = modulo 256\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x411DE2, 0x411DE6\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: idiv @ 0x411D8E, 0x411DD2\n\nencrypt data using RC4 PRGA (2 matches)\nnamespace  data-manipulation/encryption/rc4                                     \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Encrypt Data::RC4 [C0027.009], Cryptography::Generate  \n           Pseudo-random Sequence::RC4 PRGA [C0021.004]                         \nfunction @ 0x411D60\n  and:\n    match: contain loop @ 0x411D60\n      or:\n        characteristic: loop @ 0x411D60\n        characteristic: tight loop @ 0x411DB3, 0x411DCB\n    count(characteristic(nzxor)): 1 @ 0x411E4F\n    count(characteristic(calls from)): 4 or fewer @ 0x411EB0, 0x4266A0, 0x4269D0\n    count(basic block): between 4 and 50 @ 0x411D60, 0x411DB3, 0x411DC2, 0x411DCB, and 10 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x411DE2, 0x411DE6, 0x411E15, 0x411E22, and 1 more...\n    optional:\n      or:\n        number: 0x100 @ 0x411DBA, 0x411DFF, 0x411E57\nfunction @ 0x4145D0\n  and:\n    match: contain loop @ 0x4145D0\n      or:\n        characteristic: loop @ 0x4145D0\n        characteristic: tight loop @ 0x4147BB\n    count(characteristic(nzxor)): 1 @ 0x414730\n    count(characteristic(calls from)): 4 or fewer @ 0x4266C0\n    count(basic block): between 4 and 50 @ 0x4145D0, 0x414613, 0x41462B, 0x41462F, and 31 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x414641, 0x41467E, 0x4146BA, 0x414733\n\nencrypt data using Salsa20 or ChaCha\nnamespace   data-manipulation/encryption/salsa20                    \nauthor      moritz.raabe@mandiant.com                               \nscope       function                                                \natt&ck      Defense Evasion::Obfuscated Files or Information [T1027]\nreferences  http://cr.yp.to/snuffle/ecrypt.c                        \nfunction @ 0x424030\n  or: = part of key setup\n    and:\n      number: 0x61707865 = \"apxe\" @ 0x42428D, 0x424462\n      number: 0x3320646E = \"3 dn\" @ 0x42427C, 0x424448\n      number: 0x79622D32 = \"yb-2\" @ 0x424277, 0x424442\n      number: 0x6B206574 = \"k et\" @ 0x42425D, 0x42444E\n\nhash data using djb2\nnamespace   data-manipulation/hashing/djb2                                      \nauthor      awillia2@cisco.com, still@teamt5.org                                \nscope       function                                                            \nmbc         Data::Non-Cryptographic Hash::djb2 [C0030.006]                      \nreferences  https://twitter.com/r3c0nst/status/1392405576131436546,             \n            http://www.cse.yorku.ca/~oz/hash.html                               \nfunction @ 0x408B10\n  and:\n    instruction:\n      and:\n        mnemonic: mov @ 0x408C61\n        number: 0x1505 @ 0x408C61\n    or:\n      instruction:\n        and:\n          number: 0x21 @ 0x408C73\n          or:\n            mnemonic: imul @ 0x408C73\n\naccept command line arguments\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x424650\n  or:\n    api: GetCommandLine @ 0x4248CF\n\nset current directory\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x424650\n  or:\n    api: SetCurrentDirectory @ 0x42481E\n\ncopy file\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ 0x424650\n  or:\n    api: CopyFile @ 0x4247DA\n\ncreate directory\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x424650\n  or:\n    api: CreateDirectory @ 0x424886\n\nenumerate gui resources\nnamespace  host-interaction/gui                           \nauthor     johnk3r, anushka.virgaonkar@mandiant.com       \nscope      function                                       \natt&ck     Discovery::Application Window Discovery [T1010]\nfunction @ 0x424650\n  or:\n    api: EnumWindows @ 0x4247B5\n\nget disk information\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ 0x424650\n  or:\n    api: GetDriveType @ 0x42488E\n    api: GetLogicalDrives @ 0x4251BE\n\ncreate or open mutex on Windows (2 matches)\nnamespace  host-interaction/mutex                                               \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           mehunhoff@google.com                                                 \nscope      instruction                                                          \nmbc        Process::Create Mutex [C0042]                                        \ninstruction @ 0x4247E7\n  or:\n    api: CreateMutex @ 0x4247E7\ninstruction @ 0x4248E6\n  or:\n    api: OpenMutex @ 0x4248E6\n\ncheck OS version\nnamespace  host-interaction/os/version                    \nauthor     michael.hunhoff@mandiant.com, johnk3r          \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x424650\n  and:\n    match: get OS version @ 0x424650\n      or:\n        and:\n          match: PEB access @ 0x424650\n            or:\n              characteristic: peb access @ 0x424663\n          or:\n            and:\n              arch: amd64\n              or:\n                offset: 0x118 = PEB->OSMajorVersion @ 0x425946\n                offset: 0x120 = PEB->OSBuildNumber @ 0x4259AF\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x4255CE\n            number: 0x5 = Windows 2000 @ 0x4255CE\n        optional:\n          instruction:\n            and:\n              mnemonic: cmp @ 0x425180\n              or:\n                number: 0x0 @ 0x425180\n            and:\n              mnemonic: cmp @ 0x425A82\n              or:\n                number: 0x0 @ 0x425A82\n            and:\n              mnemonic: cmp @ 0x425145\n              or:\n                number: 0x0 @ 0x425145\n            and:\n              mnemonic: cmp @ 0x42518A\n              or:\n                number: 0x0 @ 0x42518A\n            and:\n              mnemonic: cmp @ 0x425D52\n              or:\n                number: 0x0 @ 0x425D52\n            and:\n              mnemonic: cmp @ 0x425715\n              or:\n                number: 0x0 @ 0x425715\n            and:\n              mnemonic: cmp @ 0x425198\n              or:\n                number: 0x0 @ 0x425198\n            and:\n              mnemonic: cmp @ 0x42511E\n              or:\n                number: 0x0 @ 0x42511E\n            and:\n              mnemonic: cmp @ 0x42571F\n              or:\n                number: 0x0 @ 0x42571F\n            and:\n              mnemonic: cmp @ 0x424960\n              or:\n                number: 0x2 = Windows XP 64-bit / Windows Server 2003 / Windows Server 2003 R2 @ 0x424960\n            and:\n              mnemonic: cmp @ 0x425C9F\n              or:\n                number: 0x0 @ 0x425C9F\n            and:\n              mnemonic: cmp @ 0x425164\n              or:\n                number: 0x0 @ 0x425164\n            and:\n              mnemonic: cmp @ 0x425729\n              or:\n                number: 0x0 @ 0x425729\n            and:\n              mnemonic: cmp @ 0x42512B\n              or:\n                number: 0x0 @ 0x42512B\n            and:\n              mnemonic: cmp @ 0x42556B\n              or:\n                number: 0x0 @ 0x42556B\n            and:\n              mnemonic: cmp @ 0x425E2E\n              or:\n                number: 0x0 @ 0x425E2E\n            and:\n              mnemonic: cmp @ 0x42516F\n              or:\n                number: 0x0 @ 0x42516F\n            and:\n              mnemonic: cmp @ 0x425733\n              or:\n                number: 0x0 @ 0x425733\n            and:\n              mnemonic: cmp @ 0x425138\n              or:\n                number: 0x0 @ 0x425138\n            and:\n              mnemonic: cmp @ 0x4255BA\n              or:\n                number: 0x1 = Windows XP @ 0x4255BA\n            and:\n              mnemonic: cmp @ 0x42573D\n              or:\n                number: 0x0 @ 0x42573D\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x4255E8\n            number: 0xA = Windows Server 2016 / Windows Server 2019 / Windows 10 @ 0x4255E8\n        optional:\n          instruction:\n            and:\n              mnemonic: cmp @ 0x425180\n              number: 0x0 @ 0x425180\n            and:\n              mnemonic: cmp @ 0x425A82\n              number: 0x0 @ 0x425A82\n            and:\n              mnemonic: cmp @ 0x425145\n              number: 0x0 @ 0x425145\n            and:\n              mnemonic: cmp @ 0x42518A\n              number: 0x0 @ 0x42518A\n            and:\n              mnemonic: cmp @ 0x425D52\n              number: 0x0 @ 0x425D52\n            and:\n              mnemonic: cmp @ 0x425715\n              number: 0x0 @ 0x425715\n            and:\n              mnemonic: cmp @ 0x425198\n              number: 0x0 @ 0x425198\n            and:\n              mnemonic: cmp @ 0x42511E\n              number: 0x0 @ 0x42511E\n            and:\n              mnemonic: cmp @ 0x425C9F\n              number: 0x0 @ 0x425C9F\n            and:\n              mnemonic: cmp @ 0x42571F\n              number: 0x0 @ 0x42571F\n            and:\n              mnemonic: cmp @ 0x425164\n              number: 0x0 @ 0x425164\n            and:\n              mnemonic: cmp @ 0x425729\n              number: 0x0 @ 0x425729\n            and:\n              mnemonic: cmp @ 0x42512B\n              number: 0x0 @ 0x42512B\n            and:\n              mnemonic: cmp @ 0x42556B\n              number: 0x0 @ 0x42556B\n            and:\n              mnemonic: cmp @ 0x425E2E\n              number: 0x0 @ 0x425E2E\n            and:\n              mnemonic: cmp @ 0x42516F\n              number: 0x0 @ 0x42516F\n            and:\n              mnemonic: cmp @ 0x425733\n              number: 0x0 @ 0x425733\n            and:\n              mnemonic: cmp @ 0x425138\n              number: 0x0 @ 0x425138\n            and:\n              mnemonic: cmp @ 0x42573D\n              number: 0x0 @ 0x42573D\n\ninject thread\nnamespace  host-interaction/process/inject                                      \nauthor     anamaria.martinezgom@mandiant.com, 0x534a@mailbox.org                \nscope      function                                                             \natt&ck     Defense Evasion::Process Injection::Thread Execution Hijacking       \n           [T1055.003], Defense Evasion::Reflective Code Loading [T1620]        \nfunction @ 0x4188E0\n  and:\n    match: write process memory @ 0x41A08C\n      or:\n        api: WriteProcessMemory @ 0x41A08C\n    match: create thread @ 0x41A329\n      or:\n        and:\n          os: windows\n          or:\n            api: CreateRemoteThread @ 0x41A348\n    or:\n      match: allocate or change RW memory @ 0x419BAF\n        and:\n          or:\n            match: allocate memory @ 0x419BAF\n              or:\n                api: VirtualAllocEx @ 0x419BC9\n          or:\n            number: 0x4 = PAGE_READWRITE @ 0x419BAF\n    optional:\n      or:\n        number: 0x3000 = MEM_COMMIT or MEM_RESERVE @ 0x419BBC\n\ncreate thread\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x41A329 in function 0x4188E0\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateRemoteThread @ 0x41A348\n\nlink function at runtime on Windows (77 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x4121C0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4121C0\ninstruction @ 0x4121E6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4121E6\ninstruction @ 0x41220C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41220C\ninstruction @ 0x412232\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412232\ninstruction @ 0x412258\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412258\ninstruction @ 0x41227E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41227E\ninstruction @ 0x4122A4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4122A4\ninstruction @ 0x4122C3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4122C3\ninstruction @ 0x4122E2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4122E2\ninstruction @ 0x412301\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412301\ninstruction @ 0x412402\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412402\ninstruction @ 0x412428\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412428\ninstruction @ 0x41244E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41244E\ninstruction @ 0x412474\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412474\ninstruction @ 0x41249A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41249A\ninstruction @ 0x4124C0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4124C0\ninstruction @ 0x4124E6\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4124E6\ninstruction @ 0x41250C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41250C\ninstruction @ 0x412532\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412532\ninstruction @ 0x412558\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412558\ninstruction @ 0x41257E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41257E\ninstruction @ 0x412697\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412697\ninstruction @ 0x412790\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412790\ninstruction @ 0x4127B2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4127B2\ninstruction @ 0x4127D4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4127D4\ninstruction @ 0x4127F2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4127F2\ninstruction @ 0x412814\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412814\ninstruction @ 0x412836\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412836\ninstruction @ 0x412858\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412858\ninstruction @ 0x41287A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41287A\ninstruction @ 0x412895\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412895\ninstruction @ 0x4128B7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4128B7\ninstruction @ 0x4128D9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4128D9\ninstruction @ 0x4128FB\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4128FB\ninstruction @ 0x41291D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41291D\ninstruction @ 0x412938\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412938\ninstruction @ 0x41295A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41295A\ninstruction @ 0x41297C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41297C\ninstruction @ 0x41299E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41299E\ninstruction @ 0x4129C0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4129C0\ninstruction @ 0x4129E2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4129E2\ninstruction @ 0x412A04\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412A04\ninstruction @ 0x412A26\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412A26\ninstruction @ 0x412A48\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412A48\ninstruction @ 0x412A88\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412A88\ninstruction @ 0x412AAA\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412AAA\ninstruction @ 0x412ACC\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412ACC\ninstruction @ 0x412AF3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412AF3\ninstruction @ 0x412B15\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412B15\ninstruction @ 0x412B37\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412B37\ninstruction @ 0x412B59\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x412B59\ninstruction @ 0x41F770\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41F770\ninstruction @ 0x41F796\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41F796\ninstruction @ 0x41F7BC\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41F7BC\ninstruction @ 0x41F831\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41F831\ninstruction @ 0x41F857\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41F857\ninstruction @ 0x41F87D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41F87D\ninstruction @ 0x41F8A3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41F8A3\ninstruction @ 0x41F8C9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41F8C9\ninstruction @ 0x41F8EF\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41F8EF\ninstruction @ 0x41F915\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41F915\ninstruction @ 0x41F9DF\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41F9DF\ninstruction @ 0x41FC47\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41FC47\ninstruction @ 0x41FC6D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41FC6D\ninstruction @ 0x41FC93\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41FC93\ninstruction @ 0x41FCB9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41FCB9\ninstruction @ 0x41FCDF\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41FCDF\ninstruction @ 0x41FD05\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41FD05\ninstruction @ 0x41FD2B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41FD2B\ninstruction @ 0x41FDC9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41FDC9\ninstruction @ 0x41FDEF\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x41FDEF\ninstruction @ 0x425641\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x425641\ninstruction @ 0x42566B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x42566B\ninstruction @ 0x425695\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x425695\ninstruction @ 0x4256BF\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4256BF\ninstruction @ 0x4256E9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4256E9\ninstruction @ 0x425713\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x425713\n\nlink many functions at runtime (5 matches)\nnamespace  linking/runtime-linking                      \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com\nscope      function                                     \natt&ck     Execution::Shared Modules [T1129]            \nfunction @ 0x412160\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x4121C0, 0x4121E6, 0x41220C, 0x412232, and 6 more...\nfunction @ 0x412370\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x412402, 0x412428, 0x41244E, 0x412474, and 7 more...\nfunction @ 0x4126D0\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x412790, 0x4127B2, 0x4127D4, 0x4127F2, and 25 more...\nfunction @ 0x41F700\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x41F770, 0x41F796, 0x41F7BC, 0x41F831, and 16 more...\nfunction @ 0x424650\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x425641, 0x42566B, 0x425695, 0x4256BF, and 2 more...\n\nparse PE header (5 matches)\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x406BB0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x406BBF, 0x406C8E, 0x406CB2, 0x406CB6, and 14 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x407191, 0x40724E\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x407172, 0x40723C\nfunction @ 0x407160\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x407172, 0x407191, 0x4071B5, 0x4071EE, and 4 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x407191\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x407172\nfunction @ 0x407230\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x407172, 0x407191, 0x4071B5, 0x4071EE, and 9 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x407191, 0x40724E\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x407172, 0x40723C\nfunction @ 0x4188E0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x4188F3, 0x419037, 0x419042, 0x419090, and 81 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x419B7F\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x419B67\n        and:\n          number: 0x4D @ 0x418A68, 0x418AFA, 0x419321\n          number: 0x5A @ 0x41932C\n      optional:\n        and:\n          operand[1].offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x419B78, 0x41A17D\n          or:\n            and:\n              arch: amd64\n              operand[1].offset: 0x50 = IMAGE_NT_HEADERS64.OptionalHeader.SizeOfImage @ 0x419B8B\n              operand[1].offset: 0x30 = IMAGE_NT_HEADERS64.OptionalHeader.ImageBase @ 0x419675, 0x419687, 0x4196CF, 0x419C6E\nfunction @ 0x424650\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x424670, 0x424681, 0x42469F, 0x4246A4, and 49 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x424681\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x424670\n\nresolve function by parsing PE exports (6 matches)\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x406BB0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x406BB0\n      mnemonic: movzx @ 0x4071D9, 0x4072C0\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x40718A, 0x407247\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x407199, 0x40725B\n      3 or more:\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x4071D0, 0x4072B6\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x406D1F, 0x406D53, 0x406D71, 0x4071AB, and 8 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x4071AE, 0x40727A\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x4071DE, 0x4072C5\nfunction @ 0x407160\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x407160\n      mnemonic: movzx @ 0x4071D9\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x40718A\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x407199\n      3 or more:\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x4071D0\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x4071AB, 0x423BDC, 0x423BF2, 0x423BF7, and 4 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x4071AE\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x4071DE\nfunction @ 0x407230\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x407230\n      mnemonic: movzx @ 0x4071D9, 0x4072C0\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x40718A, 0x407247\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x407199, 0x40725B\n      3 or more:\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x4071D0, 0x4072B6\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x4071AB, 0x407276, 0x423BDC, 0x423BF2, and 5 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x4071AE, 0x40727A\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x4071DE, 0x4072C5\nfunction @ 0x407580\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x407580\n      mnemonic: movzx @ 0x407869\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x4075B0\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x4075E3\n      3 or more:\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x4076A4\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x4075B7, 0x4075F3, 0x40760B, 0x407654, and 9 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x407646\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x40766E\nfunction @ 0x407BF0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x407BF0\n      mnemonic: movzx @ 0x407D19\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x407C59\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x407C60\n      3 or more:\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x407C7F\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x407C7B\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x407C85\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x407C82\nfunction @ 0x4188E0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x4188E0\n      mnemonic: movzx @ 0x419C14, 0x419C29, 0x419F98, 0x41A04F, and 5 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x419B78, 0x41A17D\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x4189E7, 0x418C97, 0x418E70, 0x4192AC, and 7 more...\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x419C14, 0x419C3C, 0x419F64, 0x41A09A, and 6 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x41A0CF, 0x41A1E6\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x418F36, 0x418FC4, 0x41900F, 0x41906B, and 21 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x419C10, 0x41A19F, 0x41A286\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x41A1EA\n\nidentify system language via API\nnamespace  targeting/language                                                   \nauthor     william.ballenthin@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Location Discovery::System Language Discovery      \n           [T1614.001]                                                          \nfunction @ 0x40F500\n  and:\n    os: windows\n    or:\n      api: GetUserDefaultLangID @ 0x4114A0\n\n\n\n"},"hashes":{"md5":"5dd58790c78d382d696cdfbca55f832d","sha1":"67d86cf4d4c8a064647dc468c18344541affdaea","sha256":"19ee106f5490826e09271022d24b27a0586a48c5c9db4a55a63320bafcbb8342"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 270</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 26644</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"19ee106\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"5dd58790c78d382d696cdfbca55f832d\",\n        \"sha256\": \"19ee106f5490826e09271022d24b27a0586a48c5c9db4a55a63320b\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_peb_access__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"PEB access (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Process Environment\",\n        \"Block [B0001.019]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x41016C\",\n      \"label\": \"Block 0x41016C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x41016C\"\n    },\n    {\n      \"id\": \"cap_contain_loop__221_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (221 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401000\",\n      \"label\": \"Function 0x401000\",\n      \"type\": \"function\",\n      \"address\": \"0x401000\"\n    },\n    {\n      \"id\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x417D7D\",\n      \"label\": \"Block 0x417D7D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x417D7D\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_contain_obfuscated_stackstrings\",\n      \"label\": \"contain obfuscated stackstrings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x406CBB\",\n      \"label\": \"Block 0x406CBB\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x406CBB\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_geographical_location\",\n      \"label\": \"get geographical location\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x424650\",\n      \"label\": \"Function 0x424650\",\n      \"type\": \"function\",\n      \"address\": \"0x424650\"\n    },\n    {\n      \"id\": \"api_GetLocaleInfo\",\n      \"label\": \"GetLocaleInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_http_status_code__3_matches_\",\n      \"label\": \"check HTTP status code (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Read Header [C0002.014]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4188E0\",\n      \"label\": \"Function 0x4188E0\",\n      \"type\": \"function\",\n      \"address\": \"0x4188E0\"\n    },\n    {\n      \"id\": \"func_0x40E370\",\n      \"label\": \"Function 0x40E370\",\n      \"type\": \"function\",\n      \"address\": \"0x40E370\"\n    },\n    {\n      \"id\": \"func_0x418370\",\n      \"label\": \"Function 0x418370\",\n      \"type\": \"function\",\n      \"address\": \"0x418370\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz\",\n      \"label\": \"author     @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Read Header [C0002.014]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_with_crc32\",\n      \"label\": \"hash data with CRC32\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x423F30\",\n      \"label\": \"Function 0x423F30\",\n      \"type\": \"function\",\n      \"address\": \"0x423F30\"\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_rc4_ksa\",\n      \"label\": \"encrypt data using RC4 KSA\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data::RC4 [C0027.009]\",\n        \"Cryptography::Encryption\",\n        \"Key::RC4 KSA [C0028.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x411D60\",\n      \"label\": \"Function 0x411D60\",\n      \"type\": \"function\",\n      \"address\": \"0x411D60\"\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_rc4_prga__2_matches_\",\n      \"label\": \"encrypt data using RC4 PRGA (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data::RC4 [C0027.009]\",\n        \"Cryptography::Generate\",\n        \"Pseudo-random Sequence::RC4 PRGA [C0021.004]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4145D0\",\n      \"label\": \"Function 0x4145D0\",\n      \"type\": \"function\",\n      \"address\": \"0x4145D0\"\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_salsa20_or_chacha\",\n      \"label\": \"encrypt data using Salsa20 or ChaCha\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information [T1027]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x424030\",\n      \"label\": \"Function 0x424030\",\n      \"type\": \"function\",\n      \"address\": \"0x424030\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information [T1027]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_using_djb2\",\n      \"label\": \"hash data using djb2\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::djb2 [C0030.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408B10\",\n      \"label\": \"Function 0x408B10\",\n      \"type\": \"function\",\n      \"address\": \"0x408B10\"\n    },\n    {\n      \"id\": \"cap_author______awillia2_cisco_com__still_teamt5_org\",\n      \"label\": \"author      awillia2@cisco.com, still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::djb2 [C0030.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments\",\n      \"label\": \"accept command line arguments\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_current_directory\",\n      \"label\": \"set current directory\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_SetCurrentDirectory\",\n      \"label\": \"SetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_copy_file\",\n      \"label\": \"copy file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"api_CopyFile\",\n      \"label\": \"CopyFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory\",\n      \"label\": \"create directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_enumerate_gui_resources\",\n      \"label\": \"enumerate gui resources\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"api_EnumWindows\",\n      \"label\": \"EnumWindows\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     johnk3r, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_disk_information\",\n      \"label\": \"get disk information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetDriveType\",\n      \"label\": \"GetDriveType\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetLogicalDrives\",\n      \"label\": \"GetLogicalDrives\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_or_open_mutex_on_windows__2_matches_\",\n      \"label\": \"create or open mutex on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateMutex\",\n      \"label\": \"CreateMutex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_OpenMutex\",\n      \"label\": \"OpenMutex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_mehunhoff_google_com\",\n      \"label\": \"mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_os_version\",\n      \"label\": \"check OS version\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_inject_thread\",\n      \"label\": \"inject thread\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Process Injection::Thread Execution Hijacking\",\n        \"[T1055.003]\",\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"api_WriteProcessMemory\",\n      \"label\": \"WriteProcessMemory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_VirtualAllocEx\",\n      \"label\": \"VirtualAllocEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateRemoteThread\",\n      \"label\": \"CreateRemoteThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____anamaria_martinezgom_mandiant_com__0x534a_mailbox_org\",\n      \"label\": \"author     anamaria.martinezgom@mandiant.com, 0x534a@mailbox.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Process Injection::Thread Execution Hijacking\",\n        \"[T1055.003]\",\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_thread\",\n      \"label\": \"create thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x41A329\",\n      \"label\": \"Block 0x41A329\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x41A329\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__77_matches_\",\n      \"label\": \"link function at runtime on Windows (77 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_many_functions_at_runtime__5_matches_\",\n      \"label\": \"link many functions at runtime (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x41F700\",\n      \"label\": \"Function 0x41F700\",\n      \"type\": \"function\",\n      \"address\": \"0x41F700\"\n    },\n    {\n      \"id\": \"func_0x4126D0\",\n      \"label\": \"Function 0x4126D0\",\n      \"type\": \"function\",\n      \"address\": \"0x4126D0\"\n    },\n    {\n      \"id\": \"func_0x412160\",\n      \"label\": \"Function 0x412160\",\n      \"type\": \"function\",\n      \"address\": \"0x412160\"\n    },\n    {\n      \"id\": \"func_0x412370\",\n      \"label\": \"Function 0x412370\",\n      \"type\": \"function\",\n      \"address\": \"0x412370\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header__5_matches_\",\n      \"label\": \"parse PE header (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x406BB0\",\n      \"label\": \"Function 0x406BB0\",\n      \"type\": \"function\",\n      \"address\": \"0x406BB0\"\n    },\n    {\n      \"id\": \"func_0x407160\",\n      \"label\": \"Function 0x407160\",\n      \"type\": \"function\",\n      \"address\": \"0x407160\"\n    },\n    {\n      \"id\": \"func_0x407230\",\n      \"label\": \"Function 0x407230\",\n      \"type\": \"function\",\n      \"address\": \"0x407230\"\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports__6_matches_\",\n      \"label\": \"resolve function by parsing PE exports (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x407BF0\",\n      \"label\": \"Function 0x407BF0\",\n      \"type\": \"function\",\n      \"address\": \"0x407BF0\"\n    },\n    {\n      \"id\": \"func_0x407580\",\n      \"label\": \"Function 0x407580\",\n      \"type\": \"function\",\n      \"address\": \"0x407580\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_identify_system_language_via_api\",\n      \"label\": \"identify system language via API\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery::System Language Discovery\",\n        \"[T1614.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40F500\",\n      \"label\": \"Function 0x40F500\",\n      \"type\": \"function\",\n      \"address\": \"0x40F500\"\n    },\n    {\n      \"id\": \"api_GetUserDefaultLangID\",\n      \"label\": \"GetUserDefaultLangID\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery::System Language Discovery\",\n        \"[T1614.001]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_peb_access__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_peb_access__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x41016C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__221_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__221_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x417D7D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_obfuscated_stackstrings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings\",\n      \"target\": \"bb_0x406CBB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x406CBB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_geographical_location\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x424650\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x424650\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_http_status_code__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_http_status_code__3_matches_\",\n      \"target\": \"func_0x4188E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_http_status_code__3_matches_\",\n      \"target\": \"func_0x40E370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_http_status_code__3_matches_\",\n      \"target\": \"func_0x418370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz\",\n      \"target\": \"func_0x4188E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz\",\n      \"target\": \"func_0x40E370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz\",\n      \"target\": \"func_0x418370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_crc32\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_with_crc32\",\n      \"target\": \"func_0x423F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x423F30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_rc4_ksa\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa\",\n      \"target\": \"func_0x411D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x411D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_rc4_prga__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__2_matches_\",\n      \"target\": \"func_0x4145D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__2_matches_\",\n      \"target\": \"func_0x411D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4145D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x411D60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_salsa20_or_chacha\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_salsa20_or_chacha\",\n      \"target\": \"func_0x424030\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x424030\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_djb2\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_djb2\",\n      \"target\": \"func_0x408B10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______awillia2_cisco_com__still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______awillia2_cisco_com__still_teamt5_org\",\n      \"target\": \"func_0x408B10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x424650\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x424650\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_current_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_current_directory\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x424650\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x424650\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_copy_file\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x424650\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x424650\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x424650\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x424650\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_gui_resources\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_gui_resources\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x424650\",\n      \"target\": \"api_EnumWindows\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x424650\",\n      \"target\": \"api_EnumWindows\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x424650\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x424650\",\n      \"target\": \"api_GetLogicalDrives\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x424650\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x424650\",\n      \"target\": \"api_GetLogicalDrives\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_mutex_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_os_version\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_os_version\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_inject_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_inject_thread\",\n      \"target\": \"func_0x4188E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4188E0\",\n      \"target\": \"api_WriteProcessMemory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4188E0\",\n      \"target\": \"api_VirtualAllocEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4188E0\",\n      \"target\": \"api_CreateRemoteThread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anamaria_martinezgom_mandiant_com__0x534a_mailbox_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____anamaria_martinezgom_mandiant_com__0x534a_mailbox_org\",\n      \"target\": \"func_0x4188E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4188E0\",\n      \"target\": \"api_WriteProcessMemory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4188E0\",\n      \"target\": \"api_VirtualAllocEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4188E0\",\n      \"target\": \"api_CreateRemoteThread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread\",\n      \"target\": \"bb_0x41A329\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x41A329\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__77_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_many_functions_at_runtime__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__5_matches_\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__5_matches_\",\n      \"target\": \"func_0x41F700\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__5_matches_\",\n      \"target\": \"func_0x4126D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__5_matches_\",\n      \"target\": \"func_0x412160\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__5_matches_\",\n      \"target\": \"func_0x412370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x41F700\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x4126D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x412160\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x412370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__5_matches_\",\n      \"target\": \"func_0x406BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__5_matches_\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__5_matches_\",\n      \"target\": \"func_0x407160\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__5_matches_\",\n      \"target\": \"func_0x4188E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__5_matches_\",\n      \"target\": \"func_0x407230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x406BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x424650\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x407160\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4188E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x407230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__6_matches_\",\n      \"target\": \"func_0x407BF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__6_matches_\",\n      \"target\": \"func_0x406BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__6_matches_\",\n      \"target\": \"func_0x407580\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__6_matches_\",\n      \"target\": \"func_0x407160\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__6_matches_\",\n      \"target\": \"func_0x4188E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__6_matches_\",\n      \"target\": \"func_0x407230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x407BF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x406BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x407580\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x407160\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x4188E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x407230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_identify_system_language_via_api\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_identify_system_language_via_api\",\n      \"target\": \"func_0x40F500\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40F500\",\n      \"target\": \"api_GetUserDefaultLangID\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40F500\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40F500\",\n      \"target\": \"api_GetUserDefaultLangID\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-19 12:34:52.386637\",\n    \"total_functions\": \"270\",\n    \"total_features\": \"26644\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-19 12:34:53"}
{"_id":{"$oid":"6a5c7f1eb3bed57e0e737891"},"sha256":"72344facd02bea9007c59c2a67bd96d521838b566298caf0f80c6ceecf93520f","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":true,"path":"/tmp/sdm_capa_6yft6myi/72344facd02bea9007c59c2a67bd96d521838b566298caf0f80c6ceecf93520f-019f790220a37c5398a6570acb1ec5b4.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_6yft6myi/72344facd02bea9007c59c2a67bd96d521838b566298caf0f80c6ceecf93520f-019f790220a37c5398a6570acb1ec5b4.exe_very_verbose.txt"}},"outputs":{"normal":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be an    common.py:90\n         installer.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  capa cannot handle installers   common.py:90\n         well. This means the results may be misleading or                      \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You should try to understand    common.py:90\n         the install mechanism and analyze created files with capa.             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         installer file limitation                                              \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"md5                     f238406f5cd53942450f145e1c977476                        \nsha1                    fb7cd49f47060a8514fe5c358bb2a9f74eb215f4                \nsha256                  72344facd02bea9007c59c2a67bd96d521838b566298caf0f80c6ce…\npath                    /home/apogean/projects/malware/windows/all_runs/72344fa…\ntimestamp               2026-07-19 13:08:46.392105                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIxk8OF2/rules                                   \nfunction count          555                                                     \nlibrary function count  2                                                       \ntotal feature count     101857                                                  \n\nreference anti-VM strings targeting Xen\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nget geographical location (5 matches)\nnamespace  collection\nscope      function  \nmatches    0x405DD4  \n           0x405DE8  \n           0x408EB4  \n           0x408F00  \n           0x40E658  \n\ncompiled with Borland Delphi\nnamespace  compiler/delphi\nscope      file           \n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32\nscope      function                        \nmatches    0x40C6B0                        \n\nencode data using XOR (3 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x40AA4B                      \n           0x40AA4B                      \n           0x40C70D                      \n\ngenerate random numbers using the Delphi LCG\nnamespace  data-manipulation/prng/lcg\nscope      basic block               \nmatches    0x4030E4                  \n\npackaged as an Inno Setup installer\nnamespace  executable/installer/inno-setup\nscope      file                           \n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls\nscope      file                     \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x40EE2C           \n\naccept command line arguments (3 matches)\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x40B84C            \n           0x40B89C            \n           0x40B8FC            \n\nquery environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x40B710                             \n\nget common file path (3 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x40699C                    \n           0x40B9A4                    \n           0x40B9D0                    \n\ncreate directory\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x40E42C                           \n\ndelete directory\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x411CBF                           \n\ndelete file\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x40E180                           \n\ncheck if file exists\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x40E5F4                           \n\nget file attributes\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x40B698                         \n\nclear file content\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x40C410                          \n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x4044F0                          \n           0x4096AC                          \n\nget disk size\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x408068                         \n\nshutdown system\nnamespace  host-interaction/os\nscope      function           \nmatches    0x40E550           \n\nget system information on Windows\nnamespace  host-interaction/os/info\nscope      function                \nmatches    0x40ED58                \n\nget thread local storage value\nnamespace  host-interaction/process\nscope      function                \nmatches    0x406588                \n\ncreate process on Windows\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x40EB68                       \n\ncreate process suspended\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x40EB68                       \n\nallocate or change RWX memory\nnamespace  host-interaction/process/inject\nscope      basic block                    \nmatches    0x40EDB4                       \n\nmodify access privileges\nnamespace  host-interaction/process/modify\nscope      instruction                    \nmatches    0x40E5A6                       \n\nquery or enumerate registry value (4 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x403714                 \n           0x405DD4                 \n           0x405DE8                 \n           0x40BB34                 \n\nset thread local storage value\nnamespace  host-interaction/thread/tls\nscope      function                   \nmatches    0x406544                   \n\nlink function at runtime on Windows (7 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x405C20               \n           0x40674C               \n           0x40676E               \n           0x411112               \n           0x411138               \n           0x4112FA               \n           0x411310               \n\nidentify system language via API\nnamespace  targeting/language\nscope      function          \nmatches    0x40E684          \n\n\n\n","very_verbose":"md5                     f238406f5cd53942450f145e1c977476                        \nsha1                    fb7cd49f47060a8514fe5c358bb2a9f74eb215f4                \nsha256                  72344facd02bea9007c59c2a67bd96d521838b566298caf0f80c6ce…\npath                    /home/apogean/projects/malware/windows/all_runs/72344fa…\ntimestamp               2026-07-19 13:09:09.641707                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIMpBwC9/rules                                   \nfunction count          555                                                     \nlibrary function count  2                                                       \ntotal feature count     101857                                                  \n\nallocate memory (5 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x4015E4 in function 0x4015E4\n  or:\n    api: VirtualAlloc @ 0x4015FA\n\nallocate or change RW memory (5 matches, only showing first match of library \nrule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x4015E4 in function 0x4015E4\n  and:\n    or:\n      match: allocate memory @ 0x4015E4\n        or:\n          api: VirtualAlloc @ 0x4015FA\n    or:\n      number: 0x4 = PAGE_READWRITE @ 0x4015EC\n\ncalculate modulo 256 via x86 assembly (3 matches, only showing first match of \nlibrary rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x40C70F\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x40C70F\n    or:\n      number: 0xFF @ 0x40C70F\n\nchange memory protection (2 matches, only showing first match of library rule)\nauthor  @mr-tz                                  \nscope   basic block                             \nmbc     Memory::Change Memory Protection [C0008]\nbasic block @ 0x40EDB4 in function 0x40ED58\n  or:\n    api: VirtualProtect @ 0x40EDC2\n\ncontain loop (130 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x40148C\n  or:\n    characteristic: tight loop @ 0x401497\n\ncreate or open file (library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x40C31D\n  or:\n    api: CreateFile @ 0x40C31D\n\ncreate or open registry key (10 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x403714 in function 0x403714\n  or:\n    api: RegOpenKeyEx @ 0x403736\n\ndelay execution (21 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x401670 in function 0x40165C\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x401672\n\nget OS version (2 matches, only showing first match of library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x40A358\n  or:\n    api: GetVersionEx @ 0x40A366\n\nreference anti-VM strings targeting Xen\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /^Xen/i\n    - \"XEne\" @ file+0x568931\n\nget geographical location (5 matches)\nnamespace  collection                                  \nauthor     moritz.raabe, michael.hunhoff@mandiant.com  \nscope      function                                    \natt&ck     Discovery::System Location Discovery [T1614]\nfunction @ 0x405DD4\n  or:\n    api: GetLocaleInfo @ 0x405F46\nfunction @ 0x405DE8\n  or:\n    api: GetLocaleInfo @ 0x405F46\nfunction @ 0x408EB4\n  or:\n    api: GetLocaleInfo @ 0x408ED2\nfunction @ 0x408F00\n  or:\n    api: GetLocaleInfo @ 0x408F13\nfunction @ 0x40E658\n  or:\n    api: GetLocaleInfo @ 0x40E66E\n\ncompiled with Borland Delphi\nnamespace  compiler/delphi                        \nauthor     william.ballenthin@mandiant.com, @mr-tz\nscope      file                                   \nor:\n  substring: SOFTWARE\\Borland\\Delphi\\RTL\n    - \"SOFTWARE\\\\Borland\\\\Delphi\\\\RTL\" @ file+0x2BAC\n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32 \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \nmbc        Data::Checksum::CRC32 [C0032.001]\nfunction @ 0x40C6B0\n  or:\n    and:\n      number: 0x1 = bits in a byte @ 0x40C6BF, 0x40C6C3, 0x40C6CC\n      instruction:\n        and:\n          operand[1].number: 0x1 @ 0x40C6BF\n          or:\n            mnemonic: test @ 0x40C6BF\n      instruction:\n        and:\n          mnemonic: shr @ 0x40C6C3\n          number: 0x1 @ 0x40C6C3\n        and:\n          mnemonic: shr @ 0x40C6CC\n          number: 0x1 @ 0x40C6CC\n      characteristic: nzxor @ 0x40C6C5\n      operand[1].number: 0xEDB88320 @ 0x40C6C5\n\nencode data using XOR (3 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x40AA4B in function 0x40AA03\n  and:\n    characteristic: tight loop @ 0x40AA4B\n    characteristic: nzxor @ 0x40AA5B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x40AA4B in function 0x40AA03\n  and:\n    characteristic: tight loop @ 0x40AA4B\n    characteristic: nzxor @ 0x40AA5B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x40C70D in function 0x40C6E4\n  and:\n    characteristic: tight loop @ 0x40C70D\n    characteristic: nzxor @ 0x40C718, 0x40C728\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\ngenerate random numbers using the Delphi LCG\nnamespace   data-manipulation/prng/lcg                                          \nauthor      william.ballenthin@mandiant.com                                     \nscope       basic block                                                         \nmbc         Cryptography::Generate Pseudo-random Sequence [C0021]               \nreferences  https://en.wikipedia.org/wiki/Linear_congruential_generator,        \n            https://community.osr.com/discussion/130410/generating-random-numbe…\nbasic block @ 0x4030E4 in function 0x4030E4\n  and:\n    instruction:\n      and:\n        mnemonic: imul @ 0x4030E7\n        number: 0x8088405 = multiplier a @ 0x4030E7\n    mnemonic: inc = increment c @ 0x4030F1\n\npackaged as an Inno Setup installer\nnamespace   executable/installer/inno-setup  \nauthor      awillia2@cisco.com               \nscope       file                             \nreferences  https://jrsoftware.org/isinfo.php\nand:\n  regex: /^Inno Setup Setup Data \\(/\n    - \"Inno Setup Setup Data (5.5.7) (u)\" @ file+0x1120C, file+0x622B5C\n  regex: /^Inno Setup Messages \\(/\n    - \"Inno Setup Messages (5.5.3) (u)\" @ file+0x1124C\n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls   \nauthor     michael.hunhoff@mandiant.com\nscope      file                        \nsection: .tls @ 0x41A000\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x40EE2C\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x40EE5B\n        api: LockResource @ 0x40EE6C\n      optional:\n        or:\n          api: FindResource @ 0x40EE36\n        api: SizeofResource @ 0x40EE49\n\naccept command line arguments (3 matches)\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x40B84C\n  or:\n    api: GetCommandLine @ 0x40B862\nfunction @ 0x40B89C\n  or:\n    api: GetCommandLine @ 0x40B8B1\nfunction @ 0x40B8FC\n  or:\n    api: GetCommandLine @ 0x40B947\n\nquery environment variable\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x40B710\n  or:\n    api: GetEnvironmentVariable @ 0x40B746\n\nget common file path (3 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x40699C\n  or:\n    api: GetSystemDirectory @ 0x4069AF\nfunction @ 0x40B9A4\n  or:\n    api: GetWindowsDirectory @ 0x40B9B7\nfunction @ 0x40B9D0\n  or:\n    api: GetSystemDirectory @ 0x40B9E3\n\ncreate directory\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x40E42C\n  or:\n    api: CreateDirectory @ 0x40E474\n\ndelete directory\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ 0x411CBF\n  or:\n    api: RemoveDirectory @ 0x411E1C\n\ndelete file\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x40E180\n  or:\n    api: DeleteFile @ 0x40E1B7\n\ncheck if file exists\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x40E5F4\n  or:\n    basic block:\n      and:\n        api: GetLastError @ 0x40E636\n        instruction:\n          and:\n            mnemonic: cmp @ 0x40E63B\n            number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x40E63B\n\nget file attributes\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x40B698 in function 0x40B698\n  or:\n    api: GetFileAttributes @ 0x40B6C1\n\nclear file content\nnamespace  host-interaction/file-system/write\nauthor     jakeperalta7                      \nscope      function                          \nmbc        File System::Writes File [C0052]  \nfunction @ 0x40C410\n  and:\n    api: SetEndOfFile @ 0x40C417\n    not:\n      api: SetFilePointer\n\nwrite file on Windows (2 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x4044F0\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x40453B\n      or:\n        api: WriteFile @ 0x40452F, 0x40454A\nfunction @ 0x4096AC\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x409763\n      or:\n        api: WriteFile @ 0x409758, 0x409772\n\nget disk size\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ 0x408068\n  or:\n    api: GetDiskFreeSpace @ 0x408089\n\nshutdown system\nnamespace  host-interaction/os                   \nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \natt&ck     Impact::System Shutdown/Reboot [T1529]\nfunction @ 0x40E550\n  or:\n    api: ExitWindowsEx @ 0x40E5BC\n\nget system information on Windows\nnamespace  host-interaction/os/info                       \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com  \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x40ED58\n  and:\n    os: windows\n    or:\n      api: GetSystemInfo @ 0x40ED6B\n\nget thread local storage value\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x406588\n  and:\n    api: TlsGetValue @ 0x4065AD, 0x4065BE\n\ncreate process on Windows\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x40EB68 in function 0x40EB68\n  or:\n    api: CreateProcess @ 0x40EBD8\n\ncreate process suspended\nnamespace   host-interaction/process/create                                     \nauthor      william.ballenthin@mandiant.com, mehunhoff@google.com               \nscope       basic block                                                         \nmbc         Process::Create Process::Create Suspended Process [C0017.003]       \nreferences  https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/an-…\n            https://learn.microsoft.com/en-us/windows/win32/procthread/process-…\nbasic block @ 0x40EB68 in function 0x40EB68\n  or:\n    and:\n      or:\n        number: 0x4 = CREATE_SUSPENDED @ 0x40EB99\n      or:\n        api: CreateProcess @ 0x40EBD8\n\nallocate or change RWX memory\nnamespace  host-interaction/process/inject\nauthor     @mr-tz, mehunhoff@google.com   \nscope      basic block                    \nmbc        Memory::Allocate Memory [C0007]\nbasic block @ 0x40EDB4 in function 0x40ED58\n  or:\n    basic block:\n      and:\n        or:\n          match: change memory protection @ 0x40EDB4\n            or:\n              api: VirtualProtect @ 0x40EDC2\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x40EDB9\n\nmodify access privileges\nnamespace  host-interaction/process/modify                        \nauthor     moritz.raabe@mandiant.com                              \nscope      instruction                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\ninstruction @ 0x40E5A6\n  and:\n    api: AdjustTokenPrivileges @ 0x40E5A6\n\nquery or enumerate registry value (4 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x403714\n  and:\n    optional:\n      match: create or open registry key @ 0x403714\n        or:\n          api: RegOpenKeyEx @ 0x403736\n    or:\n      api: RegQueryValueEx @ 0x403769\nfunction @ 0x405DD4\n  and:\n    optional:\n      match: create or open registry key @ 0x405E24, 0x405E2D, 0x405E4B, 0x405E69\n        or:\n          api: RegOpenKeyEx @ 0x405E7E\n        or:\n          api: RegOpenKeyEx @ 0x405E60\n        or:\n          api: RegOpenKeyEx @ 0x405E24\n        or:\n          api: RegOpenKeyEx @ 0x405E42\n    or:\n      api: RegQueryValueEx @ 0x405EC7, 0x405EE5\nfunction @ 0x405DE8\n  and:\n    optional:\n      match: create or open registry key @ 0x405DE8, 0x405E2D, 0x405E4B, 0x405E69\n        or:\n          api: RegOpenKeyEx @ 0x405E24\n        or:\n          api: RegOpenKeyEx @ 0x405E7E\n        or:\n          api: RegOpenKeyEx @ 0x405E60\n        or:\n          api: RegOpenKeyEx @ 0x405E42\n    or:\n      api: RegQueryValueEx @ 0x405EC7, 0x405EE5\nfunction @ 0x40BB34\n  and:\n    or:\n      api: RegQueryValueEx @ 0x40BB70, 0x40BBE0\n\nset thread local storage value\nnamespace  host-interaction/thread/tls                    \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \nmbc        Process::Set Thread Local Storage Value [C0041]\nfunction @ 0x406544\n  and:\n    api: TlsSetValue @ 0x406581\n\n(internal) installer file limitation\nnamespace    internal/limitation/static                                         \nauthor       william.ballenthin@mandiant.com                                    \nscope        file                                                               \ndescription  This sample appears to be an installer.                            \n                                                                                \n             capa cannot handle installers well. This means the results may be  \n             misleading or incomplete.                                          \n             You should try to understand the install mechanism and analyze     \n             created files with capa.                                           \n                                                                                \nor:\n  match: executable/installer @ global\n    and:\n      regex: /^Inno Setup Setup Data \\(/\n        - \"Inno Setup Setup Data (5.5.7) (u)\" @ file+0x1120C, file+0x622B5C\n      regex: /^Inno Setup Messages \\(/\n        - \"Inno Setup Messages (5.5.3) (u)\" @ file+0x1124C\n\nlink function at runtime on Windows (7 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x405C20\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x405C20\ninstruction @ 0x40674C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40674C\ninstruction @ 0x40676E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x40676E\ninstruction @ 0x411112\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x411112\ninstruction @ 0x411138\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x411138\ninstruction @ 0x4112FA\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4112FA\ninstruction @ 0x411310\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x411310\n\nidentify system language via API\nnamespace  targeting/language                                                   \nauthor     william.ballenthin@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Location Discovery::System Language Discovery      \n           [T1614.001]                                                          \nfunction @ 0x40E684\n  and:\n    os: windows\n    or:\n      api: GetUserDefaultLangID @ 0x40E6E6\n\n\n\n"},"hashes":{"md5":"f238406f5cd53942450f145e1c977476","sha1":"fb7cd49f47060a8514fe5c358bb2a9f74eb215f4","sha256":"72344facd02bea9007c59c2a67bd96d521838b566298caf0f80c6ceecf93520f"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 555</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 101857</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"72344fa\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"f238406f5cd53942450f145e1c977476\",\n        \"sha256\": \"72344facd02bea9007c59c2a67bd96d521838b566298caf0f80c6ce\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_allocate_memory__5_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"allocate memory (5 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4015E4\",\n      \"label\": \"Block 0x4015E4\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4015E4\"\n    },\n    {\n      \"id\": \"api_VirtualAlloc\",\n      \"label\": \"VirtualAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_library_rule_\",\n      \"label\": \"library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Modulo [C0058]\"\n      ]\n    },\n    {\n      \"id\": \"cap_change_memory_protection__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"change memory protection (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Change Memory Protection [C0008]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40EDB4\",\n      \"label\": \"Block 0x40EDB4\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40EDB4\"\n    },\n    {\n      \"id\": \"api_VirtualProtect\",\n      \"label\": \"VirtualProtect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_contain_loop__130_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (130 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x40148C\",\n      \"label\": \"Function 0x40148C\",\n      \"type\": \"function\",\n      \"address\": \"0x40148C\"\n    },\n    {\n      \"id\": \"bb_0x403714\",\n      \"label\": \"Block 0x403714\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x403714\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__21_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (21 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401670\",\n      \"label\": \"Block 0x401670\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401670\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_os_version__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"get OS version (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x40A358\",\n      \"label\": \"Function 0x40A358\",\n      \"type\": \"function\",\n      \"address\": \"0x40A358\"\n    },\n    {\n      \"id\": \"api_GetVersionEx\",\n      \"label\": \"GetVersionEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"label\": \"reference anti-VM strings targeting Xen\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_geographical_location__5_matches_\",\n      \"label\": \"get geographical location (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405DE8\",\n      \"label\": \"Function 0x405DE8\",\n      \"type\": \"function\",\n      \"address\": \"0x405DE8\"\n    },\n    {\n      \"id\": \"func_0x408F00\",\n      \"label\": \"Function 0x408F00\",\n      \"type\": \"function\",\n      \"address\": \"0x408F00\"\n    },\n    {\n      \"id\": \"func_0x40E658\",\n      \"label\": \"Function 0x40E658\",\n      \"type\": \"function\",\n      \"address\": \"0x40E658\"\n    },\n    {\n      \"id\": \"func_0x408EB4\",\n      \"label\": \"Function 0x408EB4\",\n      \"type\": \"function\",\n      \"address\": \"0x408EB4\"\n    },\n    {\n      \"id\": \"func_0x405DD4\",\n      \"label\": \"Function 0x405DD4\",\n      \"type\": \"function\",\n      \"address\": \"0x405DD4\"\n    },\n    {\n      \"id\": \"api_GetLocaleInfo\",\n      \"label\": \"GetLocaleInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"cap_compiled_with_borland_delphi\",\n      \"label\": \"compiled with Borland Delphi\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com___mr_tz\",\n      \"label\": \"author     william.ballenthin@mandiant.com, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_hash_data_with_crc32\",\n      \"label\": \"hash data with CRC32\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40C6B0\",\n      \"label\": \"Function 0x40C6B0\",\n      \"type\": \"function\",\n      \"address\": \"0x40C6B0\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_using_the_delphi_lcg\",\n      \"label\": \"generate random numbers using the Delphi LCG\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence [C0021]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4030E4\",\n      \"label\": \"Block 0x4030E4\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4030E4\"\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence [C0021]\"\n      ]\n    },\n    {\n      \"id\": \"cap_packaged_as_an_inno_setup_installer\",\n      \"label\": \"packaged as an Inno Setup installer\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author______awillia2_cisco_com\",\n      \"label\": \"author      awillia2@cisco.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"label\": \"contain a thread local storage (.tls) section\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x40EE2C\",\n      \"label\": \"Function 0x40EE2C\",\n      \"type\": \"function\",\n      \"address\": \"0x40EE2C\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments__3_matches_\",\n      \"label\": \"accept command line arguments (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40B84C\",\n      \"label\": \"Function 0x40B84C\",\n      \"type\": \"function\",\n      \"address\": \"0x40B84C\"\n    },\n    {\n      \"id\": \"func_0x40B89C\",\n      \"label\": \"Function 0x40B89C\",\n      \"type\": \"function\",\n      \"address\": \"0x40B89C\"\n    },\n    {\n      \"id\": \"func_0x40B8FC\",\n      \"label\": \"Function 0x40B8FC\",\n      \"type\": \"function\",\n      \"address\": \"0x40B8FC\"\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable\",\n      \"label\": \"query environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40B710\",\n      \"label\": \"Function 0x40B710\",\n      \"type\": \"function\",\n      \"address\": \"0x40B710\"\n    },\n    {\n      \"id\": \"api_GetEnvironmentVariable\",\n      \"label\": \"GetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path__3_matches_\",\n      \"label\": \"get common file path (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40B9D0\",\n      \"label\": \"Function 0x40B9D0\",\n      \"type\": \"function\",\n      \"address\": \"0x40B9D0\"\n    },\n    {\n      \"id\": \"func_0x40B9A4\",\n      \"label\": \"Function 0x40B9A4\",\n      \"type\": \"function\",\n      \"address\": \"0x40B9A4\"\n    },\n    {\n      \"id\": \"func_0x40699C\",\n      \"label\": \"Function 0x40699C\",\n      \"type\": \"function\",\n      \"address\": \"0x40699C\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory\",\n      \"label\": \"create directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40E42C\",\n      \"label\": \"Function 0x40E42C\",\n      \"type\": \"function\",\n      \"address\": \"0x40E42C\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_directory\",\n      \"label\": \"delete directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x411CBF\",\n      \"label\": \"Function 0x411CBF\",\n      \"type\": \"function\",\n      \"address\": \"0x411CBF\"\n    },\n    {\n      \"id\": \"api_RemoveDirectory\",\n      \"label\": \"RemoveDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_file\",\n      \"label\": \"delete file\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40E180\",\n      \"label\": \"Function 0x40E180\",\n      \"type\": \"function\",\n      \"address\": \"0x40E180\"\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists\",\n      \"label\": \"check if file exists\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40E5F4\",\n      \"label\": \"Function 0x40E5F4\",\n      \"type\": \"function\",\n      \"address\": \"0x40E5F4\"\n    },\n    {\n      \"id\": \"api_GetLastError\",\n      \"label\": \"GetLastError\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_file_attributes\",\n      \"label\": \"get file attributes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40B698\",\n      \"label\": \"Block 0x40B698\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40B698\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_clear_file_content\",\n      \"label\": \"clear file content\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40C410\",\n      \"label\": \"Function 0x40C410\",\n      \"type\": \"function\",\n      \"address\": \"0x40C410\"\n    },\n    {\n      \"id\": \"api_SetFilePointer\",\n      \"label\": \"SetFilePointer\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SetEndOfFile\",\n      \"label\": \"SetEndOfFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____jakeperalta7\",\n      \"label\": \"author     jakeperalta7\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__2_matches_\",\n      \"label\": \"write file on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4044F0\",\n      \"label\": \"Function 0x4044F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4044F0\"\n    },\n    {\n      \"id\": \"func_0x4096AC\",\n      \"label\": \"Function 0x4096AC\",\n      \"type\": \"function\",\n      \"address\": \"0x4096AC\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_disk_size\",\n      \"label\": \"get disk size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408068\",\n      \"label\": \"Function 0x408068\",\n      \"type\": \"function\",\n      \"address\": \"0x408068\"\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpace\",\n      \"label\": \"GetDiskFreeSpace\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_shutdown_system\",\n      \"label\": \"shutdown system\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::System Shutdown/Reboot [T1529]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40E550\",\n      \"label\": \"Function 0x40E550\",\n      \"type\": \"function\",\n      \"address\": \"0x40E550\"\n    },\n    {\n      \"id\": \"api_ExitWindowsEx\",\n      \"label\": \"ExitWindowsEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_system_information_on_windows\",\n      \"label\": \"get system information on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40ED58\",\n      \"label\": \"Function 0x40ED58\",\n      \"type\": \"function\",\n      \"address\": \"0x40ED58\"\n    },\n    {\n      \"id\": \"api_GetSystemInfo\",\n      \"label\": \"GetSystemInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_thread_local_storage_value\",\n      \"label\": \"get thread local storage value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x406588\",\n      \"label\": \"Function 0x406588\",\n      \"type\": \"function\",\n      \"address\": \"0x406588\"\n    },\n    {\n      \"id\": \"api_TlsGetValue\",\n      \"label\": \"TlsGetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_process_on_windows\",\n      \"label\": \"create process on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40EB68\",\n      \"label\": \"Block 0x40EB68\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40EB68\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_create_process_suspended\",\n      \"label\": \"create process suspended\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process::Create Suspended Process [C0017.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process::Create Suspended Process [C0017.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_allocate_or_change_rwx_memory\",\n      \"label\": \"allocate or change RWX memory\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"label\": \"author     @mr-tz, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_modify_access_privileges\",\n      \"label\": \"modify access privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"api_AdjustTokenPrivileges\",\n      \"label\": \"AdjustTokenPrivileges\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"label\": \"query or enumerate registry value (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x403714\",\n      \"label\": \"Function 0x403714\",\n      \"type\": \"function\",\n      \"address\": \"0x403714\"\n    },\n    {\n      \"id\": \"func_0x40BB34\",\n      \"label\": \"Function 0x40BB34\",\n      \"type\": \"function\",\n      \"address\": \"0x40BB34\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_thread_local_storage_value\",\n      \"label\": \"set thread local storage value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Set Thread Local Storage Value [C0041]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x406544\",\n      \"label\": \"Function 0x406544\",\n      \"type\": \"function\",\n      \"address\": \"0x406544\"\n    },\n    {\n      \"id\": \"api_TlsSetValue\",\n      \"label\": \"TlsSetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap__internal__installer_file_limitation\",\n      \"label\": \"(internal) installer file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__7_matches_\",\n      \"label\": \"link function at runtime on Windows (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_identify_system_language_via_api\",\n      \"label\": \"identify system language via API\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery::System Language Discovery\",\n        \"[T1614.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40E684\",\n      \"label\": \"Function 0x40E684\",\n      \"type\": \"function\",\n      \"address\": \"0x40E684\"\n    },\n    {\n      \"id\": \"api_GetUserDefaultLangID\",\n      \"label\": \"GetUserDefaultLangID\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_memory__5_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_memory__5_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x4015E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x4015E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_change_memory_protection__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_change_memory_protection__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x40EDB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__130_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__130_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x40148C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x403714\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__21_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__21_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x401670\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_os_version__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x40A358\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40A358\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_geographical_location__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__5_matches_\",\n      \"target\": \"func_0x405DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__5_matches_\",\n      \"target\": \"func_0x408F00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__5_matches_\",\n      \"target\": \"func_0x40E658\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__5_matches_\",\n      \"target\": \"func_0x408EB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__5_matches_\",\n      \"target\": \"func_0x405DD4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405DE8\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408F00\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E658\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408EB4\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DD4\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408F00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40E658\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408EB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405DD4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405DE8\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408F00\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40E658\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408EB4\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DD4\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_with_borland_delphi\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_crc32\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_with_crc32\",\n      \"target\": \"func_0x40C6B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x40C6B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_using_the_delphi_lcg\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_the_delphi_lcg\",\n      \"target\": \"bb_0x4030E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"bb_0x4030E4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_packaged_as_an_inno_setup_installer\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______awillia2_cisco_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x40EE2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40EE2C\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EE2C\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EE2C\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EE2C\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40EE2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40EE2C\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EE2C\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EE2C\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40EE2C\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__3_matches_\",\n      \"target\": \"func_0x40B84C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__3_matches_\",\n      \"target\": \"func_0x40B89C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__3_matches_\",\n      \"target\": \"func_0x40B8FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40B84C\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B89C\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B8FC\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B84C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B89C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B8FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40B84C\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B89C\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B8FC\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable\",\n      \"target\": \"func_0x40B710\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40B710\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x40B710\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40B710\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x40B9D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x40B9A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__3_matches_\",\n      \"target\": \"func_0x40699C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40B9D0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B9A4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40699C\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B9D0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B9A4\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40699C\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B9D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B9A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40699C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40B9D0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B9A4\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40699C\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B9D0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B9A4\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40699C\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory\",\n      \"target\": \"func_0x40E42C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E42C\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40E42C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E42C\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_directory\",\n      \"target\": \"func_0x411CBF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x411CBF\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x411CBF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x411CBF\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file\",\n      \"target\": \"func_0x40E180\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E180\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40E180\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E180\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists\",\n      \"target\": \"func_0x40E5F4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E5F4\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40E5F4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E5F4\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes\",\n      \"target\": \"bb_0x40B698\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40B698\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_clear_file_content\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_clear_file_content\",\n      \"target\": \"func_0x40C410\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40C410\",\n      \"target\": \"api_SetFilePointer\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C410\",\n      \"target\": \"api_SetEndOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____jakeperalta7\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____jakeperalta7\",\n      \"target\": \"func_0x40C410\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40C410\",\n      \"target\": \"api_SetFilePointer\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40C410\",\n      \"target\": \"api_SetEndOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x4044F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__2_matches_\",\n      \"target\": \"func_0x4096AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4044F0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4096AC\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4044F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4096AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4044F0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4096AC\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_size\",\n      \"target\": \"func_0x408068\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408068\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x408068\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408068\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_shutdown_system\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_shutdown_system\",\n      \"target\": \"func_0x40E550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E550\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40E550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E550\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_system_information_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_system_information_on_windows\",\n      \"target\": \"func_0x40ED58\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40ED58\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x40ED58\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40ED58\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_thread_local_storage_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value\",\n      \"target\": \"func_0x406588\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406588\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x406588\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406588\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows\",\n      \"target\": \"bb_0x40EB68\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x40EB68\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_suspended\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_suspended\",\n      \"target\": \"bb_0x40EB68\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"bb_0x40EB68\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_or_change_rwx_memory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory\",\n      \"target\": \"bb_0x40EDB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x40EDB4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_modify_access_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"target\": \"func_0x405DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"target\": \"func_0x403714\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"target\": \"func_0x40BB34\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__4_matches_\",\n      \"target\": \"func_0x405DD4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405DE8\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403714\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BB34\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DD4\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DE8\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403714\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BB34\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DD4\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403714\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40BB34\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405DD4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405DE8\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403714\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BB34\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DD4\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DE8\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403714\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40BB34\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405DD4\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_thread_local_storage_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value\",\n      \"target\": \"func_0x406544\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406544\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x406544\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x406544\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal__installer_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_identify_system_language_via_api\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_identify_system_language_via_api\",\n      \"target\": \"func_0x40E684\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E684\",\n      \"target\": \"api_GetUserDefaultLangID\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40E684\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40E684\",\n      \"target\": \"api_GetUserDefaultLangID\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-19 13:09:09.641707\",\n    \"total_functions\": \"555\",\n    \"total_features\": \"101857\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-19 13:09:10"}
{"_id":{"$oid":"6a5c869ab3bed57e0e737893"},"sha256":"0aac658075b7d9e81419d0beaa3db796569bc14fd57512f4479fb36e9cc4c1a2","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_tgab7myn/xworm-019f796a6dc57a41964b0c138810f68b.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_tgab7myn/xworm-019f796a6dc57a41964b0c138810f68b.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_tgab7myn/xworm-019f796a6dc57a41964b0c138810f68b.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 179e5c88bbd34e45830e7ee3610d5216                                  │\n│ sha1     │ e6fa8fda487392419be240e2911e7c9c346b750c                          │\n│ sha256   │ 0aac658075b7d9e81419d0beaa3db796569bc14fd57512f4479fb36e9cc4c1a2  │\n│ analysis │ static                                                            │\n│ os       │ any                                                               │\n│ format   │ dotnet                                                            │\n│ arch     │ any                                                               │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/xworm-019f796a6d… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Archive Collected Data::Archive via Library           │\n│                      │ [T1560.002]                                           │\n│                      │ Data from Information Repositories [T1213]            │\n│                      │ Input Capture::Keylogging [T1056.001]                 │\n│                      │ Screen Capture [T1113]                                │\n│ DEFENSE EVASION      │ Deobfuscate/Decode Files or Information [T1140]       │\n│                      │ File and Directory Permissions Modification [T1222]   │\n│                      │ Indicator Removal::File Deletion [T1070.004]          │\n│                      │ Modify Registry [T1112]                               │\n│                      │ Obfuscated Files or Information [T1027]               │\n│                      │ Reflective Code Loading [T1620]                       │\n│                      │ Virtualization/Sandbox Evasion::System Checks         │\n│                      │ [T1497.001]                                           │\n│ DISCOVERY            │ Account Discovery [T1087]                             │\n│                      │ File and Directory Discovery [T1083]                  │\n│                      │ Process Discovery [T1057]                             │\n│                      │ Query Registry [T1012]                                │\n│                      │ Software Discovery [T1518]                            │\n│                      │ System Information Discovery [T1082]                  │\n│                      │ System Location Discovery::System Language Discovery  │\n│                      │ [T1614.001]                                           │\n│                      │ System Owner/User Discovery [T1033]                   │\n│ EXECUTION            │ Windows Management Instrumentation [T1047]            │\n│ PERSISTENCE          │ Boot or Logon Autostart Execution::Registry Run Keys  │\n│                      │ / Startup Folder [T1547.001]                          │\n│                      │ Boot or Logon Autostart Execution::Shortcut           │\n│                      │ Modification [T1547.009]                              │\n│                      │ Scheduled Task/Job::Scheduled Task [T1053.005]        │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MAEC Category                                    ┃ MAEC Value                ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ malware-category                                 │ downloader                │\n│                                                  │ launcher                  │\n└──────────────────────────────────────────────────┴───────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Debugger Detection::CheckRemoteDebuggerPresent    │\n│                          │ [B0001.002]                                       │\n│                          │ Debugger Detection::WudfIsAnyDebuggerPresent      │\n│                          │ [B0001.031]                                       │\n│                          │ Sandbox Detection [B0007]                         │\n│                          │ Virtual Machine Detection [B0009]                 │\n│ COLLECTION               │ Keylogging::Polling [F0002.002]                   │\n│                          │ Screen Capture::WinAPI [E1113.m01]                │\n│ COMMAND AND CONTROL      │ C2 Communication::Receive Data [B0030.002]        │\n│                          │ C2 Communication::Send Data [B0030.001]           │\n│ COMMUNICATION            │ DNS Communication::Resolve [C0011.001]            │\n│                          │ HTTP Communication [C0002]                        │\n│                          │ HTTP Communication::Create Request [C0002.012]    │\n│                          │ HTTP Communication::Download URL [C0002.006]      │\n│                          │ HTTP Communication::Get Response [C0002.017]      │\n│                          │ HTTP Communication::Send Request [C0002.003]      │\n│                          │ Socket Communication::Create TCP Socket           │\n│                          │ [C0001.011]                                       │\n│                          │ Socket Communication::Create UDP Socket           │\n│                          │ [C0001.010]                                       │\n│                          │ Socket Communication::Receive Data [C0001.006]    │\n│                          │ Socket Communication::Send Data [C0001.007]       │\n│ CRYPTOGRAPHY             │ Cryptographic Hash::MD5 [C0029.001]               │\n│                          │ Generate Pseudo-random Sequence::Use API          │\n│                          │ [C0021.003]                                       │\n│ DATA                     │ Compress Data [C0024]                             │\n│                          │ Decode Data::Base64 [C0053.001]                   │\n│                          │ Encode Data::Base64 [C0026.001]                   │\n│ DEFENSE EVASION          │ Obfuscated Files or                               │\n│                          │ Information::Encoding-Standard Algorithm          │\n│                          │ [E1027.m02]                                       │\n│                          │ Self Deletion::COMSPEC Environment Variable       │\n│                          │ [F0007.001]                                       │\n│ DISCOVERY                │ Analysis Tool Discovery::Process detection        │\n│                          │ [B0013.001]                                       │\n│                          │ Application Window Discovery [E1010]              │\n│                          │ File and Directory Discovery [E1083]              │\n│                          │ System Information Discovery [E1082]              │\n│ FILE SYSTEM              │ Create Directory [C0046]                          │\n│                          │ Delete File [C0047]                               │\n│                          │ Read File [C0051]                                 │\n│                          │ Set File Attributes [C0050]                       │\n│                          │ Writes File [C0052]                               │\n│ OPERATING SYSTEM         │ Registry::Delete Registry Key [C0036.002]         │\n│                          │ Registry::Delete Registry Value [C0036.007]       │\n│                          │ Registry::Query Registry Key [C0036.005]          │\n│                          │ Registry::Query Registry Value [C0036.006]        │\n│                          │ Registry::Set Registry Key [C0036.001]            │\n│ PERSISTENCE              │ Registry Run Keys / Startup Folder [F0012]        │\n│ PROCESS                  │ Create Mutex [C0042]                              │\n│                          │ Create Process [C0017]                            │\n│                          │ Create Thread [C0038]                             │\n│                          │ Suspend Thread [C0055]                            │\n│                          │ Terminate Process [C0018]                         │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ reference analysis tools strings      │ anti-analysis                        │\n│ check for sandbox and av modules      │ anti-analysis/anti-av                │\n│ check for debugger via API            │ anti-analysis/anti-debugging/debugg… │\n│ self delete (2 matches)               │ anti-analysis/anti-forensic/self-de… │\n│ reference anti-VM strings targeting   │ anti-analysis/anti-vm/vm-detection   │\n│ VMWare                                │                                      │\n│ reference anti-VM strings targeting   │ anti-analysis/anti-vm/vm-detection   │\n│ VirtualBox                            │                                      │\n│ save image in .NET                    │ collection                           │\n│ reference WMI statements              │ collection/database/wmi              │\n│ log keystrokes                        │ collection/keylog                    │\n│ log keystrokes via polling (2         │ collection/keylog                    │\n│ matches)                              │                                      │\n│ capture screenshot                    │ collection/screenshot                │\n│ send data (2 matches)                 │ communication                        │\n│ receive and write data from server to │ communication/c2/file-transfer       │\n│ client                                │                                      │\n│ resolve DNS                           │ communication/dns                    │\n│ reference HTTP User-Agent string      │ communication/http                   │\n│ send HTTP request with Host header    │ communication/http                   │\n│ set HTTP User-Agent in .NET           │ communication/http                   │\n│ create HTTP request                   │ communication/http/client            │\n│ compress data using GZip in .NET (2   │ data-manipulation/compression        │\n│ matches)                              │                                      │\n│ decode data using Base64 in .NET (3   │ data-manipulation/encoding/base64    │\n│ matches)                              │                                      │\n│ encode data using Base64              │ data-manipulation/encoding/base64    │\n│ hash data with MD5 (4 matches)        │ data-manipulation/hashing/md5        │\n│ generate random numbers in .NET (6    │ data-manipulation/prng               │\n│ matches)                              │                                      │\n│ query environment variable            │ host-interaction/environment-variab… │\n│ check file extension in .NET          │ host-interaction/file-system         │\n│ enumerate drives (2 matches)          │ host-interaction/file-system         │\n│ generate random filename in .NET      │ host-interaction/file-system         │\n│ get common file path (4 matches)      │ host-interaction/file-system         │\n│ create directory                      │ host-interaction/file-system/create  │\n│ delete file                           │ host-interaction/file-system/delete  │\n│ check if directory exists             │ host-interaction/file-system/exists  │\n│ check if file exists (4 matches)      │ host-interaction/file-system/exists  │\n│ enumerate files in .NET (2 matches)   │ host-interaction/file-system/files/… │\n│ set file attributes                   │ host-interaction/file-system/meta    │\n│ read file on Windows (3 matches)      │ host-interaction/file-system/read    │\n│ set application hook                  │ host-interaction/gui                 │\n│ get graphical window text             │ host-interaction/gui/window/get-text │\n│ get number of processors              │ host-interaction/hardware/cpu        │\n│ get keyboard layout                   │ host-interaction/hardware/keyboard   │\n│ get disk information (2 matches)      │ host-interaction/hardware/storage    │\n│ get disk size                         │ host-interaction/hardware/storage    │\n│ manipulate unmanaged memory in .NET   │ host-interaction/memory              │\n│ (2 matches)                           │                                      │\n│ create or open mutex on Windows       │ host-interaction/mutex               │\n│ get hostname (2 matches)              │ host-interaction/os/hostname         │\n│ get OS version in .NET (3 matches)    │ host-interaction/os/version          │\n│ get process image filename            │ host-interaction/process             │\n│ create a process with modified I/O    │ host-interaction/process/create      │\n│ handles and window (4 matches)        │                                      │\n│ create process on Windows (6 matches) │ host-interaction/process/create      │\n│ enumerate processes                   │ host-interaction/process/list        │\n│ find process by PID                   │ host-interaction/process/list        │\n│ enter debug mode in .NET              │ host-interaction/process/modify      │\n│ terminate process (4 matches)         │ host-interaction/process/terminate   │\n│ query or enumerate registry key (3    │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ query or enumerate registry value (2  │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ delete registry key                   │ host-interaction/registry/delete     │\n│ delete registry value                 │ host-interaction/registry/delete     │\n│ get session integrity level           │ host-interaction/session             │\n│ get session user name (3 matches)     │ host-interaction/session             │\n│ create thread (4 matches)             │ host-interaction/thread/create       │\n│ suspend thread (8 matches)            │ host-interaction/thread/suspend      │\n│ execute via timer in .NET             │ host-interaction/thread/timer        │\n│ access WMI data in .NET (2 matches)   │ host-interaction/wmi                 │\n│ invoke .NET assembly method           │ load-code/dotnet                     │\n│ load .NET assembly (2 matches)        │ load-code/dotnet                     │\n│ persist via lnk shortcut (3 matches)  │ persistence/file-system              │\n│ persist via Run registry key (2       │ persistence/registry/run             │\n│ matches)                              │                                      │\n│ schedule task via schtasks (4         │ persistence/scheduled-tasks          │\n│ matches)                              │                                      │\n│ unmanaged call (13 matches)           │ runtime                              │\n│ compiled to the .NET platform         │ runtime/dotnet                       │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     179e5c88bbd34e45830e7ee3610d5216                        \nsha1                    e6fa8fda487392419be240e2911e7c9c346b750c                \nsha256                  0aac658075b7d9e81419d0beaa3db796569bc14fd57512f4479fb36…\npath                    /home/apogean/projects/malware/windows/all_runs/xworm-0…\ntimestamp               2026-07-19 13:41:03.170058                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    any                                                     \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIyZXJKv/rules                                   \nfunction count          340                                                     \nlibrary function count  0                                                       \ntotal feature count     8151                                                    \n\nreference analysis tools strings\nnamespace  anti-analysis\nscope      file         \n\ncheck for sandbox and av modules\nnamespace  anti-analysis/anti-av\nscope      basic block          \nmatches    token(0x600002D)     \n\ncheck for debugger via API\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    token(0x600002C)                               \n\nself delete (2 matches)\nnamespace  anti-analysis/anti-forensic/self-deletion\nscope      function                                 \nmatches    token(0x60000BE)                         \n           token(0x60000BE)                         \n\nreference anti-VM strings targeting VMWare\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nreference anti-VM strings targeting VirtualBox\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nsave image in .NET\nnamespace  collection      \nscope      function        \nmatches    token(0x600008F)\n\nreference WMI statements\nnamespace  collection/database/wmi\nscope      function               \nmatches    token(0x6000058)       \n\nlog keystrokes\nnamespace  collection/keylog\nscope      function         \nmatches    token(0x60000D4) \n\nlog keystrokes via polling (2 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    token(0x60000D3) \n           token(0x60000D4) \n\ncapture screenshot\nnamespace  collection/screenshot\nscope      function             \nmatches    token(0x600008F)     \n\nreceive data (4 matches)\nnamespace    communication                                                     \ndescription  all known techniques for receiving data from a potential C2 server\nscope        function                                                          \nmatches      token(0x6000029)                                                  \n             token(0x6000052)                                                  \n             token(0x600005B)                                                  \n             token(0x600008F)                                                  \n\nsend data (2 matches)\nnamespace    communication                                                 \ndescription  all known techniques for sending data to a potential C2 server\nscope        function                                                      \nmatches      token(0x60000BC)                                              \n             token(0x60000BC)                                              \n\nreceive and write data from server to client\nnamespace  communication/c2/file-transfer\nscope      function                      \nmatches    token(0x600008F)              \n\nresolve DNS\nnamespace  communication/dns\nscope      function         \nmatches    token(0x6000051) \n\nreference HTTP User-Agent string\nnamespace  communication/http\nscope      function          \nmatches    token(0x600011E)  \n\nsend HTTP request with Host header\nnamespace  communication/http\nscope      function          \nmatches    token(0x60000BC)  \n\nset HTTP User-Agent in .NET\nnamespace  communication/http\nscope      function          \nmatches    token(0x6000095)  \n\ncreate HTTP request\nnamespace  communication/http/client\nscope      function                 \nmatches    token(0x6000095)         \n\ndownload URL\nnamespace  communication/http/client\nscope      function                 \nmatches    token(0x600008F)         \n\nread data from Internet\nnamespace  communication/http/client\nscope      function                 \nmatches    token(0x6000029)         \n\nsend HTTP request\nnamespace  communication/http/client\nscope      function                 \nmatches    token(0x60000BC)         \n\nreceive data on socket (2 matches)\nnamespace  communication/socket/receive\nscope      function                    \nmatches    token(0x6000052)            \n           token(0x600005B)            \n\nsend data on socket\nnamespace  communication/socket/send\nscope      function                 \nmatches    token(0x60000BC)         \n\ncreate TCP socket (2 matches)\nnamespace  communication/socket/tcp\nscope      basic block             \nmatches    token(0x6000052)        \n           token(0x60000BC)        \n\ncreate UDP socket (2 matches)\nnamespace  communication/socket/udp/send\nscope      basic block                  \nmatches    token(0x6000052)             \n           token(0x60000BC)             \n\ncompress data using GZip in .NET (2 matches)\nnamespace  data-manipulation/compression\nscope      function                     \nmatches    token(0x6000130)             \n           token(0x6000131)             \n\ndecode data using Base64 in .NET (3 matches)\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    token(0x600008F)                 \n           token(0x6000090)                 \n           token(0x6000119)                 \n\nencode data using Base64\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    token(0x600008F)                 \n\nhash data with MD5 (4 matches)\nnamespace  data-manipulation/hashing/md5\nscope      function                     \nmatches    token(0x6000119)             \n           token(0x600012D)             \n           token(0x6000132)             \n           token(0x6000133)             \n\ngenerate random numbers in .NET (6 matches)\nnamespace  data-manipulation/prng\nscope      function              \nmatches    token(0x6000032)      \n           token(0x6000051)      \n           token(0x6000052)      \n           token(0x6000095)      \n           token(0x60000BC)      \n           token(0x6000121)      \n\nquery environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    token(0x6000026)                     \n\ncheck file extension in .NET\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x60000C6)            \n\nenumerate drives (2 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x60000BE)            \n           token(0x60000C6)            \n\ngenerate random filename in .NET\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x60000BE)            \n\nget common file path (4 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    token(0x6000026)            \n           token(0x600008F)            \n           token(0x60000BE)            \n           token(0x600012C)            \n\ncreate directory\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    token(0x6000026)                   \n\ndelete file\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    token(0x60000BE)                   \n\ncheck if directory exists\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x6000026)                   \n\ncheck if file exists (4 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x6000026)                   \n           token(0x6000090)                   \n           token(0x60000BE)                   \n           token(0x60000C6)                   \n\nenumerate files in .NET (2 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    token(0x60000BE)                       \n           token(0x60000C6)                       \n\nset file attributes\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    token(0x60000C6)                 \n\nread file on Windows (3 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    token(0x6000026)                 \n           token(0x600008F)                 \n           token(0x60000C6)                 \n\nwrite file on Windows (5 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    token(0x6000026)                  \n           token(0x600008F)                  \n           token(0x6000099)                  \n           token(0x60000BE)                  \n           token(0x60000C6)                  \n\nset application hook\nnamespace  host-interaction/gui \nscope      instruction          \nmatches    token(0x60000D2)+0x18\n\nget graphical window text\nnamespace  host-interaction/gui/window/get-text\nscope      function                            \nmatches    token(0x6000129)                    \n\nget number of processors\nnamespace  host-interaction/hardware/cpu\nscope      function                     \nmatches    token(0x600012C)             \n\nget keyboard layout\nnamespace  host-interaction/hardware/keyboard\nscope      function                          \nmatches    token(0x60000D4)                  \n\nget disk information (2 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    token(0x60000BE)                 \n           token(0x60000C6)                 \n\nget disk size\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    token(0x600012C)                 \n\nmanipulate unmanaged memory in .NET (2 matches)\nnamespace  host-interaction/memory\nscope      function               \nmatches    token(0x60000D3)       \n           token(0x6000123)       \n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex\nscope      instruction           \nmatches    token(0x6000134)+0x8  \n\nget hostname (2 matches)\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    token(0x6000057)            \n           token(0x600012C)            \n\nget OS version in .NET (3 matches)\nnamespace  host-interaction/os/version\nscope      basic block                \nmatches    token(0x600002A)           \n           token(0x6000053)           \n           token(0x600012C)           \n\nget process image filename\nnamespace  host-interaction/process\nscope      basic block             \nmatches    token(0x600011E)        \n\ncreate a process with modified I/O handles and window (4 matches)\nnamespace  host-interaction/process/create\nscope      function                       \nmatches    token(0x6000026)               \n           token(0x6000027)               \n           token(0x6000099)               \n           token(0x60000BE)               \n\ncreate process on Windows (6 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    token(0x6000026)               \n           token(0x6000027)               \n           token(0x600008F)               \n           token(0x6000095)               \n           token(0x6000099)               \n           token(0x60000BE)               \n\nenumerate processes\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    token(0x6000094)             \n\nfind process by PID\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    token(0x60000D5)             \n\nenter debug mode in .NET\nnamespace    host-interaction/process/modify                                    \ndescription  Often used by debuggers and malware to attach to and modify other  \n             processes.                                                         \nscope        basic block                                                        \nmatches      token(0x600010C)                                                   \n\nterminate process (4 matches)\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    token(0x6000026)                  \n           token(0x6000027)                  \n           token(0x600008F)                  \n           token(0x60000BE)                  \n\nquery or enumerate registry key (3 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    token(0x6000026)         \n           token(0x60000BE)         \n           token(0x60000C6)         \n\nquery or enumerate registry value (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    token(0x60000C6)         \n           token(0x600012F)         \n\nset registry value (4 matches)\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    token(0x6000026)                \n           token(0x6000026)                \n           token(0x60000C6)                \n           token(0x600012E)                \n\ndelete registry key\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    token(0x600008F)                \n\ndelete registry value\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    token(0x60000BE)                \n\nget session integrity level\nnamespace  host-interaction/session\nscope      function                \nmatches    token(0x6000056)        \n\nget session user name (3 matches)\nnamespace  host-interaction/session\nscope      function                \nmatches    token(0x6000053)        \n           token(0x6000056)        \n           token(0x600012C)        \n\ncreate thread (4 matches)\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    token(0x6000026)              \n           token(0x600008F)              \n           token(0x6000093)              \n           token(0x60000C4)              \n\nsuspend thread (8 matches)\nnamespace  host-interaction/thread/suspend\nscope      basic block                    \nmatches    token(0x6000026)               \n           token(0x6000032)               \n           token(0x6000093)               \n           token(0x6000094)               \n           token(0x6000099)               \n           token(0x60000BC)               \n           token(0x60000C6)               \n           token(0x6000124)               \n\nexecute via timer in .NET\nnamespace  host-interaction/thread/timer\nscope      function                     \nmatches    token(0x6000052)             \n\naccess WMI data in .NET (2 matches)\nnamespace  host-interaction/wmi\nscope      function            \nmatches    token(0x6000057)    \n           token(0x6000058)    \n\ninvoke .NET assembly method\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x600009A)\n\nload .NET assembly (2 matches)\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x6000090)\n           token(0x600009A)\n\npersist via lnk shortcut (3 matches)\nnamespace  persistence/file-system\nscope      function               \nmatches    token(0x6000026)       \n           token(0x60000BE)       \n           token(0x60000C6)       \n\npersist via Run registry key (2 matches)\nnamespace  persistence/registry/run\nscope      function                \nmatches    token(0x6000026)        \n           token(0x6000026)        \n\nschedule task via schtasks (4 matches)\nnamespace  persistence/scheduled-tasks\nscope      function                   \nmatches    token(0x6000026)           \n           token(0x6000026)           \n           token(0x6000026)           \n           token(0x6000026)           \n\nunmanaged call (13 matches)\nnamespace    runtime                                                       \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nscope        function                                                      \nmatches      token(0x600002C)                                              \n             token(0x600002D)                                              \n             token(0x600008F)                                              \n             token(0x6000098)                                              \n             token(0x60000D2)                                              \n             token(0x60000D3)                                              \n             token(0x60000D4)                                              \n             token(0x60000D5)                                              \n             token(0x600010C)                                              \n             token(0x600010D)                                              \n             token(0x6000123)                                              \n             token(0x6000128)                                              \n             token(0x6000129)                                              \n\ncompiled to the .NET platform\nnamespace  runtime/dotnet\nscope      file          \n\n\n\n","very_verbose":"md5                     179e5c88bbd34e45830e7ee3610d5216                        \nsha1                    e6fa8fda487392419be240e2911e7c9c346b750c                \nsha256                  0aac658075b7d9e81419d0beaa3db796569bc14fd57512f4479fb36…\npath                    /home/apogean/projects/malware/windows/all_runs/xworm-0…\ntimestamp               2026-07-19 13:41:05.648289                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    any                                                     \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEI6DUdtC/rules                                   \nfunction count          340                                                     \nlibrary function count  0                                                       \ntotal feature count     8151                                                    \n\ncreate or open registry key (5 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ token(0x6000026) in function token(0x6000026)\n  or:\n    api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000026)+0x257\n\nreference analysis tools strings\nnamespace   anti-analysis                                                       \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \nmbc         Discovery::Analysis Tool Discovery::Process detection [B0013.001]   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /(?<!\\w)ida?(\\.exe)?$/i\n    - \"IDAT\" @ file+0x420AE\n\ncheck for sandbox and av modules\nnamespace  anti-analysis/anti-av                                                \nauthor     @_re_fox                                                             \nscope      basic block                                                          \nmbc        Anti-Behavioral Analysis::Virtual Machine Detection [B0009],         \n           Anti-Behavioral Analysis::Sandbox Detection [B0007]                  \nbasic block @ token(0x600002D) in function token(0x600002D)\n  and:\n    api: GetModuleHandle @ token(0x600002D)+0x5\n    or:\n      regex: /sbiedll\\.dll/i\n        - \"SbieDll.dll\" @ token(0x600002D)+0x0\n\ncheck for debugger via API\nnamespace   anti-analysis/anti-debugging/debugger-detection                     \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \nmbc         Anti-Behavioral Analysis::Debugger                                  \n            Detection::CheckRemoteDebuggerPresent [B0001.002], Anti-Behavioral  \n            Analysis::Debugger Detection::WudfIsAnyDebuggerPresent [B0001.031]  \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ token(0x600002C)\n  or:\n    api: CheckRemoteDebuggerPresent @ token(0x600002C)+0xE\n\nself delete (2 matches)\nnamespace  anti-analysis/anti-forensic/self-deletion                            \nauthor     michael.hunhoff@mandiant.com, @mr-tz                                 \nscope      function                                                             \natt&ck     Defense Evasion::Indicator Removal::File Deletion [T1070.004]        \nmbc        Defense Evasion::Self Deletion::COMSPEC Environment Variable         \n           [F0007.001]                                                          \nfunction @ token(0x60000BE)\n  and:\n    optional:\n      regex: /\\s*>\\s*nul\\s*/i\n        - \"timeout 3 > NUL\" @ token(0x60000BE)+0x249\n    or:\n      match: host-interaction/process/create @ token(0x60000BE)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x60000BE)+0xD2, token(0x60000BE)+0x2CE, token(0x60000BE)+0x314\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x60000BE)+0xD2, token(0x60000BE)+0x2CE, token(0x60000BE)+0x314\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x60000BE)+0x305\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x60000BE)+0xC3, token(0x60000BE)+0x30D\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x60000BE)+0x9B, token(0x60000BE)+0x2ED\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x60000BE)+0xBB\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x60000BE)+0xCB, token(0x60000BE)+0x2F5\n    or:\n      regex: /(^|[\\&;\\|]\\s*)del(\\s.*)?/i\n        - \"DEL \\\"\" @ token(0x60000BE)+0x26B, token(0x60000BE)+0x2A1\nfunction @ token(0x60000BE)\n  and:\n    optional:\n      regex: /\\s*>\\s*nul\\s*/i\n        - \"timeout 3 > NUL\" @ token(0x60000BE)+0x249\n    or:\n      match: host-interaction/process/create @ token(0x60000BE)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x60000BE)+0xD2, token(0x60000BE)+0x2CE, token(0x60000BE)+0x314\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x60000BE)+0xD2, token(0x60000BE)+0x2CE, token(0x60000BE)+0x314\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x60000BE)+0x305\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x60000BE)+0xC3, token(0x60000BE)+0x30D\n              property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x60000BE)+0x9B, token(0x60000BE)+0x2ED\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x60000BE)+0xBB\n              property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x60000BE)+0xCB, token(0x60000BE)+0x2F5\n    or:\n      regex: /(^|[\\&;\\|]\\s*)del(\\s.*)?/i\n        - \"DEL \\\"\" @ token(0x60000BE)+0x26B, token(0x60000BE)+0x2A1\n\nreference anti-VM strings targeting VMWare\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com, @johnk3r                              \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /VMWare/i\n    - \"vmware\" @ file+0xE6B5\n\nreference anti-VM strings targeting VirtualBox\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /VirtualBox/i\n    - \"VirtualBox\" @ file+0xE6C3\n\nsave image in .NET\nnamespace  collection                  \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x600008F)\n  and:\n    api: System.Drawing.Image::Save @ token(0x600008F)+0x71E\n    optional:\n      class: System.Drawing.Imaging.ImageFormat @ token(0x600008F)+0x719\n\nreference WMI statements\nnamespace  collection/database/wmi                               \nauthor     michael.hunhoff@mandiant.com                          \nscope      function                                              \natt&ck     Collection::Data from Information Repositories [T1213]\nfunction @ token(0x6000058)\n  or:\n    regex: /SELECT\\s+\\*\\s+FROM\\s+Win32_./\n      - \"SELECT * FROM Win32_VideoController\" @ token(0x6000058)+0x6\n\nlog keystrokes\nnamespace  collection/keylog                                \nauthor     moritz.raabe@mandiant.com                        \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nfunction @ token(0x60000D4)\n  or:\n    api: MapVirtualKey @ token(0x60000D4)+0x2C\n\nlog keystrokes via polling (2 matches)\nnamespace  collection/keylog                                \nauthor     michael.hunhoff@mandiant.com                     \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nmbc        Collection::Keylogging::Polling [F0002.002]      \nfunction @ token(0x60000D3)\n  or:\n    api: GetKeyState @ token(0x60000D3)+0x2B, token(0x60000D3)+0x47, token(0x60000D3)+0x5A\nfunction @ token(0x60000D4)\n  or:\n    api: GetKeyboardState @ token(0x60000D4)+0x1B\n\ncapture screenshot\nnamespace  collection/screenshot                                            \nauthor     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\nscope      function                                                         \natt&ck     Collection::Screen Capture [T1113]                               \nmbc        Collection::Screen Capture::WinAPI [E1113.m01]                   \nfunction @ token(0x600008F)\n  or:\n    api: System.Drawing.Graphics::CopyFromScreen @ token(0x600008F)+0x6B7\n\nreceive data (4 matches)\nnamespace    communication                                                     \nauthor       william.ballenthin@mandiant.com                                   \nscope        function                                                          \nmbc          Command and Control::C2 Communication::Receive Data [B0030.002]   \ndescription  all known techniques for receiving data from a potential C2 server\nfunction @ token(0x6000029)\n  or:\n    match: read data from Internet @ token(0x6000029)\n      and:\n        or:\n          api: System.Net.WebClient::DownloadString @ token(0x6000029)+0xA\nfunction @ token(0x6000052)\n  or:\n    match: receive data on socket @ token(0x6000052)\n      or:\n        api: System.Net.Sockets.Socket::BeginReceive @ token(0x6000052)+0xAC\nfunction @ token(0x600005B)\n  or:\n    match: receive data on socket @ token(0x600005B)\n      or:\n        api: System.Net.Sockets.Socket::BeginReceive @ token(0x600005B)+0x99, token(0x600005B)+0x1A1\n        api: System.Net.Sockets.Socket::EndReceive @ token(0x600005B)+0x12\nfunction @ token(0x600008F)\n  or:\n    match: download URL @ token(0x600008F)\n      or:\n        api: System.Net.WebClient::DownloadFile @ token(0x600008F)+0x1B1\n\nsend data (2 matches)\nnamespace    communication                                                 \nauthor       william.ballenthin@mandiant.com, joakim@intezer.com           \nscope        function                                                      \nmbc          Command and Control::C2 Communication::Send Data [B0030.001]  \ndescription  all known techniques for sending data to a potential C2 server\nfunction @ token(0x60000BC)\n  or:\n    and:\n      os: windows\n      or:\n        match: send HTTP request @ token(0x60000BC)\n          or:\n            and:\n              match: send data on socket @ token(0x60000BC)\n                or:\n                  api: System.Net.Sockets.Socket::Send @ token(0x60000BC)+0x83\n              regex: /HTTP/i\n                - \"POST / HTTP/1.1\\r\\nHost: \" @ token(0x60000BC)+0x2B\n        match: send data on socket @ token(0x60000BC)\n          or:\n            api: System.Net.Sockets.Socket::Send @ token(0x60000BC)+0x83\n    and:\n      os: linux\n      or:\n        match: create TCP socket @ token(0x60000BC)\n          or:\n            and:\n              or:\n                number: 0x0 = protocol (default) @ token(0x60000BC)+0x2A, token(0x60000BC)+0x7E, token(0x60000BC)+0x82\n                number: 0x6 = IPPROTO_TCP @ token(0x60000BC)+0x2\n              number: 0x1 = SOCK_STREAM @ token(0x60000BC)+0x1, token(0x60000BC)+0x33\n              number: 0x2 = AF_INET @ token(0x60000BC)+0x0, token(0x60000BC)+0x3D\n              or:\n                api: System.Net.Sockets.Socket::ctor @ token(0x60000BC)+0x3\n        match: create UDP socket @ token(0x60000BC)\n          or:\n            and:\n              number: 0x2 = AF_INET @ token(0x60000BC)+0x0, token(0x60000BC)+0x3D\n              or:\n                number: 0x0 = protocol (default) @ token(0x60000BC)+0x2A, token(0x60000BC)+0x7E, token(0x60000BC)+0x82\n              or:\n                api: System.Net.Sockets.Socket::ctor @ token(0x60000BC)+0x3\n      or:\n        match: send HTTP request @ token(0x60000BC)\n          or:\n            and:\n              match: send data on socket @ token(0x60000BC)\n                or:\n                  api: System.Net.Sockets.Socket::Send @ token(0x60000BC)+0x83\n              regex: /HTTP/i\n                - \"POST / HTTP/1.1\\r\\nHost: \" @ token(0x60000BC)+0x2B\n        match: send data on socket @ token(0x60000BC)\n          or:\n            api: System.Net.Sockets.Socket::Send @ token(0x60000BC)+0x83\nfunction @ token(0x60000BC)\n  or:\n    and:\n      os: windows\n      or:\n        match: send HTTP request @ token(0x60000BC)\n          or:\n            and:\n              match: send data on socket @ token(0x60000BC)\n                or:\n                  api: System.Net.Sockets.Socket::Send @ token(0x60000BC)+0x83\n              regex: /HTTP/i\n                - \"POST / HTTP/1.1\\r\\nHost: \" @ token(0x60000BC)+0x2B\n        match: send data on socket @ token(0x60000BC)\n          or:\n            api: System.Net.Sockets.Socket::Send @ token(0x60000BC)+0x83\n    and:\n      os: linux\n      or:\n        match: create TCP socket @ token(0x60000BC)\n          or:\n            and:\n              or:\n                number: 0x0 = protocol (default) @ token(0x60000BC)+0x2A, token(0x60000BC)+0x7E, token(0x60000BC)+0x82\n                number: 0x6 = IPPROTO_TCP @ token(0x60000BC)+0x2\n              number: 0x1 = SOCK_STREAM @ token(0x60000BC)+0x1, token(0x60000BC)+0x33\n              number: 0x2 = AF_INET @ token(0x60000BC)+0x0, token(0x60000BC)+0x3D\n              or:\n                api: System.Net.Sockets.Socket::ctor @ token(0x60000BC)+0x3\n        match: create UDP socket @ token(0x60000BC)\n          or:\n            and:\n              number: 0x2 = AF_INET @ token(0x60000BC)+0x0, token(0x60000BC)+0x3D\n              or:\n                number: 0x0 = protocol (default) @ token(0x60000BC)+0x2A, token(0x60000BC)+0x7E, token(0x60000BC)+0x82\n              or:\n                api: System.Net.Sockets.Socket::ctor @ token(0x60000BC)+0x3\n      or:\n        match: send HTTP request @ token(0x60000BC)\n          or:\n            and:\n              match: send data on socket @ token(0x60000BC)\n                or:\n                  api: System.Net.Sockets.Socket::Send @ token(0x60000BC)+0x83\n              regex: /HTTP/i\n                - \"POST / HTTP/1.1\\r\\nHost: \" @ token(0x60000BC)+0x2B\n        match: send data on socket @ token(0x60000BC)\n          or:\n            api: System.Net.Sockets.Socket::Send @ token(0x60000BC)+0x83\n\ndownload and write a file\nnamespace              communication/c2/file-transfer                           \nmaec/malware-category  downloader                                               \nauthor                 moritz.raabe@mandiant.com                                \nscope                  function                                                 \natt&ck                 Command and Control::Ingress Tool Transfer [T1105]       \nmbc                    Command and Control::C2 Communication::Server to Client  \n                       File Transfer [B0030.003]                                \nfunction @ token(0x600008F)\n  and:\n    match: receive data @ token(0x600008F)\n      or:\n        match: download URL @ token(0x600008F)\n          or:\n            api: System.Net.WebClient::DownloadFile @ token(0x600008F)+0x1B1\n    match: host-interaction/file-system/write @ token(0x600008F)\n      or:\n        api: System.IO.File::WriteAllText @ token(0x600008F)+0x44E\n\nreceive and write data from server to client\nnamespace  communication/c2/file-transfer \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ token(0x600008F)\n  and:\n    match: receive data @ token(0x600008F)\n      or:\n        match: download URL @ token(0x600008F)\n          or:\n            api: System.Net.WebClient::DownloadFile @ token(0x600008F)+0x1B1\n    match: host-interaction/file-system/write @ token(0x600008F)\n      or:\n        api: System.IO.File::WriteAllText @ token(0x600008F)+0x44E\n\nwrite and execute a file (4 matches)\nnamespace              communication/c2/file-transfer               \nmaec/malware-category  launcher                                     \nauthor                 moritz.raabe@mandiant.com                    \nscope                  function                                     \nmbc                    Execution::Install Additional Program [B0023]\nfunction @ token(0x6000026)\n  and:\n    match: host-interaction/file-system/write @ token(0x6000026)\n      or:\n        api: System.IO.File::WriteAllBytes @ token(0x6000026)+0x161\n    match: host-interaction/process/create @ token(0x6000026)\n      or:\n        api: System.Diagnostics.Process::Start @ token(0x6000026)+0x223\n      or:\n        and:\n          api: System.Diagnostics.Process::Start @ token(0x6000026)+0x223\n          or:\n            property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000026)+0x186\n            property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000026)+0x1D6, token(0x6000026)+0x21C\nfunction @ token(0x600008F)\n  and:\n    match: host-interaction/file-system/write @ token(0x600008F)\n      or:\n        api: System.IO.File::WriteAllText @ token(0x600008F)+0x44E\n    match: host-interaction/process/create @ token(0x600008F)\n      or:\n        api: System.Diagnostics.Process::Start @ token(0x600008F)+0x1B7\nfunction @ token(0x6000099)\n  and:\n    match: host-interaction/file-system/write @ token(0x6000099)\n      or:\n        api: System.IO.File::WriteAllBytes @ token(0x6000099)+0x1E\n    match: host-interaction/process/create @ token(0x6000099)\n      or:\n        api: System.Diagnostics.Process::Start @ token(0x6000099)+0x72\n      or:\n        and:\n          api: System.Diagnostics.Process::Start @ token(0x6000099)+0x72\n          or:\n            property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000099)+0x4C\n            property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000099)+0x6C\nfunction @ token(0x60000BE)\n  and:\n    match: host-interaction/file-system/write @ token(0x60000BE)\n      or:\n        api: System.IO.File::WriteAllBytes @ token(0x60000BE)+0x1D\n    match: host-interaction/process/create @ token(0x60000BE)\n      or:\n        api: System.Diagnostics.Process::Start @ token(0x60000BE)+0xD2, token(0x60000BE)+0x2CE, token(0x60000BE)+0x314\n      or:\n        and:\n          api: System.Diagnostics.Process::Start @ token(0x60000BE)+0xD2, token(0x60000BE)+0x2CE, token(0x60000BE)+0x314\n          or:\n            property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x60000BE)+0x305\n            property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x60000BE)+0xC3, token(0x60000BE)+0x30D\n            property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x60000BE)+0x9B, token(0x60000BE)+0x2ED\n            property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x60000BE)+0xBB\n            property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x60000BE)+0xCB, token(0x60000BE)+0x2F5\n\nresolve DNS\nnamespace  communication/dns                                                    \nauthor     william.ballenthin@mandiant.com, johnk3r, joakim@intezer.com,        \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::DNS Communication::Resolve [C0011.001]                \nfunction @ token(0x6000051)\n  or:\n    api: System.Net.Dns::GetHostAddresses @ token(0x6000051)+0x4B\n\nreference HTTP User-Agent string\nnamespace   communication/http                                                  \nauthor      @mr-tz                                                              \nscope       function                                                            \nmbc         Communication::HTTP Communication [C0002]                           \nreferences  https://www.useragents.me/,                                         \n            https://www.whatismybrowser.com/guides/the-latest-user-agent/       \nfunction @ token(0x600011E)\n  or:\n    substring: Mozilla/5.0\n      - \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like \nGecko) Chrome/60.0.3112.113 Safari/537.36\" @ token(0x600011E)+0x68\n      - \"Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0\" @ token(0x600011E)+0x58\n      - \"Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 \n(KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1\" @ token(0x600011E)+0x60\n    substring: like Gecko\n      - \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like \nGecko) Chrome/60.0.3112.113 Safari/537.36\" @ token(0x600011E)+0x68\n      - \"Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 \n(KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1\" @ token(0x600011E)+0x60\n\nsend HTTP request with Host header\nnamespace  communication/http               \nauthor     anamaria.martinezgom@mandiant.com\nscope      function                         \nfunction @ token(0x60000BC)\n  and:\n    match: send HTTP request @ token(0x60000BC)\n      or:\n        and:\n          match: send data on socket @ token(0x60000BC)\n            or:\n              api: System.Net.Sockets.Socket::Send @ token(0x60000BC)+0x83\n          regex: /HTTP/i\n            - \"POST / HTTP/1.1\\r\\nHost: \" @ token(0x60000BC)+0x2B\n    regex: /Host:/i\n      - \"POST / HTTP/1.1\\r\\nHost: \" @ token(0x60000BC)+0x2B\n\nset HTTP User-Agent in .NET\nnamespace  communication/http          \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x6000095)\n  or:\n    property/write: System.Net.HttpWebRequest::UserAgent @ token(0x6000095)+0x52\n\ncreate HTTP request\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Create Request [C0002.012]\nfunction @ token(0x6000095)\n  and:\n    or:\n      api: System.Net.WebRequest::Create @ token(0x6000095)+0x2F\n\ndownload URL\nnamespace  communication/http/client                                            \nauthor     matthew.williams@mandiant.com, michael.hunhoff@mandiant.com,         \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Communication::HTTP Communication::Download URL [C0002.006]          \nfunction @ token(0x600008F)\n  or:\n    api: System.Net.WebClient::DownloadFile @ token(0x600008F)+0x1B1\n\nread data from Internet\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Get Response [C0002.017]  \nfunction @ token(0x6000029)\n  and:\n    or:\n      api: System.Net.WebClient::DownloadString @ token(0x6000029)+0xA\n\nsend HTTP request\nnamespace  communication/http/client                                  \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com    \nscope      function                                                   \nmbc        Communication::HTTP Communication::Send Request [C0002.003]\nfunction @ token(0x60000BC)\n  or:\n    and:\n      match: send data on socket @ token(0x60000BC)\n        or:\n          api: System.Net.Sockets.Socket::Send @ token(0x60000BC)+0x83\n      regex: /HTTP/i\n        - \"POST / HTTP/1.1\\r\\nHost: \" @ token(0x60000BC)+0x2B\n\nreceive data on socket (2 matches)\nnamespace  communication/socket/receive                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Receive Data [C0001.006]        \nfunction @ token(0x6000052)\n  or:\n    api: System.Net.Sockets.Socket::BeginReceive @ token(0x6000052)+0xAC\nfunction @ token(0x600005B)\n  or:\n    api: System.Net.Sockets.Socket::BeginReceive @ token(0x600005B)+0x99, token(0x600005B)+0x1A1\n    api: System.Net.Sockets.Socket::EndReceive @ token(0x600005B)+0x12\n\nsend data on socket\nnamespace  communication/socket/send                                            \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Communication::Socket Communication::Send Data [C0001.007]           \nfunction @ token(0x60000BC)\n  or:\n    api: System.Net.Sockets.Socket::Send @ token(0x60000BC)+0x83\n\ncreate TCP socket (2 matches)\nnamespace   communication/socket/tcp                                            \nauthor      william.ballenthin@mandiant.com, joakim@intezer.com,                \n            anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com       \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create TCP Socket [C0001.011]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ token(0x6000052) in function token(0x6000052)\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ token(0x6000052)+0x86, token(0x6000052)+0x96, token(0x6000052)+0x9E, \ntoken(0x6000052)+0x115\n        number: 0x6 = IPPROTO_TCP @ token(0x6000052)+0x2\n      number: 0x1 = SOCK_STREAM @ token(0x6000052)+0x1, token(0x6000052)+0x14, token(0x6000052)+0x62, \ntoken(0x6000052)+0x100, and 1 more...\n      number: 0x2 = AF_INET @ token(0x6000052)+0x0\n      or:\n        api: System.Net.Sockets.Socket::ctor @ token(0x6000052)+0x3\nbasic block @ token(0x60000BC) in function token(0x60000BC)\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ token(0x60000BC)+0x2A, token(0x60000BC)+0x7E, token(0x60000BC)+0x82\n        number: 0x6 = IPPROTO_TCP @ token(0x60000BC)+0x2\n      number: 0x1 = SOCK_STREAM @ token(0x60000BC)+0x1, token(0x60000BC)+0x33\n      number: 0x2 = AF_INET @ token(0x60000BC)+0x0, token(0x60000BC)+0x3D\n      or:\n        api: System.Net.Sockets.Socket::ctor @ token(0x60000BC)+0x3\n\ncreate UDP socket (2 matches)\nnamespace   communication/socket/udp/send                                       \nauthor      moritz.raabe@mandiant.com, joakim@intezer.com,                      \n            michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create UDP Socket [C0001.010]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ token(0x6000052) in function token(0x6000052)\n  or:\n    and:\n      number: 0x2 = AF_INET @ token(0x6000052)+0x0\n      or:\n        number: 0x0 = protocol (default) @ token(0x6000052)+0x86, token(0x6000052)+0x96, token(0x6000052)+0x9E, \ntoken(0x6000052)+0x115\n      or:\n        api: System.Net.Sockets.Socket::ctor @ token(0x6000052)+0x3\nbasic block @ token(0x60000BC) in function token(0x60000BC)\n  or:\n    and:\n      number: 0x2 = AF_INET @ token(0x60000BC)+0x0, token(0x60000BC)+0x3D\n      or:\n        number: 0x0 = protocol (default) @ token(0x60000BC)+0x2A, token(0x60000BC)+0x7E, token(0x60000BC)+0x82\n      or:\n        api: System.Net.Sockets.Socket::ctor @ token(0x60000BC)+0x3\n\ncompress data using GZip in .NET (2 matches)\nnamespace  data-manipulation/compression                                      \nauthor     michael.hunhoff@mandiant.com                                       \nscope      function                                                           \natt&ck     Collection::Archive Collected Data::Archive via Library [T1560.002]\nmbc        Data::Compress Data [C0024]                                        \nfunction @ token(0x6000130)\n  or:\n    api: System.IO.Compression.GZipStream::ctor @ token(0x6000130)+0x96\nfunction @ token(0x6000131)\n  or:\n    api: System.IO.Compression.GZipStream::ctor @ token(0x6000131)+0x7B\n\ndecode data using Base64 in .NET (3 matches)\nnamespace  data-manipulation/encoding/base64                               \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \natt&ck     Defense Evasion::Deobfuscate/Decode Files or Information [T1140]\nmbc        Data::Decode Data::Base64 [C0053.001]                           \nfunction @ token(0x600008F)\n  or:\n    api: System.Convert::FromBase64String @ token(0x600008F)+0xEF, token(0x600008F)+0x119, token(0x600008F)+0x140, \ntoken(0x600008F)+0x56F\nfunction @ token(0x6000090)\n  or:\n    api: System.Convert::FromBase64String @ token(0x6000090)+0x27E, token(0x6000090)+0x392\nfunction @ token(0x6000119)\n  or:\n    api: System.Convert::FromBase64String @ token(0x6000119)+0x62\n\nencode data using Base64\nnamespace  data-manipulation/encoding/base64                                    \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::Base64 [C0026.001]         \nfunction @ token(0x600008F)\n  or:\n    api: System.Convert::ToBase64String @ token(0x600008F)+0x75E\n\nhash data with MD5 (4 matches)\nnamespace   data-manipulation/hashing/md5                                       \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,         \n            michael.hunhoff@mandiant.com                                        \nscope       function                                                            \nmbc         Cryptography::Cryptographic Hash::MD5 [C0029.001]                   \nreferences  https://github.com/rwfpl/rewolf-x86-virtualizer/blob/master/src/tes…\nfunction @ token(0x6000119)\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Security.Cryptography.MD5CryptoServiceProvider::ctor @ token(0x6000119)+0x6\n      optional:\n        api: System.Security.Cryptography.HashAlgorithm::ComputeHash @ token(0x6000119)+0x28\nfunction @ token(0x600012D)\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Security.Cryptography.MD5CryptoServiceProvider::ctor @ token(0x600012D)+0x0\n      optional:\n        api: System.Security.Cryptography.HashAlgorithm::ComputeHash @ token(0x600012D)+0x14\nfunction @ token(0x6000132)\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Security.Cryptography.MD5CryptoServiceProvider::ctor @ token(0x6000132)+0x6\n      optional:\n        api: System.Security.Cryptography.HashAlgorithm::ComputeHash @ token(0x6000132)+0x18\nfunction @ token(0x6000133)\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Security.Cryptography.MD5CryptoServiceProvider::ctor @ token(0x6000133)+0x6\n      optional:\n        api: System.Security.Cryptography.HashAlgorithm::ComputeHash @ token(0x6000133)+0x18\n\ngenerate random numbers in .NET (6 matches)\nnamespace  data-manipulation/prng                                            \nauthor     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com     \nscope      function                                                          \nmbc        Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\nfunction @ token(0x6000032)\n  or:\n    api: System.Random::Next @ token(0x6000032)+0x11\nfunction @ token(0x6000051)\n  or:\n    api: System.Random::Next @ token(0x6000051)+0x3B\nfunction @ token(0x6000052)\n  or:\n    api: System.Random::Next @ token(0x6000052)+0xD0, token(0x6000052)+0xE4\nfunction @ token(0x6000095)\n  or:\n    api: System.Random::Next @ token(0x6000095)+0x4C\nfunction @ token(0x60000BC)\n  or:\n    api: System.Random::Next @ token(0x60000BC)+0x58\nfunction @ token(0x6000121)\n  or:\n    api: System.Random::Next @ token(0x6000121)+0x24\n\nquery environment variable\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ token(0x6000026)\n  or:\n    api: System.Environment::ExpandEnvironmentVariables @ token(0x6000026)+0x97\n\ncheck file extension in .NET\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x60000C6)\n  or:\n    api: System.IO.Path::GetExtension @ token(0x60000C6)+0x120\n\nenumerate drives (2 matches)\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x60000BE)\n  or:\n    api: System.IO.DriveInfo::GetDrives @ token(0x60000BE)+0x13A\nfunction @ token(0x60000C6)\n  or:\n    api: System.IO.DriveInfo::GetDrives @ token(0x60000C6)+0x77\n\ngenerate random filename in .NET\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x60000BE)\n  or:\n    api: System.IO.Path::GetTempFileName @ token(0x60000BE)+0x221\n\nget common file path (4 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ token(0x6000026)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x6000026)+0x27E\nfunction @ token(0x600008F)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x600008F)+0x3CD\nfunction @ token(0x60000BE)\n  or:\n    api: System.Environment::GetFolderPath @ token(0x60000BE)+0xEA\nfunction @ token(0x600012C)\n  or:\n    property/read: System.Environment::SystemDirectory @ token(0x600012C)+0x2E\n\ncreate directory\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ token(0x6000026)\n  or:\n    api: System.IO.Directory::CreateDirectory @ token(0x6000026)+0x12F\n\ndelete file\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ token(0x60000BE)\n  or:\n    api: System.IO.File::Delete @ token(0x60000BE)+0x46, token(0x60000BE)+0x11F, token(0x60000BE)+0x198, \ntoken(0x60000BE)+0x1D3\n\ncheck if directory exists\nnamespace  host-interaction/file-system/exists            \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nfunction @ token(0x6000026)\n  or:\n    api: System.IO.Directory::Exists @ token(0x6000026)+0x121\n\ncheck if file exists (4 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ token(0x6000026)\n  or:\n    api: System.IO.File::Exists @ token(0x6000026)+0x136\nfunction @ token(0x6000090)\n  or:\n    api: System.IO.File::Exists @ token(0x6000090)+0x243\nfunction @ token(0x60000BE)\n  or:\n    api: System.IO.File::Exists @ token(0x60000BE)+0x10C\nfunction @ token(0x60000C6)\n  or:\n    api: System.IO.File::Exists @ token(0x60000C6)+0xC5\n\nenumerate files in .NET (2 matches)\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ token(0x60000BE)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x60000BE)+0x1B5\nfunction @ token(0x60000C6)\n  or:\n    api: System.IO.Directory::GetFiles @ token(0x60000C6)+0x104\n    api: System.IO.Directory::GetDirectories @ token(0x60000C6)+0x477\n\nset file attributes\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ token(0x60000C6) in function token(0x60000C6)\n  or:\n    api: System.IO.File::SetAttributes @ token(0x60000C6)+0xFA, token(0x60000C6)+0x170, token(0x60000C6)+0x494\n\nread file on Windows (3 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ token(0x6000026)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x6000026)+0x15C\nfunction @ token(0x600008F)\n  or:\n    api: System.IO.File::ReadAllText @ token(0x600008F)+0x41E, token(0x600008F)+0x60E\nfunction @ token(0x60000C6)\n  or:\n    api: System.IO.File::ReadAllBytes @ token(0x60000C6)+0xE0\n\nwrite file on Windows (5 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ token(0x6000026)\n  or:\n    api: System.IO.File::WriteAllBytes @ token(0x6000026)+0x161\nfunction @ token(0x600008F)\n  or:\n    api: System.IO.File::WriteAllText @ token(0x600008F)+0x44E\nfunction @ token(0x6000099)\n  or:\n    api: System.IO.File::WriteAllBytes @ token(0x6000099)+0x1E\nfunction @ token(0x60000BE)\n  or:\n    api: System.IO.File::WriteAllBytes @ token(0x60000BE)+0x1D\nfunction @ token(0x60000C6)\n  or:\n    api: System.IO.File::WriteAllBytes @ token(0x60000C6)+0xE5\n\nset application hook\nnamespace  host-interaction/gui        \nauthor     michael.hunhoff@mandiant.com\nscope      instruction                 \ninstruction @ token(0x60000D2)+0x18\n  or:\n    api: SetWindowsHookEx @ token(0x60000D2)+0x18\n\nget graphical window text\nnamespace  host-interaction/gui/window/get-text           \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \nmbc        Discovery::Application Window Discovery [E1010]\nfunction @ token(0x6000129)\n  or:\n    and:\n      optional:\n        api: GetForegroundWindow @ token(0x6000129)+0xB\n      api: GetWindowText @ token(0x6000129)+0x18\n\nget number of processors\nnamespace   host-interaction/hardware/cpu                                       \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/bed03d2f849d9060c6…\nfunction @ token(0x600012C)\n  or:\n    property/read: System.Environment::ProcessorCount @ token(0x600012C)+0x9\n\nget keyboard layout\nnamespace  host-interaction/hardware/keyboard                                   \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Discovery::System Location Discovery::System Language Discovery      \n           [T1614.001]                                                          \nfunction @ token(0x60000D4)\n  and:\n    or:\n      api: GetKeyboardLayout @ token(0x60000D4)+0x44\n\nget disk information (2 matches)\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ token(0x60000BE)\n  or:\n    property/read: System.IO.DriveInfo::DriveType @ token(0x60000BE)+0x15E\n    property/read: System.IO.DriveInfo::Name @ token(0x60000BE)+0x16B\nfunction @ token(0x60000C6)\n  or:\n    property/read: System.IO.DriveInfo::DriveType @ token(0x60000C6)+0xA0\n    property/read: System.IO.DriveInfo::Name @ token(0x60000C6)+0xB0\n\nget disk size\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ token(0x600012C)\n  or:\n    property/read: System.IO.DriveInfo::TotalSize @ token(0x600012C)+0x3D\n\nmanipulate unmanaged memory in .NET (2 matches)\nnamespace  host-interaction/memory     \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ token(0x60000D3)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x60000D3)+0x1D\nfunction @ token(0x6000123)\n  or:\n    class: System.Runtime.InteropServices.Marshal @ token(0x6000123)+0x10\n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex                                               \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           mehunhoff@google.com                                                 \nscope      instruction                                                          \nmbc        Process::Create Mutex [C0042]                                        \ninstruction @ token(0x6000134)+0x8\n  or:\n    and:\n      format: dotnet\n      or:\n        api: System.Threading.Mutex::ctor @ token(0x6000134)+0x8\n\nget hostname (2 matches)\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ token(0x6000057)\n  or:\n    property/read: System.Environment::MachineName @ token(0x6000057)+0x5\nfunction @ token(0x600012C)\n  or:\n    property/read: System.Environment::MachineName @ token(0x600012C)+0x1E\n\nget OS version in .NET (3 matches)\nnamespace  host-interaction/os/version                    \nauthor     michael.hunhoff@mandiant.com                   \nscope      basic block                                    \natt&ck     Discovery::System Information Discovery [T1082]\nbasic block @ token(0x600002A) in function token(0x600002A)\n  or:\n    property/read: Microsoft.VisualBasic.Devices.ComputerInfo::OSFullName @ token(0x600002A)+0x5\nbasic block @ token(0x6000053) in function token(0x6000053)\n  or:\n    property/read: System.Environment::OSVersion @ token(0x6000053)+0x54\n    property/read: System.Environment::Is64BitOperatingSystem @ token(0x6000053)+0x7A\n    property/read: Microsoft.VisualBasic.Devices.ComputerInfo::OSFullName @ token(0x6000053)+0x41\nbasic block @ token(0x600012C) in function token(0x600012C)\n  or:\n    property/read: System.Environment::OSVersion @ token(0x600012C)+0x26\n\nget process image filename\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ token(0x600011E) in function token(0x600011E)\n  or:\n    and:\n      api: System.Diagnostics.Process::GetCurrentProcess @ token(0x600011E)+0x24\n      property/read: System.Diagnostics.Process::MainModule @ token(0x600011E)+0x29\n      property/read: System.Diagnostics.ProcessModule::FileName @ token(0x600011E)+0x2E\n\ncreate a process with modified I/O handles and window (4 matches)\nnamespace   host-interaction/process/create                                     \nauthor      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com      \nscope       function                                                            \nmbc         Process::Create Process [C0017]                                     \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/processthreadsap…\nfunction @ token(0x6000026)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000026)+0x223\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000026)+0x186\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000026)+0x1D6, token(0x6000026)+0x21C\nfunction @ token(0x6000027)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000027)+0x42, token(0x6000027)+0x71, token(0x6000027)+0xB7, \ntoken(0x6000027)+0xE1\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000027)+0x22\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x6000027)+0x1B\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000027)+0x3C, token(0x6000027)+0x6B, token(0x6000027)+0xB1, \ntoken(0x6000027)+0xDB\nfunction @ token(0x6000099)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x6000099)+0x72\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000099)+0x4C\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000099)+0x6C\nfunction @ token(0x60000BE)\n  or:\n    and:\n      api: System.Diagnostics.Process::Start @ token(0x60000BE)+0xD2, token(0x60000BE)+0x2CE, token(0x60000BE)+0x314\n      or:\n        property/write: System.Diagnostics.ProcessStartInfo::UseShellExecute @ token(0x60000BE)+0x305\n        property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x60000BE)+0xC3, token(0x60000BE)+0x30D\n        property/write: System.Diagnostics.ProcessStartInfo::FileName @ token(0x60000BE)+0x9B, token(0x60000BE)+0x2ED\n        property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x60000BE)+0xBB\n        property/write: System.Diagnostics.ProcessStartInfo::CreateNoWindow @ token(0x60000BE)+0xCB, token(0x60000BE)+0x2F5\n\ncreate process on Windows (6 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ token(0x6000026) in function token(0x6000026)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000026)+0x223\nbasic block @ token(0x6000027) in function token(0x6000027)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000027)+0x42, token(0x6000027)+0x71, token(0x6000027)+0xB7, \ntoken(0x6000027)+0xE1\nbasic block @ token(0x600008F) in function token(0x600008F)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x600008F)+0x1B7\nbasic block @ token(0x6000095) in function token(0x6000095)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000095)+0x8F\nbasic block @ token(0x6000099) in function token(0x6000099)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x6000099)+0x72\nbasic block @ token(0x60000BE) in function token(0x60000BE)\n  or:\n    api: System.Diagnostics.Process::Start @ token(0x60000BE)+0xD2, token(0x60000BE)+0x2CE, token(0x60000BE)+0x314\n\nenumerate processes\nnamespace  host-interaction/process/list                                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      function                                                             \natt&ck     Discovery::Process Discovery [T1057], Discovery::Software Discovery  \n           [T1518]                                                              \nfunction @ token(0x6000094)\n  or:\n    api: System.Diagnostics.Process::GetProcesses @ token(0x6000094)+0x56\n\nfind process by PID\nnamespace  host-interaction/process/list                                \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::Process Discovery [T1057]                         \nfunction @ token(0x60000D5)\n  and:\n    or:\n      api: System.Diagnostics.Process::GetProcessById @ token(0x60000D5)+0x13\n\nenter debug mode in .NET\nnamespace    host-interaction/process/modify                                    \nauthor       @v1bh475u                                                          \nscope        basic block                                                        \nreferences   https://learn.microsoft.com/en-us/dotnet/api/system.diagnostics.pr…\ndescription  Often used by debuggers and malware to attach to and modify other  \n             processes.                                                         \nbasic block @ token(0x600010C) in function token(0x600010C)\n  and:\n    format: dotnet\n    api: System.Diagnostics.Process::EnterDebugMode @ token(0x600010C)+0x11\n\nterminate process (4 matches)\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ token(0x6000026)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x6000026)+0x22C\n    api: System.Environment::Exit @ token(0x6000026)+0xBF, token(0x6000026)+0xD3\nfunction @ token(0x6000027)\n  or:\n    api: System.Diagnostics.Process::WaitForExit @ token(0x6000027)+0x47, token(0x6000027)+0x76, token(0x6000027)+0xBC, \ntoken(0x6000027)+0xE6\nfunction @ token(0x600008F)\n  or:\n    api: System.Environment::Exit @ token(0x600008F)+0x7C, token(0x600008F)+0xB1\nfunction @ token(0x60000BE)\n  or:\n    api: System.Environment::Exit @ token(0x60000BE)+0x31B\n\nquery or enumerate registry key (3 matches)\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ token(0x6000026)\n  and:\n    optional:\n      match: create or open registry key @ token(0x6000026)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000026)+0x257\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000026)+0x257\nfunction @ token(0x60000BE)\n  and:\n    optional:\n      match: create or open registry key @ token(0x60000BE)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000BE)+0x66\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000BE)+0x66\nfunction @ token(0x60000C6)\n  and:\n    optional:\n      match: create or open registry key @ token(0x60000C6)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000C6)+0x3D\n    or:\n      api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000C6)+0x3D\n\nquery or enumerate registry value (2 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ token(0x60000C6)\n  and:\n    optional:\n      match: create or open registry key @ token(0x60000C6)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000C6)+0x3D\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x60000C6)+0x4C\nfunction @ token(0x600012F)\n  and:\n    optional:\n      match: create or open registry key @ token(0x600012F)\n        or:\n          api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x600012F)+0xA\n    or:\n      api: Microsoft.Win32.RegistryKey::GetValue @ token(0x600012F)+0x12\n\nset registry value (4 matches)\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ token(0x6000026)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x6000026)\n          or:\n            api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000026)+0x257\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000026)+0x267\nfunction @ token(0x6000026)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x6000026)\n          or:\n            api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000026)+0x257\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000026)+0x267\nfunction @ token(0x60000C6)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x60000C6)\n          or:\n            api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000C6)+0x3D\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x60000C6)+0x6E\nfunction @ token(0x600012E)\n  or:\n    and:\n      optional:\n        match: create or open registry key @ token(0x600012E)\n          or:\n            api: Microsoft.Win32.RegistryKey::CreateSubKey @ token(0x600012E)+0xB\n      or:\n        api: Microsoft.Win32.RegistryKey::SetValue @ token(0x600012E)+0x15\n\ndelete registry key\nnamespace  host-interaction/registry/delete                                \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\nscope      function                                                        \natt&ck     Defense Evasion::Modify Registry [T1112]                        \nmbc        Operating System::Registry::Delete Registry Key [C0036.002]     \nfunction @ token(0x600008F)\n  and:\n    or:\n      api: Microsoft.Win32.RegistryKey::DeleteSubKey @ token(0x600008F)+0x5B6\n\ndelete registry value\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ token(0x60000BE)\n  and:\n    optional:\n      match: create or open registry key @ token(0x60000BE)\n        or:\n          api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x60000BE)+0x66\n    or:\n      api: Microsoft.Win32.RegistryKey::DeleteValue @ token(0x60000BE)+0x78\n\nget session integrity level\nnamespace  host-interaction/session                                     \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::System Owner/User Discovery [T1033]               \nfunction @ token(0x6000056)\n  or:\n    and:\n      api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x6000056)+0x0\n      number: 0x220 = BUILTIN\\Administrators @ token(0x6000056)+0xA\n      api: System.Security.Principal.WindowsPrincipal::IsInRole @ token(0x6000056)+0xF\n\nget session user name (3 matches)\nnamespace  host-interaction/session                                             \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope      function                                                             \natt&ck     Discovery::System Owner/User Discovery [T1033], Discovery::Account   \n           Discovery [T1087]                                                    \nfunction @ token(0x6000053)\n  or:\n    property/read: System.Environment::UserName @ token(0x6000053)+0x30\nfunction @ token(0x6000056)\n  or:\n    api: System.Security.Principal.WindowsIdentity::GetCurrent @ token(0x6000056)+0x0\nfunction @ token(0x600012C)\n  or:\n    property/read: System.Environment::UserName @ token(0x600012C)+0x16\n\ncreate thread (4 matches)\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ token(0x6000026) in function token(0x6000026)\n  or:\n    and:\n      api: System.Threading.Thread::Start @ token(0x6000026)+0x39C, token(0x6000026)+0x3D7, token(0x6000026)+0x3DD\n      optional:\n        api: System.Threading.Thread::ctor @ token(0x6000026)+0x397, token(0x6000026)+0x3BE, token(0x6000026)+0x3D0\nbasic block @ token(0x600008F) in function token(0x600008F)\n  or:\n    and:\n      api: System.Threading.Thread::Start @ token(0x600008F)+0x2D0, token(0x600008F)+0x353\n      optional:\n        api: System.Threading.Thread::ctor @ token(0x600008F)+0x2BE, token(0x600008F)+0x341\nbasic block @ token(0x6000093) in function token(0x6000093)\n  or:\n    and:\n      api: System.Threading.Thread::Start @ token(0x6000093)+0x92\n      optional:\n        api: System.Threading.Thread::ctor @ token(0x6000093)+0x89\nbasic block @ token(0x60000C4) in function token(0x60000C4)\n  or:\n    and:\n      api: System.Threading.Thread::Start @ token(0x60000C4)+0x1C\n      optional:\n        api: System.Threading.Thread::ctor @ token(0x60000C4)+0xD\n\nsuspend thread (8 matches)\nnamespace  host-interaction/thread/suspend                    \nauthor     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\nscope      basic block                                        \nmbc        Process::Suspend Thread [C0055]                    \nbasic block @ token(0x6000026) in function token(0x6000026)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000026)+0xB, token(0x6000026)+0x151\nbasic block @ token(0x6000032) in function token(0x6000032)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000032)+0x16\nbasic block @ token(0x6000093) in function token(0x6000093)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000093)+0xA8\nbasic block @ token(0x6000094) in function token(0x6000094)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000094)+0xD3\nbasic block @ token(0x6000099) in function token(0x6000099)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000099)+0x28\nbasic block @ token(0x60000BC) in function token(0x60000BC)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x60000BC)+0x8E\nbasic block @ token(0x60000C6) in function token(0x60000C6)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x60000C6)+0x748\nbasic block @ token(0x6000124) in function token(0x6000124)\n  or:\n    api: System.Threading.Thread::Sleep @ token(0x6000124)+0x7\n\nexecute via timer in .NET\nnamespace  host-interaction/thread/timer\nauthor     michael.hunhoff@mandiant.com \nscope      function                     \nfunction @ token(0x6000052)\n  or:\n    api: System.Threading.Timer::ctor @ token(0x6000052)+0xE9, token(0x6000052)+0x102\n\naccess WMI data in .NET (2 matches)\nnamespace  host-interaction/wmi                                 \nauthor     michael.hunhoff@mandiant.com                         \nscope      function                                             \natt&ck     Execution::Windows Management Instrumentation [T1047]\nfunction @ token(0x6000057)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000057)+0x26\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000057)+0x19\nfunction @ token(0x6000058)\n  or:\n    and:\n      api: System.Management.ManagementObjectSearcher::Get @ token(0x6000058)+0x19\n      optional:\n        api: System.Management.ManagementObjectSearcher::ctor @ token(0x6000058)+0x12\n\n(internal) .NET file limitation\nnamespace    internal/limitation/dynamic                        \nauthor       @v1bh475u                                          \nscope        file                                               \ndescription  This dynamic analysis trace describes a .NET file. \n                                                                \n             capa rules are not yet tuned for the .NET runtime, \n             so its analysis may be incomplete or misleading.   \n                                                                \nor:\n  format: dotnet\n\ninvoke .NET assembly method\nnamespace  load-code/dotnet                                     \nauthor     anushka.virgaonkar@mandiant.com, mehunhoff@google.com\nscope      function                                             \natt&ck     Defense Evasion::Reflective Code Loading [T1620]     \nfunction @ token(0x600009A)\n  and:\n    format: dotnet\n    or:\n      api: System.Reflection.MethodBase::Invoke @ token(0x600009A)+0x44\n\nload .NET assembly (2 matches)\nnamespace  load-code/dotnet                                \nauthor     anushka.virgaonkar@mandiant.com                 \nscope      function                                        \natt&ck     Defense Evasion::Reflective Code Loading [T1620]\nfunction @ token(0x6000090)\n  or:\n    api: System.AppDomain::Load @ token(0x6000090)+0x6\nfunction @ token(0x600009A)\n  or:\n    api: System.AppDomain::Load @ token(0x600009A)+0x6\n\npersist via lnk shortcut (3 matches)\nnamespace   persistence/file-system                                             \nauthor      j.j.vannielen@utwente.nl                                            \nscope       function                                                            \natt&ck      Persistence::Boot or Logon Autostart Execution::Shortcut            \n            Modification [T1547.009]                                            \nreferences  https://www.ired.team/offensive-security/persistence/modifying-.lnk…\nfunction @ token(0x6000026)\n  and:\n    regex: /\\.lnk$/i\n      - \".lnk\" @ token(0x6000026)+0x292\n    or:\n      match: write file on Windows @ token(0x6000026)\n        or:\n          api: System.IO.File::WriteAllBytes @ token(0x6000026)+0x161\nfunction @ token(0x60000BE)\n  and:\n    regex: /\\.lnk$/i\n      - \"*.lnk\" @ token(0x60000BE)+0x1B0\n      - \".lnk\" @ token(0x60000BE)+0xFE\n    or:\n      match: write file on Windows @ token(0x60000BE)\n        or:\n          api: System.IO.File::WriteAllBytes @ token(0x60000BE)+0x1D\nfunction @ token(0x60000C6)\n  and:\n    regex: /\\.lnk$/i\n      - \" .lnk\" @ token(0x60000C6)+0x4B7, token(0x60000C6)+0x61C\n      - \".lnk\" @ token(0x60000C6)+0x12A, token(0x60000C6)+0x198, token(0x60000C6)+0x364\n    or:\n      match: write file on Windows @ token(0x60000C6)\n        or:\n          api: System.IO.File::WriteAllBytes @ token(0x60000C6)+0xE5\n\npersist via Run registry key (2 matches)\nnamespace  persistence/registry/run                                             \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com                      \nscope      function                                                             \natt&ck     Persistence::Boot or Logon Autostart Execution::Registry Run Keys /  \n           Startup Folder [T1547.001]                                           \nmbc        Persistence::Registry Run Keys / Startup Folder [F0012]              \nfunction @ token(0x6000026)\n  and:\n    or:\n      match: set registry value @ token(0x6000026)\n        or:\n          and:\n            optional:\n              match: create or open registry key @ token(0x6000026)\n                or:\n                  api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000026)+0x257\n            or:\n              api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000026)+0x267\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\" @ token(0x6000026)+0x251\nfunction @ token(0x6000026)\n  and:\n    or:\n      match: set registry value @ token(0x6000026)\n        or:\n          and:\n            optional:\n              match: create or open registry key @ token(0x6000026)\n                or:\n                  api: Microsoft.Win32.RegistryKey::OpenSubKey @ token(0x6000026)+0x257\n            or:\n              api: Microsoft.Win32.RegistryKey::SetValue @ token(0x6000026)+0x267\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\" @ token(0x6000026)+0x251\n\nschedule task via schtasks (4 matches)\nnamespace   persistence/scheduled-tasks                                         \nauthor      0x534a@mailbox.org, j.j.vannielen@utwente.nl                        \nscope       function                                                            \natt&ck      Persistence::Scheduled Task/Job::Scheduled Task [T1053.005]         \nreferences  https://learn.microsoft.com/en-us/windows/win32/taskschd/task-sched…\n            https://stmxcsr.com/persistence/scheduled-tasks.html                \nfunction @ token(0x6000026)\n  or:\n    and:\n      match: host-interaction/process/create @ token(0x6000026)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x6000026)+0x223\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x6000026)+0x223\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000026)+0x186\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000026)+0x1D6, token(0x6000026)+0x21C\n      or:\n        and:\n          regex: /schtasks/i\n            - \"schtasks.exe\" @ token(0x6000026)+0x177\n          or:\n            regex: /\\/create/i\n              - \"/create /f /RL HIGHEST /sc minute /mo 1 /tn \\\"\" @ token(0x6000026)+0x1A4\n              - \"/create /f /sc minute /mo 1 /tn \\\"\" @ token(0x6000026)+0x1EA\nfunction @ token(0x6000026)\n  or:\n    and:\n      match: host-interaction/process/create @ token(0x6000026)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x6000026)+0x223\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x6000026)+0x223\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000026)+0x186\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000026)+0x1D6, token(0x6000026)+0x21C\n      or:\n        and:\n          regex: /schtasks/i\n            - \"schtasks.exe\" @ token(0x6000026)+0x177\n          or:\n            regex: /\\/create/i\n              - \"/create /f /RL HIGHEST /sc minute /mo 1 /tn \\\"\" @ token(0x6000026)+0x1A4\n              - \"/create /f /sc minute /mo 1 /tn \\\"\" @ token(0x6000026)+0x1EA\nfunction @ token(0x6000026)\n  or:\n    and:\n      match: host-interaction/process/create @ token(0x6000026)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x6000026)+0x223\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x6000026)+0x223\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000026)+0x186\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000026)+0x1D6, token(0x6000026)+0x21C\n      or:\n        and:\n          regex: /schtasks/i\n            - \"schtasks.exe\" @ token(0x6000026)+0x177\n          or:\n            regex: /\\/create/i\n              - \"/create /f /RL HIGHEST /sc minute /mo 1 /tn \\\"\" @ token(0x6000026)+0x1A4\n              - \"/create /f /sc minute /mo 1 /tn \\\"\" @ token(0x6000026)+0x1EA\nfunction @ token(0x6000026)\n  or:\n    and:\n      match: host-interaction/process/create @ token(0x6000026)\n        or:\n          api: System.Diagnostics.Process::Start @ token(0x6000026)+0x223\n        or:\n          and:\n            api: System.Diagnostics.Process::Start @ token(0x6000026)+0x223\n            or:\n              property/write: System.Diagnostics.ProcessStartInfo::WindowStyle @ token(0x6000026)+0x186\n              property/write: System.Diagnostics.ProcessStartInfo::Arguments @ token(0x6000026)+0x1D6, token(0x6000026)+0x21C\n      or:\n        and:\n          regex: /schtasks/i\n            - \"schtasks.exe\" @ token(0x6000026)+0x177\n          or:\n            regex: /\\/create/i\n              - \"/create /f /RL HIGHEST /sc minute /mo 1 /tn \\\"\" @ token(0x6000026)+0x1A4\n              - \"/create /f /sc minute /mo 1 /tn \\\"\" @ token(0x6000026)+0x1EA\n\nunmanaged call (13 matches)\nnamespace    runtime                                                       \nauthor       michael.hunhoff@mandiant.com                                  \nscope        function                                                      \ndescription  managed code calls unmanaged (native) code, often seen in .NET\nfunction @ token(0x600002C)\n  or:\n    characteristic: unmanaged call @ token(0x600002C)+0xE\nfunction @ token(0x600002D)\n  or:\n    characteristic: unmanaged call @ token(0x600002D)+0x5\nfunction @ token(0x600008F)\n  or:\n    characteristic: unmanaged call @ token(0x600008F)+0x640\nfunction @ token(0x6000098)\n  or:\n    characteristic: unmanaged call @ token(0x6000098)+0x17\nfunction @ token(0x60000D2)\n  or:\n    characteristic: unmanaged call @ token(0x60000D2)+0x12, token(0x60000D2)+0x18\nfunction @ token(0x60000D3)\n  or:\n    characteristic: unmanaged call @ token(0x60000D3)+0x2B, token(0x60000D3)+0x47, token(0x60000D3)+0x5A, \ntoken(0x60000D3)+0x2CF\nfunction @ token(0x60000D4)\n  or:\n    characteristic: unmanaged call @ token(0x60000D4)+0x1B, token(0x60000D4)+0x2C, token(0x60000D4)+0x38, \ntoken(0x60000D4)+0x3F, and 2 more...\nfunction @ token(0x60000D5)\n  or:\n    characteristic: unmanaged call @ token(0x60000D5)+0x2, token(0x60000D5)+0xB\nfunction @ token(0x600010C)\n  or:\n    characteristic: unmanaged call @ token(0x600010C)+0x1A\nfunction @ token(0x600010D)\n  or:\n    characteristic: unmanaged call @ token(0x600010D)+0x4\nfunction @ token(0x6000123)\n  or:\n    characteristic: unmanaged call @ token(0x6000123)+0x2A\nfunction @ token(0x6000128)\n  or:\n    characteristic: unmanaged call @ token(0x6000128)+0x5\nfunction @ token(0x6000129)\n  or:\n    characteristic: unmanaged call @ token(0x6000129)+0xB, token(0x6000129)+0x18\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  format: dotnet\n\n\n\n"},"hashes":{"md5":"179e5c88bbd34e45830e7ee3610d5216","sha1":"e6fa8fda487392419be240e2911e7c9c346b750c","sha256":"0aac658075b7d9e81419d0beaa3db796569bc14fd57512f4479fb36e9cc4c1a2"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 340</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 8151</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"xworm-0\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"179e5c88bbd34e45830e7ee3610d5216\",\n        \"sha256\": \"0aac658075b7d9e81419d0beaa3db796569bc14fd57512f4479fb36\",\n        \"arch\": \"any\",\n        \"os\": \"any\",\n        \"format\": \"dotnet\"\n      }\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_Microsoft\",\n      \"label\": \"Microsoft\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_reference_analysis_tools_strings\",\n      \"label\": \"reference analysis tools strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_for_sandbox_and_av_modules\",\n      \"label\": \"check for sandbox and av modules\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\",\n        \"Anti-Behavioral Analysis::Sandbox Detection [B0007]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetModuleHandle\",\n      \"label\": \"GetModuleHandle\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox\",\n      \"label\": \"author     @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\",\n        \"Anti-Behavioral Analysis::Sandbox Detection [B0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_for_debugger_via_api\",\n      \"label\": \"check for debugger via API\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger\",\n        \"Detection::CheckRemoteDebuggerPresent [B0001.002]\",\n        \"Anti-Behavioral\",\n        \"Analysis::Debugger Detection::WudfIsAnyDebuggerPresent [B0001.031]\"\n      ]\n    },\n    {\n      \"id\": \"api_CheckRemoteDebuggerPresent\",\n      \"label\": \"CheckRemoteDebuggerPresent\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger\",\n        \"Detection::CheckRemoteDebuggerPresent [B0001.002]\",\n        \"Anti-Behavioral\",\n        \"Analysis::Debugger Detection::WudfIsAnyDebuggerPresent [B0001.031]\"\n      ]\n    },\n    {\n      \"id\": \"cap_self_delete__2_matches_\",\n      \"label\": \"self delete (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_System\",\n      \"label\": \"System\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_vmware\",\n      \"label\": \"reference anti-VM strings targeting VMWare\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com___johnk3r\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, @johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_virtualbox\",\n      \"label\": \"reference anti-VM strings targeting VirtualBox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_save_image_in__net\",\n      \"label\": \"save image in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_reference_wmi_statements\",\n      \"label\": \"reference WMI statements\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Data from Information Repositories [T1213]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes\",\n      \"label\": \"log keystrokes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_MapVirtualKey\",\n      \"label\": \"MapVirtualKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"label\": \"log keystrokes via polling (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetKeyboardState\",\n      \"label\": \"GetKeyboardState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetKeyState\",\n      \"label\": \"GetKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_capture_screenshot\",\n      \"label\": \"capture screenshot\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_data__4_matches_\",\n      \"label\": \"receive data (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data__2_matches_\",\n      \"label\": \"send data (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_download_and_write_a_file\",\n      \"label\": \"download and write a file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"downloader\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Server to Client\",\n        \"File Transfer [B0030.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_maec_malware_category__downloader\",\n      \"label\": \"maec/malware-category  downloader\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"downloader\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Server to Client\",\n        \"File Transfer [B0030.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_and_write_data_from_server_to_client\",\n      \"label\": \"receive and write data from server to client\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_write_and_execute_a_file__4_matches_\",\n      \"label\": \"write and execute a file (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_maec_malware_category__launcher\",\n      \"label\": \"maec/malware-category  launcher\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_resolve_dns\",\n      \"label\": \"resolve DNS\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::DNS Communication::Resolve [C0011.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::DNS Communication::Resolve [C0011.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_http_user_agent_string\",\n      \"label\": \"reference HTTP User-Agent string\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication [C0002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______mr_tz\",\n      \"label\": \"author      @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication [C0002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_http_request_with_host_header\",\n      \"label\": \"send HTTP request with Host header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____anamaria_martinezgom_mandiant_com\",\n      \"label\": \"author     anamaria.martinezgom@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_set_http_user_agent_in__net\",\n      \"label\": \"set HTTP User-Agent in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_http_request\",\n      \"label\": \"create HTTP request\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_download_url\",\n      \"label\": \"download URL\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Download URL [C0002.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Download URL [C0002.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_data_from_internet\",\n      \"label\": \"read data from Internet\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_http_request\",\n      \"label\": \"send HTTP request\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Send Request [C0002.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Send Request [C0002.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_data_on_socket__2_matches_\",\n      \"label\": \"receive data on socket (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Receive Data [C0001.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data_on_socket\",\n      \"label\": \"send data on socket\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_tcp_socket__2_matches_\",\n      \"label\": \"create TCP socket (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_udp_socket__2_matches_\",\n      \"label\": \"create UDP socket (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create UDP Socket [C0001.010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_compress_data_using_gzip_in__net__2_matches_\",\n      \"label\": \"compress data using GZip in .NET (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Compress Data [C0024]\"\n      ]\n    },\n    {\n      \"id\": \"cap_decode_data_using_base64_in__net__3_matches_\",\n      \"label\": \"decode data using Base64 in .NET (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decode Data::Base64 [C0053.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encode_data_using_base64\",\n      \"label\": \"encode data using Base64\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_with_md5__4_matches_\",\n      \"label\": \"hash data with MD5 (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Cryptographic Hash::MD5 [C0029.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_in__net__6_matches_\",\n      \"label\": \"generate random numbers in .NET (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable\",\n      \"label\": \"query environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_file_extension_in__net\",\n      \"label\": \"check file extension in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_enumerate_drives__2_matches_\",\n      \"label\": \"enumerate drives (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_generate_random_filename_in__net\",\n      \"label\": \"generate random filename in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__4_matches_\",\n      \"label\": \"get common file path (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_directory\",\n      \"label\": \"create directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_file\",\n      \"label\": \"delete file\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_directory_exists\",\n      \"label\": \"check if directory exists\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__4_matches_\",\n      \"label\": \"check if file exists (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_in__net__2_matches_\",\n      \"label\": \"enumerate files in .NET (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_file_attributes\",\n      \"label\": \"set file attributes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__3_matches_\",\n      \"label\": \"read file on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__5_matches_\",\n      \"label\": \"write file on Windows (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_application_hook\",\n      \"label\": \"set application hook\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_SetWindowsHookEx\",\n      \"label\": \"SetWindowsHookEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_graphical_window_text\",\n      \"label\": \"get graphical window text\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetWindowText\",\n      \"label\": \"GetWindowText\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetForegroundWindow\",\n      \"label\": \"GetForegroundWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_number_of_processors\",\n      \"label\": \"get number of processors\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_keyboard_layout\",\n      \"label\": \"get keyboard layout\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery::System Language Discovery\",\n        \"[T1614.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetKeyboardLayout\",\n      \"label\": \"GetKeyboardLayout\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_information__2_matches_\",\n      \"label\": \"get disk information (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_disk_size\",\n      \"label\": \"get disk size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_manipulate_unmanaged_memory_in__net__2_matches_\",\n      \"label\": \"manipulate unmanaged memory in .NET (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_or_open_mutex_on_windows\",\n      \"label\": \"create or open mutex on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_mehunhoff_google_com\",\n      \"label\": \"mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_hostname__2_matches_\",\n      \"label\": \"get hostname (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_os_version_in__net__3_matches_\",\n      \"label\": \"get OS version in .NET (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_process_image_filename\",\n      \"label\": \"get process image filename\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_a_process_with_modified_i_o_handles_and_window__4_matches_\",\n      \"label\": \"create a process with modified I/O handles and window (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__6_matches_\",\n      \"label\": \"create process on Windows (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_processes\",\n      \"label\": \"enumerate processes\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\",\n        \"Discovery::Software Discovery\",\n        \"[T1518]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_process_by_pid\",\n      \"label\": \"find process by PID\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enter_debug_mode_in__net\",\n      \"label\": \"enter debug mode in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author________v1bh475u\",\n      \"label\": \"author       @v1bh475u\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_terminate_process__4_matches_\",\n      \"label\": \"terminate process (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key__3_matches_\",\n      \"label\": \"query or enumerate registry key (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"label\": \"query or enumerate registry value (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_registry_value__4_matches_\",\n      \"label\": \"set registry value (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_key\",\n      \"label\": \"delete registry key\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_value\",\n      \"label\": \"delete registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_session_integrity_level\",\n      \"label\": \"get session integrity level\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_session_user_name__3_matches_\",\n      \"label\": \"get session user name (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\",\n        \"Discovery::Account\",\n        \"Discovery [T1087]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_thread__4_matches_\",\n      \"label\": \"create thread (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_suspend_thread__8_matches_\",\n      \"label\": \"suspend thread (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Suspend Thread [C0055]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Suspend Thread [C0055]\"\n      ]\n    },\n    {\n      \"id\": \"cap_execute_via_timer_in__net\",\n      \"label\": \"execute via timer in .NET\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_access_wmi_data_in__net__2_matches_\",\n      \"label\": \"access WMI data in .NET (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Windows Management Instrumentation [T1047]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal___net_file_limitation\",\n      \"label\": \"(internal) .NET file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_invoke__net_assembly_method\",\n      \"label\": \"invoke .NET assembly method\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_load__net_assembly__2_matches_\",\n      \"label\": \"load .NET assembly (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_persist_via_lnk_shortcut__3_matches_\",\n      \"label\": \"persist via lnk shortcut (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______j_j_vannielen_utwente_nl\",\n      \"label\": \"author      j.j.vannielen@utwente.nl\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_persist_via_run_registry_key__2_matches_\",\n      \"label\": \"persist via Run registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Registry Run Keys / Startup Folder [F0012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Registry Run Keys / Startup Folder [F0012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_schedule_task_via_schtasks__4_matches_\",\n      \"label\": \"schedule task via schtasks (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Scheduled Task/Job::Scheduled Task [T1053.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______0x534a_mailbox_org__j_j_vannielen_utwente_nl\",\n      \"label\": \"author      0x534a@mailbox.org, j.j.vannielen@utwente.nl\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Scheduled Task/Job::Scheduled Task [T1053.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_unmanaged_call__13_matches_\",\n      \"label\": \"unmanaged call (13 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"label\": \"author       michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compiled_to_the__net_platform\",\n      \"label\": \"compiled to the .NET platform\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_analysis_tools_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_sandbox_and_av_modules\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_debugger_via_api\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_self_delete__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_vmware\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com___johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_virtualbox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_save_image_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_wmi_statements\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_polling__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_capture_screenshot\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_download_and_write_a_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_maec_malware_category__downloader\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_and_write_data_from_server_to_client\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_and_execute_a_file__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_maec_malware_category__launcher\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_dns\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_http_user_agent_string\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_http_request_with_host_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anamaria_martinezgom_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_http_user_agent_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_http_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_download_url\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_data_from_internet\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_http_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data_on_socket__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data_on_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_tcp_socket__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_udp_socket__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compress_data_using_gzip_in__net__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decode_data_using_base64_in__net__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encode_data_using_base64\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_md5__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_in__net__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_file_extension_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_drives__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_filename_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_directory_exists\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_in__net__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_application_hook\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_graphical_window_text\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_number_of_processors\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_keyboard_layout\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_manipulate_unmanaged_memory_in__net__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_mutex_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version_in__net__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_process_image_filename\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_a_process_with_modified_i_o_handles_and_window__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_processes\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_process_by_pid\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enter_debug_mode_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________v1bh475u\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_key\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_integrity_level\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_user_name__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_suspend_thread__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_execute_via_timer_in__net\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_wmi_data_in__net__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal___net_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_invoke__net_assembly_method\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_load__net_assembly__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_persist_via_lnk_shortcut__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______j_j_vannielen_utwente_nl\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_persist_via_run_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_schedule_task_via_schtasks__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______0x534a_mailbox_org__j_j_vannielen_utwente_nl\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_unmanaged_call__13_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_to_the__net_platform\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_and_execute_a_file__4_matches_\",\n      \"target\": \"cap_execute_via_timer_in__net\",\n      \"relationship\": \"depends_on\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-19 13:41:05.648289\",\n    \"total_functions\": \"340\",\n    \"total_features\": \"8151\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-19 13:41:06"}
{"_id":{"$oid":"6a5c8a05b3bed57e0e737898"},"sha256":"64fa25e0e80a527b9caec41f68d96f696ca41467ab4e5edefc1bf1795ee3ffad","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_ike8dm7t/002_overlay_carved_pe_0.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_ike8dm7t/002_overlay_carved_pe_0.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_ike8dm7t/002_overlay_carved_pe_0.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ a087f5992eda1732d0a32d2742298df2                                  │\n│ sha1     │ bfb9e0f64b88b12fc864ed255799fb457f998f4c                          │\n│ sha256   │ 4ff1ec66b9f9d6248e499db145f254d49db9f9dd3df4273ba2d32c48a8e8cffb  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /tmp/sdm_unpack_nopzmtin/wanna_cry-019f7976bdb175e2a6a998210b4d3… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Indicator Removal    │\n│                      │ from Tools [T1027.005]                                │\n│ DISCOVERY            │ File and Directory Discovery [T1083]                  │\n│                      │ System Information Discovery [T1082]                  │\n│                      │ System Network Configuration Discovery [T1016]        │\n│ EXECUTION            │ Shared Modules [T1129]                                │\n│                      │ System Services::Service Execution [T1569.002]        │\n│ PERSISTENCE          │ Create or Modify System Process::Windows Service      │\n│                      │ [T1543.003]                                           │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Conditional Execution::Runs as Service            │\n│                          │ [B0025.007]                                       │\n│                          │ Debugger Detection::Timing/Delay Check            │\n│                          │ QueryPerformanceCounter [B0001.033]               │\n│ ANTI-STATIC ANALYSIS     │ Executable Code Obfuscation::Argument Obfuscation │\n│                          │ [B0032.020]                                       │\n│                          │ Executable Code Obfuscation::Stack Strings        │\n│                          │ [B0032.017]                                       │\n│ COMMAND AND CONTROL      │ C2 Communication::Receive Data [B0030.002]        │\n│                          │ C2 Communication::Send Data [B0030.001]           │\n│ COMMUNICATION            │ HTTP Communication::Create Request [C0002.012]    │\n│                          │ HTTP Communication::Open URL [C0002.004]          │\n│                          │ Socket Communication::Connect Socket [C0001.004]  │\n│                          │ Socket Communication::Create TCP Socket           │\n│                          │ [C0001.011]                                       │\n│                          │ Socket Communication::Create UDP Socket           │\n│                          │ [C0001.010]                                       │\n│                          │ Socket Communication::Get Socket Status           │\n│                          │ [C0001.012]                                       │\n│                          │ Socket Communication::Initialize Winsock Library  │\n│                          │ [C0001.009]                                       │\n│                          │ Socket Communication::Receive Data [C0001.006]    │\n│                          │ Socket Communication::Send Data [C0001.007]       │\n│                          │ Socket Communication::Set Socket Config           │\n│                          │ [C0001.001]                                       │\n│                          │ Socket Communication::TCP Client [C0001.008]      │\n│                          │ Socket Communication::UDP Client [C0001.013]      │\n│ CRYPTOGRAPHY             │ Generate Pseudo-random Sequence::Use API          │\n│                          │ [C0021.003]                                       │\n│ DISCOVERY                │ Code Discovery::Inspect Section Memory            │\n│                          │ Permissions [B0046.002]                           │\n│                          │ File and Directory Discovery [E1083]              │\n│ FILE SYSTEM              │ Move File [C0063]                                 │\n│                          │ Read File [C0051]                                 │\n│ PROCESS                  │ Create Thread [C0038]                             │\n│                          │ Terminate Process [C0018]                         │\n│                          │ Terminate Thread [C0039]                          │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ check for time delay via              │ anti-analysis/anti-debugging/debugg… │\n│ QueryPerformanceCounter               │                                      │\n│ contain obfuscated stackstrings       │ anti-analysis/obfuscation/string/st… │\n│ receive data (5 matches)              │ communication                        │\n│ send data (5 matches)                 │ communication                        │\n│ connect to URL                        │ communication/http/client            │\n│ create HTTP request                   │ communication/http/client            │\n│ get socket status                     │ communication/socket                 │\n│ initialize Winsock library            │ communication/socket                 │\n│ set socket configuration              │ communication/socket                 │\n│ connect UDP socket (3 matches)        │ communication/socket/udp             │\n│ act as TCP client (4 matches)         │ communication/tcp/client             │\n│ generate random numbers via WinAPI    │ data-manipulation/prng               │\n│ extract resource via kernel32         │ executable/resource                  │\n│ functions                             │                                      │\n│ get file size                         │ host-interaction/file-system/meta    │\n│ move file                             │ host-interaction/file-system/move    │\n│ read file on Windows                  │ host-interaction/file-system/read    │\n│ get number of processors              │ host-interaction/hardware/cpu        │\n│ terminate process                     │ host-interaction/process/terminate   │\n│ run as service                        │ host-interaction/service             │\n│ create service                        │ host-interaction/service/create      │\n│ modify service                        │ host-interaction/service/modify      │\n│ start service                         │ host-interaction/service/start       │\n│ create thread (4 matches)             │ host-interaction/thread/create       │\n│ terminate thread                      │ host-interaction/thread/terminate    │\n│ link function at runtime on Windows   │ linking/runtime-linking              │\n│ (4 matches)                           │                                      │\n│ inspect section memory permissions    │ load-code/pe                         │\n│ persist via Windows service           │ persistence/service                  │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     a087f5992eda1732d0a32d2742298df2                        \nsha1                    bfb9e0f64b88b12fc864ed255799fb457f998f4c                \nsha256                  4ff1ec66b9f9d6248e499db145f254d49db9f9dd3df4273ba2d32c4…\npath                    /tmp/sdm_unpack_nopzmtin/wanna_cry-019f7976bdb175e2a6a9…\ntimestamp               2026-07-19 13:55:31.670259                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIIaQ0LU/rules                                   \nfunction count          82                                                      \nlibrary function count  5                                                       \ntotal feature count     10314                                                   \n\ncheck for time delay via QueryPerformanceCounter\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    0x401660                                       \n\ncontain obfuscated stackstrings\nnamespace  anti-analysis/obfuscation/string/stackstring\nscope      basic block                                 \nmatches    0x401D80                                    \n\nreceive data (5 matches)\nnamespace    communication                                                     \ndescription  all known techniques for receiving data from a potential C2 server\nscope        function                                                          \nmatches      0x401370                                                          \n             0x401980                                                          \n             0x401B70                                                          \n             0x406F50                                                          \n             0x4072A0                                                          \n\nsend data (5 matches)\nnamespace    communication                                                 \ndescription  all known techniques for sending data to a potential C2 server\nscope        function                                                      \nmatches      0x401370                                                      \n             0x401980                                                      \n             0x401B70                                                      \n             0x406F50                                                      \n             0x4072A0                                                      \n\nconnect to URL\nnamespace  communication/http/client\nscope      instruction              \nmatches    0x408194                 \n\ncreate HTTP request\nnamespace  communication/http/client\nscope      function                 \nmatches    0x408140                 \n\nconnect socket (5 matches)\nnamespace    communication/socket                                               \ndescription  Detects socket connection attempts using common APIs or ConnectEx  \n             setup.                                                             \nscope        basic block                                                        \nmatches      0x401470                                                           \n             0x4019DD                                                           \n             0x401BCE                                                           \n             0x4072FE                                                           \n             0x4074E1                                                           \n\nget socket status\nnamespace  communication/socket\nscope      function            \nmatches    0x407480            \n\ninitialize Winsock library\nnamespace  communication/socket\nscope      function            \nmatches    0x407B90            \n\nset socket configuration\nnamespace  communication/socket\nscope      function            \nmatches    0x407480            \n\nreceive data on socket (5 matches)\nnamespace  communication/socket/receive\nscope      function                    \nmatches    0x401370                    \n           0x401980                    \n           0x401B70                    \n           0x406F50                    \n           0x4072A0                    \n\nsend data on socket (5 matches)\nnamespace  communication/socket/send\nscope      function                 \nmatches    0x401370                 \n           0x401980                 \n           0x401B70                 \n           0x406F50                 \n           0x4072A0                 \n\nconnect TCP socket (4 matches)\nnamespace  communication/socket/tcp\nscope      function                \nmatches    0x401980                \n           0x401B70                \n           0x4072A0                \n           0x407480                \n\ncreate TCP socket (4 matches)\nnamespace  communication/socket/tcp\nscope      basic block             \nmatches    0x401980                \n           0x401B70                \n           0x4072A0                \n           0x407480                \n\nconnect UDP socket (3 matches)\nnamespace    communication/socket/udp                                           \ndescription  Detects UDP socket connections by combining UDP socket creation    \n             with connection attempts.                                          \nscope        function                                                           \nmatches      0x401980                                                           \n             0x401B70                                                           \n             0x4072A0                                                           \n\ncreate UDP socket (3 matches)\nnamespace  communication/socket/udp/send\nscope      basic block                  \nmatches    0x401980                     \n           0x401B70                     \n           0x4072A0                     \n\nact as TCP client (4 matches)\nnamespace  communication/tcp/client\nscope      function                \nmatches    0x401980                \n           0x401B70                \n           0x4072A0                \n           0x407480                \n\ngenerate random numbers via WinAPI\nnamespace  data-manipulation/prng\nscope      function              \nmatches    0x407660              \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x407CE0           \n\nget file size\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x407A20                         \n\nmove file\nnamespace  host-interaction/file-system/move\nscope      function                         \nmatches    0x407CE0                         \n\nread file on Windows\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x407A20                         \n\nget number of processors\nnamespace  host-interaction/hardware/cpu\nscope      function                     \nmatches    0x407720                     \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x408000                          \n\nrun as service\nnamespace  host-interaction/service\nscope      file                    \n\ncreate service\nnamespace  host-interaction/service/create\nscope      function                       \nmatches    0x407C40                       \n\nmodify service\nnamespace  host-interaction/service/modify\nscope      function                       \nmatches    0x407FA0                       \n\nstart service\nnamespace  host-interaction/service/start\nscope      function                      \nmatches    0x407C40                      \n\ncreate thread (4 matches)\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x4076C2                      \n           0x4077C3                      \n           0x407BDA                      \n           0x407C0D                      \n\nterminate thread\nnamespace  host-interaction/thread/terminate\nscope      basic block                      \nmatches    0x4076F2                         \n\nlink function at runtime on Windows (4 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x407D0D               \n           0x407D1A               \n           0x407D27               \n           0x407D34               \n\ninspect section memory permissions\nnamespace    load-code/pe                                                       \ndescription  translate section memory permissions (specified in the             \n             'Characteristics' field of the image section header) into page     \n             protection constants                                               \nscope        function                                                           \nmatches      0x401D80                                                           \n\npersist via Windows service\nnamespace  persistence/service\nscope      function           \nmatches    0x407C40           \n\n\n\n","very_verbose":"md5                     a087f5992eda1732d0a32d2742298df2                        \nsha1                    bfb9e0f64b88b12fc864ed255799fb457f998f4c                \nsha256                  4ff1ec66b9f9d6248e499db145f254d49db9f9dd3df4273ba2d32c4…\npath                    /tmp/sdm_unpack_nopzmtin/wanna_cry-019f7976bdb175e2a6a9…\ntimestamp               2026-07-19 13:55:40.917743                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIJtvzBP/rules                                   \nfunction count          82                                                      \nlibrary function count  5                                                       \ntotal feature count     10314                                                   \n\nPEB access (2 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Debugger Detection::Process Environment   \n            Block [B0001.019]                                                   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nbasic block @ 0x407720 in function 0x407720\n  or:\n    and:\n      arch: i386\n      characteristic: fs access @ 0x407727, 0x40772E\n      or:\n        offset: 0x30 @ 0x40774E\n\ncalculate modulo 256 via x86 assembly (library rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x408E87\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x408E87\n    or:\n      number: 0xFF @ 0x408E87\n\ncontain loop (27 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401055\n  or:\n    characteristic: tight loop @ 0x40107F, 0x4010C6\n\ncreate or open file (library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x407AE3\n  or:\n    api: CreateFile @ 0x407AE3\n\ndelay execution (12 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x401640 in function 0x401370\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x40164A\n\nget service handle (2 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x407C40\n  or:\n    api: CreateService @ 0x407C9B\n\ncheck for time delay via QueryPerformanceCounter\nnamespace  anti-analysis/anti-debugging/debugger-detection                      \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check     \n           QueryPerformanceCounter [B0001.033]                                  \nfunction @ 0x401660\n  and:\n    count(api(QueryPerformanceCounter)): 2 or more @ 0x40174A, 0x401777, 0x401790\n\ncontain obfuscated stackstrings\nnamespace  anti-analysis/obfuscation/string/stackstring                         \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information::Indicator Removal  \n           from Tools [T1027.005]                                               \nmbc        Anti-Static Analysis::Executable Code Obfuscation::Argument          \n           Obfuscation [B0032.020], Anti-Static Analysis::Executable Code       \n           Obfuscation::Stack Strings [B0032.017]                               \nbasic block @ 0x401D80 in function 0x401D80\n  characteristic: stack string @ 0x401D80\n\nreceive data (5 matches)\nnamespace    communication                                                     \nauthor       william.ballenthin@mandiant.com                                   \nscope        function                                                          \nmbc          Command and Control::C2 Communication::Receive Data [B0030.002]   \ndescription  all known techniques for receiving data from a potential C2 server\nfunction @ 0x401370\n  or:\n    match: receive data on socket @ 0x401370\n      or:\n        api: recv @ 0x4015A4\nfunction @ 0x401980\n  or:\n    match: receive data on socket @ 0x401980\n      or:\n        api: recv @ 0x401A18, 0x401A4B, 0x401A9B, 0x401B15\nfunction @ 0x401B70\n  or:\n    match: receive data on socket @ 0x401B70\n      or:\n        api: recv @ 0x401C0C, 0x401C42, 0x401C8D, 0x401CE3, and 1 more...\nfunction @ 0x406F50\n  or:\n    match: receive data on socket @ 0x406F50\n      or:\n        api: recv @ 0x407194, 0x407282\nfunction @ 0x4072A0\n  or:\n    match: receive data on socket @ 0x4072A0\n      or:\n        api: recv @ 0x40733C, 0x407372, 0x4073BC, 0x407425\n\nsend data (5 matches)\nnamespace    communication                                                 \nauthor       william.ballenthin@mandiant.com, joakim@intezer.com           \nscope        function                                                      \nmbc          Command and Control::C2 Communication::Send Data [B0030.001]  \ndescription  all known techniques for sending data to a potential C2 server\nfunction @ 0x401370\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x401370\n          or:\n            api: send @ 0x401552\nfunction @ 0x401980\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x401980\n          or:\n            api: send @ 0x4019FD, 0x401A30, 0x401A80, 0x401AFE\nfunction @ 0x401B70\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x401B70\n          or:\n            api: send @ 0x401BF1, 0x401C27, 0x401C72, 0x401CC8, and 1 more...\nfunction @ 0x406F50\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x406F50\n          or:\n            api: send @ 0x40717A, 0x407268\nfunction @ 0x4072A0\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x4072A0\n          or:\n            api: send @ 0x407321, 0x407357, 0x4073A1, 0x40740E\n\nconnect to URL\nnamespace  communication/http/client                              \nauthor     michael.hunhoff@mandiant.com                           \nscope      instruction                                            \nmbc        Communication::HTTP Communication::Open URL [C0002.004]\ninstruction @ 0x408194\n  and:\n    api: InternetOpenUrl @ 0x408194\n\ncreate HTTP request\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Create Request [C0002.012]\nfunction @ 0x408140\n  and:\n    optional:\n      api: InternetCloseHandle @ 0x4081A7, 0x4081AB\n    or:\n      api: InternetOpen @ 0x40817B\n\nconnect socket (5 matches)\nnamespace    communication/socket                                               \nauthor       moritz.raabe@mandiant.com, joakim@intezer.com,                     \n             mrhafizfarhad@gmail.com                                            \nscope        basic block                                                        \ndescription  Detects socket connection attempts using common APIs or ConnectEx  \n             setup.                                                             \nbasic block @ 0x401470 in function 0x401370\n  or:\n    api: connect @ 0x401478\nbasic block @ 0x4019DD in function 0x401980\n  or:\n    api: connect @ 0x4019E5\nbasic block @ 0x401BCE in function 0x401B70\n  or:\n    api: connect @ 0x401BD6\nbasic block @ 0x4072FE in function 0x4072A0\n  or:\n    api: connect @ 0x407306\nbasic block @ 0x4074E1 in function 0x407480\n  or:\n    api: connect @ 0x40750D\n\nget socket status\nnamespace  communication/socket                                              \nauthor     michael.hunhoff@mandiant.com                                      \nscope      function                                                          \natt&ck     Discovery::System Network Configuration Discovery [T1016]         \nmbc        Communication::Socket Communication::Get Socket Status [C0001.012]\nfunction @ 0x407480\n  or:\n    api: select @ 0x407522\n\ninitialize Winsock library\nnamespace  communication/socket                                                 \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Initialize Winsock Library      \n           [C0001.009]                                                          \nfunction @ 0x407B90\n  or:\n    api: WSAStartup @ 0x407BA0\n\nset socket configuration\nnamespace  communication/socket                                              \nauthor     michael.hunhoff@mandiant.com                                      \nscope      function                                                          \nmbc        Communication::Socket Communication::Set Socket Config [C0001.001]\nfunction @ 0x407480\n  or:\n    api: ioctlsocket @ 0x4074EC\n\nreceive data on socket (5 matches)\nnamespace  communication/socket/receive                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Receive Data [C0001.006]        \nfunction @ 0x401370\n  or:\n    api: recv @ 0x4015A4\nfunction @ 0x401980\n  or:\n    api: recv @ 0x401A18, 0x401A4B, 0x401A9B, 0x401B15\nfunction @ 0x401B70\n  or:\n    api: recv @ 0x401C0C, 0x401C42, 0x401C8D, 0x401CE3, and 1 more...\nfunction @ 0x406F50\n  or:\n    api: recv @ 0x407194, 0x407282\nfunction @ 0x4072A0\n  or:\n    api: recv @ 0x40733C, 0x407372, 0x4073BC, 0x407425\n\nsend data on socket (5 matches)\nnamespace  communication/socket/send                                            \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Communication::Socket Communication::Send Data [C0001.007]           \nfunction @ 0x401370\n  or:\n    api: send @ 0x401552\nfunction @ 0x401980\n  or:\n    api: send @ 0x4019FD, 0x401A30, 0x401A80, 0x401AFE\nfunction @ 0x401B70\n  or:\n    api: send @ 0x401BF1, 0x401C27, 0x401C72, 0x401CC8, and 1 more...\nfunction @ 0x406F50\n  or:\n    api: send @ 0x40717A, 0x407268\nfunction @ 0x4072A0\n  or:\n    api: send @ 0x407321, 0x407357, 0x4073A1, 0x40740E\n\nconnect TCP socket (4 matches)\nnamespace  communication/socket/tcp                                             \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           mrhafizfarhad@gmail.com                                              \nscope      function                                                             \nmbc        Communication::Socket Communication::Connect Socket [C0001.004]      \nfunction @ 0x401980\n  and:\n    match: create TCP socket @ 0x401980\n      or:\n        and:\n          or:\n            number: 0x0 = protocol (default) @ 0x401993, 0x4019C2\n          number: 0x1 = SOCK_STREAM @ 0x4019C4\n          number: 0x2 = AF_INET @ 0x4019A4, 0x4019C6\n          or:\n            api: socket @ 0x4019CD\n    match: connect socket @ 0x4019DD\n      or:\n        api: connect @ 0x4019E5\nfunction @ 0x401B70\n  and:\n    match: create TCP socket @ 0x401B70\n      or:\n        and:\n          or:\n            number: 0x0 = protocol (default) @ 0x401B84, 0x401BB3\n          number: 0x1 = SOCK_STREAM @ 0x401BB5\n          number: 0x2 = AF_INET @ 0x401B89, 0x401BB7\n          or:\n            api: socket @ 0x401BBE\n    match: connect socket @ 0x401BCE\n      or:\n        api: connect @ 0x401BD6\nfunction @ 0x4072A0\n  and:\n    match: create TCP socket @ 0x4072A0\n      or:\n        and:\n          or:\n            number: 0x0 = protocol (default) @ 0x4072B4, 0x4072E3\n          number: 0x1 = SOCK_STREAM @ 0x4072E5\n          number: 0x2 = AF_INET @ 0x4072B9, 0x4072E7\n          or:\n            api: socket @ 0x4072EE\n    match: connect socket @ 0x4072FE\n      or:\n        api: connect @ 0x407306\nfunction @ 0x407480\n  and:\n    match: create TCP socket @ 0x407480\n      or:\n        and:\n          or:\n            number: 0x6 = IPPROTO_TCP @ 0x4074C0\n          number: 0x1 = SOCK_STREAM @ 0x40749D\n          number: 0x2 = AF_INET @ 0x4074B4, 0x4074C3\n          or:\n            api: socket @ 0x4074CA\n    match: connect socket @ 0x4074E1\n      or:\n        api: connect @ 0x40750D\n\ncreate TCP socket (4 matches)\nnamespace   communication/socket/tcp                                            \nauthor      william.ballenthin@mandiant.com, joakim@intezer.com,                \n            anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com       \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create TCP Socket [C0001.011]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ 0x401980 in function 0x401980\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ 0x401993, 0x4019C2\n      number: 0x1 = SOCK_STREAM @ 0x4019C4\n      number: 0x2 = AF_INET @ 0x4019A4, 0x4019C6\n      or:\n        api: socket @ 0x4019CD\nbasic block @ 0x401B70 in function 0x401B70\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ 0x401B84, 0x401BB3\n      number: 0x1 = SOCK_STREAM @ 0x401BB5\n      number: 0x2 = AF_INET @ 0x401B89, 0x401BB7\n      or:\n        api: socket @ 0x401BBE\nbasic block @ 0x4072A0 in function 0x4072A0\n  or:\n    and:\n      or:\n        number: 0x0 = protocol (default) @ 0x4072B4, 0x4072E3\n      number: 0x1 = SOCK_STREAM @ 0x4072E5\n      number: 0x2 = AF_INET @ 0x4072B9, 0x4072E7\n      or:\n        api: socket @ 0x4072EE\nbasic block @ 0x407480 in function 0x407480\n  or:\n    and:\n      or:\n        number: 0x6 = IPPROTO_TCP @ 0x4074C0\n      number: 0x1 = SOCK_STREAM @ 0x40749D\n      number: 0x2 = AF_INET @ 0x4074B4, 0x4074C3\n      or:\n        api: socket @ 0x4074CA\n\nconnect UDP socket (3 matches)\nnamespace    communication/socket/udp                                           \nauthor       mrhafizfarhad@gmail.com                                            \nscope        function                                                           \nmbc          Communication::Socket Communication::UDP Client [C0001.013]        \ndescription  Detects UDP socket connections by combining UDP socket creation    \n             with connection attempts.                                          \nfunction @ 0x401980\n  and:\n    match: create UDP socket @ 0x401980\n      or:\n        and:\n          number: 0x2 = AF_INET @ 0x4019A4, 0x4019C6\n          or:\n            number: 0x0 = protocol (default) @ 0x401993, 0x4019C2\n          or:\n            api: socket @ 0x4019CD\n    match: connect socket @ 0x4019DD\n      or:\n        api: connect @ 0x4019E5\nfunction @ 0x401B70\n  and:\n    match: create UDP socket @ 0x401B70\n      or:\n        and:\n          number: 0x2 = AF_INET @ 0x401B89, 0x401BB7\n          or:\n            number: 0x0 = protocol (default) @ 0x401B84, 0x401BB3\n          or:\n            api: socket @ 0x401BBE\n    match: connect socket @ 0x401BCE\n      or:\n        api: connect @ 0x401BD6\nfunction @ 0x4072A0\n  and:\n    match: create UDP socket @ 0x4072A0\n      or:\n        and:\n          number: 0x2 = AF_INET @ 0x4072B9, 0x4072E7\n          or:\n            number: 0x0 = protocol (default) @ 0x4072B4, 0x4072E3\n          or:\n            api: socket @ 0x4072EE\n    match: connect socket @ 0x4072FE\n      or:\n        api: connect @ 0x407306\n\ncreate UDP socket (3 matches)\nnamespace   communication/socket/udp/send                                       \nauthor      moritz.raabe@mandiant.com, joakim@intezer.com,                      \n            michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create UDP Socket [C0001.010]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ 0x401980 in function 0x401980\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x4019A4, 0x4019C6\n      or:\n        number: 0x0 = protocol (default) @ 0x401993, 0x4019C2\n      or:\n        api: socket @ 0x4019CD\nbasic block @ 0x401B70 in function 0x401B70\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x401B89, 0x401BB7\n      or:\n        number: 0x0 = protocol (default) @ 0x401B84, 0x401BB3\n      or:\n        api: socket @ 0x401BBE\nbasic block @ 0x4072A0 in function 0x4072A0\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x4072B9, 0x4072E7\n      or:\n        number: 0x0 = protocol (default) @ 0x4072B4, 0x4072E3\n      or:\n        api: socket @ 0x4072EE\n\nact as TCP client (4 matches)\nnamespace  communication/tcp/client                                     \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                                     \nmbc        Communication::Socket Communication::TCP Client [C0001.008]  \nfunction @ 0x401980\n  or:\n    match: connect TCP socket @ 0x401980\n      and:\n        match: create TCP socket @ 0x401980\n          or:\n            and:\n              or:\n                number: 0x0 = protocol (default) @ 0x401993, 0x4019C2\n              number: 0x1 = SOCK_STREAM @ 0x4019C4\n              number: 0x2 = AF_INET @ 0x4019A4, 0x4019C6\n              or:\n                api: socket @ 0x4019CD\n        match: connect socket @ 0x4019DD\n          or:\n            api: connect @ 0x4019E5\nfunction @ 0x401B70\n  or:\n    match: connect TCP socket @ 0x401B70\n      and:\n        match: create TCP socket @ 0x401B70\n          or:\n            and:\n              or:\n                number: 0x0 = protocol (default) @ 0x401B84, 0x401BB3\n              number: 0x1 = SOCK_STREAM @ 0x401BB5\n              number: 0x2 = AF_INET @ 0x401B89, 0x401BB7\n              or:\n                api: socket @ 0x401BBE\n        match: connect socket @ 0x401BCE\n          or:\n            api: connect @ 0x401BD6\nfunction @ 0x4072A0\n  or:\n    match: connect TCP socket @ 0x4072A0\n      and:\n        match: create TCP socket @ 0x4072A0\n          or:\n            and:\n              or:\n                number: 0x0 = protocol (default) @ 0x4072B4, 0x4072E3\n              number: 0x1 = SOCK_STREAM @ 0x4072E5\n              number: 0x2 = AF_INET @ 0x4072B9, 0x4072E7\n              or:\n                api: socket @ 0x4072EE\n        match: connect socket @ 0x4072FE\n          or:\n            api: connect @ 0x407306\nfunction @ 0x407480\n  or:\n    match: connect TCP socket @ 0x407480\n      and:\n        match: create TCP socket @ 0x407480\n          or:\n            and:\n              or:\n                number: 0x6 = IPPROTO_TCP @ 0x4074C0\n              number: 0x1 = SOCK_STREAM @ 0x40749D\n              number: 0x2 = AF_INET @ 0x4074B4, 0x4074C3\n              or:\n                api: socket @ 0x4074CA\n        match: connect socket @ 0x4074E1\n          or:\n            api: connect @ 0x40750D\n\ngenerate random numbers via WinAPI\nnamespace  data-manipulation/prng                                            \nauthor     michael.hunhoff@mandiant.com, johnk3r                             \nscope      function                                                          \nmbc        Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\nfunction @ 0x407660\n  and:\n    or:\n      api: CryptGenRandom @ 0x40768B\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x407CE0\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x407D86\n        api: LockResource @ 0x407D95\n      optional:\n        api: GetModuleHandle @ 0x407CEF\n        or:\n          api: FindResource @ 0x407D74\n        api: SizeofResource @ 0x407DA9\n\nget file size\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x407A20\n  or:\n    api: GetFileSize @ 0x407B14\n\nmove file\nnamespace  host-interaction/file-system/move                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Move File [C0063]                         \nfunction @ 0x407CE0\n  or:\n    api: MoveFileEx @ 0x407E2C\n\nread file on Windows\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x407A20\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x407AD9\n          match: create or open file @ 0x407AE3\n            or:\n              api: CreateFile @ 0x407AE3\n      or:\n        api: ReadFile @ 0x407B2F\n\nget number of processors\nnamespace   host-interaction/hardware/cpu                                       \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/bed03d2f849d9060c6…\nfunction @ 0x407720\n  or:\n    and:\n      match: PEB access @ 0x407720, 0x4077FA\n        or:\n          and:\n            arch: i386\n            characteristic: fs access @ 0x407727, 0x40772E\n            or:\n              offset: 0x30 @ 0x40774E\n        or:\n          and:\n            arch: i386\n            characteristic: fs access @ 0x40782A\n            or:\n              offset: 0x30 @ 0x40780B\n      or:\n        and:\n          arch: i386\n          number: 0x64 = PEB->NumberOfProcessors @ 0x4077B3\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x408000\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x408086\n\nrun as service\nnamespace  host-interaction/service                                             \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      file                                                                 \nmbc        Anti-Behavioral Analysis::Conditional Execution::Runs as Service     \n           [B0025.007]                                                          \nor:\n  function:\n    or:\n      api: RegisterServiceCtrlHandler @ 0x408043\n    or:\n      api: StartServiceCtrlDispatcher @ 0x408126\n\ncreate service\nnamespace  host-interaction/service/create                                      \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003], Execution::System Services::Service Execution           \n           [T1569.002]                                                          \nfunction @ 0x407C40\n  and:\n    api: CreateService @ 0x407C9B\n    optional:\n      api: OpenSCManager @ 0x407C68\n\nmodify service\nnamespace  host-interaction/service/modify                                      \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003], Execution::System Services::Service Execution           \n           [T1569.002]                                                          \nfunction @ 0x407FA0\n  and:\n    or:\n      api: ChangeServiceConfig2 @ 0x407FF4\n\nstart service\nnamespace  host-interaction/service/start                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003]                                                          \nfunction @ 0x407C40\n  and:\n    api: StartService @ 0x407CB2\n    optional:\n      match: get service handle @ 0x407C40\n        or:\n          api: CreateService @ 0x407C9B\n\ncreate thread (4 matches)\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x4076C2 in function 0x4076B0\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthreadex @ 0x4076D0\nbasic block @ 0x4077C3 in function 0x407720\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthreadex @ 0x4077D4\nbasic block @ 0x407BDA in function 0x407BD0\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthreadex @ 0x407BF3\nbasic block @ 0x407C0D in function 0x407BD0\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthreadex @ 0x407C1B\n\nterminate thread\nnamespace  host-interaction/thread/terminate                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \nmbc        Process::Terminate Thread [C0039]                                    \nbasic block @ 0x4076F2 in function 0x4076B0\n  or:\n    api: TerminateThread @ 0x4076F5\n\nlink function at runtime on Windows (4 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x407D0D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x407D0D\ninstruction @ 0x407D1A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x407D1A\ninstruction @ 0x407D27\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x407D27\ninstruction @ 0x407D34\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x407D34\n\ninspect section memory permissions\nnamespace    load-code/pe                                                       \nauthor       @Ana06                                                             \nscope        function                                                           \nmbc          Discovery::Code Discovery::Inspect Section Memory Permissions      \n             [B0046.002]                                                        \ndescription  translate section memory permissions (specified in the             \n             'Characteristics' field of the image section header) into page     \n             protection constants                                               \nfunction @ 0x401D80\n  and:\n    os: windows\n    optional:\n      number: 0x1 = PAGE_NOACCESS @ 0x401D90\n    3 or more:\n      and:\n        number: 0x40000000 = IMAGE_SCN_MEM_READ @ 0x4032E9, 0x4035CE, 0x406E04\n        number: 0x2 = PAGE_READONLY @ 0x401DAB, 0x402A13, 0x402A92, 0x402B34, and 9 more...\n      and:\n        number: 0x20000000 = IMAGE_SCN_MEM_EXECUTE @ 0x402557, 0x40263E, 0x4030AD, 0x403217, and 4 more...\n        number: 0x10 = PAGE_EXECUTE @ 0x402AA4, 0x402DAC, 0x403071, 0x403136, and 9 more...\n      and:\n        or:\n          number: 0x60000000 = IMAGE_SCN_MEM_READ | IMAGE_SCN_MEM_EXECUTE @ 0x4021F1, 0x402817, 0x4028EA, 0x402972, and 2 more...\n          and:\n            number: 0x40000000 = IMAGE_SCN_MEM_READ @ 0x4032E9, 0x4035CE, 0x406E04\n            number: 0x20000000 = IMAGE_SCN_MEM_EXECUTE @ 0x402557, 0x40263E, 0x4030AD, 0x403217, and 4 more...\n        number: 0x20 = PAGE_EXECUTE_READ @ 0x403A62, 0x403C48, 0x404892, 0x406091\n      and:\n        or:\n          number: 0xC0000000 = IMAGE_SCN_MEM_READ | IMAGE_SCN_MEM_WRITE @ 0x4020CC, 0x40272A, 0x4027DA, 0x4031A1, and 5 more...\n          and:\n            number: 0x40000000 = IMAGE_SCN_MEM_READ @ 0x4032E9, 0x4035CE, 0x406E04\n            number: 0x80000000 = IMAGE_SCN_MEM_WRITE @ 0x402131, 0x4021B4, 0x4023C4, 0x402C29, and 6 more...\n        number: 0x4 = PAGE_READWRITE @ 0x402B90, 0x402C09, 0x4034F4, 0x40352F, and 13 more...\n      and:\n        or:\n          number: 0xE0000000 = IMAGE_SCN_MEM_READ | IMAGE_SCN_MEM_WRITE | IMAGE_SCN_MEM_EXECUTE @ 0x40250B, 0x40267A, 0x4029E5, 0x402C63, and 4 more...\n          and:\n            number: 0x40000000 = IMAGE_SCN_MEM_READ @ 0x4032E9, 0x4035CE, 0x406E04\n            number: 0x80000000 = IMAGE_SCN_MEM_WRITE @ 0x402131, 0x4021B4, 0x4023C4, 0x402C29, and 6 more...\n            number: 0x20000000 = IMAGE_SCN_MEM_EXECUTE @ 0x402557, 0x40263E, 0x4030AD, 0x403217, and 4 more...\n        number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x403FDF, 0x404037, 0x404463, 0x404AA8, and 2 more...\n\npersist via Windows service\nnamespace  persistence/service                                                  \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003], Execution::System Services::Service Execution           \n           [T1569.002]                                                          \nfunction @ 0x407C40\n  or:\n    and:\n      or:\n        basic block:\n          and:\n            number: 0x2 = SERVICE_AUTO_START @ 0x407C87\n            api: CreateService @ 0x407C9B\n      optional:\n        or:\n          api: StartService @ 0x407CB2\n\n\n\n"},"hashes":{"md5":"a087f5992eda1732d0a32d2742298df2","sha1":"bfb9e0f64b88b12fc864ed255799fb457f998f4c","sha256":"4ff1ec66b9f9d6248e499db145f254d49db9f9dd3df4273ba2d32c48a8e8cffb"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 82</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 10314</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"wanna_cry-019f7976bdb175e2a6a9\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"a087f5992eda1732d0a32d2742298df2\",\n        \"sha256\": \"4ff1ec66b9f9d6248e499db145f254d49db9f9dd3df4273ba2d32c4\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_peb_access__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"PEB access (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Process Environment\",\n        \"Block [B0001.019]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x407720\",\n      \"label\": \"Block 0x407720\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x407720\"\n    },\n    {\n      \"id\": \"cap_contain_loop__27_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (27 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401055\",\n      \"label\": \"Function 0x401055\",\n      \"type\": \"function\",\n      \"address\": \"0x401055\"\n    },\n    {\n      \"id\": \"cap_delay_execution__12_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (12 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401640\",\n      \"label\": \"Block 0x401640\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401640\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_service_handle__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"get service handle (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x407C40\",\n      \"label\": \"Function 0x407C40\",\n      \"type\": \"function\",\n      \"address\": \"0x407C40\"\n    },\n    {\n      \"id\": \"api_CreateService\",\n      \"label\": \"CreateService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_check_for_time_delay_via_queryperformancecounter\",\n      \"label\": \"check for time delay via QueryPerformanceCounter\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"QueryPerformanceCounter [B0001.033]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401660\",\n      \"label\": \"Function 0x401660\",\n      \"type\": \"function\",\n      \"address\": \"0x401660\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"QueryPerformanceCounter [B0001.033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_obfuscated_stackstrings\",\n      \"label\": \"contain obfuscated stackstrings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401D80\",\n      \"label\": \"Block 0x401D80\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401D80\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_data__5_matches_\",\n      \"label\": \"receive data (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401980\",\n      \"label\": \"Function 0x401980\",\n      \"type\": \"function\",\n      \"address\": \"0x401980\"\n    },\n    {\n      \"id\": \"func_0x406F50\",\n      \"label\": \"Function 0x406F50\",\n      \"type\": \"function\",\n      \"address\": \"0x406F50\"\n    },\n    {\n      \"id\": \"func_0x401370\",\n      \"label\": \"Function 0x401370\",\n      \"type\": \"function\",\n      \"address\": \"0x401370\"\n    },\n    {\n      \"id\": \"func_0x4072A0\",\n      \"label\": \"Function 0x4072A0\",\n      \"type\": \"function\",\n      \"address\": \"0x4072A0\"\n    },\n    {\n      \"id\": \"func_0x401B70\",\n      \"label\": \"Function 0x401B70\",\n      \"type\": \"function\",\n      \"address\": \"0x401B70\"\n    },\n    {\n      \"id\": \"api_recv\",\n      \"label\": \"recv\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data__5_matches_\",\n      \"label\": \"send data (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_send\",\n      \"label\": \"send\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_to_url\",\n      \"label\": \"connect to URL\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Open URL [C0002.004]\"\n      ]\n    },\n    {\n      \"id\": \"api_InternetOpenUrl\",\n      \"label\": \"InternetOpenUrl\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_create_http_request\",\n      \"label\": \"create HTTP request\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408140\",\n      \"label\": \"Function 0x408140\",\n      \"type\": \"function\",\n      \"address\": \"0x408140\"\n    },\n    {\n      \"id\": \"api_InternetOpen\",\n      \"label\": \"InternetOpen\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"api_InternetCloseHandle\",\n      \"label\": \"InternetCloseHandle\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_socket__5_matches_\",\n      \"label\": \"connect socket (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x4072FE\",\n      \"label\": \"Block 0x4072FE\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4072FE\"\n    },\n    {\n      \"id\": \"bb_0x401BCE\",\n      \"label\": \"Block 0x401BCE\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401BCE\"\n    },\n    {\n      \"id\": \"bb_0x401470\",\n      \"label\": \"Block 0x401470\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401470\"\n    },\n    {\n      \"id\": \"bb_0x4074E1\",\n      \"label\": \"Block 0x4074E1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4074E1\"\n    },\n    {\n      \"id\": \"bb_0x4019DD\",\n      \"label\": \"Block 0x4019DD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4019DD\"\n    },\n    {\n      \"id\": \"api_connect\",\n      \"label\": \"connect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_mrhafizfarhad_gmail_com\",\n      \"label\": \"mrhafizfarhad@gmail.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_socket_status\",\n      \"label\": \"get socket status\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Get Socket Status [C0001.012]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407480\",\n      \"label\": \"Function 0x407480\",\n      \"type\": \"function\",\n      \"address\": \"0x407480\"\n    },\n    {\n      \"id\": \"api_select\",\n      \"label\": \"select\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_initialize_winsock_library\",\n      \"label\": \"initialize Winsock library\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Initialize Winsock Library\",\n        \"[C0001.009]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407B90\",\n      \"label\": \"Function 0x407B90\",\n      \"type\": \"function\",\n      \"address\": \"0x407B90\"\n    },\n    {\n      \"id\": \"api_WSAStartup\",\n      \"label\": \"WSAStartup\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_socket_configuration\",\n      \"label\": \"set socket configuration\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Set Socket Config [C0001.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_ioctlsocket\",\n      \"label\": \"ioctlsocket\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_receive_data_on_socket__5_matches_\",\n      \"label\": \"receive data on socket (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Receive Data [C0001.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Receive Data [C0001.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data_on_socket__5_matches_\",\n      \"label\": \"send data on socket (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_tcp_socket__4_matches_\",\n      \"label\": \"connect TCP socket (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Connect Socket [C0001.004]\"\n      ]\n    },\n    {\n      \"id\": \"api_socket\",\n      \"label\": \"socket\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_tcp_socket__4_matches_\",\n      \"label\": \"create TCP socket (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x407480\",\n      \"label\": \"Block 0x407480\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x407480\"\n    },\n    {\n      \"id\": \"bb_0x4072A0\",\n      \"label\": \"Block 0x4072A0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4072A0\"\n    },\n    {\n      \"id\": \"bb_0x401B70\",\n      \"label\": \"Block 0x401B70\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401B70\"\n    },\n    {\n      \"id\": \"bb_0x401980\",\n      \"label\": \"Block 0x401980\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401980\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_udp_socket__3_matches_\",\n      \"label\": \"connect UDP socket (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::UDP Client [C0001.013]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______mrhafizfarhad_gmail_com\",\n      \"label\": \"author       mrhafizfarhad@gmail.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::UDP Client [C0001.013]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_udp_socket__3_matches_\",\n      \"label\": \"create UDP socket (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create UDP Socket [C0001.010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_act_as_tcp_client__4_matches_\",\n      \"label\": \"act as TCP client (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_via_winapi\",\n      \"label\": \"generate random numbers via WinAPI\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407660\",\n      \"label\": \"Function 0x407660\",\n      \"type\": \"function\",\n      \"address\": \"0x407660\"\n    },\n    {\n      \"id\": \"api_CryptGenRandom\",\n      \"label\": \"CryptGenRandom\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x407CE0\",\n      \"label\": \"Function 0x407CE0\",\n      \"type\": \"function\",\n      \"address\": \"0x407CE0\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetModuleHandle\",\n      \"label\": \"GetModuleHandle\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_file_size\",\n      \"label\": \"get file size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407A20\",\n      \"label\": \"Function 0x407A20\",\n      \"type\": \"function\",\n      \"address\": \"0x407A20\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_move_file\",\n      \"label\": \"move file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"api_MoveFileEx\",\n      \"label\": \"MoveFileEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows\",\n      \"label\": \"read file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_number_of_processors\",\n      \"label\": \"get number of processors\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407720\",\n      \"label\": \"Function 0x407720\",\n      \"type\": \"function\",\n      \"address\": \"0x407720\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408000\",\n      \"label\": \"Function 0x408000\",\n      \"type\": \"function\",\n      \"address\": \"0x408000\"\n    },\n    {\n      \"id\": \"api_ExitProcess\",\n      \"label\": \"ExitProcess\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_run_as_service\",\n      \"label\": \"run as service\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Conditional Execution::Runs as Service\",\n        \"[B0025.007]\"\n      ]\n    },\n    {\n      \"id\": \"api_StartServiceCtrlDispatcher\",\n      \"label\": \"StartServiceCtrlDispatcher\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegisterServiceCtrlHandler\",\n      \"label\": \"RegisterServiceCtrlHandler\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_service\",\n      \"label\": \"create service\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\",\n        \"Execution::System Services::Service Execution\",\n        \"[T1569.002]\"\n      ]\n    },\n    {\n      \"id\": \"api_OpenSCManager\",\n      \"label\": \"OpenSCManager\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_modify_service\",\n      \"label\": \"modify service\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\",\n        \"Execution::System Services::Service Execution\",\n        \"[T1569.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x407FA0\",\n      \"label\": \"Function 0x407FA0\",\n      \"type\": \"function\",\n      \"address\": \"0x407FA0\"\n    },\n    {\n      \"id\": \"api_ChangeServiceConfig2\",\n      \"label\": \"ChangeServiceConfig2\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_start_service\",\n      \"label\": \"start service\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_StartService\",\n      \"label\": \"StartService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_thread__4_matches_\",\n      \"label\": \"create thread (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x407BDA\",\n      \"label\": \"Block 0x407BDA\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x407BDA\"\n    },\n    {\n      \"id\": \"bb_0x407C0D\",\n      \"label\": \"Block 0x407C0D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x407C0D\"\n    },\n    {\n      \"id\": \"bb_0x4077C3\",\n      \"label\": \"Block 0x4077C3\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4077C3\"\n    },\n    {\n      \"id\": \"bb_0x4076C2\",\n      \"label\": \"Block 0x4076C2\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4076C2\"\n    },\n    {\n      \"id\": \"api__beginthreadex\",\n      \"label\": \"_beginthreadex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_thread\",\n      \"label\": \"terminate thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Thread [C0039]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4076F2\",\n      \"label\": \"Block 0x4076F2\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4076F2\"\n    },\n    {\n      \"id\": \"api_TerminateThread\",\n      \"label\": \"TerminateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__4_matches_\",\n      \"label\": \"link function at runtime on Windows (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_inspect_section_memory_permissions\",\n      \"label\": \"inspect section memory permissions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Inspect Section Memory Permissions\",\n        \"[B0046.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401D80\",\n      \"label\": \"Function 0x401D80\",\n      \"type\": \"function\",\n      \"address\": \"0x401D80\"\n    },\n    {\n      \"id\": \"cap_author________ana06\",\n      \"label\": \"author       @Ana06\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Inspect Section Memory Permissions\",\n        \"[B0046.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_persist_via_windows_service\",\n      \"label\": \"persist via Windows service\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\",\n        \"Execution::System Services::Service Execution\",\n        \"[T1569.002]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_peb_access__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_peb_access__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x407720\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__27_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__27_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401055\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__12_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__12_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x401640\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_service_handle__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_service_handle__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x407C40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407C40\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_time_delay_via_queryperformancecounter\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_queryperformancecounter\",\n      \"target\": \"func_0x401660\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401660\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_obfuscated_stackstrings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings\",\n      \"target\": \"bb_0x401D80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x401D80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data__5_matches_\",\n      \"target\": \"func_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__5_matches_\",\n      \"target\": \"func_0x406F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__5_matches_\",\n      \"target\": \"func_0x401370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__5_matches_\",\n      \"target\": \"func_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__5_matches_\",\n      \"target\": \"func_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406F50\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401370\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x406F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x401370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406F50\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401370\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data__5_matches_\",\n      \"target\": \"func_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__5_matches_\",\n      \"target\": \"func_0x406F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__5_matches_\",\n      \"target\": \"func_0x401370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__5_matches_\",\n      \"target\": \"func_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__5_matches_\",\n      \"target\": \"func_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406F50\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401370\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x406F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x401370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406F50\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401370\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_to_url\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_http_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_http_request\",\n      \"target\": \"func_0x408140\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408140\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408140\",\n      \"target\": \"api_InternetCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x408140\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408140\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408140\",\n      \"target\": \"api_InternetCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_socket__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_socket__5_matches_\",\n      \"target\": \"bb_0x4072FE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_socket__5_matches_\",\n      \"target\": \"bb_0x401BCE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_socket__5_matches_\",\n      \"target\": \"bb_0x401470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_socket__5_matches_\",\n      \"target\": \"bb_0x4074E1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_socket__5_matches_\",\n      \"target\": \"bb_0x4019DD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mrhafizfarhad_gmail_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x4072FE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x401BCE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x401470\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x4074E1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x4019DD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_socket_status\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_socket_status\",\n      \"target\": \"func_0x407480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407480\",\n      \"target\": \"api_select\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407480\",\n      \"target\": \"api_select\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_initialize_winsock_library\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_initialize_winsock_library\",\n      \"target\": \"func_0x407B90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407B90\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407B90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407B90\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_socket_configuration\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration\",\n      \"target\": \"func_0x407480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407480\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407480\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data_on_socket__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__5_matches_\",\n      \"target\": \"func_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__5_matches_\",\n      \"target\": \"func_0x406F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__5_matches_\",\n      \"target\": \"func_0x401370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__5_matches_\",\n      \"target\": \"func_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__5_matches_\",\n      \"target\": \"func_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406F50\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401370\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x406F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406F50\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401370\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data_on_socket__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__5_matches_\",\n      \"target\": \"func_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__5_matches_\",\n      \"target\": \"func_0x406F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__5_matches_\",\n      \"target\": \"func_0x401370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__5_matches_\",\n      \"target\": \"func_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__5_matches_\",\n      \"target\": \"func_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406F50\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401370\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x406F50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x406F50\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401370\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_tcp_socket__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_tcp_socket__4_matches_\",\n      \"target\": \"func_0x407480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_tcp_socket__4_matches_\",\n      \"target\": \"func_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_tcp_socket__4_matches_\",\n      \"target\": \"func_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_tcp_socket__4_matches_\",\n      \"target\": \"func_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407480\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407480\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x407480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407480\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407480\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_tcp_socket__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__4_matches_\",\n      \"target\": \"bb_0x407480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__4_matches_\",\n      \"target\": \"bb_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__4_matches_\",\n      \"target\": \"bb_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__4_matches_\",\n      \"target\": \"bb_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x407480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_udp_socket__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_udp_socket__3_matches_\",\n      \"target\": \"func_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_udp_socket__3_matches_\",\n      \"target\": \"func_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_udp_socket__3_matches_\",\n      \"target\": \"func_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______mrhafizfarhad_gmail_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_udp_socket__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__3_matches_\",\n      \"target\": \"bb_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__3_matches_\",\n      \"target\": \"bb_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__3_matches_\",\n      \"target\": \"bb_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_act_as_tcp_client__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_act_as_tcp_client__4_matches_\",\n      \"target\": \"func_0x407480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_act_as_tcp_client__4_matches_\",\n      \"target\": \"func_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_act_as_tcp_client__4_matches_\",\n      \"target\": \"func_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_act_as_tcp_client__4_matches_\",\n      \"target\": \"func_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407480\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407480\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407480\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4072A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407480\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407480\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4072A0\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B70\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_via_winapi\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_via_winapi\",\n      \"target\": \"func_0x407660\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407660\",\n      \"target\": \"api_CryptGenRandom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x407660\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407660\",\n      \"target\": \"api_CryptGenRandom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x407CE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407CE0\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407CE0\",\n      \"target\": \"api_GetModuleHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407CE0\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407CE0\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407CE0\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x407CE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407CE0\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407CE0\",\n      \"target\": \"api_GetModuleHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407CE0\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407CE0\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407CE0\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size\",\n      \"target\": \"func_0x407A20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407A20\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x407A20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407A20\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_move_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_move_file\",\n      \"target\": \"func_0x407CE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407CE0\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x407CE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407CE0\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows\",\n      \"target\": \"func_0x407A20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407A20\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407A20\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x407A20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407A20\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407A20\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_number_of_processors\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_number_of_processors\",\n      \"target\": \"func_0x407720\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x407720\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x408000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408000\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x408000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408000\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_run_as_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_service\",\n      \"target\": \"func_0x407C40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407C40\",\n      \"target\": \"api_OpenSCManager\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407C40\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x407C40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407C40\",\n      \"target\": \"api_OpenSCManager\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407C40\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_modify_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_modify_service\",\n      \"target\": \"func_0x407FA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407FA0\",\n      \"target\": \"api_ChangeServiceConfig2\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x407FA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407FA0\",\n      \"target\": \"api_ChangeServiceConfig2\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_start_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_start_service\",\n      \"target\": \"func_0x407C40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407C40\",\n      \"target\": \"api_StartService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407C40\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x407C40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407C40\",\n      \"target\": \"api_StartService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407C40\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread__4_matches_\",\n      \"target\": \"bb_0x407BDA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__4_matches_\",\n      \"target\": \"bb_0x407C0D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__4_matches_\",\n      \"target\": \"bb_0x4077C3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__4_matches_\",\n      \"target\": \"bb_0x4076C2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x407BDA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x407C0D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4077C3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4076C2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_thread\",\n      \"target\": \"bb_0x4076F2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4076F2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_inspect_section_memory_permissions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_inspect_section_memory_permissions\",\n      \"target\": \"func_0x401D80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________ana06\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author________ana06\",\n      \"target\": \"func_0x401D80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_persist_via_windows_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_persist_via_windows_service\",\n      \"target\": \"func_0x407C40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407C40\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407C40\",\n      \"target\": \"api_StartService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x407C40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x407C40\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x407C40\",\n      \"target\": \"api_StartService\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-19 13:55:40.917743\",\n    \"total_functions\": \"82\",\n    \"total_features\": \"10314\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-19 13:55:41"}
{"_id":{"$oid":"6a5c8bbcb3bed57e0e73789a"},"sha256":"bd20fcc313adbb44d82a033fbae527bc2b522b93ed80ba88ec0094644005df81","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"010d62381199e3131b778a19b75d36df","sha1":"84ab41d0563cf7220ee2cef52bc7347c90737763","sha256":"bd20fcc313adbb44d82a033fbae527bc2b522b93ed80ba88ec0094644005df81"}},"timestamp":"2026-07-19 15:41:01"}
{"_id":{"$oid":"6a5c8fafb3bed57e0e7378ab"},"sha256":"ce4aed382f325fb8c3d31091b7ab08a14975db08457b46b6b44f2a41c347fc9c","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_5k2t0anr/001_upx_unpacked.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_5k2t0anr/001_upx_unpacked.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_5k2t0anr/001_upx_unpacked.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 91c49a21332198c2eba50d0d0fa30304                                  │\n│ sha1     │ b5a78e977ec7d88bb9c890a6055b5a26d11ff706                          │\n│ sha256   │ 880520a4ef03fd51e8fb31f0ea3b1afe150958b872fe793f34d6a62c3544d848  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ amd64                                                             │\n│ path     │ /tmp/sdm_unpack_wflthx9i/vi-019f798ddabc77d2976e0d64376b880d.exe… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION      │ Obfuscated Files or Information [T1027]               │\n│                      │ Obfuscated Files or Information::Indicator Removal    │\n│                      │ from Tools [T1027.005]                                │\n│ EXECUTION            │ Shared Modules [T1129]                                │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Debugger Detection::Anti-debugging Instructions   │\n│                          │ [B0001.034]                                       │\n│                          │ Debugger Detection::Process Environment Block     │\n│                          │ NtGlobalFlag [B0001.036]                          │\n│ ANTI-STATIC ANALYSIS     │ Executable Code Obfuscation::Argument Obfuscation │\n│                          │ [B0032.020]                                       │\n│                          │ Executable Code Obfuscation::Stack Strings        │\n│                          │ [B0032.017]                                       │\n│ CRYPTOGRAPHY             │ Encrypt Data::RC4 [C0027.009]                     │\n│                          │ Generate Pseudo-random Sequence::RC4 PRGA         │\n│                          │ [C0021.004]                                       │\n│                          │ Hashed Message Authentication Code [C0061]        │\n│ DATA                     │ Encode Data::Base64 [C0026.001]                   │\n│                          │ Encode Data::XOR [C0026.002]                      │\n│                          │ Non-Cryptographic Hash::FNV [C0030.005]           │\n│ DEFENSE EVASION          │ Obfuscated Files or Information::Encoding-Custom  │\n│                          │ Algorithm [E1027.m03]                             │\n│                          │ Obfuscated Files or                               │\n│                          │ Information::Encoding-Standard Algorithm          │\n│                          │ [E1027.m02]                                       │\n│                          │ Obfuscated Files or                               │\n│                          │ Information::Encryption-Standard Algorithm        │\n│                          │ [E1027.m05]                                       │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ check for PEB NtGlobalFlag flag       │ anti-analysis/anti-debugging/debugg… │\n│ execute anti-debugging instructions   │ anti-analysis/anti-debugging/debugg… │\n│ (7 matches)                           │                                      │\n│ contain obfuscated stackstrings (321  │ anti-analysis/obfuscation/string/st… │\n│ matches)                              │                                      │\n│ encode data using ADD XOR SUB         │ data-manipulation/encoding           │\n│ operations (2 matches)                │                                      │\n│ encode data using Base64 (11 matches) │ data-manipulation/encoding/base64    │\n│ encode data using XOR (232 matches)   │ data-manipulation/encoding/xor       │\n│ encrypt data using chaskey (2         │ data-manipulation/encryption/chaskey │\n│ matches)                              │                                      │\n│ encrypt data using RC4 PRGA (40       │ data-manipulation/encryption/rc4     │\n│ matches)                              │                                      │\n│ hash data using fnv                   │ data-manipulation/hashing/fnv        │\n│ authenticate HMAC (3 matches)         │ data-manipulation/hmac               │\n│ access PEB ldr_data (2 matches)       │ linking/runtime-linking              │\n│ parse PE header (94 matches)          │ load-code/pe                         │\n│ resolve function by parsing PE        │ load-code/pe                         │\n│ exports (3 matches)                   │                                      │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     91c49a21332198c2eba50d0d0fa30304                        \nsha1                    b5a78e977ec7d88bb9c890a6055b5a26d11ff706                \nsha256                  880520a4ef03fd51e8fb31f0ea3b1afe150958b872fe793f34d6a62…\npath                    /tmp/sdm_unpack_wflthx9i/vi-019f798ddabc77d2976e0d64376…\ntimestamp               2026-07-19 14:18:56.282194                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x1A0000000                                             \nrules                   /tmp/_MEIv3DTNX/rules                                   \nfunction count          1179                                                    \nlibrary function count  0                                                       \ntotal feature count     208868                                                  \n\ncheck for PEB NtGlobalFlag flag\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    0x1A00F3D4C                                    \n\nexecute anti-debugging instructions (7 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    0x1A0001188                                    \n           0x1A0001678                                    \n           0x1A00049C0                                    \n           0x1A0013B84                                    \n           0x1A00DFF00                                    \n           0x1A00F3D4C                                    \n           0x1A00FCCC0                                    \n\ncontain obfuscated stackstrings (321 matches)\nnamespace  anti-analysis/obfuscation/string/stackstring\nscope      basic block                                 \nmatches    0x1A00BA629                                 \n           0x1A001C561                                 \n           0x1A001D3A1                                 \n           0x1A001E887                                 \n           0x1A001F375                                 \n           0x1A00206B5                                 \n           0x1A0021035                                 \n           0x1A00227ED                                 \n           0x1A0022D95                                 \n           0x1A0023999                                 \n           0x1A00248B5                                 \n           0x1A00254E5                                 \n           0x1A002624D                                 \n           0x1A0026815                                 \n           0x1A0027075                                 \n           0x1A0027709                                 \n           0x1A0027EB9                                 \n           0x1A00285D1                                 \n           0x1A0028BFD                                 \n           0x1A0029220                                 \n           0x1A00294E0                                 \n           0x1A002A1F9                                 \n           0x1A002AA0F                                 \n           0x1A002BCAD                                 \n           0x1A002DCE5                                 \n           0x1A002F3AD                                 \n           0x1A002FC19                                 \n           0x1A0031059                                 \n           0x1A00317F1                                 \n           0x1A0032481                                 \n           0x1A0032B5D                                 \n           0x1A0033120                                 \n           0x1A00340F1                                 \n           0x1A00347A5                                 \n           0x1A0034D4C                                 \n           0x1A0035653                                 \n           0x1A0035C9D                                 \n           0x1A0036450                                 \n           0x1A00368D9                                 \n           0x1A0036ED8                                 \n           0x1A0037145                                 \n           0x1A0037910                                 \n           0x1A00381A9                                 \n           0x1A00387A8                                 \n           0x1A0038A29                                 \n           0x1A0038FDC                                 \n           0x1A003927D                                 \n           0x1A0039871                                 \n           0x1A0039DF5                                 \n           0x1A003A395                                 \n           0x1A003A96D                                 \n           0x1A003B2D5                                 \n           0x1A003B8D5                                 \n           0x1A003BF01                                 \n           0x1A003C63D                                 \n           0x1A003CE85                                 \n           0x1A003D449                                 \n           0x1A003DAF9                                 \n           0x1A003E229                                 \n           0x1A003E98C                                 \n           0x1A003F079                                 \n           0x1A003FDB5                                 \n           0x1A00405F5                                 \n           0x1A0040F8D                                 \n           0x1A0041961                                 \n           0x1A0042395                                 \n           0x1A0042B29                                 \n           0x1A004334C                                 \n           0x1A00435DC                                 \n           0x1A0043879                                 \n           0x1A0043F79                                 \n           0x1A0044528                                 \n           0x1A0044747                                 \n           0x1A0044C75                                 \n           0x1A004524D                                 \n           0x1A0045A6D                                 \n           0x1A0046045                                 \n           0x1A0046611                                 \n           0x1A0046BDD                                 \n           0x1A00475B1                                 \n           0x1A0047AD5                                 \n           0x1A0048021                                 \n           0x1A00485ED                                 \n           0x1A004907D                                 \n           0x1A00496A5                                 \n           0x1A004A0D9                                 \n           0x1A004A9D1                                 \n           0x1A004AFB9                                 \n           0x1A004B8C1                                 \n           0x1A004C055                                 \n           0x1A004C7CD                                 \n           0x1A004CDED                                 \n           0x1A004D435                                 \n           0x1A004E113                                 \n           0x1A004E8CD                                 \n           0x1A004F067                                 \n           0x1A00507E9                                 \n           0x1A00517EF                                 \n           0x1A00520C9                                 \n           0x1A005261B                                 \n           0x1A0053411                                 \n           0x1A0053995                                 \n           0x1A005407C                                 \n           0x1A005436D                                 \n           0x1A005540B                                 \n           0x1A00562AD                                 \n           0x1A00577B9                                 \n           0x1A005854F                                 \n           0x1A0058C31                                 \n           0x1A0059915                                 \n           0x1A0059F85                                 \n           0x1A005A711                                 \n           0x1A005ACCD                                 \n           0x1A005B211                                 \n           0x1A005B805                                 \n           0x1A005BD9D                                 \n           0x1A005C61D                                 \n           0x1A005CB91                                 \n           0x1A005D2DF                                 \n           0x1A005D7D1                                 \n           0x1A005E710                                 \n           0x1A005E9C3                                 \n           0x1A0060293                                 \n           0x1A0060FD9                                 \n           0x1A006157B                                 \n           0x1A0062361                                 \n           0x1A00631DD                                 \n           0x1A0064C99                                 \n           0x1A00659C5                                 \n           0x1A0066219                                 \n           0x1A0066ADD                                 \n           0x1A006709F                                 \n           0x1A006774D                                 \n           0x1A0067DFC                                 \n           0x1A00682BF                                 \n           0x1A0068A3B                                 \n           0x1A006916D                                 \n           0x1A00697D1                                 \n           0x1A006A3F9                                 \n           0x1A006B0B4                                 \n           0x1A006B3FD                                 \n           0x1A006B9F1                                 \n           0x1A006C56D                                 \n           0x1A006D005                                 \n           0x1A006D6A4                                 \n           0x1A006DA29                                 \n           0x1A006E201                                 \n           0x1A006E89D                                 \n           0x1A006F963                                 \n           0x1A006FDB9                                 \n           0x1A0071960                                 \n           0x1A0071C44                                 \n           0x1A0071ECB                                 \n           0x1A00722B9                                 \n           0x1A0072DAD                                 \n           0x1A0073A7D                                 \n           0x1A0075685                                 \n           0x1A0075C4D                                 \n           0x1A0076EEC                                 \n           0x1A00773E5                                 \n           0x1A0077CAB                                 \n           0x1A00780A5                                 \n           0x1A00787CD                                 \n           0x1A007A1D5                                 \n           0x1A007AAE1                                 \n           0x1A007B729                                 \n           0x1A007D50D                                 \n           0x1A007DD79                                 \n           0x1A007E3A5                                 \n           0x1A007EF5F                                 \n           0x1A007F6F1                                 \n           0x1A007FC59                                 \n           0x1A008094C                                 \n           0x1A008103B                                 \n           0x1A0081508                                 \n           0x1A0081AD9                                 \n           0x1A0082191                                 \n           0x1A0082855                                 \n           0x1A00836AB                                 \n           0x1A0084701                                 \n           0x1A0084DD5                                 \n           0x1A00853E5                                 \n           0x1A0086344                                 \n           0x1A0086771                                 \n           0x1A008702B                                 \n           0x1A0087A19                                 \n           0x1A0088B0F                                 \n           0x1A0089961                                 \n           0x1A008A448                                 \n           0x1A008AA09                                 \n           0x1A008AFE1                                 \n           0x1A008B584                                 \n           0x1A008B7F0                                 \n           0x1A008BA81                                 \n           0x1A008CDB5                                 \n           0x1A008DBFB                                 \n           0x1A008E72C                                 \n           0x1A008EA59                                 \n           0x1A008F3E1                                 \n           0x1A008FF4F                                 \n           0x1A0090367                                 \n           0x1A00907E7                                 \n           0x1A0091099                                 \n           0x1A0091789                                 \n           0x1A0091DD1                                 \n           0x1A0092C4D                                 \n           0x1A009439D                                 \n           0x1A0094B85                                 \n           0x1A00953C1                                 \n           0x1A0095D51                                 \n           0x1A0097011                                 \n           0x1A00978BD                                 \n           0x1A00982B5                                 \n           0x1A0099DA7                                 \n           0x1A009A6E5                                 \n           0x1A009AC79                                 \n           0x1A009C457                                 \n           0x1A009DCA7                                 \n           0x1A009E18B                                 \n           0x1A009E699                                 \n           0x1A009EC25                                 \n           0x1A009F203                                 \n           0x1A009FBC7                                 \n           0x1A00A0795                                 \n           0x1A00A1AE1                                 \n           0x1A00A2385                                 \n           0x1A00A2C84                                 \n           0x1A00A2EA1                                 \n           0x1A00A3F21                                 \n           0x1A00A4A6D                                 \n           0x1A00A5044                                 \n           0x1A00A52BC                                 \n           0x1A00A5771                                 \n           0x1A00A6415                                 \n           0x1A00A69DD                                 \n           0x1A00A7049                                 \n           0x1A00A76AD                                 \n           0x1A00A86C1                                 \n           0x1A00A8DD8                                 \n           0x1A00A9C21                                 \n           0x1A00AA4F9                                 \n           0x1A00AAA89                                 \n           0x1A00AB07D                                 \n           0x1A00AC43D                                 \n           0x1A00AD16D                                 \n           0x1A00AD881                                 \n           0x1A00AE3D9                                 \n           0x1A00AE9E0                                 \n           0x1A00AF0B5                                 \n           0x1A00AFBCB                                 \n           0x1A00B0AF9                                 \n           0x1A00B14BC                                 \n           0x1A00B1959                                 \n           0x1A00B3191                                 \n           0x1A00B3701                                 \n           0x1A00B3CB9                                 \n           0x1A00B44FD                                 \n           0x1A00B5229                                 \n           0x1A00B578B                                 \n           0x1A00B5C59                                 \n           0x1A00B6389                                 \n           0x1A00B6F60                                 \n           0x1A00B73CD                                 \n           0x1A00B7B99                                 \n           0x1A00B8C90                                 \n           0x1A00B8F55                                 \n           0x1A00BA629                                 \n           0x1A00BAE24                                 \n           0x1A00BB0C9                                 \n           0x1A00BB675                                 \n           0x1A00BC3DB                                 \n           0x1A00BC939                                 \n           0x1A00BD099                                 \n           0x1A00BDDD9                                 \n           0x1A00BE505                                 \n           0x1A00C064D                                 \n           0x1A00C113D                                 \n           0x1A00C209D                                 \n           0x1A00C2739                                 \n           0x1A00C2CC9                                 \n           0x1A00C3397                                 \n           0x1A00C3867                                 \n           0x1A00C4021                                 \n           0x1A00C5709                                 \n           0x1A00C5DF9                                 \n           0x1A00C6C5D                                 \n           0x1A00C800D                                 \n           0x1A00C867B                                 \n           0x1A00C956F                                 \n           0x1A00C9A1B                                 \n           0x1A00CA371                                 \n           0x1A00CB7A8                                 \n           0x1A00CC543                                 \n           0x1A00CC9A4                                 \n           0x1A00CCBA9                                 \n           0x1A00CD29B                                 \n           0x1A00CD763                                 \n           0x1A00CE191                                 \n           0x1A00CF81F                                 \n           0x1A00CFF34                                 \n           0x1A00D01AC                                 \n           0x1A00D0B24                                 \n           0x1A00D1177                                 \n           0x1A00D1D09                                 \n           0x1A00D25DD                                 \n           0x1A00D2C39                                 \n           0x1A00D3217                                 \n           0x1A00D3764                                 \n           0x1A00D4247                                 \n           0x1A00D4AB1                                 \n           0x1A00D5185                                 \n           0x1A00D593B                                 \n           0x1A00D6A39                                 \n           0x1A00D7DF9                                 \n           0x1A00D90D1                                 \n           0x1A00DA305                                 \n           0x1A00DB495                                 \n           0x1A00E0828                                 \n           0x1A00E816D                                 \n           0x1A00E8408                                 \n           0x1A00E880A                                 \n\nencode data using ADD XOR SUB operations (2 matches)\nnamespace    data-manipulation/encoding                                         \ndescription  Data encoding using a sequence of ADD/XOR/SUB (or SUB/XOR/ADD)     \n             operations common for PlugX but also used by other malware         \n             families.                                                          \nscope        function                                                           \nmatches      0x1A0004744                                                        \n             0x1A00EB9B0                                                        \n\nencode data using Base64 (11 matches)\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    0x1A001F334                      \n           0x1A00227AC                      \n           0x1A00254A4                      \n           0x1A002620C                      \n           0x1A0036EA0                      \n           0x1A0071C0C                      \n           0x1A00A0754                      \n           0x1A00A63D4                      \n           0x1A00B36C0                      \n           0x1A00D0AEC                      \n           0x1A00E0B64                      \n\nencode data using XOR (232 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x1A0001326                   \n           0x1A0001963                   \n           0x1A0001A45                   \n           0x1A00EB820                   \n           0x1A00F0E1A                   \n           0x1A00F1050                   \n           0x1A00EF563                   \n           0x1A000D4C0                   \n           0x1A0005600                   \n           0x1A00E58CB                   \n           0x1A0003027                   \n           0x1A00033A0                   \n           0x1A0003430                   \n           0x1A0003760                   \n           0x1A0003C60                   \n           0x1A0003D70                   \n           0x1A0004461                   \n           0x1A00F3259                   \n           0x1A00F32D1                   \n           0x1A00F3A0A                   \n           0x1A0007707                   \n           0x1A0007735                   \n           0x1A0004789                   \n           0x1A0013C1B                   \n           0x1A0013CF8                   \n           0x1A0013DB3                   \n           0x1A0004B9F                   \n           0x1A000A8F2                   \n           0x1A0005600                   \n           0x1A0006120                   \n           0x1A00061C0                   \n           0x1A0006240                   \n           0x1A0006420                   \n           0x1A0016528                   \n           0x1A000702C                   \n           0x1A0007396                   \n           0x1A0007707                   \n           0x1A0007735                   \n           0x1A0007EFD                   \n           0x1A0008C70                   \n           0x1A000A570                   \n           0x1A000A7CC                   \n           0x1A000A8F2                   \n           0x1A000A9EF                   \n           0x1A000ACE2                   \n           0x1A000AEAF                   \n           0x1A000AFA9                   \n           0x1A000B06F                   \n           0x1A000B5B0                   \n           0x1A000B760                   \n           0x1A000B7F0                   \n           0x1A000B880                   \n           0x1A000BB40                   \n           0x1A000C270                   \n           0x1A000CBD0                   \n           0x1A000CF67                   \n           0x1A000D164                   \n           0x1A000D4C0                   \n           0x1A000DEB0                   \n           0x1A000E2A4                   \n           0x1A000E333                   \n           0x1A000E478                   \n           0x1A000E4E5                   \n           0x1A000E5A3                   \n           0x1A000E6D0                   \n           0x1A000E810                   \n           0x1A000E900                   \n           0x1A0010101                   \n           0x1A0010706                   \n           0x1A001083A                   \n           0x1A00116C8                   \n           0x1A0011D30                   \n           0x1A00120F0                   \n           0x1A0013190                   \n           0x1A0013C1B                   \n           0x1A0013CF8                   \n           0x1A0013DB3                   \n           0x1A0014240                   \n           0x1A0014350                   \n           0x1A00143C0                   \n           0x1A0015B40                   \n           0x1A0015C40                   \n           0x1A0015FA0                   \n           0x1A00163A0                   \n           0x1A00163A0                   \n           0x1A0016528                   \n           0x1A0016A94                   \n           0x1A0016D86                   \n           0x1A00171C3                   \n           0x1A0017262                   \n           0x1A00173D1                   \n           0x1A0017690                   \n           0x1A0017CA5                   \n           0x1A0017D32                   \n           0x1A001829E                   \n           0x1A00185A2                   \n           0x1A001864A                   \n           0x1A001A4F0                   \n           0x1A001A704                   \n           0x1A001AA5E                   \n           0x1A001AB1F                   \n           0x1A001AD32                   \n           0x1A00DD936                   \n           0x1A00DE0C8                   \n           0x1A00DE1A0                   \n           0x1A00DE271                   \n           0x1A00DE82B                   \n           0x1A00DEF65                   \n           0x1A00DF0ED                   \n           0x1A00DF590                   \n           0x1A00E0690                   \n           0x1A00E0B9E                   \n           0x1A00E0C0C                   \n           0x1A00E0E99                   \n           0x1A00E1040                   \n           0x1A00E1B2A                   \n           0x1A00E1CE0                   \n           0x1A00E1EC0                   \n           0x1A00E243D                   \n           0x1A00E24EB                   \n           0x1A00E25F0                   \n           0x1A00E26EB                   \n           0x1A00E2980                   \n           0x1A00E2DDA                   \n           0x1A00E2F13                   \n           0x1A00E30A3                   \n           0x1A00E30EA                   \n           0x1A00E3158                   \n           0x1A00E34D0                   \n           0x1A00E38D6                   \n           0x1A00E3D51                   \n           0x1A00E3FC3                   \n           0x1A00E4D9C                   \n           0x1A00E55B7                   \n           0x1A00E58CB                   \n           0x1A00E5FE0                   \n           0x1A00E6153                   \n           0x1A00E6DA0                   \n           0x1A00E7B44                   \n           0x1A00E7BF7                   \n           0x1A00E7C57                   \n           0x1A00E7EF0                   \n           0x1A00E7F50                   \n           0x1A00E7FF1                   \n           0x1A00E8D68                   \n           0x1A00E8ED0                   \n           0x1A00E90E4                   \n           0x1A00E9330                   \n           0x1A00E94AE                   \n           0x1A00E9666                   \n           0x1A00EA99B                   \n           0x1A00EAD24                   \n           0x1A00EAE01                   \n           0x1A00E1B2A                   \n           0x1A00EB495                   \n           0x1A00EB820                   \n           0x1A00EBA51                   \n           0x1A00EBBC7                   \n           0x1A00EBF43                   \n           0x1A00EC91F                   \n           0x1A00ECABF                   \n           0x1A00ECB54                   \n           0x1A00ECCBF                   \n           0x1A00ECE9B                   \n           0x1A00ECFC5                   \n           0x1A00EE080                   \n           0x1A00EE350                   \n           0x1A00EE426                   \n           0x1A00EE531                   \n           0x1A00EE600                   \n           0x1A00EF563                   \n           0x1A00EF94A                   \n           0x1A00F05F8                   \n           0x1A00F0BB9                   \n           0x1A00F0E1A                   \n           0x1A00F1050                   \n           0x1A00F146B                   \n           0x1A00F1680                   \n           0x1A00F1A70                   \n           0x1A00F2FAF                   \n           0x1A00F3259                   \n           0x1A00F32D1                   \n           0x1A00F3A0A                   \n           0x1A00F3F89                   \n           0x1A00F4166                   \n           0x1A00F4598                   \n           0x1A00F4830                   \n           0x1A00F4A2B                   \n           0x1A00F4AC6                   \n           0x1A00F4D9E                   \n           0x1A00F4EE1                   \n           0x1A00F5568                   \n           0x1A00F58F6                   \n           0x1A00F5BE2                   \n           0x1A00F5D90                   \n           0x1A00F6A44                   \n           0x1A00F6F65                   \n           0x1A00F7158                   \n           0x1A00F73E0                   \n           0x1A00F74D0                   \n           0x1A00F7660                   \n           0x1A00F7DA0                   \n           0x1A00F84D0                   \n           0x1A00F92E6                   \n           0x1A00F93A2                   \n           0x1A00F93EC                   \n           0x1A00F9EF0                   \n           0x1A00FA1E0                   \n           0x1A00FA6B5                   \n           0x1A00FAD70                   \n           0x1A00FB010                   \n           0x1A00FB370                   \n           0x1A00FB42A                   \n           0x1A00FB772                   \n           0x1A00FBE06                   \n           0x1A00FC190                   \n           0x1A00FC5C0                   \n           0x1A00FC700                   \n           0x1A00FD2B0                   \n           0x1A00FD7B0                   \n           0x1A00FDCD7                   \n           0x1A00FE1D5                   \n           0x1A00FE5BE                   \n           0x1A00FEE90                   \n           0x1A00FEFA6                   \n           0x1A00FF4F2                   \n           0x1A0100011                   \n           0x1A0101054                   \n           0x1A01010EF                   \n           0x1A0101700                   \n           0x1A01019ED                   \n           0x1A0101A7E                   \n\nencrypt data using chaskey (2 matches)\nnamespace  data-manipulation/encryption/chaskey\nscope      function                            \nmatches    0x1A00E3DEC                         \n           0x1A00F3D4C                         \n\nencrypt data using RC4 PRGA (40 matches)\nnamespace  data-manipulation/encryption/rc4\nscope      function                        \nmatches    0x1A000BB10                     \n           0x1A001E84C                     \n           0x1A00291E8                     \n           0x1A002F9D0                     \n           0x1A0036418                     \n           0x1A00376B0                     \n           0x1A0038770                     \n           0x1A00435A4                     \n           0x1A00444F0                     \n           0x1A004735C                     \n           0x1A0052F70                     \n           0x1A0054044                     \n           0x1A0057370                     \n           0x1A005DDBC                     \n           0x1A005E468                     \n           0x1A006B07C                     \n           0x1A006D66C                     \n           0x1A0077C70                     \n           0x1A007EF24                     \n           0x1A00814D0                     \n           0x1A0084494                     \n           0x1A008B54C                     \n           0x1A008FF14                     \n           0x1A009A26C                     \n           0x1A00A0524                     \n           0x1A00AA288                     \n           0x1A00AE9A8                     \n           0x1A00B1248                     \n           0x1A00B1484                     \n           0x1A00B6868                     \n           0x1A00B6F28                     \n           0x1A00B792C                     \n           0x1A00BADEC                     \n           0x1A00BC3A0                     \n           0x1A00BF0FC                     \n           0x1A00CBEE4                     \n           0x1A00CEBB0                     \n           0x1A00CFEFC                     \n           0x1A00DF1FC                     \n           0x1A00FB590                     \n\nhash data using fnv\nnamespace    data-manipulation/hashing/fnv                                      \ndescription  can be any Fowler-Noll-Vo (FNV) hash variant, including FNV-1,     \n             FNV-1a, FNV-0                                                      \nscope        function                                                           \nmatches      0x1A001AF38                                                        \n\nauthenticate HMAC (3 matches)\nnamespace  data-manipulation/hmac\nscope      function              \nmatches    0x1A001F334           \n           0x1A00254A4           \n           0x1A00A0754           \n\naccess PEB ldr_data (2 matches)\nnamespace  linking/runtime-linking\nscope      basic block            \nmatches    0x1A00DD0F0            \n           0x1A00F55CC            \n\nparse PE header (94 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x1A0018FB0 \n           0x1A00199C0 \n           0x1A001C520 \n           0x1A001D360 \n           0x1A001F334 \n           0x1A0020FF4 \n           0x1A0022D54 \n           0x1A00254A4 \n           0x1A00267D4 \n           0x1A0027034 \n           0x1A002BC6C \n           0x1A002DCA4 \n           0x1A002FBD8 \n           0x1A0032440 \n           0x1A00340B0 \n           0x1A0035C5C \n           0x1A0036898 \n           0x1A0038168 \n           0x1A003A92C \n           0x1A003BEC0 \n           0x1A003CE44 \n           0x1A003D408 \n           0x1A003DAB8 \n           0x1A003F038 \n           0x1A0040F4C \n           0x1A0042354 \n           0x1A0042AE8 \n           0x1A00485AC \n           0x1A004903C \n           0x1A0049664 \n           0x1A004A098 \n           0x1A004AF78 \n           0x1A004B880 \n           0x1A004C014 \n           0x1A004E88C \n           0x1A005432C \n           0x1A0057778 \n           0x1A0058BF0 \n           0x1A005BD5C \n           0x1A0062320 \n           0x1A006319C \n           0x1A00661D8 \n           0x1A0069790 \n           0x1A006A3B8 \n           0x1A006B9B0 \n           0x1A006C52C \n           0x1A006D9E8 \n           0x1A006E85C \n           0x1A006FD78 \n           0x1A0072278 \n           0x1A0072D6C \n           0x1A0073A3C \n           0x1A0075C0C \n           0x1A007878C \n           0x1A007AAA0 \n           0x1A007B6E8 \n           0x1A0082814 \n           0x1A00853A4 \n           0x1A0089920 \n           0x1A008BA40 \n           0x1A0091D90 \n           0x1A0092C0C \n           0x1A009435C \n           0x1A0094B44 \n           0x1A0096FD0 \n           0x1A009787C \n           0x1A0098274 \n           0x1A009AC38 \n           0x1A00A0754 \n           0x1A00A3EE0 \n           0x1A00A4A2C \n           0x1A00A5730 \n           0x1A00A699C \n           0x1A00A8680 \n           0x1A00AB03C \n           0x1A00AD12C \n           0x1A00AD840 \n           0x1A00AF074 \n           0x1A00B1918 \n           0x1A00B44BC \n           0x1A00B5C18 \n           0x1A00BE4C4 \n           0x1A00C10FC \n           0x1A00C3FE0 \n           0x1A00CA330 \n           0x1A00CCB68 \n           0x1A00D1CC8 \n           0x1A00D259C \n           0x1A00D5144 \n           0x1A00D69F8 \n           0x1A00D7DB8 \n           0x1A00D9090 \n           0x1A00DA2C4 \n           0x1A00DB454 \n\nresolve function by parsing PE exports (3 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x1A0018FB0 \n           0x1A00199C0 \n           0x1A0019B94 \n\n\n\n","very_verbose":"md5                     91c49a21332198c2eba50d0d0fa30304                        \nsha1                    b5a78e977ec7d88bb9c890a6055b5a26d11ff706                \nsha256                  880520a4ef03fd51e8fb31f0ea3b1afe150958b872fe793f34d6a62…\npath                    /tmp/sdm_unpack_wflthx9i/vi-019f798ddabc77d2976e0d64376…\ntimestamp               2026-07-19 14:19:45.584819                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x1A0000000                                             \nrules                   /tmp/_MEILI3dBP/rules                                   \nfunction count          1179                                                    \nlibrary function count  0                                                       \ntotal feature count     208868                                                  \n\nPEB access (7 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Debugger Detection::Process Environment   \n            Block [B0001.019]                                                   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nbasic block @ 0x1A0016574 in function 0x1A0016574\n  or:\n    characteristic: peb access @ 0x1A0016658\n\ncalculate modulo 256 via x86 assembly (library rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x1A00DD399\n  and:\n    or:\n      arch: amd64\n    mnemonic: and @ 0x1A00DD399\n    or:\n      number: 0xFF @ 0x1A00DD399\n\ncontain loop (352 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x1A0001000\n  or:\n    characteristic: tight loop @ 0x1A000102A\n\nget OS version (2 matches, only showing first match of library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x1A001A98C\n  or:\n    and:\n      match: PEB access @ 0x1A001A98C\n        or:\n          characteristic: peb access @ 0x1A001A9BF\n      or:\n        and:\n          arch: amd64\n          or:\n            offset: 0x120 = PEB->OSBuildNumber @ 0x1A001AE16\n\ncheck for PEB NtGlobalFlag flag\nnamespace   anti-analysis/anti-debugging/debugger-detection                     \nauthor      moritz.raabe@mandiant.com                                           \nscope       function                                                            \nmbc         Anti-Behavioral Analysis::Debugger Detection::Process Environment   \n            Block NtGlobalFlag [B0001.036]                                      \nreferences  Practical Malware Analysis, Chapter 16, p. 355,                     \n            https://www.geoffchappell.com/studies/windows/win32/ntdll/structs/p…\nfunction @ 0x1A00F3D4C\n  and:\n    basic block:\n      and:\n        match: PEB access @ 0x1A00F470C\n          or:\n            characteristic: peb access @ 0x1A00F47D4\n        or:\n          and:\n            arch: amd64\n            offset: 0xBC = PEB.NtGlobalFlag @ 0x1A00F47DD\n    number: 0x70 = (FLG_HEAP_ENABLE_TAIL_CHECK | FLG_HEAP_ENABLE_FREE_CHECK | \nFLG_HEAP_VALIDATE_PARAMETERS) @ 0x1A00F47E3, 0x1A00F47F6\n\nexecute anti-debugging instructions (7 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection                      \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \nmbc        Anti-Behavioral Analysis::Debugger Detection::Anti-debugging         \n           Instructions [B0001.034]                                             \nfunction @ 0x1A0001188\n  or:\n    count(mnemonic(rdtsc)): 2 or more @ 0x1A00011A3, 0x1A00012AD, 0x1A0001342, 0x1A0001401\nfunction @ 0x1A0001678\n  or:\n    count(mnemonic(rdtsc)): 2 or more @ 0x1A0001693, 0x1A00017A8, 0x1A0001879, 0x1A00019A1, and 1 more...\nfunction @ 0x1A00049C0\n  or:\n    count(mnemonic(rdtsc)): 2 or more @ 0x1A0013CE3, 0x1A0013D20, 0x1A0013DFE\nfunction @ 0x1A0013B84\n  or:\n    count(mnemonic(rdtsc)): 2 or more @ 0x1A0013CE3, 0x1A0013D20, 0x1A0013DFE\nfunction @ 0x1A00DFF00\n  or:\n    count(mnemonic(rdtsc)): 2 or more @ 0x1A00E00A3, 0x1A00E00C3\nfunction @ 0x1A00F3D4C\n  or:\n    count(mnemonic(rdtsc)): 2 or more @ 0x1A00F3F6D, 0x1A00F3FA8, 0x1A00F4067, 0x1A00F44C1, and 2 more...\nfunction @ 0x1A00FCCC0\n  or:\n    count(mnemonic(rdtsc)): 2 or more @ 0x1A00FD142, 0x1A00FD324, 0x1A00FD5A9, 0x1A00FD80D\n\ncontain obfuscated stackstrings (321 matches)\nnamespace  anti-analysis/obfuscation/string/stackstring                         \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information::Indicator Removal  \n           from Tools [T1027.005]                                               \nmbc        Anti-Static Analysis::Executable Code Obfuscation::Argument          \n           Obfuscation [B0032.020], Anti-Static Analysis::Executable Code       \n           Obfuscation::Stack Strings [B0032.017]                               \nbasic block @ 0x1A001C561 in function 0x1A001C520\n  characteristic: stack string @ 0x1A001C561\nbasic block @ 0x1A001D3A1 in function 0x1A001D360\n  characteristic: stack string @ 0x1A001D3A1\nbasic block @ 0x1A001E887 in function 0x1A001E84C\n  characteristic: stack string @ 0x1A001E887\nbasic block @ 0x1A001F375 in function 0x1A001F334\n  characteristic: stack string @ 0x1A001F375\nbasic block @ 0x1A00206B5 in function 0x1A0020674\n  characteristic: stack string @ 0x1A00206B5\nbasic block @ 0x1A0021035 in function 0x1A0020FF4\n  characteristic: stack string @ 0x1A0021035\nbasic block @ 0x1A00227ED in function 0x1A00227AC\n  characteristic: stack string @ 0x1A00227ED\nbasic block @ 0x1A0022D95 in function 0x1A0022D54\n  characteristic: stack string @ 0x1A0022D95\nbasic block @ 0x1A0023999 in function 0x1A0023958\n  characteristic: stack string @ 0x1A0023999\nbasic block @ 0x1A00248B5 in function 0x1A0024874\n  characteristic: stack string @ 0x1A00248B5\nbasic block @ 0x1A00254E5 in function 0x1A00254A4\n  characteristic: stack string @ 0x1A00254E5\nbasic block @ 0x1A002624D in function 0x1A002620C\n  characteristic: stack string @ 0x1A002624D\nbasic block @ 0x1A0026815 in function 0x1A00267D4\n  characteristic: stack string @ 0x1A0026815\nbasic block @ 0x1A0027075 in function 0x1A0027034\n  characteristic: stack string @ 0x1A0027075\nbasic block @ 0x1A0027709 in function 0x1A00276C8\n  characteristic: stack string @ 0x1A0027709\nbasic block @ 0x1A0027EB9 in function 0x1A0027E78\n  characteristic: stack string @ 0x1A0027EB9\nbasic block @ 0x1A00285D1 in function 0x1A0028590\n  characteristic: stack string @ 0x1A00285D1\nbasic block @ 0x1A0028BFD in function 0x1A0028BBC\n  characteristic: stack string @ 0x1A0028BFD\nbasic block @ 0x1A0029220 in function 0x1A00291E8\n  characteristic: stack string @ 0x1A0029220\nbasic block @ 0x1A00294E0 in function 0x1A00294A8\n  characteristic: stack string @ 0x1A00294E0\nbasic block @ 0x1A002A1F9 in function 0x1A002A1B8\n  characteristic: stack string @ 0x1A002A1F9\nbasic block @ 0x1A002AA0F in function 0x1A002A9D4\n  characteristic: stack string @ 0x1A002AA0F\nbasic block @ 0x1A002BCAD in function 0x1A002BC6C\n  characteristic: stack string @ 0x1A002BCAD\nbasic block @ 0x1A002DCE5 in function 0x1A002DCA4\n  characteristic: stack string @ 0x1A002DCE5\nbasic block @ 0x1A002F3AD in function 0x1A002F36C\n  characteristic: stack string @ 0x1A002F3AD\nbasic block @ 0x1A002FC19 in function 0x1A002FBD8\n  characteristic: stack string @ 0x1A002FC19\nbasic block @ 0x1A0031059 in function 0x1A0031018\n  characteristic: stack string @ 0x1A0031059\nbasic block @ 0x1A00317F1 in function 0x1A00317B0\n  characteristic: stack string @ 0x1A00317F1\nbasic block @ 0x1A0032481 in function 0x1A0032440\n  characteristic: stack string @ 0x1A0032481\nbasic block @ 0x1A0032B5D in function 0x1A0032B1C\n  characteristic: stack string @ 0x1A0032B5D\nbasic block @ 0x1A0033120 in function 0x1A00330E8\n  characteristic: stack string @ 0x1A0033120\nbasic block @ 0x1A00340F1 in function 0x1A00340B0\n  characteristic: stack string @ 0x1A00340F1\nbasic block @ 0x1A00347A5 in function 0x1A0034764\n  characteristic: stack string @ 0x1A00347A5\nbasic block @ 0x1A0034D4C in function 0x1A0034D14\n  characteristic: stack string @ 0x1A0034D4C\nbasic block @ 0x1A0035653 in function 0x1A0035618\n  characteristic: stack string @ 0x1A0035653\nbasic block @ 0x1A0035C9D in function 0x1A0035C5C\n  characteristic: stack string @ 0x1A0035C9D\nbasic block @ 0x1A0036450 in function 0x1A0036418\n  characteristic: stack string @ 0x1A0036450\nbasic block @ 0x1A00368D9 in function 0x1A0036898\n  characteristic: stack string @ 0x1A00368D9\nbasic block @ 0x1A0036ED8 in function 0x1A0036EA0\n  characteristic: stack string @ 0x1A0036ED8\nbasic block @ 0x1A0037145 in function 0x1A0037104\n  characteristic: stack string @ 0x1A0037145\nbasic block @ 0x1A0037910 in function 0x1A00378D8\n  characteristic: stack string @ 0x1A0037910\nbasic block @ 0x1A00381A9 in function 0x1A0038168\n  characteristic: stack string @ 0x1A00381A9\nbasic block @ 0x1A00387A8 in function 0x1A0038770\n  characteristic: stack string @ 0x1A00387A8\nbasic block @ 0x1A0038A29 in function 0x1A00389E8\n  characteristic: stack string @ 0x1A0038A29\nbasic block @ 0x1A0038FDC in function 0x1A0038FA4\n  characteristic: stack string @ 0x1A0038FDC\nbasic block @ 0x1A003927D in function 0x1A003923C\n  characteristic: stack string @ 0x1A003927D\nbasic block @ 0x1A0039871 in function 0x1A0039830\n  characteristic: stack string @ 0x1A0039871\nbasic block @ 0x1A0039DF5 in function 0x1A0039DB4\n  characteristic: stack string @ 0x1A0039DF5\nbasic block @ 0x1A003A395 in function 0x1A003A354\n  characteristic: stack string @ 0x1A003A395\nbasic block @ 0x1A003A96D in function 0x1A003A92C\n  characteristic: stack string @ 0x1A003A96D\nbasic block @ 0x1A003B2D5 in function 0x1A003B294\n  characteristic: stack string @ 0x1A003B2D5\nbasic block @ 0x1A003B8D5 in function 0x1A003B894\n  characteristic: stack string @ 0x1A003B8D5\nbasic block @ 0x1A003BF01 in function 0x1A003BEC0\n  characteristic: stack string @ 0x1A003BF01\nbasic block @ 0x1A003C63D in function 0x1A003C5FC\n  characteristic: stack string @ 0x1A003C63D\nbasic block @ 0x1A003CE85 in function 0x1A003CE44\n  characteristic: stack string @ 0x1A003CE85\nbasic block @ 0x1A003D449 in function 0x1A003D408\n  characteristic: stack string @ 0x1A003D449\nbasic block @ 0x1A003DAF9 in function 0x1A003DAB8\n  characteristic: stack string @ 0x1A003DAF9\nbasic block @ 0x1A003E229 in function 0x1A003E1E8\n  characteristic: stack string @ 0x1A003E229\nbasic block @ 0x1A003E98C in function 0x1A003E954\n  characteristic: stack string @ 0x1A003E98C\nbasic block @ 0x1A003F079 in function 0x1A003F038\n  characteristic: stack string @ 0x1A003F079\nbasic block @ 0x1A003FDB5 in function 0x1A003FD74\n  characteristic: stack string @ 0x1A003FDB5\nbasic block @ 0x1A00405F5 in function 0x1A00405B4\n  characteristic: stack string @ 0x1A00405F5\nbasic block @ 0x1A0040F8D in function 0x1A0040F4C\n  characteristic: stack string @ 0x1A0040F8D\nbasic block @ 0x1A0041961 in function 0x1A0041920\n  characteristic: stack string @ 0x1A0041961\nbasic block @ 0x1A0042395 in function 0x1A0042354\n  characteristic: stack string @ 0x1A0042395\nbasic block @ 0x1A0042B29 in function 0x1A0042AE8\n  characteristic: stack string @ 0x1A0042B29\nbasic block @ 0x1A004334C in function 0x1A0043314\n  characteristic: stack string @ 0x1A004334C\nbasic block @ 0x1A00435DC in function 0x1A00435A4\n  characteristic: stack string @ 0x1A00435DC\nbasic block @ 0x1A0043879 in function 0x1A0043838\n  characteristic: stack string @ 0x1A0043879\nbasic block @ 0x1A0043F79 in function 0x1A0043F38\n  characteristic: stack string @ 0x1A0043F79\nbasic block @ 0x1A0044528 in function 0x1A00444F0\n  characteristic: stack string @ 0x1A0044528\nbasic block @ 0x1A0044747 in function 0x1A004470C\n  characteristic: stack string @ 0x1A0044747\nbasic block @ 0x1A0044C75 in function 0x1A0044C34\n  characteristic: stack string @ 0x1A0044C75\nbasic block @ 0x1A004524D in function 0x1A004520C\n  characteristic: stack string @ 0x1A004524D\nbasic block @ 0x1A0045A6D in function 0x1A0045A2C\n  characteristic: stack string @ 0x1A0045A6D\nbasic block @ 0x1A0046045 in function 0x1A0046004\n  characteristic: stack string @ 0x1A0046045\nbasic block @ 0x1A0046611 in function 0x1A00465D0\n  characteristic: stack string @ 0x1A0046611\nbasic block @ 0x1A0046BDD in function 0x1A0046B9C\n  characteristic: stack string @ 0x1A0046BDD\nbasic block @ 0x1A00475B1 in function 0x1A0047570\n  characteristic: stack string @ 0x1A00475B1\nbasic block @ 0x1A0047AD5 in function 0x1A0047A94\n  characteristic: stack string @ 0x1A0047AD5\nbasic block @ 0x1A0048021 in function 0x1A0047FE0\n  characteristic: stack string @ 0x1A0048021\nbasic block @ 0x1A00485ED in function 0x1A00485AC\n  characteristic: stack string @ 0x1A00485ED\nbasic block @ 0x1A004907D in function 0x1A004903C\n  characteristic: stack string @ 0x1A004907D\nbasic block @ 0x1A00496A5 in function 0x1A0049664\n  characteristic: stack string @ 0x1A00496A5\nbasic block @ 0x1A004A0D9 in function 0x1A004A098\n  characteristic: stack string @ 0x1A004A0D9\nbasic block @ 0x1A004A9D1 in function 0x1A004A990\n  characteristic: stack string @ 0x1A004A9D1\nbasic block @ 0x1A004AFB9 in function 0x1A004AF78\n  characteristic: stack string @ 0x1A004AFB9\nbasic block @ 0x1A004B8C1 in function 0x1A004B880\n  characteristic: stack string @ 0x1A004B8C1\nbasic block @ 0x1A004C055 in function 0x1A004C014\n  characteristic: stack string @ 0x1A004C055\nbasic block @ 0x1A004C7CD in function 0x1A004C78C\n  characteristic: stack string @ 0x1A004C7CD\nbasic block @ 0x1A004CDED in function 0x1A004CDAC\n  characteristic: stack string @ 0x1A004CDED\nbasic block @ 0x1A004D435 in function 0x1A004D3F4\n  characteristic: stack string @ 0x1A004D435\nbasic block @ 0x1A004E113 in function 0x1A004E0D8\n  characteristic: stack string @ 0x1A004E113\nbasic block @ 0x1A004E8CD in function 0x1A004E88C\n  characteristic: stack string @ 0x1A004E8CD\nbasic block @ 0x1A004F067 in function 0x1A004F02C\n  characteristic: stack string @ 0x1A004F067\nbasic block @ 0x1A00507E9 in function 0x1A00507A8\n  characteristic: stack string @ 0x1A00507E9\nbasic block @ 0x1A00517EF in function 0x1A00517B4\n  characteristic: stack string @ 0x1A00517EF\nbasic block @ 0x1A00520C9 in function 0x1A0052088\n  characteristic: stack string @ 0x1A00520C9\nbasic block @ 0x1A005261B in function 0x1A00525E0\n  characteristic: stack string @ 0x1A005261B\nbasic block @ 0x1A0053411 in function 0x1A00533D0\n  characteristic: stack string @ 0x1A0053411\nbasic block @ 0x1A0053995 in function 0x1A0053954\n  characteristic: stack string @ 0x1A0053995\nbasic block @ 0x1A005407C in function 0x1A0054044\n  characteristic: stack string @ 0x1A005407C\nbasic block @ 0x1A005436D in function 0x1A005432C\n  characteristic: stack string @ 0x1A005436D\nbasic block @ 0x1A005540B in function 0x1A00553D0\n  characteristic: stack string @ 0x1A005540B\nbasic block @ 0x1A00562AD in function 0x1A005626C\n  characteristic: stack string @ 0x1A00562AD\nbasic block @ 0x1A00577B9 in function 0x1A0057778\n  characteristic: stack string @ 0x1A00577B9\nbasic block @ 0x1A005854F in function 0x1A0058514\n  characteristic: stack string @ 0x1A005854F\nbasic block @ 0x1A0058C31 in function 0x1A0058BF0\n  characteristic: stack string @ 0x1A0058C31\nbasic block @ 0x1A0059915 in function 0x1A00598D4\n  characteristic: stack string @ 0x1A0059915\nbasic block @ 0x1A0059F85 in function 0x1A0059F44\n  characteristic: stack string @ 0x1A0059F85\nbasic block @ 0x1A005A711 in function 0x1A005A6D0\n  characteristic: stack string @ 0x1A005A711\nbasic block @ 0x1A005ACCD in function 0x1A005AC8C\n  characteristic: stack string @ 0x1A005ACCD\nbasic block @ 0x1A005B211 in function 0x1A005B1D0\n  characteristic: stack string @ 0x1A005B211\nbasic block @ 0x1A005B805 in function 0x1A005B7C4\n  characteristic: stack string @ 0x1A005B805\nbasic block @ 0x1A005BD9D in function 0x1A005BD5C\n  characteristic: stack string @ 0x1A005BD9D\nbasic block @ 0x1A005C61D in function 0x1A005C5DC\n  characteristic: stack string @ 0x1A005C61D\nbasic block @ 0x1A005CB91 in function 0x1A005CB50\n  characteristic: stack string @ 0x1A005CB91\nbasic block @ 0x1A005D2DF in function 0x1A005D2A4\n  characteristic: stack string @ 0x1A005D2DF\nbasic block @ 0x1A005D7D1 in function 0x1A005D790\n  characteristic: stack string @ 0x1A005D7D1\nbasic block @ 0x1A005E710 in function 0x1A005E6D8\n  characteristic: stack string @ 0x1A005E710\nbasic block @ 0x1A005E9C3 in function 0x1A005E988\n  characteristic: stack string @ 0x1A005E9C3\nbasic block @ 0x1A0060293 in function 0x1A0060258\n  characteristic: stack string @ 0x1A0060293\nbasic block @ 0x1A0060FD9 in function 0x1A0060F98\n  characteristic: stack string @ 0x1A0060FD9\nbasic block @ 0x1A006157B in function 0x1A0061540\n  characteristic: stack string @ 0x1A006157B\nbasic block @ 0x1A0062361 in function 0x1A0062320\n  characteristic: stack string @ 0x1A0062361\nbasic block @ 0x1A00631DD in function 0x1A006319C\n  characteristic: stack string @ 0x1A00631DD\nbasic block @ 0x1A0064C99 in function 0x1A0064C58\n  characteristic: stack string @ 0x1A0064C99\nbasic block @ 0x1A00659C5 in function 0x1A0065984\n  characteristic: stack string @ 0x1A00659C5\nbasic block @ 0x1A0066219 in function 0x1A00661D8\n  characteristic: stack string @ 0x1A0066219\nbasic block @ 0x1A0066ADD in function 0x1A0066A9C\n  characteristic: stack string @ 0x1A0066ADD\nbasic block @ 0x1A006709F in function 0x1A0067064\n  characteristic: stack string @ 0x1A006709F\nbasic block @ 0x1A006774D in function 0x1A006770C\n  characteristic: stack string @ 0x1A006774D\nbasic block @ 0x1A0067DFC in function 0x1A0067DC4\n  characteristic: stack string @ 0x1A0067DFC\nbasic block @ 0x1A00682BF in function 0x1A0068284\n  characteristic: stack string @ 0x1A00682BF\nbasic block @ 0x1A0068A3B in function 0x1A0068A00\n  characteristic: stack string @ 0x1A0068A3B\nbasic block @ 0x1A006916D in function 0x1A006912C\n  characteristic: stack string @ 0x1A006916D\nbasic block @ 0x1A00697D1 in function 0x1A0069790\n  characteristic: stack string @ 0x1A00697D1\nbasic block @ 0x1A006A3F9 in function 0x1A006A3B8\n  characteristic: stack string @ 0x1A006A3F9\nbasic block @ 0x1A006B0B4 in function 0x1A006B07C\n  characteristic: stack string @ 0x1A006B0B4\nbasic block @ 0x1A006B3FD in function 0x1A006B3BC\n  characteristic: stack string @ 0x1A006B3FD\nbasic block @ 0x1A006B9F1 in function 0x1A006B9B0\n  characteristic: stack string @ 0x1A006B9F1\nbasic block @ 0x1A006C56D in function 0x1A006C52C\n  characteristic: stack string @ 0x1A006C56D\nbasic block @ 0x1A006D005 in function 0x1A006CFC4\n  characteristic: stack string @ 0x1A006D005\nbasic block @ 0x1A006D6A4 in function 0x1A006D66C\n  characteristic: stack string @ 0x1A006D6A4\nbasic block @ 0x1A006DA29 in function 0x1A006D9E8\n  characteristic: stack string @ 0x1A006DA29\nbasic block @ 0x1A006E201 in function 0x1A006E1C0\n  characteristic: stack string @ 0x1A006E201\nbasic block @ 0x1A006E89D in function 0x1A006E85C\n  characteristic: stack string @ 0x1A006E89D\nbasic block @ 0x1A006F963 in function 0x1A006F928\n  characteristic: stack string @ 0x1A006F963\nbasic block @ 0x1A006FDB9 in function 0x1A006FD78\n  characteristic: stack string @ 0x1A006FDB9\nbasic block @ 0x1A0071960 in function 0x1A0071928\n  characteristic: stack string @ 0x1A0071960\nbasic block @ 0x1A0071C44 in function 0x1A0071C0C\n  characteristic: stack string @ 0x1A0071C44\nbasic block @ 0x1A0071ECB in function 0x1A0071E90\n  characteristic: stack string @ 0x1A0071ECB\nbasic block @ 0x1A00722B9 in function 0x1A0072278\n  characteristic: stack string @ 0x1A00722B9\nbasic block @ 0x1A0072DAD in function 0x1A0072D6C\n  characteristic: stack string @ 0x1A0072DAD\nbasic block @ 0x1A0073A7D in function 0x1A0073A3C\n  characteristic: stack string @ 0x1A0073A7D\nbasic block @ 0x1A0075685 in function 0x1A0075644\n  characteristic: stack string @ 0x1A0075685\nbasic block @ 0x1A0075C4D in function 0x1A0075C0C\n  characteristic: stack string @ 0x1A0075C4D\nbasic block @ 0x1A0076EEC in function 0x1A0076EB4\n  characteristic: stack string @ 0x1A0076EEC\nbasic block @ 0x1A00773E5 in function 0x1A00773A4\n  characteristic: stack string @ 0x1A00773E5\nbasic block @ 0x1A0077CAB in function 0x1A0077C70\n  characteristic: stack string @ 0x1A0077CAB\nbasic block @ 0x1A00780A5 in function 0x1A0078064\n  characteristic: stack string @ 0x1A00780A5\nbasic block @ 0x1A00787CD in function 0x1A007878C\n  characteristic: stack string @ 0x1A00787CD\nbasic block @ 0x1A007A1D5 in function 0x1A007A194\n  characteristic: stack string @ 0x1A007A1D5\nbasic block @ 0x1A007AAE1 in function 0x1A007AAA0\n  characteristic: stack string @ 0x1A007AAE1\nbasic block @ 0x1A007B729 in function 0x1A007B6E8\n  characteristic: stack string @ 0x1A007B729\nbasic block @ 0x1A007D50D in function 0x1A007D4CC\n  characteristic: stack string @ 0x1A007D50D\nbasic block @ 0x1A007DD79 in function 0x1A007DD38\n  characteristic: stack string @ 0x1A007DD79\nbasic block @ 0x1A007E3A5 in function 0x1A007E364\n  characteristic: stack string @ 0x1A007E3A5\nbasic block @ 0x1A007EF5F in function 0x1A007EF24\n  characteristic: stack string @ 0x1A007EF5F\nbasic block @ 0x1A007F6F1 in function 0x1A007F6B0\n  characteristic: stack string @ 0x1A007F6F1\nbasic block @ 0x1A007FC59 in function 0x1A007FC18\n  characteristic: stack string @ 0x1A007FC59\nbasic block @ 0x1A008094C in function 0x1A0080914\n  characteristic: stack string @ 0x1A008094C\nbasic block @ 0x1A008103B in function 0x1A0081000\n  characteristic: stack string @ 0x1A008103B\nbasic block @ 0x1A0081508 in function 0x1A00814D0\n  characteristic: stack string @ 0x1A0081508\nbasic block @ 0x1A0081AD9 in function 0x1A0081A98\n  characteristic: stack string @ 0x1A0081AD9\nbasic block @ 0x1A0082191 in function 0x1A0082150\n  characteristic: stack string @ 0x1A0082191\nbasic block @ 0x1A0082855 in function 0x1A0082814\n  characteristic: stack string @ 0x1A0082855\nbasic block @ 0x1A00836AB in function 0x1A0083670\n  characteristic: stack string @ 0x1A00836AB\nbasic block @ 0x1A0084701 in function 0x1A00846C0\n  characteristic: stack string @ 0x1A0084701\nbasic block @ 0x1A0084DD5 in function 0x1A0084D94\n  characteristic: stack string @ 0x1A0084DD5\nbasic block @ 0x1A00853E5 in function 0x1A00853A4\n  characteristic: stack string @ 0x1A00853E5\nbasic block @ 0x1A0086344 in function 0x1A008630C\n  characteristic: stack string @ 0x1A0086344\nbasic block @ 0x1A0086771 in function 0x1A0086730\n  characteristic: stack string @ 0x1A0086771\nbasic block @ 0x1A008702B in function 0x1A0086FF0\n  characteristic: stack string @ 0x1A008702B\nbasic block @ 0x1A0087A19 in function 0x1A00879D8\n  characteristic: stack string @ 0x1A0087A19\nbasic block @ 0x1A0088B0F in function 0x1A0088AD4\n  characteristic: stack string @ 0x1A0088B0F\nbasic block @ 0x1A0089961 in function 0x1A0089920\n  characteristic: stack string @ 0x1A0089961\nbasic block @ 0x1A008A448 in function 0x1A008A410\n  characteristic: stack string @ 0x1A008A448\nbasic block @ 0x1A008AA09 in function 0x1A008A9C8\n  characteristic: stack string @ 0x1A008AA09\nbasic block @ 0x1A008AFE1 in function 0x1A008AFA0\n  characteristic: stack string @ 0x1A008AFE1\nbasic block @ 0x1A008B584 in function 0x1A008B54C\n  characteristic: stack string @ 0x1A008B584\nbasic block @ 0x1A008B7F0 in function 0x1A008B7B8\n  characteristic: stack string @ 0x1A008B7F0\nbasic block @ 0x1A008BA81 in function 0x1A008BA40\n  characteristic: stack string @ 0x1A008BA81\nbasic block @ 0x1A008CDB5 in function 0x1A008CD74\n  characteristic: stack string @ 0x1A008CDB5\nbasic block @ 0x1A008DBFB in function 0x1A008DBC0\n  characteristic: stack string @ 0x1A008DBFB\nbasic block @ 0x1A008E72C in function 0x1A008E6F4\n  characteristic: stack string @ 0x1A008E72C\nbasic block @ 0x1A008EA59 in function 0x1A008EA18\n  characteristic: stack string @ 0x1A008EA59\nbasic block @ 0x1A008F3E1 in function 0x1A008F3A0\n  characteristic: stack string @ 0x1A008F3E1\nbasic block @ 0x1A008FF4F in function 0x1A008FF14\n  characteristic: stack string @ 0x1A008FF4F\nbasic block @ 0x1A0090367 in function 0x1A009032C\n  characteristic: stack string @ 0x1A0090367\nbasic block @ 0x1A00907E7 in function 0x1A00907AC\n  characteristic: stack string @ 0x1A00907E7\nbasic block @ 0x1A0091099 in function 0x1A0091058\n  characteristic: stack string @ 0x1A0091099\nbasic block @ 0x1A0091789 in function 0x1A0091748\n  characteristic: stack string @ 0x1A0091789\nbasic block @ 0x1A0091DD1 in function 0x1A0091D90\n  characteristic: stack string @ 0x1A0091DD1\nbasic block @ 0x1A0092C4D in function 0x1A0092C0C\n  characteristic: stack string @ 0x1A0092C4D\nbasic block @ 0x1A009439D in function 0x1A009435C\n  characteristic: stack string @ 0x1A009439D\nbasic block @ 0x1A0094B85 in function 0x1A0094B44\n  characteristic: stack string @ 0x1A0094B85\nbasic block @ 0x1A00953C1 in function 0x1A0095380\n  characteristic: stack string @ 0x1A00953C1\nbasic block @ 0x1A0095D51 in function 0x1A0095D10\n  characteristic: stack string @ 0x1A0095D51\nbasic block @ 0x1A0097011 in function 0x1A0096FD0\n  characteristic: stack string @ 0x1A0097011\nbasic block @ 0x1A00978BD in function 0x1A009787C\n  characteristic: stack string @ 0x1A00978BD\nbasic block @ 0x1A00982B5 in function 0x1A0098274\n  characteristic: stack string @ 0x1A00982B5\nbasic block @ 0x1A0099DA7 in function 0x1A0099D6C\n  characteristic: stack string @ 0x1A0099DA7\nbasic block @ 0x1A009A6E5 in function 0x1A009A6A4\n  characteristic: stack string @ 0x1A009A6E5\nbasic block @ 0x1A009AC79 in function 0x1A009AC38\n  characteristic: stack string @ 0x1A009AC79\nbasic block @ 0x1A009C457 in function 0x1A009C41C\n  characteristic: stack string @ 0x1A009C457\nbasic block @ 0x1A009DCA7 in function 0x1A009DC6C\n  characteristic: stack string @ 0x1A009DCA7\nbasic block @ 0x1A009E18B in function 0x1A009E150\n  characteristic: stack string @ 0x1A009E18B\nbasic block @ 0x1A009E699 in function 0x1A009E658\n  characteristic: stack string @ 0x1A009E699\nbasic block @ 0x1A009EC25 in function 0x1A009EBE4\n  characteristic: stack string @ 0x1A009EC25\nbasic block @ 0x1A009F203 in function 0x1A009F1C8\n  characteristic: stack string @ 0x1A009F203\nbasic block @ 0x1A009FBC7 in function 0x1A009FB8C\n  characteristic: stack string @ 0x1A009FBC7\nbasic block @ 0x1A00A0795 in function 0x1A00A0754\n  characteristic: stack string @ 0x1A00A0795\nbasic block @ 0x1A00A1AE1 in function 0x1A00A1AA0\n  characteristic: stack string @ 0x1A00A1AE1\nbasic block @ 0x1A00A2385 in function 0x1A00A2344\n  characteristic: stack string @ 0x1A00A2385\nbasic block @ 0x1A00A2C84 in function 0x1A00A2C4C\n  characteristic: stack string @ 0x1A00A2C84\nbasic block @ 0x1A00A2EA1 in function 0x1A00A2E60\n  characteristic: stack string @ 0x1A00A2EA1\nbasic block @ 0x1A00A3F21 in function 0x1A00A3EE0\n  characteristic: stack string @ 0x1A00A3F21\nbasic block @ 0x1A00A4A6D in function 0x1A00A4A2C\n  characteristic: stack string @ 0x1A00A4A6D\nbasic block @ 0x1A00A5044 in function 0x1A00A500C\n  characteristic: stack string @ 0x1A00A5044\nbasic block @ 0x1A00A52BC in function 0x1A00A5284\n  characteristic: stack string @ 0x1A00A52BC\nbasic block @ 0x1A00A5771 in function 0x1A00A5730\n  characteristic: stack string @ 0x1A00A5771\nbasic block @ 0x1A00A6415 in function 0x1A00A63D4\n  characteristic: stack string @ 0x1A00A6415\nbasic block @ 0x1A00A69DD in function 0x1A00A699C\n  characteristic: stack string @ 0x1A00A69DD\nbasic block @ 0x1A00A7049 in function 0x1A00A7008\n  characteristic: stack string @ 0x1A00A7049\nbasic block @ 0x1A00A76AD in function 0x1A00A766C\n  characteristic: stack string @ 0x1A00A76AD\nbasic block @ 0x1A00A86C1 in function 0x1A00A8680\n  characteristic: stack string @ 0x1A00A86C1\nbasic block @ 0x1A00A8DD8 in function 0x1A00A8DA0\n  characteristic: stack string @ 0x1A00A8DD8\nbasic block @ 0x1A00A9C21 in function 0x1A00A9BE0\n  characteristic: stack string @ 0x1A00A9C21\nbasic block @ 0x1A00AA4F9 in function 0x1A00AA4B8\n  characteristic: stack string @ 0x1A00AA4F9\nbasic block @ 0x1A00AAA89 in function 0x1A00AAA48\n  characteristic: stack string @ 0x1A00AAA89\nbasic block @ 0x1A00AB07D in function 0x1A00AB03C\n  characteristic: stack string @ 0x1A00AB07D\nbasic block @ 0x1A00AC43D in function 0x1A00AC3FC\n  characteristic: stack string @ 0x1A00AC43D\nbasic block @ 0x1A00AD16D in function 0x1A00AD12C\n  characteristic: stack string @ 0x1A00AD16D\nbasic block @ 0x1A00AD881 in function 0x1A00AD840\n  characteristic: stack string @ 0x1A00AD881\nbasic block @ 0x1A00AE3D9 in function 0x1A00AE398\n  characteristic: stack string @ 0x1A00AE3D9\nbasic block @ 0x1A00AE9E0 in function 0x1A00AE9A8\n  characteristic: stack string @ 0x1A00AE9E0\nbasic block @ 0x1A00AF0B5 in function 0x1A00AF074\n  characteristic: stack string @ 0x1A00AF0B5\nbasic block @ 0x1A00AFBCB in function 0x1A00AFB90\n  characteristic: stack string @ 0x1A00AFBCB\nbasic block @ 0x1A00B0AF9 in function 0x1A00B0AB8\n  characteristic: stack string @ 0x1A00B0AF9\nbasic block @ 0x1A00B14BC in function 0x1A00B1484\n  characteristic: stack string @ 0x1A00B14BC\nbasic block @ 0x1A00B1959 in function 0x1A00B1918\n  characteristic: stack string @ 0x1A00B1959\nbasic block @ 0x1A00B3191 in function 0x1A00B3150\n  characteristic: stack string @ 0x1A00B3191\nbasic block @ 0x1A00B3701 in function 0x1A00B36C0\n  characteristic: stack string @ 0x1A00B3701\nbasic block @ 0x1A00B3CB9 in function 0x1A00B3C78\n  characteristic: stack string @ 0x1A00B3CB9\nbasic block @ 0x1A00B44FD in function 0x1A00B44BC\n  characteristic: stack string @ 0x1A00B44FD\nbasic block @ 0x1A00B5229 in function 0x1A00B51E8\n  characteristic: stack string @ 0x1A00B5229\nbasic block @ 0x1A00B578B in function 0x1A00B5750\n  characteristic: stack string @ 0x1A00B578B\nbasic block @ 0x1A00B5C59 in function 0x1A00B5C18\n  characteristic: stack string @ 0x1A00B5C59\nbasic block @ 0x1A00B6389 in function 0x1A00B6348\n  characteristic: stack string @ 0x1A00B6389\nbasic block @ 0x1A00B6F60 in function 0x1A00B6F28\n  characteristic: stack string @ 0x1A00B6F60\nbasic block @ 0x1A00B73CD in function 0x1A00B738C\n  characteristic: stack string @ 0x1A00B73CD\nbasic block @ 0x1A00B7B99 in function 0x1A00B7B58\n  characteristic: stack string @ 0x1A00B7B99\nbasic block @ 0x1A00B8C90 in function 0x1A00B8C58\n  characteristic: stack string @ 0x1A00B8C90\nbasic block @ 0x1A00B8F55 in function 0x1A00B8F14\n  characteristic: stack string @ 0x1A00B8F55\nbasic block @ 0x1A00BA629 in function 0x1A00BA5E8\n  characteristic: stack string @ 0x1A00BA629\nbasic block @ 0x1A00BA629 in function 0x1A00BA5E8\n  characteristic: stack string @ 0x1A00BA629\nbasic block @ 0x1A00BAE24 in function 0x1A00BADEC\n  characteristic: stack string @ 0x1A00BAE24\nbasic block @ 0x1A00BB0C9 in function 0x1A00BB088\n  characteristic: stack string @ 0x1A00BB0C9\nbasic block @ 0x1A00BB675 in function 0x1A00BB634\n  characteristic: stack string @ 0x1A00BB675\nbasic block @ 0x1A00BC3DB in function 0x1A00BC3A0\n  characteristic: stack string @ 0x1A00BC3DB\nbasic block @ 0x1A00BC939 in function 0x1A00BC8F8\n  characteristic: stack string @ 0x1A00BC939\nbasic block @ 0x1A00BD099 in function 0x1A00BD058\n  characteristic: stack string @ 0x1A00BD099\nbasic block @ 0x1A00BDDD9 in function 0x1A00BDD98\n  characteristic: stack string @ 0x1A00BDDD9\nbasic block @ 0x1A00BE505 in function 0x1A00BE4C4\n  characteristic: stack string @ 0x1A00BE505\nbasic block @ 0x1A00C064D in function 0x1A00C060C\n  characteristic: stack string @ 0x1A00C064D\nbasic block @ 0x1A00C113D in function 0x1A00C10FC\n  characteristic: stack string @ 0x1A00C113D\nbasic block @ 0x1A00C209D in function 0x1A00C205C\n  characteristic: stack string @ 0x1A00C209D\nbasic block @ 0x1A00C2739 in function 0x1A00C26F8\n  characteristic: stack string @ 0x1A00C2739\nbasic block @ 0x1A00C2CC9 in function 0x1A00C2C88\n  characteristic: stack string @ 0x1A00C2CC9\nbasic block @ 0x1A00C3397 in function 0x1A00C335C\n  characteristic: stack string @ 0x1A00C3397\nbasic block @ 0x1A00C3867 in function 0x1A00C382C\n  characteristic: stack string @ 0x1A00C3867\nbasic block @ 0x1A00C4021 in function 0x1A00C3FE0\n  characteristic: stack string @ 0x1A00C4021\nbasic block @ 0x1A00C5709 in function 0x1A00C56C8\n  characteristic: stack string @ 0x1A00C5709\nbasic block @ 0x1A00C5DF9 in function 0x1A00C5DB8\n  characteristic: stack string @ 0x1A00C5DF9\nbasic block @ 0x1A00C6C5D in function 0x1A00C6C1C\n  characteristic: stack string @ 0x1A00C6C5D\nbasic block @ 0x1A00C800D in function 0x1A00C7FCC\n  characteristic: stack string @ 0x1A00C800D\nbasic block @ 0x1A00C867B in function 0x1A00C8640\n  characteristic: stack string @ 0x1A00C867B\nbasic block @ 0x1A00C956F in function 0x1A00C9534\n  characteristic: stack string @ 0x1A00C956F\nbasic block @ 0x1A00C9A1B in function 0x1A00C99E0\n  characteristic: stack string @ 0x1A00C9A1B\nbasic block @ 0x1A00CA371 in function 0x1A00CA330\n  characteristic: stack string @ 0x1A00CA371\nbasic block @ 0x1A00CB7A8 in function 0x1A00CB770\n  characteristic: stack string @ 0x1A00CB7A8\nbasic block @ 0x1A00CC543 in function 0x1A00CC508\n  characteristic: stack string @ 0x1A00CC543\nbasic block @ 0x1A00CC9A4 in function 0x1A00CC96C\n  characteristic: stack string @ 0x1A00CC9A4\nbasic block @ 0x1A00CCBA9 in function 0x1A00CCB68\n  characteristic: stack string @ 0x1A00CCBA9\nbasic block @ 0x1A00CD29B in function 0x1A00CD260\n  characteristic: stack string @ 0x1A00CD29B\nbasic block @ 0x1A00CD763 in function 0x1A00CD728\n  characteristic: stack string @ 0x1A00CD763\nbasic block @ 0x1A00CE191 in function 0x1A00CE150\n  characteristic: stack string @ 0x1A00CE191\nbasic block @ 0x1A00CF81F in function 0x1A00CF7E4\n  characteristic: stack string @ 0x1A00CF81F\nbasic block @ 0x1A00CFF34 in function 0x1A00CFEFC\n  characteristic: stack string @ 0x1A00CFF34\nbasic block @ 0x1A00D01AC in function 0x1A00D0174\n  characteristic: stack string @ 0x1A00D01AC\nbasic block @ 0x1A00D0B24 in function 0x1A00D0AEC\n  characteristic: stack string @ 0x1A00D0B24\nbasic block @ 0x1A00D1177 in function 0x1A00D113C\n  characteristic: stack string @ 0x1A00D1177\nbasic block @ 0x1A00D1D09 in function 0x1A00D1CC8\n  characteristic: stack string @ 0x1A00D1D09\nbasic block @ 0x1A00D25DD in function 0x1A00D259C\n  characteristic: stack string @ 0x1A00D25DD\nbasic block @ 0x1A00D2C39 in function 0x1A00D2BF8\n  characteristic: stack string @ 0x1A00D2C39\nbasic block @ 0x1A00D3217 in function 0x1A00D31DC\n  characteristic: stack string @ 0x1A00D3217\nbasic block @ 0x1A00D3764 in function 0x1A00D372C\n  characteristic: stack string @ 0x1A00D3764\nbasic block @ 0x1A00D4247 in function 0x1A00D420C\n  characteristic: stack string @ 0x1A00D4247\nbasic block @ 0x1A00D4AB1 in function 0x1A00D4A70\n  characteristic: stack string @ 0x1A00D4AB1\nbasic block @ 0x1A00D5185 in function 0x1A00D5144\n  characteristic: stack string @ 0x1A00D5185\nbasic block @ 0x1A00D593B in function 0x1A00D5900\n  characteristic: stack string @ 0x1A00D593B\nbasic block @ 0x1A00D6A39 in function 0x1A00D69F8\n  characteristic: stack string @ 0x1A00D6A39\nbasic block @ 0x1A00D7DF9 in function 0x1A00D7DB8\n  characteristic: stack string @ 0x1A00D7DF9\nbasic block @ 0x1A00D90D1 in function 0x1A00D9090\n  characteristic: stack string @ 0x1A00D90D1\nbasic block @ 0x1A00DA305 in function 0x1A00DA2C4\n  characteristic: stack string @ 0x1A00DA305\nbasic block @ 0x1A00DB495 in function 0x1A00DB454\n  characteristic: stack string @ 0x1A00DB495\nbasic block @ 0x1A00E0828 in function 0x1A00E0828\n  characteristic: stack string @ 0x1A00E0828\nbasic block @ 0x1A00E816D in function 0x1A00E7D90\n  characteristic: stack string @ 0x1A00E816D\nbasic block @ 0x1A00E8408 in function 0x1A00E7D90\n  characteristic: stack string @ 0x1A00E8408\nbasic block @ 0x1A00E880A in function 0x1A00E8730\n  characteristic: stack string @ 0x1A00E880A\n\nencode data using ADD XOR SUB operations (2 matches)\nnamespace    data-manipulation/encoding                                         \nauthor       jakub.jozwiak@mandiant.com                                         \nscope        function                                                           \natt&ck       Defense Evasion::Obfuscated Files or Information [T1027]           \nmbc          Defense Evasion::Obfuscated Files or Information::Encoding-Custom  \n             Algorithm [E1027.m03]                                              \ndescription  Data encoding using a sequence of ADD/XOR/SUB (or SUB/XOR/ADD)     \n             operations common for PlugX but also used by other malware         \n             families.                                                          \nfunction @ 0x1A0004744\n  and:\n    basic block:\n      and:\n        characteristic: tight loop @ 0x1A0004789\n        characteristic: nzxor @ 0x1A0004793\n        count(mnemonic(add)): 1 @ 0x1A000478E\n        count(mnemonic(sub)): 1 @ 0x1A00047AF\n    count(basic block): 6 or fewer @ 0x1A0004744, 0x1A0004789, 0x1A00047B5\nfunction @ 0x1A00EB9B0\n  and:\n    basic block:\n      and:\n        characteristic: tight loop @ 0x1A00EBA51\n        characteristic: nzxor @ 0x1A00EBA60\n        count(mnemonic(add)): 1 @ 0x1A00EBA59\n        count(mnemonic(sub)): 1 @ 0x1A00EBA82\n    count(basic block): 6 or fewer @ 0x1A00EB9B0, 0x1A00EBA51, 0x1A00EBA88\n\nencode data using Base64 (11 matches)\nnamespace  data-manipulation/encoding/base64                                    \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::Base64 [C0026.001]         \nfunction @ 0x1A001F334\n  or:\n    and:\n      mnemonic: shl @ 0x1A002036E, 0x1A00203B0\n      mnemonic: shr @ 0x1A002037A\n      number: 0x3F = modulo 64 @ 0x1A001F6FC, 0x1A001FC9E, 0x1A00200BB\n      or:\n        number: 0x3D = '=' @ 0x1A001F6E0\n      match: contain loop @ 0x1A001F334\n        or:\n          characteristic: loop @ 0x1A001F334\n      optional:\n        number: 0x2 @ 0x1A001F396, 0x1A001F908, 0x1A001FC6B\n        number: 0x3 @ 0x1A001F3A4, 0x1A002036B, 0x1A002036E\n        number: 0x4 @ 0x1A001F3B2, 0x1A001F514, 0x1A00203B0, 0x1A00203B8\n        number: 0x6 @ 0x1A001F3CE\n        number: 0xF @ 0x1A001F44C, 0x1A001F88A, 0x1A001FA68, 0x1A00201CA\nfunction @ 0x1A00227AC\n  or:\n    and:\n      mnemonic: shl @ 0x1A0022C6A, 0x1A0022CB0\n      mnemonic: shr @ 0x1A0022C76\n      number: 0x3F = modulo 64 @ 0x1A0022B74\n      or:\n        number: 0x3D = '=' @ 0x1A0022830, 0x1A0022A1A, 0x1A0022B58\n      match: contain loop @ 0x1A00227AC\n        or:\n          characteristic: loop @ 0x1A00227AC\n      optional:\n        number: 0x2 @ 0x1A002281E, 0x1A0022884, 0x1A0022A28, 0x1A0022CB0\n        number: 0x3 @ 0x1A002282C, 0x1A0022C67, 0x1A0022C6A\n        number: 0x4 @ 0x1A0022822, 0x1A002283A, 0x1A00229B8, 0x1A0022A0C\n        number: 0x6 @ 0x1A0022856, 0x1A0022CA8\n        number: 0xF @ 0x1A00228D4\nfunction @ 0x1A00254A4\n  or:\n    and:\n      mnemonic: shl @ 0x1A002612A, 0x1A0026174\n      mnemonic: shr @ 0x1A0026136\n      number: 0x3F = modulo 64 @ 0x1A002586C\n      or:\n        number: 0x3D = '=' @ 0x1A002581C, 0x1A0025850, 0x1A0025BAA\n      match: contain loop @ 0x1A00254A4\n        or:\n          characteristic: loop @ 0x1A00254A4\n      optional:\n        number: 0x2 @ 0x1A0025516, 0x1A0026174\n        number: 0x3 @ 0x1A00254FE, 0x1A0025524, 0x1A0025B3A, 0x1A0026127, and 1 more...\n        number: 0x4 @ 0x1A0025532\n        number: 0x6 @ 0x1A002554E, 0x1A002616C\n        number: 0xF @ 0x1A00255CC\nfunction @ 0x1A002620C\n  or:\n    and:\n      mnemonic: shl @ 0x1A00266EA\n      mnemonic: shr @ 0x1A00266F6\n      number: 0x3F = modulo 64 @ 0x1A00265F4\n      or:\n        number: 0x3D = '=' @ 0x1A00265D8\n      match: contain loop @ 0x1A002620C\n        or:\n          characteristic: loop @ 0x1A002620C\n      optional:\n        number: 0x2 @ 0x1A002626E\n        number: 0x3 @ 0x1A002627C, 0x1A002631A, 0x1A002664C, 0x1A00266E7, and 1 more...\n        number: 0x4 @ 0x1A002628A, 0x1A00263DE\n        number: 0x6 @ 0x1A00262A6\n        number: 0xF @ 0x1A0026324\nfunction @ 0x1A0036EA0\n  or:\n    and:\n      mnemonic: shl @ 0x1A0037032\n      mnemonic: shr @ 0x1A003703B\n      number: 0x3F = modulo 64 @ 0x1A0036F0B\n      or:\n        number: 0x3D = '=' @ 0x1A0036EEF\n      match: contain loop @ 0x1A0036EA0\n        or:\n          characteristic: loop @ 0x1A0036EA0\n      optional:\n        number: 0x2 @ 0x1A0036EF9\n        number: 0x3 @ 0x1A0036F07, 0x1A003702F, 0x1A0037032\n        number: 0x4 @ 0x1A0036F15, 0x1A0036FA5\n        number: 0x6 @ 0x1A0036F31\n        number: 0xF @ 0x1A0036FAF\nfunction @ 0x1A0071C0C\n  or:\n    and:\n      mnemonic: shl @ 0x1A0071DD2, 0x1A0071DF2\n      mnemonic: shr @ 0x1A0071DDB\n      number: 0x3F = modulo 64 @ 0x1A0071D8F\n      or:\n        number: 0x3D = '=' @ 0x1A0071C85\n      match: contain loop @ 0x1A0071C0C\n        or:\n          characteristic: loop @ 0x1A0071C0C\n      optional:\n        number: 0x2 @ 0x1A0071C65, 0x1A0071DF2\n        number: 0x3 @ 0x1A0071C73, 0x1A0071C93, 0x1A0071DCF, 0x1A0071DD2\n        number: 0x4 @ 0x1A0071C81\n        number: 0x6 @ 0x1A0071C9D, 0x1A0071DFA\n        number: 0xF @ 0x1A0071D1B\nfunction @ 0x1A00A0754\n  or:\n    and:\n      mnemonic: shl @ 0x1A00A0DE0, 0x1A00A0E35\n      mnemonic: shr @ 0x1A00A0DEC\n      number: 0x3F = modulo 64 @ 0x1A00A0A6A, 0x1A00A0B1C\n      or:\n        number: 0x3D = '=' @ 0x1A00A0B00\n      match: contain loop @ 0x1A00A0754\n        or:\n          characteristic: loop @ 0x1A00A0754\n      optional:\n        number: 0x2 @ 0x1A00A07B6, 0x1A00A0CD2\n        number: 0x3 @ 0x1A00A07C4, 0x1A00A0DDD, 0x1A00A0DE0, 0x1A00A0E2D\n        number: 0x4 @ 0x1A00A07D2\n        number: 0x6 @ 0x1A00A07EE, 0x1A00A0C7E\n        number: 0xF @ 0x1A00A087C\nfunction @ 0x1A00A63D4\n  or:\n    and:\n      mnemonic: shl @ 0x1A00A68D8\n      mnemonic: shr @ 0x1A00A68E4\n      number: 0x3F = modulo 64 @ 0x1A00A67BC\n      or:\n        number: 0x3D = '=' @ 0x1A00A67A0\n      match: contain loop @ 0x1A00A63D4\n        or:\n          characteristic: loop @ 0x1A00A63D4\n      optional:\n        number: 0x2 @ 0x1A00A6446\n        number: 0x3 @ 0x1A00A6454, 0x1A00A68D5, 0x1A00A68D8\n        number: 0x4 @ 0x1A00A6462\n        number: 0x6 @ 0x1A00A647E\n        number: 0xF @ 0x1A00A64FC\nfunction @ 0x1A00B36C0\n  or:\n    and:\n      mnemonic: shl @ 0x1A00B3B90, 0x1A00B3BE1\n      mnemonic: shr @ 0x1A00B3B9C\n      number: 0x3F = modulo 64 @ 0x1A00B3742, 0x1A00B3A98\n      or:\n        number: 0x3D = '=' @ 0x1A00B3A7C\n      match: contain loop @ 0x1A00B36C0\n        or:\n          characteristic: loop @ 0x1A00B36C0\n      optional:\n        number: 0x2 @ 0x1A00B3722, 0x1A00B3A64, 0x1A00B3B1A, 0x1A00B3BD9, and 1 more...\n        number: 0x3 @ 0x1A00B3730, 0x1A00B3B8D, 0x1A00B3B90\n        number: 0x4 @ 0x1A00B373E, 0x1A00B3A80\n        number: 0x6 @ 0x1A00B375A, 0x1A00B3A9C, 0x1A00B3BE1\n        number: 0xF @ 0x1A00B37E8, 0x1A00B3987, 0x1A00B3A02\nfunction @ 0x1A00D0AEC\n  or:\n    and:\n      mnemonic: shl @ 0x1A00D0C62, 0x1A00D0CB7\n      mnemonic: shr @ 0x1A00D0C6B\n      number: 0x3F = modulo 64 @ 0x1A00D0C90\n      or:\n        number: 0x3D = '=' @ 0x1A00D0C1B\n      match: contain loop @ 0x1A00D0AEC\n        or:\n          characteristic: loop @ 0x1A00D0AEC\n      optional:\n        number: 0x2 @ 0x1A00D0B45, 0x1A00D0CB7\n        number: 0x3 @ 0x1A00D0B53, 0x1A00D0C5F, 0x1A00D0C62\n        number: 0x4 @ 0x1A00D0B61\n        number: 0x6 @ 0x1A00D0B7D, 0x1A00D0CAF\n        number: 0xF @ 0x1A00D0BFB\nfunction @ 0x1A00E0B64\n  or:\n    and:\n      mnemonic: shl @ 0x1A00E0C2D, 0x1A00E0C85, 0x1A00E0CD6, 0x1A00E0D73, and 1 more...\n      mnemonic: shr @ 0x1A00E0C31, 0x1A00E0C88, 0x1A00E0CA5, 0x1A00E0CD3, and 6 more...\n      number: 0x3F = modulo 64 @ 0x1A00E0DCB, 0x1A00E0DE6, 0x1A00E0E03\n      or:\n        number: 0x3D = '=' @ 0x1A00E0DEF, 0x1A00E0E0C\n      match: contain loop @ 0x1A00E0B64\n        or:\n          characteristic: loop @ 0x1A00E0B64\n          characteristic: tight loop @ 0x1A00E0B9E, 0x1A00E0C0C\n      optional:\n        number: 0x2 @ 0x1A00E0D53\n        number: 0x3 @ 0x1A00E0E14\n        number: 0x4 @ 0x1A00E0CD6\n        number: 0x6 @ 0x1A00E0BF6, 0x1A00E0DE2\n\nencode data using XOR (232 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x1A0001326 in function 0x1A0001188\n  and:\n    characteristic: tight loop @ 0x1A0001326\n    characteristic: nzxor @ 0x1A000132B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0001963 in function 0x1A0001678\n  and:\n    characteristic: tight loop @ 0x1A0001963\n    characteristic: nzxor @ 0x1A0001975\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0001A45 in function 0x1A0001678\n  and:\n    characteristic: tight loop @ 0x1A0001A45\n    characteristic: nzxor @ 0x1A0001A52\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0003027 in function 0x1A0002FC8\n  and:\n    characteristic: tight loop @ 0x1A0003027\n    characteristic: nzxor @ 0x1A0003033\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00033A0 in function 0x1A0003370\n  and:\n    characteristic: tight loop @ 0x1A00033A0\n    characteristic: nzxor @ 0x1A00033A8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0003430 in function 0x1A0003370\n  and:\n    characteristic: tight loop @ 0x1A0003430\n    characteristic: nzxor @ 0x1A0003442\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0003760 in function 0x1A0003370\n  and:\n    characteristic: tight loop @ 0x1A0003760\n    characteristic: nzxor @ 0x1A000376B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0003C60 in function 0x1A00037E0\n  and:\n    characteristic: tight loop @ 0x1A0003C60\n    characteristic: nzxor @ 0x1A0003C79, 0x1A0003C8D, 0x1A0003CB5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0003D70 in function 0x1A00037E0\n  and:\n    characteristic: tight loop @ 0x1A0003D70\n    characteristic: nzxor @ 0x1A0003D85\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0004461 in function 0x1A0004450\n  and:\n    characteristic: tight loop @ 0x1A0004461\n    characteristic: nzxor @ 0x1A0004465\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0004789 in function 0x1A0004744\n  and:\n    characteristic: tight loop @ 0x1A0004789\n    characteristic: nzxor @ 0x1A0004793\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0004B9F in function 0x1A0004B90\n  and:\n    characteristic: tight loop @ 0x1A0004B9F\n    characteristic: nzxor @ 0x1A0004BA5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0005600 in function 0x1A0005000\n  and:\n    characteristic: tight loop @ 0x1A0005600\n    characteristic: nzxor @ 0x1A0005612\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0005600 in function 0x1A0005000\n  and:\n    characteristic: tight loop @ 0x1A0005600\n    characteristic: nzxor @ 0x1A0005612\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0006120 in function 0x1A0006040\n  and:\n    characteristic: tight loop @ 0x1A0006120\n    characteristic: nzxor @ 0x1A0006136\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00061C0 in function 0x1A0006040\n  and:\n    characteristic: tight loop @ 0x1A00061C0\n    characteristic: nzxor @ 0x1A00061D2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0006240 in function 0x1A0006040\n  and:\n    characteristic: tight loop @ 0x1A0006240\n    characteristic: nzxor @ 0x1A000624A, 0x1A0006275\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0006420 in function 0x1A0006040\n  and:\n    characteristic: tight loop @ 0x1A0006420\n    characteristic: nzxor @ 0x1A0006444, 0x1A0006460\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000702C in function 0x1A0007010\n  and:\n    characteristic: tight loop @ 0x1A000702C\n    characteristic: nzxor @ 0x1A0007030\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0007396 in function 0x1A00072B0\n  and:\n    characteristic: tight loop @ 0x1A0007396\n    characteristic: nzxor @ 0x1A000739A\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0007707 in function 0x1A00076C0\n  and:\n    characteristic: tight loop @ 0x1A0007707\n    characteristic: nzxor @ 0x1A0007717\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0007707 in function 0x1A00076C0\n  and:\n    characteristic: tight loop @ 0x1A0007707\n    characteristic: nzxor @ 0x1A0007717\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0007735 in function 0x1A00076C0\n  and:\n    characteristic: tight loop @ 0x1A0007735\n    characteristic: nzxor @ 0x1A000774D, 0x1A000777F\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0007735 in function 0x1A00076C0\n  and:\n    characteristic: tight loop @ 0x1A0007735\n    characteristic: nzxor @ 0x1A000774D, 0x1A000777F\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0007EFD in function 0x1A00079B4\n  and:\n    characteristic: tight loop @ 0x1A0007EFD\n    characteristic: nzxor @ 0x1A0007F0A\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0008C70 in function 0x1A0008BE0\n  and:\n    characteristic: tight loop @ 0x1A0008C70\n    characteristic: nzxor @ 0x1A0008C85\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000A570 in function 0x1A000A500\n  and:\n    characteristic: tight loop @ 0x1A000A570\n    characteristic: nzxor @ 0x1A000A582\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000A7CC in function 0x1A000A718\n  and:\n    characteristic: tight loop @ 0x1A000A7CC\n    characteristic: nzxor @ 0x1A000A7D9\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000A8F2 in function 0x1A000A890\n  and:\n    characteristic: tight loop @ 0x1A000A8F2\n    characteristic: nzxor @ 0x1A000A8FF\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000A8F2 in function 0x1A000A890\n  and:\n    characteristic: tight loop @ 0x1A000A8F2\n    characteristic: nzxor @ 0x1A000A8FF\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000A9EF in function 0x1A000A988\n  and:\n    characteristic: tight loop @ 0x1A000A9EF\n    characteristic: nzxor @ 0x1A000A9FE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000ACE2 in function 0x1A000AC68\n  and:\n    characteristic: tight loop @ 0x1A000ACE2\n    characteristic: nzxor @ 0x1A000ACF1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000AEAF in function 0x1A000AC68\n  and:\n    characteristic: tight loop @ 0x1A000AEAF\n    characteristic: nzxor @ 0x1A000AEF0, 0x1A000AF05\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000AFA9 in function 0x1A000AF4C\n  and:\n    characteristic: tight loop @ 0x1A000AFA9\n    characteristic: nzxor @ 0x1A000AFB8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000B06F in function 0x1A000B048\n  and:\n    characteristic: tight loop @ 0x1A000B06F\n    characteristic: nzxor @ 0x1A000B075\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000B5B0 in function 0x1A000B460\n  and:\n    characteristic: tight loop @ 0x1A000B5B0\n    characteristic: nzxor @ 0x1A000B5BF\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000B760 in function 0x1A000B6D0\n  and:\n    characteristic: tight loop @ 0x1A000B760\n    characteristic: nzxor @ 0x1A000B772\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000B7F0 in function 0x1A000B6D0\n  and:\n    characteristic: tight loop @ 0x1A000B7F0\n    characteristic: nzxor @ 0x1A000B7FA\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000B880 in function 0x1A000B6D0\n  and:\n    characteristic: tight loop @ 0x1A000B880\n    characteristic: nzxor @ 0x1A000B8B2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000BB40 in function 0x1A000BB10\n  and:\n    characteristic: tight loop @ 0x1A000BB40\n    characteristic: nzxor @ 0x1A000BB48\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000C270 in function 0x1A000BDE0\n  and:\n    characteristic: tight loop @ 0x1A000C270\n    characteristic: nzxor @ 0x1A000C27B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000CBD0 in function 0x1A000CB50\n  and:\n    characteristic: tight loop @ 0x1A000CBD0\n    characteristic: nzxor @ 0x1A000CBE2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000CF67 in function 0x1A000CE58\n  and:\n    characteristic: tight loop @ 0x1A000CF67\n    characteristic: nzxor @ 0x1A000CF71\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000D164 in function 0x1A000CFB0\n  and:\n    characteristic: tight loop @ 0x1A000D164\n    characteristic: nzxor @ 0x1A000D169, 0x1A000D176\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000D4C0 in function 0x1A000D290\n  and:\n    characteristic: tight loop @ 0x1A000D4C0\n    characteristic: nzxor @ 0x1A000D4D3\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000D4C0 in function 0x1A000D290\n  and:\n    characteristic: tight loop @ 0x1A000D4C0\n    characteristic: nzxor @ 0x1A000D4D3\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000DEB0 in function 0x1A000DE2C\n  and:\n    characteristic: tight loop @ 0x1A000DEB0\n    characteristic: nzxor @ 0x1A000DEBD\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000E2A4 in function 0x1A000DE2C\n  and:\n    characteristic: tight loop @ 0x1A000E2A4\n    characteristic: nzxor @ 0x1A000E2B8, 0x1A000E2D0, 0x1A000E2E8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000E333 in function 0x1A000DE2C\n  and:\n    characteristic: tight loop @ 0x1A000E333\n    characteristic: nzxor @ 0x1A000E365\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000E478 in function 0x1A000E3C0\n  and:\n    characteristic: tight loop @ 0x1A000E478\n    characteristic: nzxor @ 0x1A000E487\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000E4E5 in function 0x1A000E3C0\n  and:\n    characteristic: tight loop @ 0x1A000E4E5\n    characteristic: nzxor @ 0x1A000E4F5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000E5A3 in function 0x1A000E3C0\n  and:\n    characteristic: tight loop @ 0x1A000E5A3\n    characteristic: nzxor @ 0x1A000E5CC, 0x1A000E5E0, 0x1A000E5F2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000E6D0 in function 0x1A000E6A0\n  and:\n    characteristic: tight loop @ 0x1A000E6D0\n    characteristic: nzxor @ 0x1A000E6D7\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000E810 in function 0x1A000E6A0\n  and:\n    characteristic: tight loop @ 0x1A000E810\n    characteristic: nzxor @ 0x1A000E81A, 0x1A000E83C, 0x1A000E85C\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A000E900 in function 0x1A000E6A0\n  and:\n    characteristic: tight loop @ 0x1A000E900\n    characteristic: nzxor @ 0x1A000E90D\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0010101 in function 0x1A000FE20\n  and:\n    characteristic: tight loop @ 0x1A0010101\n    characteristic: nzxor @ 0x1A0010154\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0010706 in function 0x1A0010324\n  and:\n    characteristic: tight loop @ 0x1A0010706\n    characteristic: nzxor @ 0x1A001073A\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A001083A in function 0x1A0010324\n  and:\n    characteristic: tight loop @ 0x1A001083A\n    characteristic: nzxor @ 0x1A0010844, 0x1A0010877\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00116C8 in function 0x1A00111C4\n  and:\n    characteristic: tight loop @ 0x1A00116C8\n    characteristic: nzxor @ 0x1A00116D6, 0x1A00116FC, 0x1A0011711\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0011D30 in function 0x1A0011750\n  and:\n    characteristic: tight loop @ 0x1A0011D30\n    characteristic: nzxor @ 0x1A0011D3A\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00120F0 in function 0x1A0011D80\n  and:\n    characteristic: tight loop @ 0x1A00120F0\n    characteristic: nzxor @ 0x1A0012102\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0013190 in function 0x1A0013160\n  and:\n    characteristic: tight loop @ 0x1A0013190\n    characteristic: nzxor @ 0x1A0013198\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0013C1B in function 0x1A0013B84\n  and:\n    characteristic: tight loop @ 0x1A0013C1B\n    characteristic: nzxor @ 0x1A0013C28\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0013C1B in function 0x1A0013B84\n  and:\n    characteristic: tight loop @ 0x1A0013C1B\n    characteristic: nzxor @ 0x1A0013C28\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0013CF8 in function 0x1A0013B84\n  and:\n    characteristic: tight loop @ 0x1A0013CF8\n    characteristic: nzxor @ 0x1A0013D0F, 0x1A0013D3A\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0013CF8 in function 0x1A0013B84\n  and:\n    characteristic: tight loop @ 0x1A0013CF8\n    characteristic: nzxor @ 0x1A0013D0F, 0x1A0013D3A\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0013DB3 in function 0x1A0013B84\n  and:\n    characteristic: tight loop @ 0x1A0013DB3\n    characteristic: nzxor @ 0x1A0013DCF, 0x1A0013DD3\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0013DB3 in function 0x1A0013B84\n  and:\n    characteristic: tight loop @ 0x1A0013DB3\n    characteristic: nzxor @ 0x1A0013DCF, 0x1A0013DD3\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0014240 in function 0x1A0014020\n  and:\n    characteristic: tight loop @ 0x1A0014240\n    characteristic: nzxor @ 0x1A0014255\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0014350 in function 0x1A0014020\n  and:\n    characteristic: tight loop @ 0x1A0014350\n    characteristic: nzxor @ 0x1A0014366\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00143C0 in function 0x1A0014020\n  and:\n    characteristic: tight loop @ 0x1A00143C0\n    characteristic: nzxor @ 0x1A00143DB\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0015B40 in function 0x1A0015270\n  and:\n    characteristic: tight loop @ 0x1A0015B40\n    characteristic: nzxor @ 0x1A0015B59\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0015C40 in function 0x1A0015270\n  and:\n    characteristic: tight loop @ 0x1A0015C40\n    characteristic: nzxor @ 0x1A0015C4A, 0x1A0015C73, 0x1A0015C87\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0015FA0 in function 0x1A0015270\n  and:\n    characteristic: tight loop @ 0x1A0015FA0\n    characteristic: nzxor @ 0x1A0015FB2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00163A0 in function 0x1A0016280\n  and:\n    characteristic: tight loop @ 0x1A00163A0\n    characteristic: nzxor @ 0x1A00163B2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00163A0 in function 0x1A0016280\n  and:\n    characteristic: tight loop @ 0x1A00163A0\n    characteristic: nzxor @ 0x1A00163B2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0016528 in function 0x1A0016510\n  and:\n    characteristic: tight loop @ 0x1A0016528\n    characteristic: nzxor @ 0x1A001652C\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0016528 in function 0x1A0016510\n  and:\n    characteristic: tight loop @ 0x1A0016528\n    characteristic: nzxor @ 0x1A001652C\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0016A94 in function 0x1A0016980\n  and:\n    characteristic: tight loop @ 0x1A0016A94\n    characteristic: nzxor @ 0x1A0016AC7\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0016D86 in function 0x1A0016980\n  and:\n    characteristic: tight loop @ 0x1A0016D86\n    characteristic: nzxor @ 0x1A0016D8E, 0x1A0016DA5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00171C3 in function 0x1A0016980\n  and:\n    characteristic: tight loop @ 0x1A00171C3\n    characteristic: nzxor @ 0x1A00171CD\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0017262 in function 0x1A0016980\n  and:\n    characteristic: tight loop @ 0x1A0017262\n    characteristic: nzxor @ 0x1A0017271\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00173D1 in function 0x1A0016980\n  and:\n    characteristic: tight loop @ 0x1A00173D1\n    characteristic: nzxor @ 0x1A00173DB\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0017690 in function 0x1A00174A0\n  and:\n    characteristic: tight loop @ 0x1A0017690\n    characteristic: nzxor @ 0x1A00176A2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0017CA5 in function 0x1A0017B9C\n  and:\n    characteristic: tight loop @ 0x1A0017CA5\n    characteristic: nzxor @ 0x1A0017CAA, 0x1A0017CB7, 0x1A0017CD5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0017D32 in function 0x1A0017B9C\n  and:\n    characteristic: tight loop @ 0x1A0017D32\n    characteristic: nzxor @ 0x1A0017D3C\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A001829E in function 0x1A0017FCC\n  and:\n    characteristic: tight loop @ 0x1A001829E\n    characteristic: nzxor @ 0x1A00182A6, 0x1A00182C6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00185A2 in function 0x1A0018560\n  and:\n    characteristic: tight loop @ 0x1A00185A2\n    characteristic: nzxor @ 0x1A00185A9, 0x1A00185C2, 0x1A00185D4\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A001864A in function 0x1A0018560\n  and:\n    characteristic: tight loop @ 0x1A001864A\n    characteristic: nzxor @ 0x1A0018657\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A001A4F0 in function 0x1A001A4B8\n  and:\n    characteristic: tight loop @ 0x1A001A4F0\n    characteristic: nzxor @ 0x1A001A501, 0x1A001A512\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A001A704 in function 0x1A001A6DC\n  and:\n    characteristic: tight loop @ 0x1A001A704\n    characteristic: nzxor @ 0x1A001A712\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A001AA5E in function 0x1A001A98C\n  and:\n    characteristic: tight loop @ 0x1A001AA5E\n    characteristic: nzxor @ 0x1A001AA6A\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A001AB1F in function 0x1A001A98C\n  and:\n    characteristic: tight loop @ 0x1A001AB1F\n    characteristic: nzxor @ 0x1A001AB26\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A001AD32 in function 0x1A001A98C\n  and:\n    characteristic: tight loop @ 0x1A001AD32\n    characteristic: nzxor @ 0x1A001AD3F\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00DD936 in function 0x1A00DD8F0\n  and:\n    characteristic: tight loop @ 0x1A00DD936\n    characteristic: nzxor @ 0x1A00DD953\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00DE0C8 in function 0x1A00DE078\n  and:\n    characteristic: tight loop @ 0x1A00DE0C8\n    characteristic: nzxor @ 0x1A00DE0D6, 0x1A00DE0EE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00DE1A0 in function 0x1A00DE130\n  and:\n    characteristic: tight loop @ 0x1A00DE1A0\n    characteristic: nzxor @ 0x1A00DE1B2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00DE271 in function 0x1A00DE130\n  and:\n    characteristic: tight loop @ 0x1A00DE271\n    characteristic: nzxor @ 0x1A00DE283\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00DE82B in function 0x1A00DE804\n  and:\n    characteristic: tight loop @ 0x1A00DE82B\n    characteristic: nzxor @ 0x1A00DE82F\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00DEF65 in function 0x1A00DEDFC\n  and:\n    characteristic: tight loop @ 0x1A00DEF65\n    characteristic: nzxor @ 0x1A00DEF72\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00DF0ED in function 0x1A00DF0A0\n  and:\n    characteristic: tight loop @ 0x1A00DF0ED\n    characteristic: nzxor @ 0x1A00DF107, 0x1A00DF11C, 0x1A00DF12C\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00DF590 in function 0x1A00DF2B0\n  and:\n    characteristic: tight loop @ 0x1A00DF590\n    characteristic: nzxor @ 0x1A00DF5A5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E0690 in function 0x1A00E0260\n  and:\n    characteristic: tight loop @ 0x1A00E0690\n    characteristic: nzxor @ 0x1A00E06A5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E0B9E in function 0x1A00E0B64\n  and:\n    characteristic: tight loop @ 0x1A00E0B9E\n    characteristic: nzxor @ 0x1A00E0BA4\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E0C0C in function 0x1A00E0B64\n  and:\n    characteristic: tight loop @ 0x1A00E0C0C\n    characteristic: nzxor @ 0x1A00E0C19\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E0E99 in function 0x1A00E0E88\n  and:\n    characteristic: tight loop @ 0x1A00E0E99\n    characteristic: nzxor @ 0x1A00E0E9D\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E1040 in function 0x1A00E0FB0\n  and:\n    characteristic: tight loop @ 0x1A00E1040\n    characteristic: nzxor @ 0x1A00E1052\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E1B2A in function 0x1A00EB410\n  and:\n    characteristic: tight loop @ 0x1A00E1B2A\n    characteristic: nzxor @ 0x1A00E1B34\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E1B2A in function 0x1A00EB410\n  and:\n    characteristic: tight loop @ 0x1A00E1B2A\n    characteristic: nzxor @ 0x1A00E1B34\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E1CE0 in function 0x1A00E1C70\n  and:\n    characteristic: tight loop @ 0x1A00E1CE0\n    characteristic: nzxor @ 0x1A00E1CF2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E1EC0 in function 0x1A00E1E70\n  and:\n    characteristic: tight loop @ 0x1A00E1EC0\n    characteristic: nzxor @ 0x1A00E1ED4\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E243D in function 0x1A00E23F4\n  and:\n    characteristic: tight loop @ 0x1A00E243D\n    characteristic: nzxor @ 0x1A00E2458\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E24EB in function 0x1A00E23F4\n  and:\n    characteristic: tight loop @ 0x1A00E24EB\n    characteristic: nzxor @ 0x1A00E24F8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E25F0 in function 0x1A00E23F4\n  and:\n    characteristic: tight loop @ 0x1A00E25F0\n    characteristic: nzxor @ 0x1A00E25FF\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E26EB in function 0x1A00E2674\n  and:\n    characteristic: tight loop @ 0x1A00E26EB\n    characteristic: nzxor @ 0x1A00E26F5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E2980 in function 0x1A00E2840\n  and:\n    characteristic: tight loop @ 0x1A00E2980\n    characteristic: nzxor @ 0x1A00E2992\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E2DDA in function 0x1A00E2D74\n  and:\n    characteristic: tight loop @ 0x1A00E2DDA\n    characteristic: nzxor @ 0x1A00E2DF2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E2F13 in function 0x1A00E2E88\n  and:\n    characteristic: tight loop @ 0x1A00E2F13\n    characteristic: nzxor @ 0x1A00E2F20\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E30A3 in function 0x1A00E3070\n  and:\n    characteristic: tight loop @ 0x1A00E30A3\n    characteristic: nzxor @ 0x1A00E30C3\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E30EA in function 0x1A00E3070\n  and:\n    characteristic: tight loop @ 0x1A00E30EA\n    characteristic: nzxor @ 0x1A00E310A\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E3158 in function 0x1A00E3130\n  and:\n    characteristic: tight loop @ 0x1A00E3158\n    characteristic: nzxor @ 0x1A00E3171\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E34D0 in function 0x1A00E3420\n  and:\n    characteristic: tight loop @ 0x1A00E34D0\n    characteristic: nzxor @ 0x1A00E34E0, 0x1A00E34E3\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E38D6 in function 0x1A00E38A4\n  and:\n    characteristic: tight loop @ 0x1A00E38D6\n    characteristic: nzxor @ 0x1A00E38F1, 0x1A00E3920, 0x1A00E3933\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E3D51 in function 0x1A00E3C00\n  and:\n    characteristic: tight loop @ 0x1A00E3D51\n    characteristic: nzxor @ 0x1A00E3D70, 0x1A00E3D83\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E3FC3 in function 0x1A00E3DEC\n  and:\n    characteristic: tight loop @ 0x1A00E3FC3\n    characteristic: nzxor @ 0x1A00E3FE9\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E4D9C in function 0x1A00E3DEC\n  and:\n    characteristic: tight loop @ 0x1A00E4D9C\n    characteristic: nzxor @ 0x1A00E4DAD, 0x1A00E4DB8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E55B7 in function 0x1A00E3DEC\n  and:\n    characteristic: tight loop @ 0x1A00E55B7\n    characteristic: nzxor @ 0x1A00E55C5, 0x1A00E55EE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E58CB in function 0x1A00E5830\n  and:\n    characteristic: tight loop @ 0x1A00E58CB\n    characteristic: nzxor @ 0x1A00E58D8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E58CB in function 0x1A00E5830\n  and:\n    characteristic: tight loop @ 0x1A00E58CB\n    characteristic: nzxor @ 0x1A00E58D8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E5FE0 in function 0x1A00E5E14\n  and:\n    characteristic: tight loop @ 0x1A00E5FE0\n    characteristic: nzxor @ 0x1A00E5FEE, 0x1A00E5FFD\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E6153 in function 0x1A00E5E14\n  and:\n    characteristic: tight loop @ 0x1A00E6153\n    characteristic: nzxor @ 0x1A00E6163\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E6DA0 in function 0x1A00E6D90\n  and:\n    characteristic: tight loop @ 0x1A00E6DA0\n    characteristic: nzxor @ 0x1A00E6DA7\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E7B44 in function 0x1A00E7B34\n  and:\n    characteristic: tight loop @ 0x1A00E7B44\n    characteristic: nzxor @ 0x1A00E7B48\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E7BF7 in function 0x1A00E7B34\n  and:\n    characteristic: tight loop @ 0x1A00E7BF7\n    characteristic: nzxor @ 0x1A00E7C0C, 0x1A00E7C1F\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E7C57 in function 0x1A00E7B34\n  and:\n    characteristic: tight loop @ 0x1A00E7C57\n    characteristic: nzxor @ 0x1A00E7C6F, 0x1A00E7C8E\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E7EF0 in function 0x1A00E7D90\n  and:\n    characteristic: tight loop @ 0x1A00E7EF0\n    characteristic: nzxor @ 0x1A00E7EF7\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E7F50 in function 0x1A00E7D90\n  and:\n    characteristic: tight loop @ 0x1A00E7F50\n    characteristic: nzxor @ 0x1A00E7F6B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E7FF1 in function 0x1A00E7D90\n  and:\n    characteristic: tight loop @ 0x1A00E7FF1\n    characteristic: nzxor @ 0x1A00E7FFD, 0x1A00E800C\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E8D68 in function 0x1A00E8CE4\n  and:\n    characteristic: tight loop @ 0x1A00E8D68\n    characteristic: nzxor @ 0x1A00E8D72\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E8ED0 in function 0x1A00E8CE4\n  and:\n    characteristic: tight loop @ 0x1A00E8ED0\n    characteristic: nzxor @ 0x1A00E8EDE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E90E4 in function 0x1A00E90AC\n  and:\n    characteristic: tight loop @ 0x1A00E90E4\n    characteristic: nzxor @ 0x1A00E9106, 0x1A00E911C, 0x1A00E9140\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E9330 in function 0x1A00E92F0\n  and:\n    characteristic: tight loop @ 0x1A00E9330\n    characteristic: nzxor @ 0x1A00E9338, 0x1A00E9349\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E94AE in function 0x1A00E9478\n  and:\n    characteristic: tight loop @ 0x1A00E94AE\n    characteristic: nzxor @ 0x1A00E94BB\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00E9666 in function 0x1A00E94DC\n  and:\n    characteristic: tight loop @ 0x1A00E9666\n    characteristic: nzxor @ 0x1A00E9692\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EA99B in function 0x1A00EA94C\n  and:\n    characteristic: tight loop @ 0x1A00EA99B\n    characteristic: nzxor @ 0x1A00EA9A5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EAD24 in function 0x1A00EAD0C\n  and:\n    characteristic: tight loop @ 0x1A00EAD24\n    characteristic: nzxor @ 0x1A00EAD3F, 0x1A00EAD57, 0x1A00EAD64\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EAE01 in function 0x1A00EADA0\n  and:\n    characteristic: tight loop @ 0x1A00EAE01\n    characteristic: nzxor @ 0x1A00EAE13\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EB495 in function 0x1A00EB474\n  and:\n    characteristic: tight loop @ 0x1A00EB495\n    characteristic: nzxor @ 0x1A00EB499\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EB820 in function 0x1A00EB7F0\n  and:\n    characteristic: tight loop @ 0x1A00EB820\n    characteristic: nzxor @ 0x1A00EB836, 0x1A00EB859\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EB820 in function 0x1A00EB7F0\n  and:\n    characteristic: tight loop @ 0x1A00EB820\n    characteristic: nzxor @ 0x1A00EB836, 0x1A00EB859\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EBA51 in function 0x1A00EB9B0\n  and:\n    characteristic: tight loop @ 0x1A00EBA51\n    characteristic: nzxor @ 0x1A00EBA60\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EBBC7 in function 0x1A00EBB00\n  and:\n    characteristic: tight loop @ 0x1A00EBBC7\n    characteristic: nzxor @ 0x1A00EBBD9\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EBF43 in function 0x1A00EBB00\n  and:\n    characteristic: tight loop @ 0x1A00EBF43\n    characteristic: nzxor @ 0x1A00EBF50\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EC91F in function 0x1A00EC44C\n  and:\n    characteristic: tight loop @ 0x1A00EC91F\n    characteristic: nzxor @ 0x1A00EC929, 0x1A00EC949, 0x1A00EC95B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00ECABF in function 0x1A00ECA48\n  and:\n    characteristic: tight loop @ 0x1A00ECABF\n    characteristic: nzxor @ 0x1A00ECACE\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00ECB54 in function 0x1A00ECA48\n  and:\n    characteristic: tight loop @ 0x1A00ECB54\n    characteristic: nzxor @ 0x1A00ECB63\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00ECCBF in function 0x1A00ECA48\n  and:\n    characteristic: tight loop @ 0x1A00ECCBF\n    characteristic: nzxor @ 0x1A00ECCCF, 0x1A00ECD1E\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00ECE9B in function 0x1A00ECDAC\n  and:\n    characteristic: tight loop @ 0x1A00ECE9B\n    characteristic: nzxor @ 0x1A00ECEAA\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00ECFC5 in function 0x1A00ECDAC\n  and:\n    characteristic: tight loop @ 0x1A00ECFC5\n    characteristic: nzxor @ 0x1A00ECFD2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EE080 in function 0x1A00EDF10\n  and:\n    characteristic: tight loop @ 0x1A00EE080\n    characteristic: nzxor @ 0x1A00EE090\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EE350 in function 0x1A00EE104\n  and:\n    characteristic: tight loop @ 0x1A00EE350\n    characteristic: nzxor @ 0x1A00EE364\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EE426 in function 0x1A00EE3F8\n  and:\n    characteristic: tight loop @ 0x1A00EE426\n    characteristic: nzxor @ 0x1A00EE445, 0x1A00EE487\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EE531 in function 0x1A00EE4D0\n  and:\n    characteristic: tight loop @ 0x1A00EE531\n    characteristic: nzxor @ 0x1A00EE543\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EE600 in function 0x1A00EE4D0\n  and:\n    characteristic: tight loop @ 0x1A00EE600\n    characteristic: nzxor @ 0x1A00EE612\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EF563 in function 0x1A00EF110\n  and:\n    characteristic: tight loop @ 0x1A00EF563\n    characteristic: nzxor @ 0x1A00EF59D, 0x1A00EF5B5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EF563 in function 0x1A00EF110\n  and:\n    characteristic: tight loop @ 0x1A00EF563\n    characteristic: nzxor @ 0x1A00EF59D, 0x1A00EF5B5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00EF94A in function 0x1A00EF91C\n  and:\n    characteristic: tight loop @ 0x1A00EF94A\n    characteristic: nzxor @ 0x1A00EF94E\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F05F8 in function 0x1A00F004C\n  and:\n    characteristic: tight loop @ 0x1A00F05F8\n    characteristic: nzxor @ 0x1A00F061D\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F0BB9 in function 0x1A00F0B78\n  and:\n    characteristic: tight loop @ 0x1A00F0BB9\n    characteristic: nzxor @ 0x1A00F0BCB, 0x1A00F0BE5, 0x1A00F0BF5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F0E1A in function 0x1A00F0DA8\n  and:\n    characteristic: tight loop @ 0x1A00F0E1A\n    characteristic: nzxor @ 0x1A00F0E21\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F0E1A in function 0x1A00F0DA8\n  and:\n    characteristic: tight loop @ 0x1A00F0E1A\n    characteristic: nzxor @ 0x1A00F0E21\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F1050 in function 0x1A00F0DA8\n  and:\n    characteristic: tight loop @ 0x1A00F1050\n    characteristic: nzxor @ 0x1A00F1068, 0x1A00F1080\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F1050 in function 0x1A00F0DA8\n  and:\n    characteristic: tight loop @ 0x1A00F1050\n    characteristic: nzxor @ 0x1A00F1068, 0x1A00F1080\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F146B in function 0x1A00F1410\n  and:\n    characteristic: tight loop @ 0x1A00F146B\n    characteristic: nzxor @ 0x1A00F1481\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F1680 in function 0x1A00F1670\n  and:\n    characteristic: tight loop @ 0x1A00F1680\n    characteristic: nzxor @ 0x1A00F1687\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F1A70 in function 0x1A00F1670\n  and:\n    characteristic: tight loop @ 0x1A00F1A70\n    characteristic: nzxor @ 0x1A00F1A82\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F2FAF in function 0x1A00F2278\n  and:\n    characteristic: tight loop @ 0x1A00F2FAF\n    characteristic: nzxor @ 0x1A00F2FB3\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F3259 in function 0x1A00F31CC\n  and:\n    characteristic: tight loop @ 0x1A00F3259\n    characteristic: nzxor @ 0x1A00F3268\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F3259 in function 0x1A00F31CC\n  and:\n    characteristic: tight loop @ 0x1A00F3259\n    characteristic: nzxor @ 0x1A00F3268\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F32D1 in function 0x1A00F31CC\n  and:\n    characteristic: tight loop @ 0x1A00F32D1\n    characteristic: nzxor @ 0x1A00F32DB\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F32D1 in function 0x1A00F31CC\n  and:\n    characteristic: tight loop @ 0x1A00F32D1\n    characteristic: nzxor @ 0x1A00F32DB\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F3A0A in function 0x1A00F31CC\n  and:\n    characteristic: tight loop @ 0x1A00F3A0A\n    characteristic: nzxor @ 0x1A00F3A2A\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F3A0A in function 0x1A00F31CC\n  and:\n    characteristic: tight loop @ 0x1A00F3A0A\n    characteristic: nzxor @ 0x1A00F3A2A\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F3F89 in function 0x1A00F3D4C\n  and:\n    characteristic: tight loop @ 0x1A00F3F89\n    characteristic: nzxor @ 0x1A00F3FBF, 0x1A00F3FC9\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F4166 in function 0x1A00F3D4C\n  and:\n    characteristic: tight loop @ 0x1A00F4166\n    characteristic: nzxor @ 0x1A00F4175\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F4598 in function 0x1A00F3D4C\n  and:\n    characteristic: tight loop @ 0x1A00F4598\n    characteristic: nzxor @ 0x1A00F45A5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F4830 in function 0x1A00F3D4C\n  and:\n    characteristic: tight loop @ 0x1A00F4830\n    characteristic: nzxor @ 0x1A00F4845, 0x1A00F4857\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F4A2B in function 0x1A00F3D4C\n  and:\n    characteristic: tight loop @ 0x1A00F4A2B\n    characteristic: nzxor @ 0x1A00F4A39, 0x1A00F4A5C\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F4AC6 in function 0x1A00F3D4C\n  and:\n    characteristic: tight loop @ 0x1A00F4AC6\n    characteristic: nzxor @ 0x1A00F4ACF\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F4D9E in function 0x1A00F3D4C\n  and:\n    characteristic: tight loop @ 0x1A00F4D9E\n    characteristic: nzxor @ 0x1A00F4DB2, 0x1A00F4DC3, 0x1A00F4DE6\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F4EE1 in function 0x1A00F3D4C\n  and:\n    characteristic: tight loop @ 0x1A00F4EE1\n    characteristic: nzxor @ 0x1A00F4EE9, 0x1A00F4F0D\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F5568 in function 0x1A00F3D4C\n  and:\n    characteristic: tight loop @ 0x1A00F5568\n    characteristic: nzxor @ 0x1A00F5577\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F58F6 in function 0x1A00F586C\n  and:\n    characteristic: tight loop @ 0x1A00F58F6\n    characteristic: nzxor @ 0x1A00F5903\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F5BE2 in function 0x1A00F5A18\n  and:\n    characteristic: tight loop @ 0x1A00F5BE2\n    characteristic: nzxor @ 0x1A00F5C07, 0x1A00F5C1A\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F5D90 in function 0x1A00F5D50\n  and:\n    characteristic: tight loop @ 0x1A00F5D90\n    characteristic: nzxor @ 0x1A00F5DAC\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F6A44 in function 0x1A00F69CC\n  and:\n    characteristic: tight loop @ 0x1A00F6A44\n    characteristic: nzxor @ 0x1A00F6A53\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F6F65 in function 0x1A00F6DB8\n  and:\n    characteristic: tight loop @ 0x1A00F6F65\n    characteristic: nzxor @ 0x1A00F6F74\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F7158 in function 0x1A00F6DB8\n  and:\n    characteristic: tight loop @ 0x1A00F7158\n    characteristic: nzxor @ 0x1A00F7167\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F73E0 in function 0x1A00F71D0\n  and:\n    characteristic: tight loop @ 0x1A00F73E0\n    characteristic: nzxor @ 0x1A00F73F2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F74D0 in function 0x1A00F71D0\n  and:\n    characteristic: tight loop @ 0x1A00F74D0\n    characteristic: nzxor @ 0x1A00F74E5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F7660 in function 0x1A00F71D0\n  and:\n    characteristic: tight loop @ 0x1A00F7660\n    characteristic: nzxor @ 0x1A00F7675\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F7DA0 in function 0x1A00F71D0\n  and:\n    characteristic: tight loop @ 0x1A00F7DA0\n    characteristic: nzxor @ 0x1A00F7DB3\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F84D0 in function 0x1A00F84A0\n  and:\n    characteristic: tight loop @ 0x1A00F84D0\n    characteristic: nzxor @ 0x1A00F84D7\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F92E6 in function 0x1A00F8E80\n  and:\n    characteristic: tight loop @ 0x1A00F92E6\n    characteristic: nzxor @ 0x1A00F9313\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F93A2 in function 0x1A00F9368\n  and:\n    characteristic: tight loop @ 0x1A00F93A2\n    characteristic: nzxor @ 0x1A00F93A8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F93EC in function 0x1A00F9368\n  and:\n    characteristic: tight loop @ 0x1A00F93EC\n    characteristic: nzxor @ 0x1A00F93F9\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00F9EF0 in function 0x1A00F9E60\n  and:\n    characteristic: tight loop @ 0x1A00F9EF0\n    characteristic: nzxor @ 0x1A00F9F05\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FA1E0 in function 0x1A00F9E60\n  and:\n    characteristic: tight loop @ 0x1A00FA1E0\n    characteristic: nzxor @ 0x1A00FA1EA, 0x1A00FA22A\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FA6B5 in function 0x1A00FA660\n  and:\n    characteristic: tight loop @ 0x1A00FA6B5\n    characteristic: nzxor @ 0x1A00FA6C4\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FAD70 in function 0x1A00FACA0\n  and:\n    characteristic: tight loop @ 0x1A00FAD70\n    characteristic: nzxor @ 0x1A00FAD86\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FB010 in function 0x1A00FB000\n  and:\n    characteristic: tight loop @ 0x1A00FB010\n    characteristic: nzxor @ 0x1A00FB017\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FB370 in function 0x1A00FB300\n  and:\n    characteristic: tight loop @ 0x1A00FB370\n    characteristic: nzxor @ 0x1A00FB37F\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FB42A in function 0x1A00FB300\n  and:\n    characteristic: tight loop @ 0x1A00FB42A\n    characteristic: nzxor @ 0x1A00FB434\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FB772 in function 0x1A00FB70C\n  and:\n    characteristic: tight loop @ 0x1A00FB772\n    characteristic: nzxor @ 0x1A00FB781\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FBE06 in function 0x1A00FBBA4\n  and:\n    characteristic: tight loop @ 0x1A00FBE06\n    characteristic: nzxor @ 0x1A00FBE13\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FC190 in function 0x1A00FC170\n  and:\n    characteristic: tight loop @ 0x1A00FC190\n    characteristic: nzxor @ 0x1A00FC197\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FC5C0 in function 0x1A00FC170\n  and:\n    characteristic: tight loop @ 0x1A00FC5C0\n    characteristic: nzxor @ 0x1A00FC5D5\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FC700 in function 0x1A00FC170\n  and:\n    characteristic: tight loop @ 0x1A00FC700\n    characteristic: nzxor @ 0x1A00FC715\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FD2B0 in function 0x1A00FCCC0\n  and:\n    characteristic: tight loop @ 0x1A00FD2B0\n    characteristic: nzxor @ 0x1A00FD2BA, 0x1A00FD2C3\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FD7B0 in function 0x1A00FCCC0\n  and:\n    characteristic: tight loop @ 0x1A00FD7B0\n    characteristic: nzxor @ 0x1A00FD7C2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FDCD7 in function 0x1A00FDC7C\n  and:\n    characteristic: tight loop @ 0x1A00FDCD7\n    characteristic: nzxor @ 0x1A00FDCF3, 0x1A00FDCF8\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FE1D5 in function 0x1A00FE0FC\n  and:\n    characteristic: tight loop @ 0x1A00FE1D5\n    characteristic: nzxor @ 0x1A00FE1E2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FE5BE in function 0x1A00FE0FC\n  and:\n    characteristic: tight loop @ 0x1A00FE5BE\n    characteristic: nzxor @ 0x1A00FE5CA, 0x1A00FE5DA, 0x1A00FE5EA\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FEE90 in function 0x1A00FED3C\n  and:\n    characteristic: tight loop @ 0x1A00FEE90\n    characteristic: nzxor @ 0x1A00FEE9D\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FEFA6 in function 0x1A00FED3C\n  and:\n    characteristic: tight loop @ 0x1A00FEFA6\n    characteristic: nzxor @ 0x1A00FEFC1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A00FF4F2 in function 0x1A00FF150\n  and:\n    characteristic: tight loop @ 0x1A00FF4F2\n    characteristic: nzxor @ 0x1A00FF508\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0100011 in function 0x1A00FFD70\n  and:\n    characteristic: tight loop @ 0x1A0100011\n    characteristic: nzxor @ 0x1A0100027, 0x1A0100037\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0101054 in function 0x1A010102C\n  and:\n    characteristic: tight loop @ 0x1A0101054\n    characteristic: nzxor @ 0x1A0101066\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A01010EF in function 0x1A010102C\n  and:\n    characteristic: tight loop @ 0x1A01010EF\n    characteristic: nzxor @ 0x1A01010FC\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0101700 in function 0x1A0101460\n  and:\n    characteristic: tight loop @ 0x1A0101700\n    characteristic: nzxor @ 0x1A0101716\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A01019ED in function 0x1A0101888\n  and:\n    characteristic: tight loop @ 0x1A01019ED\n    characteristic: nzxor @ 0x1A01019FA\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x1A0101A7E in function 0x1A0101888\n  and:\n    characteristic: tight loop @ 0x1A0101A7E\n    characteristic: nzxor @ 0x1A0101A8D\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nencrypt data using chaskey (2 matches)\nnamespace   data-manipulation/encryption/chaskey                                \nauthor      still@teamt5.org                                                    \nscope       function                                                            \natt&ck      Defense Evasion::Obfuscated Files or Information [T1027]            \nmbc         Defense Evasion::Obfuscated Files or                                \n            Information::Encryption-Standard Algorithm [E1027.m05]              \nreferences  https://mouha.be/chaskey/,                                          \n            https://github.com/TheWover/donut/blob/47758d787209dd1744f58c140102…\nfunction @ 0x1A00E3DEC\n  and:\n    match: contain loop @ 0x1A00E3DEC\n      or:\n        characteristic: loop @ 0x1A00E3DEC\n        characteristic: tight loop @ 0x1A00E3FC3, 0x1A00E4D9C, 0x1A00E55B7\n    instruction:\n      and:\n        number: 0xD @ 0x1A00E4F3A\n        or:\n          mnemonic: shl @ 0x1A00E4F3A\n      and:\n        number: 0xD @ 0x1A00E545D\n        or:\n          mnemonic: shl @ 0x1A00E545D\n      and:\n        number: 0xD @ 0x1A00E4D5D\n        or:\n          mnemonic: shl @ 0x1A00E4D5D\n      and:\n        number: 0xD @ 0x1A00E42A6\n        or:\n          mnemonic: shl @ 0x1A00E42A6\n    instruction:\n      and:\n        number: 0x8 @ 0x1A00E45FC\n        or:\n          mnemonic: shl @ 0x1A00E45FC\n      and:\n        number: 0x8 @ 0x1A00E54DD\n        or:\n          mnemonic: shl @ 0x1A00E54DD\n    instruction:\n      and:\n        number: 0x7 @ 0x1A00E573B\n        or:\n          mnemonic: shl @ 0x1A00E573B\n      and:\n        number: 0x7 @ 0x1A00E4DFA\n        or:\n          mnemonic: shl @ 0x1A00E4DFA\n      and:\n        number: 0x7 @ 0x1A00E4E8B\n        or:\n          mnemonic: shl @ 0x1A00E4E8B\n    instruction:\n      and:\n        number: 0x5 @ 0x1A00E5756\n        or:\n          mnemonic: shl @ 0x1A00E5756\n      and:\n        number: 0x5 @ 0x1A00E5277\n        or:\n          mnemonic: shl @ 0x1A00E5277\n      and:\n        number: 0x5 @ 0x1A00E56D6\n        or:\n          mnemonic: shl @ 0x1A00E56D6\n      and:\n        number: 0x5 @ 0x1A00E42C9\n        or:\n          mnemonic: shl @ 0x1A00E42C9\n      and:\n        number: 0x5 @ 0x1A00E578E\n        or:\n          mnemonic: shl @ 0x1A00E578E\n    count(characteristic(nzxor)): 6 or more @ 0x1A00E3E67, 0x1A00E3E75, 0x1A00E3E89, 0x1A00E3E9D, and 278 more...\nfunction @ 0x1A00F3D4C\n  and:\n    match: contain loop @ 0x1A00F3D4C\n      or:\n        characteristic: loop @ 0x1A00F3D4C\n        characteristic: tight loop @ 0x1A00F3E82, 0x1A00F3F89, 0x1A00F4166, 0x1A00F44DC, and 9 more...\n    instruction:\n      and:\n        number: 0xD @ 0x1A00F473D\n        or:\n          mnemonic: shl @ 0x1A00F473D\n    instruction:\n      and:\n        number: 0x8 @ 0x1A00F403C\n        or:\n          mnemonic: shl @ 0x1A00F403C\n    instruction:\n      and:\n        number: 0x7 @ 0x1A00F475D\n        or:\n          mnemonic: shl @ 0x1A00F475D\n    instruction:\n      and:\n        number: 0x5 @ 0x1A00F4189\n        or:\n          mnemonic: shl @ 0x1A00F4189\n    count(characteristic(nzxor)): 6 or more @ 0x1A00F3DCA, 0x1A00F3DFC, 0x1A00F3E13, 0x1A00F3F09, and 67 more...\n\nencrypt data using RC4 PRGA (40 matches)\nnamespace  data-manipulation/encryption/rc4                                     \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Encrypt Data::RC4 [C0027.009], Cryptography::Generate  \n           Pseudo-random Sequence::RC4 PRGA [C0021.004]                         \nfunction @ 0x1A000BB10\n  and:\n    match: contain loop @ 0x1A000BB10\n      or:\n        characteristic: loop @ 0x1A000BB10\n        characteristic: tight loop @ 0x1A000BB40\n    count(characteristic(nzxor)): 1 @ 0x1A000BB48\n    count(characteristic(calls from)): 4 or fewer @ 0x1A0019AAC, 0x1A001A7A8\n    count(basic block): between 4 and 50 @ 0x1A000BB10, 0x1A000BB40, 0x1A000BB57, 0x1A000BB70, and 10 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A000BB40, 0x1A000BC05, 0x1A000BC10, 0x1A000BC20, and 2 more...\nfunction @ 0x1A001E84C\n  and:\n    match: contain loop @ 0x1A001E84C\n      or:\n        characteristic: loop @ 0x1A001E84C\n    count(characteristic(nzxor)): 1 @ 0x1A001EBA9\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A001E84C, 0x1A001E85D, 0x1A001E869, 0x1A001E880, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A001EB7F, 0x1A001EB84, 0x1A001EB8F, 0x1A001EB94, and 2 more...\n    optional:\n      or:\n        number: 0xFF @ 0x1A001E9ED\nfunction @ 0x1A00291E8\n  and:\n    match: contain loop @ 0x1A00291E8\n      or:\n        characteristic: loop @ 0x1A00291E8\n    count(characteristic(nzxor)): 1 @ 0x1A0029400\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00291E8, 0x1A00291F6, 0x1A0029202, 0x1A0029219, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00293F6, 0x1A00293FB, 0x1A0029406, 0x1A0029414, and 3 more...\nfunction @ 0x1A002F9D0\n  and:\n    match: contain loop @ 0x1A002F9D0\n      or:\n        characteristic: loop @ 0x1A002F9D0\n    count(characteristic(nzxor)): 1 @ 0x1A002FB3D\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A002F9D0, 0x1A002F9DE, 0x1A002F9EA, 0x1A002FA01, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A002FB33, 0x1A002FB38, 0x1A002FB43, 0x1A002FB56\nfunction @ 0x1A0036418\n  and:\n    match: contain loop @ 0x1A0036418\n      or:\n        characteristic: loop @ 0x1A0036418\n    count(characteristic(nzxor)): 1 @ 0x1A00365AD\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A0036418, 0x1A0036426, 0x1A0036432, 0x1A0036449, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A003658D, 0x1A0036595, 0x1A00365A3, 0x1A00365A8, and 3 more...\nfunction @ 0x1A00376B0\n  and:\n    match: contain loop @ 0x1A00376B0\n      or:\n        characteristic: loop @ 0x1A00376B0\n    count(characteristic(nzxor)): 1 @ 0x1A0037857\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00376B0, 0x1A00376BE, 0x1A00376CA, 0x1A00376E1, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A003783D, 0x1A0037842, 0x1A003784D, 0x1A0037852, and 2 more...\nfunction @ 0x1A0038770\n  and:\n    match: contain loop @ 0x1A0038770\n      or:\n        characteristic: loop @ 0x1A0038770\n    count(characteristic(nzxor)): 1 @ 0x1A0038972\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A0038770, 0x1A003877E, 0x1A003878A, 0x1A00387A1, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A0038942, 0x1A003894D, 0x1A0038952, 0x1A003895D, and 2 more...\nfunction @ 0x1A00435A4\n  and:\n    match: contain loop @ 0x1A00435A4\n      or:\n        characteristic: loop @ 0x1A00435A4\n    count(characteristic(nzxor)): 1 @ 0x1A00437A6\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00435A4, 0x1A00435B2, 0x1A00435BE, 0x1A00435D5, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A004377B, 0x1A004378E, 0x1A00437A1, 0x1A00437AF, and 1 more...\nfunction @ 0x1A00444F0\n  and:\n    match: contain loop @ 0x1A00444F0\n      or:\n        characteristic: loop @ 0x1A00444F0\n    count(characteristic(nzxor)): 1 @ 0x1A0044661\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00444F0, 0x1A00444FE, 0x1A004450A, 0x1A0044521, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A0044657, 0x1A004465C, 0x1A0044667, 0x1A0044673, and 2 more...\nfunction @ 0x1A004735C\n  and:\n    match: contain loop @ 0x1A004735C\n      or:\n        characteristic: loop @ 0x1A004735C\n    count(characteristic(nzxor)): 1 @ 0x1A00474BD\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A004735C, 0x1A004736A, 0x1A0047376, 0x1A004738D, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00474A7, 0x1A00474B3, 0x1A00474B8, 0x1A00474C3, and 4 more...\nfunction @ 0x1A0052F70\n  and:\n    match: contain loop @ 0x1A0052F70\n      or:\n        characteristic: loop @ 0x1A0052F70\n    count(characteristic(nzxor)): 1 @ 0x1A00530FB\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A0052F70, 0x1A0052F7E, 0x1A0052F8A, 0x1A0052FA1, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00530F1, 0x1A00530F6, 0x1A0053101, 0x1A005310F, and 2 more...\nfunction @ 0x1A0054044\n  and:\n    match: contain loop @ 0x1A0054044\n      or:\n        characteristic: loop @ 0x1A0054044\n    count(characteristic(nzxor)): 1 @ 0x1A00542A0\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A0054044, 0x1A0054052, 0x1A005405E, 0x1A0054075, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A0054286, 0x1A005428B, 0x1A0054296, 0x1A005429B, and 2 more...\nfunction @ 0x1A0057370\n  and:\n    match: contain loop @ 0x1A0057370\n      or:\n        characteristic: loop @ 0x1A0057370\n    count(characteristic(nzxor)): 1 @ 0x1A00574F0\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A0057370, 0x1A005737E, 0x1A005738A, 0x1A00573A1, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00574D3, 0x1A00574E6, 0x1A00574EB, 0x1A00574F6, and 1 more...\nfunction @ 0x1A005DDBC\n  and:\n    match: contain loop @ 0x1A005DDBC\n      or:\n        characteristic: loop @ 0x1A005DDBC\n    count(characteristic(nzxor)): 1 @ 0x1A005DF37\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A005DDBC, 0x1A005DDCA, 0x1A005DDD6, 0x1A005DDED, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A005DF2D, 0x1A005DF32, 0x1A005DF3D, 0x1A005DF42, and 1 more...\nfunction @ 0x1A005E468\n  and:\n    match: contain loop @ 0x1A005E468\n      or:\n        characteristic: loop @ 0x1A005E468\n    count(characteristic(nzxor)): 1 @ 0x1A005E636\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A005E468, 0x1A005E476, 0x1A005E482, 0x1A005E499, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A005E62C, 0x1A005E631, 0x1A005E63C, 0x1A005E644, and 2 more...\nfunction @ 0x1A006B07C\n  and:\n    match: contain loop @ 0x1A006B07C\n      or:\n        characteristic: loop @ 0x1A006B07C\n    count(characteristic(nzxor)): 1 @ 0x1A006B326\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A006B07C, 0x1A006B08A, 0x1A006B096, 0x1A006B0AD, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A006B321, 0x1A006B32D, 0x1A006B339, 0x1A006B341\nfunction @ 0x1A006D66C\n  and:\n    match: contain loop @ 0x1A006D66C\n      or:\n        characteristic: loop @ 0x1A006D66C\n    count(characteristic(nzxor)): 1 @ 0x1A006D974\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A006D66C, 0x1A006D67A, 0x1A006D686, 0x1A006D69D, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A006D92E, 0x1A006D936, 0x1A006D944, 0x1A006D957, and 2 more...\nfunction @ 0x1A0077C70\n  and:\n    match: contain loop @ 0x1A0077C70\n      or:\n        characteristic: loop @ 0x1A0077C70\n    count(characteristic(nzxor)): 1 @ 0x1A0077FA3\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A0077C70, 0x1A0077C81, 0x1A0077C8D, 0x1A0077CA4, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A0077F99, 0x1A0077F9E, 0x1A0077FA9, 0x1A0077FB7, and 3 more...\nfunction @ 0x1A007EF24\n  and:\n    match: contain loop @ 0x1A007EF24\n      or:\n        characteristic: loop @ 0x1A007EF24\n    count(characteristic(nzxor)): 1 @ 0x1A007F2DE\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A007EF24, 0x1A007EF35, 0x1A007EF41, 0x1A007EF58, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A007F2B9, 0x1A007F2BE, 0x1A007F2C9, 0x1A007F2CE, and 1 more...\nfunction @ 0x1A00814D0\n  and:\n    match: contain loop @ 0x1A00814D0\n      or:\n        characteristic: loop @ 0x1A00814D0\n    count(characteristic(nzxor)): 1 @ 0x1A00817CE\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00814D0, 0x1A00814DE, 0x1A00814EA, 0x1A0081501, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00817C9, 0x1A00817D7, 0x1A00817E2, 0x1A00817EE\nfunction @ 0x1A0084494\n  and:\n    match: contain loop @ 0x1A0084494\n      or:\n        characteristic: loop @ 0x1A0084494\n    count(characteristic(nzxor)): 1 @ 0x1A008464A\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A0084494, 0x1A00844A2, 0x1A00844AE, 0x1A00844C5, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A0084621, 0x1A008462F, 0x1A0084637, 0x1A0084645\nfunction @ 0x1A008B54C\n  and:\n    match: contain loop @ 0x1A008B54C\n      or:\n        characteristic: loop @ 0x1A008B54C\n    count(characteristic(nzxor)): 1 @ 0x1A008B733\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A008B54C, 0x1A008B55A, 0x1A008B566, 0x1A008B57D, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A008B71E, 0x1A008B729, 0x1A008B72E, 0x1A008B739, and 1 more...\nfunction @ 0x1A008FF14\n  and:\n    match: contain loop @ 0x1A008FF14\n      or:\n        characteristic: loop @ 0x1A008FF14\n    count(characteristic(nzxor)): 1 @ 0x1A009027A\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A008FF14, 0x1A008FF25, 0x1A008FF31, 0x1A008FF48, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A009025A, 0x1A0090262, 0x1A0090270, 0x1A0090275, and 5 more...\nfunction @ 0x1A009A26C\n  and:\n    match: contain loop @ 0x1A009A26C\n      or:\n        characteristic: loop @ 0x1A009A26C\n    count(characteristic(nzxor)): 1 @ 0x1A009A3F0\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A009A26C, 0x1A009A27A, 0x1A009A286, 0x1A009A29D, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A009A3D3, 0x1A009A3E6, 0x1A009A3EB, 0x1A009A3F6, and 3 more...\nfunction @ 0x1A00A0524\n  and:\n    match: contain loop @ 0x1A00A0524\n      or:\n        characteristic: loop @ 0x1A00A0524\n    count(characteristic(nzxor)): 1 @ 0x1A00A06B9\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00A0524, 0x1A00A0532, 0x1A00A053E, 0x1A00A0555, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00A0699, 0x1A00A06A1, 0x1A00A06AF, 0x1A00A06B4, and 4 more...\nfunction @ 0x1A00AA288\n  and:\n    match: contain loop @ 0x1A00AA288\n      or:\n        characteristic: loop @ 0x1A00AA288\n    count(characteristic(nzxor)): 1 @ 0x1A00AA445\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00AA288, 0x1A00AA296, 0x1A00AA2A2, 0x1A00AA2B9, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00AA415, 0x1A00AA428, 0x1A00AA43B, 0x1A00AA440\nfunction @ 0x1A00AE9A8\n  and:\n    match: contain loop @ 0x1A00AE9A8\n      or:\n        characteristic: loop @ 0x1A00AE9A8\n    count(characteristic(nzxor)): 1 @ 0x1A00AEBA2\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00AE9A8, 0x1A00AE9B6, 0x1A00AE9C2, 0x1A00AE9D9, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00AEB62, 0x1A00AEB75, 0x1A00AEB81, 0x1A00AEB8C, and 2 more...\nfunction @ 0x1A00B1248\n  and:\n    match: contain loop @ 0x1A00B1248\n      or:\n        characteristic: loop @ 0x1A00B1248\n    count(characteristic(nzxor)): 1 @ 0x1A00B1400\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00B1248, 0x1A00B1256, 0x1A00B1262, 0x1A00B1279, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00B13D5, 0x1A00B13DD, 0x1A00B13EB, 0x1A00B13F0, and 2 more...\nfunction @ 0x1A00B1484\n  and:\n    match: contain loop @ 0x1A00B1484\n      or:\n        characteristic: loop @ 0x1A00B1484\n    count(characteristic(nzxor)): 1 @ 0x1A00B165B\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00B1484, 0x1A00B1492, 0x1A00B149E, 0x1A00B14B5, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00B1623, 0x1A00B1628, 0x1A00B1633, 0x1A00B163E, and 4 more...\nfunction @ 0x1A00B6868\n  and:\n    match: contain loop @ 0x1A00B6868\n      or:\n        characteristic: loop @ 0x1A00B6868\n    count(characteristic(nzxor)): 1 @ 0x1A00B69CB\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00B6868, 0x1A00B6876, 0x1A00B6882, 0x1A00B6899, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00B69B3, 0x1A00B69C1, 0x1A00B69C6, 0x1A00B69D1, and 4 more...\nfunction @ 0x1A00B6F28\n  and:\n    match: contain loop @ 0x1A00B6F28\n      or:\n        characteristic: loop @ 0x1A00B6F28\n    count(characteristic(nzxor)): 1 @ 0x1A00B70B1\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00B6F28, 0x1A00B6F36, 0x1A00B6F42, 0x1A00B6F59, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00B708B, 0x1A00B7099, 0x1A00B70A7, 0x1A00B70AC, and 1 more...\nfunction @ 0x1A00B792C\n  and:\n    match: contain loop @ 0x1A00B792C\n      or:\n        characteristic: loop @ 0x1A00B792C\n    count(characteristic(nzxor)): 1 @ 0x1A00B7A9D\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00B792C, 0x1A00B793A, 0x1A00B7946, 0x1A00B795D, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00B7A93, 0x1A00B7A98, 0x1A00B7AA3, 0x1A00B7AA8, and 4 more...\nfunction @ 0x1A00BADEC\n  and:\n    match: contain loop @ 0x1A00BADEC\n      or:\n        characteristic: loop @ 0x1A00BADEC\n    count(characteristic(nzxor)): 1 @ 0x1A00BAFDE\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00BADEC, 0x1A00BADFA, 0x1A00BAE06, 0x1A00BAE1D, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00BAFD9, 0x1A00BAFE7, 0x1A00BAFEC, 0x1A00BAFF7, and 2 more...\nfunction @ 0x1A00BC3A0\n  and:\n    match: contain loop @ 0x1A00BC3A0\n      or:\n        characteristic: loop @ 0x1A00BC3A0\n    count(characteristic(nzxor)): 1 @ 0x1A00BC6B2\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00BC3A0, 0x1A00BC3B1, 0x1A00BC3BD, 0x1A00BC3D4, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00BC682, 0x1A00BC687, 0x1A00BC692, 0x1A00BC69A, and 3 more...\nfunction @ 0x1A00BF0FC\n  and:\n    match: contain loop @ 0x1A00BF0FC\n      or:\n        characteristic: loop @ 0x1A00BF0FC\n    count(characteristic(nzxor)): 1 @ 0x1A00BF28E\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00BF0FC, 0x1A00BF10A, 0x1A00BF116, 0x1A00BF12D, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00BF262, 0x1A00BF26D, 0x1A00BF27B, 0x1A00BF289, and 1 more...\nfunction @ 0x1A00CBEE4\n  and:\n    match: contain loop @ 0x1A00CBEE4\n      or:\n        characteristic: loop @ 0x1A00CBEE4\n    count(characteristic(nzxor)): 1 @ 0x1A00CC071\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00CBEE4, 0x1A00CBEF2, 0x1A00CBEFE, 0x1A00CBF15, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00CC067, 0x1A00CC06C, 0x1A00CC077, 0x1A00CC085, and 3 more...\nfunction @ 0x1A00CEBB0\n  and:\n    match: contain loop @ 0x1A00CEBB0\n      or:\n        characteristic: loop @ 0x1A00CEBB0\n    count(characteristic(nzxor)): 1 @ 0x1A00CED5D\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00CEBB0, 0x1A00CEBBE, 0x1A00CEBCA, 0x1A00CEBE1, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00CED2D, 0x1A00CED32, 0x1A00CED3D, 0x1A00CED45, and 2 more...\nfunction @ 0x1A00CFEFC\n  and:\n    match: contain loop @ 0x1A00CFEFC\n      or:\n        characteristic: loop @ 0x1A00CFEFC\n    count(characteristic(nzxor)): 1 @ 0x1A00D00FE\n    count(characteristic(calls from)): 4 or fewer @ 0x1A001A2F8, 0x1A001B370, 0x1A001B3E0, 0x1A00DD0C0\n    count(basic block): between 4 and 50 @ 0x1A00CFEFC, 0x1A00CFF0A, 0x1A00CFF16, 0x1A00CFF2D, and 6 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00D00CF, 0x1A00D00DB, 0x1A00D00E9, 0x1A00D00F4, and 1 more...\nfunction @ 0x1A00DF1FC\n  and:\n    match: contain loop @ 0x1A00DF1FC\n      or:\n        characteristic: loop @ 0x1A00DF1FC\n    count(characteristic(nzxor)): 1 @ 0x1A00DF21D\n    count(characteristic(calls from)): 4 or fewer\n    count(basic block): between 4 and 50 @ 0x1A00DF1FC, 0x1A00DF241, 0x1A00DF24A, 0x1A00DF255, and 8 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00DF241, 0x1A00DF24A, 0x1A00DF25C, 0x1A00DF26E, and 1 more...\nfunction @ 0x1A00FB590\n  and:\n    match: contain loop @ 0x1A00FB590\n      or:\n        characteristic: loop @ 0x1A00FB590\n        characteristic: tight loop @ 0x1A00FB670\n    count(characteristic(nzxor)): 1 @ 0x1A00FB617\n    count(characteristic(calls from)): 4 or fewer\n    count(basic block): between 4 and 50 @ 0x1A00FB590, 0x1A00FB5D5, 0x1A00FB5DA, 0x1A00FB5E6, and 19 more...\n    or:\n      count(mnemonic(movzx)): 4 or more @ 0x1A00FB5DA, 0x1A00FB5FA, 0x1A00FB610, 0x1A00FB61D, and 2 more...\n\nhash data using fnv\nnamespace    data-manipulation/hashing/fnv                                      \nauthor       moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com  \nscope        function                                                           \nmbc          Data::Non-Cryptographic Hash::FNV [C0030.005]                      \nreferences   https://en.wikipedia.org/wiki/Fowler%E2%80%93Noll%E2%80%93Vo_hash_…\n             http://isthe.com/chongo/tech/comp/fnv/,                            \n             https://create.stephan-brumme.com/fnv-hash/                        \ndescription  can be any Fowler-Noll-Vo (FNV) hash variant, including FNV-1,     \n             FNV-1a, FNV-0                                                      \nfunction @ 0x1A001AF38\n  and:\n    basic block:\n      and:\n        characteristic: nzxor @ 0x1A001AF84\n        or:\n          mnemonic: imul @ 0x1A001AF8B\n    or:\n      number: 0x1000193 = FNV prime @ 0x1A001AF8B\n    optional:\n      characteristic: loop @ 0x1A001AF38\n\nauthenticate HMAC (3 matches)\nnamespace   data-manipulation/hmac                                              \nauthor      moritz.raabe@mandiant.com                                           \nscope       function                                                            \nmbc         Cryptography::Hashed Message Authentication Code [C0061]            \nreferences  https://tools.ietf.org/html/rfc2104,                                \n            https://tools.ietf.org/html/rfc4634, https://github.com/ogay/hmac   \nfunction @ 0x1A001F334\n  and:\n    number: 0x36 = inner padding byte value @ 0x1A001F67E, 0x1A001FF23\n    number: 0x5C = outer padding byte value @ 0x1A001F568, 0x1A001F610, 0x1A001F8A2, 0x1A001FA30, and 1 more...\n    match: contain loop @ 0x1A001F334\n      or:\n        characteristic: loop @ 0x1A001F334\n    count(characteristic(nzxor)): 2 or more @ 0x1A00203A4, 0x1A00203CB, 0x1A00203DB\n    optional: = block size\n      number: 0x40 = MD5, SHA-1, SHA-224, or SHA-256 @ 0x1A001F506, 0x1A001F70A, 0x1A001FA4C, 0x1A0020088\n      number: 0x80 = SHA-384 or SHA-512 @ 0x1A001FAAA\nfunction @ 0x1A00254A4\n  and:\n    number: 0x36 = inner padding byte value @ 0x1A00257EE\n    number: 0x5C = outer padding byte value @ 0x1A002564E, 0x1A00259A4, 0x1A0025A02, 0x1A0025D77, and 1 more...\n    match: contain loop @ 0x1A00254A4\n      or:\n        characteristic: loop @ 0x1A00254A4\n    count(characteristic(nzxor)): 2 or more @ 0x1A0026150, 0x1A0026161, 0x1A0026187\n    optional: = block size\n      number: 0x40 = MD5, SHA-1, SHA-224, or SHA-256 @ 0x1A00257E4, 0x1A002587A, 0x1A0025B72\n      number: 0x80 = SHA-384 or SHA-512 @ 0x1A0025BFA\nfunction @ 0x1A00A0754\n  and:\n    number: 0x36 = inner padding byte value @ 0x1A00A0A9E, 0x1A00A0C9A\n    number: 0x5C = outer padding byte value @ 0x1A00A0CB2\n    match: contain loop @ 0x1A00A0754\n      or:\n        characteristic: loop @ 0x1A00A0754\n    count(characteristic(nzxor)): 2 or more @ 0x1A00A0E16, 0x1A00A0E21, 0x1A00A0E48\n    optional: = block size\n      number: 0x40 = MD5, SHA-1, SHA-224, or SHA-256 @ 0x1A00A0B2A\n\naccess PEB ldr_data (2 matches)\nnamespace   linking/runtime-linking                                             \nauthor      moritz.raabe@mandiant.com                                           \nscope       basic block                                                         \natt&ck      Execution::Shared Modules [T1129]                                   \nreferences  https://www.geoffchappell.com/studies/windows/km/ntoskrnl/inc/api/n…\n            https://github.com/d35ha/CallObfuscator/blob/5834aff9ff4511f1408ae4…\nbasic block @ 0x1A00DD0F0 in function 0x1A00DD0F0\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1A00DD0F0\n        or:\n          characteristic: peb access @ 0x1A00DD0F4\n      offset: 0x18 = PEB.LDR_DATA @ 0x1A00DD112, 0x1A00DD117\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1A00DD0FD, 0x1A00DD109, 0x1A00DD10E\nbasic block @ 0x1A00F55CC in function 0x1A00F55CC\n  or:\n    and: = x64\n      arch: amd64\n      match: PEB access @ 0x1A00F55CC\n        or:\n          characteristic: peb access @ 0x1A00F560A\n      offset: 0x18 = PEB.LDR_DATA @ 0x1A00F55CF\n      or: = resolve a module list\n        offset: 0x10 = PEB.LDR_DATA.InLoadOrderModuleList @ 0x1A00F55E8, 0x1A00F55F7\n\nparse PE header (94 matches)\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x1A0018FB0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0019058, 0x1A00190BE, 0x1A00190EB, 0x1A001912A, and 14 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x1A001912A\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x1A00190EB\n      optional:\n        and:\n          operand[1].offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x1A0019108, 0x1A00196E5, 0x1A00196F6, 0x1A0019713\n          or:\n            and:\n              arch: amd64\n              operand[1].offset: 0x50 = IMAGE_NT_HEADERS64.OptionalHeader.SizeOfImage @ 0x1A0019367, 0x1A001938F, 0x1A00193AD, 0x1A00193CD, and 1 more...\n              operand[1].offset: 0x30 = IMAGE_NT_HEADERS64.OptionalHeader.ImageBase @ 0x1A001942D, 0x1A001943C, 0x1A001944A, 0x1A0019452, and 7 more...\nfunction @ 0x1A00199C0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0019058, 0x1A00190BE, 0x1A00190EB, 0x1A001912A, and 15 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x1A001912A\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x1A00190EB\n      optional:\n        and:\n          operand[1].offset: 0x3C = IMAGE_DOS_HEADER.e_lfanew @ 0x1A0019108, 0x1A00196E5, 0x1A00196F6, 0x1A0019713\n          or:\n            and:\n              arch: amd64\n              operand[1].offset: 0x50 = IMAGE_NT_HEADERS64.OptionalHeader.SizeOfImage @ 0x1A0019367, 0x1A001938F, 0x1A00193AD, 0x1A00193CD, and 1 more...\n              operand[1].offset: 0x30 = IMAGE_NT_HEADERS64.OptionalHeader.ImageBase @ 0x1A001942D, 0x1A001943C, 0x1A001944A, 0x1A0019452, and 7 more...\nfunction @ 0x1A001C520\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A001C527, 0x1A001C54F\n      or:\n        and:\n          number: 0x50 @ 0x1A001CDC6\n          number: 0x45 @ 0x1A001CD0B\n      or:\n        and:\n          number: 0x4D @ 0x1A001CD93\n          number: 0x5A @ 0x1A001CE70\nfunction @ 0x1A001D360\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A001D367, 0x1A001D38F\n      or:\n        and:\n          number: 0x50 @ 0x1A001D806\n          number: 0x45 @ 0x1A001D76C\n      or:\n        and:\n          number: 0x4D @ 0x1A001D690, 0x1A001D7DC, 0x1A001D826\n          number: 0x5A @ 0x1A001D892\nfunction @ 0x1A001F334\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A001F33B, 0x1A001F363, 0x1A0020359\n      or:\n        and:\n          number: 0x50 @ 0x1A001F7EA\n          number: 0x45 @ 0x1A001F750, 0x1A001F818\n      or:\n        and:\n          number: 0x4D @ 0x1A001F7C0\n          number: 0x5A @ 0x1A001F886, 0x1A001FF89\nfunction @ 0x1A0020FF4\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0020FFB, 0x1A0021023\n      or:\n        and:\n          number: 0x50 @ 0x1A00218C4, 0x1A00225AB\n          number: 0x45 @ 0x1A0021809, 0x1A00221C3, 0x1A00222EF\n      or:\n        and:\n          number: 0x4D @ 0x1A0021862, 0x1A0021891, 0x1A00221AF\n          number: 0x5A @ 0x1A002196E\nfunction @ 0x1A0022D54\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0022D5B, 0x1A0022D83\n      or:\n        and:\n          number: 0x50 @ 0x1A00231FA\n          number: 0x45 @ 0x1A0023014, 0x1A0023160\n      or:\n        and:\n          number: 0x4D @ 0x1A00231D0\n          number: 0x5A @ 0x1A0023286\nfunction @ 0x1A00254A4\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00254AB, 0x1A00254D3, 0x1A0026115\n      or:\n        and:\n          number: 0x50 @ 0x1A002595A, 0x1A0025F20\n          number: 0x45 @ 0x1A00258C0\n      or:\n        and:\n          number: 0x4D @ 0x1A00256E8, 0x1A0025930, 0x1A0025A3E, 0x1A0025E32\n          number: 0x5A @ 0x1A00259E6\nfunction @ 0x1A00267D4\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00267DB, 0x1A0026803\n      or:\n        and:\n          number: 0x50 @ 0x1A0026C7A\n          number: 0x45 @ 0x1A0026BE0\n      or:\n        and:\n          number: 0x4D @ 0x1A00268C6, 0x1A0026A4E, 0x1A0026C50\n          number: 0x5A @ 0x1A0026D06\nfunction @ 0x1A0027034\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A002703B, 0x1A0027063\n      or:\n        and:\n          number: 0x50 @ 0x1A00274DA\n          number: 0x45 @ 0x1A0027440\n      or:\n        and:\n          number: 0x4D @ 0x1A00274B0\n          number: 0x5A @ 0x1A0027566\nfunction @ 0x1A002BC6C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A002BC73, 0x1A002BC9B\n      or:\n        and:\n          number: 0x50 @ 0x1A002C566\n          number: 0x45 @ 0x1A002C4AB\n      or:\n        and:\n          number: 0x4D @ 0x1A002C207, 0x1A002C3C1, 0x1A002C533\n          number: 0x5A @ 0x1A002C610\nfunction @ 0x1A002DCA4\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A002DCAB, 0x1A002DCD3\n      or:\n        and:\n          number: 0x50 @ 0x1A002E14A\n          number: 0x45 @ 0x1A002E0B0\n      or:\n        and:\n          number: 0x4D @ 0x1A002E120\n          number: 0x5A @ 0x1A002E1D6\nfunction @ 0x1A002FBD8\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A002FBDF, 0x1A002FC07\n      or:\n        and:\n          number: 0x50 @ 0x1A003007E\n          number: 0x45 @ 0x1A002FFE4, 0x1A0030CF9\n      or:\n        and:\n          number: 0x4D @ 0x1A0030054, 0x1A003059A\n          number: 0x5A @ 0x1A003010A\nfunction @ 0x1A0032440\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0032447, 0x1A003246F\n      or:\n        and:\n          number: 0x50 @ 0x1A00328E6\n          number: 0x45 @ 0x1A003284C\n      or:\n        and:\n          number: 0x4D @ 0x1A00328BC\n          number: 0x5A @ 0x1A0032972\nfunction @ 0x1A00340B0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00340B7, 0x1A00340DF\n      or:\n        and:\n          number: 0x50 @ 0x1A0034556\n          number: 0x45 @ 0x1A00344BC, 0x1A00345BC\n      or:\n        and:\n          number: 0x4D @ 0x1A003452C\n          number: 0x5A @ 0x1A00345E2\nfunction @ 0x1A0035C5C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0035C63, 0x1A0035C8B\n      or:\n        and:\n          number: 0x50 @ 0x1A0036102\n          number: 0x45 @ 0x1A0035E20, 0x1A0036068\n      or:\n        and:\n          number: 0x4D @ 0x1A00360D8\n          number: 0x5A @ 0x1A003618E\nfunction @ 0x1A0036898\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A003689F, 0x1A00368C7\n      or:\n        and:\n          number: 0x50 @ 0x1A0036D3E\n          number: 0x45 @ 0x1A0036CA4\n      or:\n        and:\n          number: 0x4D @ 0x1A0036D14\n          number: 0x5A @ 0x1A0036DCA\nfunction @ 0x1A0038168\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A003816F, 0x1A0038197\n      or:\n        and:\n          number: 0x50 @ 0x1A003860E\n          number: 0x45 @ 0x1A0038574\n      or:\n        and:\n          number: 0x4D @ 0x1A00385E4\n          number: 0x5A @ 0x1A003869A\nfunction @ 0x1A003A92C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A003A933, 0x1A003A95B\n      or:\n        and:\n          number: 0x50 @ 0x1A003ADD2\n          number: 0x45 @ 0x1A003AB98, 0x1A003AD38\n      or:\n        and:\n          number: 0x4D @ 0x1A003ADA8\n          number: 0x5A @ 0x1A003AE5E\nfunction @ 0x1A003BEC0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A003BEC7, 0x1A003BEEF\n      or:\n        and:\n          number: 0x50 @ 0x1A003C366\n          number: 0x45 @ 0x1A003C2CC\n      or:\n        and:\n          number: 0x4D @ 0x1A003C33C\n          number: 0x5A @ 0x1A003C3F2\nfunction @ 0x1A003CE44\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A003CE4B, 0x1A003CE73\n      or:\n        and:\n          number: 0x50 @ 0x1A003D2EA\n          number: 0x45 @ 0x1A003D250\n      or:\n        and:\n          number: 0x4D @ 0x1A003D2C0\n          number: 0x5A @ 0x1A003D37F, 0x1A003D3D3\nfunction @ 0x1A003D408\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A003D40F, 0x1A003D437\n      or:\n        and:\n          number: 0x50 @ 0x1A003D8AE\n          number: 0x45 @ 0x1A003D814\n      or:\n        and:\n          number: 0x4D @ 0x1A003D884\n          number: 0x5A @ 0x1A003D93A\nfunction @ 0x1A003DAB8\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A003DABF, 0x1A003DAE7\n      or:\n        and:\n          number: 0x50 @ 0x1A003DF5E\n          number: 0x45 @ 0x1A003DEC4\n      or:\n        and:\n          number: 0x4D @ 0x1A003DF34\n          number: 0x5A @ 0x1A003DFEA\nfunction @ 0x1A003F038\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A003F03F, 0x1A003F067\n      or:\n        and:\n          number: 0x50 @ 0x1A003F4DE\n          number: 0x45 @ 0x1A003F444\n      or:\n        and:\n          number: 0x4D @ 0x1A003F4B4\n          number: 0x5A @ 0x1A003F56A\nfunction @ 0x1A0040F4C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0040F53, 0x1A0040F7B\n      or:\n        and:\n          number: 0x50 @ 0x1A00413F2\n          number: 0x45 @ 0x1A0041358\n      or:\n        and:\n          number: 0x4D @ 0x1A00413C8\n          number: 0x5A @ 0x1A004147E\nfunction @ 0x1A0042354\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A004235B, 0x1A0042383\n      or:\n        and:\n          number: 0x50 @ 0x1A00427FA\n          number: 0x45 @ 0x1A0042760\n      or:\n        and:\n          number: 0x4D @ 0x1A00427D0\n          number: 0x5A @ 0x1A0042886\nfunction @ 0x1A0042AE8\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0042AEF, 0x1A0042B17\n      or:\n        and:\n          number: 0x50 @ 0x1A0042F8E\n          number: 0x45 @ 0x1A0042EF4\n      or:\n        and:\n          number: 0x4D @ 0x1A0042F64\n          number: 0x5A @ 0x1A004301A\nfunction @ 0x1A00485AC\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00485B3, 0x1A00485DB\n      or:\n        and:\n          number: 0x50 @ 0x1A0048A52\n          number: 0x45 @ 0x1A00489B8\n      or:\n        and:\n          number: 0x4D @ 0x1A00489F4, 0x1A0048A28\n          number: 0x5A @ 0x1A0048ADE\nfunction @ 0x1A004903C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0049043, 0x1A004906B\n      or:\n        and:\n          number: 0x50 @ 0x1A00494E2\n          number: 0x45 @ 0x1A0049448\n      or:\n        and:\n          number: 0x4D @ 0x1A00494B8\n          number: 0x5A @ 0x1A004956E\nfunction @ 0x1A0049664\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A004966B, 0x1A0049693\n      or:\n        and:\n          number: 0x50 @ 0x1A0049B0A\n          number: 0x45 @ 0x1A0049A70\n      or:\n        and:\n          number: 0x4D @ 0x1A0049AE0\n          number: 0x5A @ 0x1A0049AD6, 0x1A0049B96\nfunction @ 0x1A004A098\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A004A09F, 0x1A004A0C7\n      or:\n        and:\n          number: 0x50 @ 0x1A004A53E\n          number: 0x45 @ 0x1A004A4A4\n      or:\n        and:\n          number: 0x4D @ 0x1A004A514\n          number: 0x5A @ 0x1A004A5CA\nfunction @ 0x1A004AF78\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A004AF7F, 0x1A004AFA7\n      or:\n        and:\n          number: 0x50 @ 0x1A004B41E\n          number: 0x45 @ 0x1A004B384\n      or:\n        and:\n          number: 0x4D @ 0x1A004B3F4\n          number: 0x5A @ 0x1A004B4AA\nfunction @ 0x1A004B880\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A004B887, 0x1A004B8AF\n      or:\n        and:\n          number: 0x50 @ 0x1A004BD26\n          number: 0x45 @ 0x1A004BC8C\n      or:\n        and:\n          number: 0x4D @ 0x1A004BCFC\n          number: 0x5A @ 0x1A004BDB2\nfunction @ 0x1A004C014\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A004C01B, 0x1A004C043\n      or:\n        and:\n          number: 0x50 @ 0x1A004C4BA\n          number: 0x45 @ 0x1A004C420\n      or:\n        and:\n          number: 0x4D @ 0x1A004C490\n          number: 0x5A @ 0x1A004C546\nfunction @ 0x1A004E88C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A004E893, 0x1A004E8BB\n      or:\n        and:\n          number: 0x50 @ 0x1A004ED28, 0x1A004ED32\n          number: 0x45 @ 0x1A004EC98\n      or:\n        and:\n          number: 0x4D @ 0x1A004ED08\n          number: 0x5A @ 0x1A004EDBE\nfunction @ 0x1A005432C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0054333, 0x1A005435B\n      or:\n        and:\n          number: 0x50 @ 0x1A00547D2\n          number: 0x45 @ 0x1A0054738\n      or:\n        and:\n          number: 0x4D @ 0x1A00547A8\n          number: 0x5A @ 0x1A005485E\nfunction @ 0x1A0057778\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A005777F, 0x1A00577A7\n      or:\n        and:\n          number: 0x50 @ 0x1A0057C1E\n          number: 0x45 @ 0x1A0057B84\n      or:\n        and:\n          number: 0x4D @ 0x1A0057BF4\n          number: 0x5A @ 0x1A0057CAA, 0x1A0057F4D\nfunction @ 0x1A0058BF0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0058BF7, 0x1A0058C1F\n      or:\n        and:\n          number: 0x50 @ 0x1A0059096\n          number: 0x45 @ 0x1A0058C64, 0x1A0058FFC\n      or:\n        and:\n          number: 0x4D @ 0x1A005906C\n          number: 0x5A @ 0x1A0059122\nfunction @ 0x1A005BD5C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A005BD63, 0x1A005BD8B\n      or:\n        and:\n          number: 0x50 @ 0x1A005C202\n          number: 0x45 @ 0x1A005C168\n      or:\n        and:\n          number: 0x4D @ 0x1A005C1D8\n          number: 0x5A @ 0x1A005C28E\nfunction @ 0x1A0062320\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0062327, 0x1A006234F\n      or:\n        and:\n          number: 0x50 @ 0x1A00627C6\n          number: 0x45 @ 0x1A006272C\n      or:\n        and:\n          number: 0x4D @ 0x1A006279C\n          number: 0x5A @ 0x1A0062852, 0x1A00628D4\nfunction @ 0x1A006319C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00631A3, 0x1A00631CB\n      or:\n        and:\n          number: 0x50 @ 0x1A0063642\n          number: 0x45 @ 0x1A00635A8, 0x1A006428A\n      or:\n        and:\n          number: 0x4D @ 0x1A0063618\n          number: 0x5A @ 0x1A00636CE\nfunction @ 0x1A00661D8\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00661DF, 0x1A0066207\n      or:\n        and:\n          number: 0x50 @ 0x1A006667E\n          number: 0x45 @ 0x1A00665E4\n      or:\n        and:\n          number: 0x4D @ 0x1A0066654\n          number: 0x5A @ 0x1A006670A\nfunction @ 0x1A0069790\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0069797, 0x1A00697BF\n      or:\n        and:\n          number: 0x50 @ 0x1A0069C36\n          number: 0x45 @ 0x1A0069B9C\n      or:\n        and:\n          number: 0x4D @ 0x1A0069C0C\n          number: 0x5A @ 0x1A0069CC2\nfunction @ 0x1A006A3B8\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A006A3BF, 0x1A006A3E7\n      or:\n        and:\n          number: 0x50 @ 0x1A006A85E\n          number: 0x45 @ 0x1A006A7C4, 0x1A006ABC0\n      or:\n        and:\n          number: 0x4D @ 0x1A006A834\n          number: 0x5A @ 0x1A006A8EA\nfunction @ 0x1A006B9B0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A006B9B7, 0x1A006B9DF\n      or:\n        and:\n          number: 0x50 @ 0x1A006BE56\n          number: 0x45 @ 0x1A006BDBC\n      or:\n        and:\n          number: 0x4D @ 0x1A006BE2C\n          number: 0x5A @ 0x1A006BEE2\nfunction @ 0x1A006C52C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A006C533, 0x1A006C55B\n      or:\n        and:\n          number: 0x50 @ 0x1A006CE0A\n          number: 0x45 @ 0x1A006CD4F\n      or:\n        and:\n          number: 0x4D @ 0x1A006CDD7\n          number: 0x5A @ 0x1A006CEB4\nfunction @ 0x1A006D9E8\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A006D9EF, 0x1A006DA17\n      or:\n        and:\n          number: 0x50 @ 0x1A006DE8E\n          number: 0x45 @ 0x1A006DDF4, 0x1A006DF80\n      or:\n        and:\n          number: 0x4D @ 0x1A006DE64\n          number: 0x5A @ 0x1A006DF1A\nfunction @ 0x1A006E85C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A006E863, 0x1A006E88B\n      or:\n        and:\n          number: 0x50 @ 0x1A006ED02\n          number: 0x45 @ 0x1A006EC68\n      or:\n        and:\n          number: 0x4D @ 0x1A006ECD8, 0x1A006EF1A\n          number: 0x5A @ 0x1A006ED8E\nfunction @ 0x1A006FD78\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A006FD7F, 0x1A006FDA7\n      or:\n        and:\n          number: 0x50 @ 0x1A007021E\n          number: 0x45 @ 0x1A0070184\n      or:\n        and:\n          number: 0x4D @ 0x1A00701F4\n          number: 0x5A @ 0x1A00702AA, 0x1A0071790\nfunction @ 0x1A0072278\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A007227F, 0x1A00722A7\n      or:\n        and:\n          number: 0x50 @ 0x1A007271E\n          number: 0x45 @ 0x1A0072684\n      or:\n        and:\n          number: 0x4D @ 0x1A00726F4\n          number: 0x5A @ 0x1A00727AA\nfunction @ 0x1A0072D6C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0072D73, 0x1A0072D9B\n      or:\n        and:\n          number: 0x50 @ 0x1A0073212\n          number: 0x45 @ 0x1A0073178\n      or:\n        and:\n          number: 0x4D @ 0x1A00731E8\n          number: 0x5A @ 0x1A0072EC0, 0x1A007329E\nfunction @ 0x1A0073A3C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0073A43, 0x1A0073A6B\n      or:\n        and:\n          number: 0x50 @ 0x1A0073EE2, 0x1A007400C, 0x1A0074E9E\n          number: 0x45 @ 0x1A0073E48\n      or:\n        and:\n          number: 0x4D @ 0x1A0073ABE, 0x1A0073EB8\n          number: 0x5A @ 0x1A0073F6E, 0x1A0074052\nfunction @ 0x1A0075C0C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0075C13, 0x1A0075C3B\n      or:\n        and:\n          number: 0x50 @ 0x1A00760B2\n          number: 0x45 @ 0x1A0076018\n      or:\n        and:\n          number: 0x4D @ 0x1A0076088\n          number: 0x5A @ 0x1A007613E\nfunction @ 0x1A007878C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0078793, 0x1A00787BB\n      or:\n        and:\n          number: 0x50 @ 0x1A0078C32\n          number: 0x45 @ 0x1A0078B98\n      or:\n        and:\n          number: 0x4D @ 0x1A0078854, 0x1A0078C08, 0x1A0079638, 0x1A0079C43\n          number: 0x5A @ 0x1A0078CBE\nfunction @ 0x1A007AAA0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A007AAA7, 0x1A007AACF\n      or:\n        and:\n          number: 0x50 @ 0x1A007B362\n          number: 0x45 @ 0x1A007B2A7, 0x1A007B421\n      or:\n        and:\n          number: 0x4D @ 0x1A007AE49, 0x1A007B157, 0x1A007B32F\n          number: 0x5A @ 0x1A007B40C\nfunction @ 0x1A007B6E8\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A007B6EF, 0x1A007B717\n      or:\n        and:\n          number: 0x50 @ 0x1A007BB8E, 0x1A007C341\n          number: 0x45 @ 0x1A007BAF4\n      or:\n        and:\n          number: 0x4D @ 0x1A007BB64, 0x1A007CB9F\n          number: 0x5A @ 0x1A007BC1A\nfunction @ 0x1A0082814\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A008281B, 0x1A0082843\n      or:\n        and:\n          number: 0x50 @ 0x1A0082CBA\n          number: 0x45 @ 0x1A0082C20\n      or:\n        and:\n          number: 0x4D @ 0x1A0082C90\n          number: 0x5A @ 0x1A0082D46\nfunction @ 0x1A00853A4\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00853AB, 0x1A00853D3\n      or:\n        and:\n          number: 0x50 @ 0x1A008584A, 0x1A0085C12\n          number: 0x45 @ 0x1A00857B0, 0x1A0085832\n      or:\n        and:\n          number: 0x4D @ 0x1A0085820\n          number: 0x5A @ 0x1A00858D6\nfunction @ 0x1A0089920\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0089927, 0x1A008994F\n      or:\n        and:\n          number: 0x50 @ 0x1A0089DC6\n          number: 0x45 @ 0x1A0089D2C\n      or:\n        and:\n          number: 0x4D @ 0x1A0089C6C, 0x1A0089D9C\n          number: 0x5A @ 0x1A0089CEA, 0x1A0089E52\nfunction @ 0x1A008BA40\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A008BA47, 0x1A008BA6F\n      or:\n        and:\n          number: 0x50 @ 0x1A008BEE6\n          number: 0x45 @ 0x1A008BE4C\n      or:\n        and:\n          number: 0x4D @ 0x1A008BEBC\n          number: 0x5A @ 0x1A008BF72\nfunction @ 0x1A0091D90\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0091D97, 0x1A0091DBF\n      or:\n        and:\n          number: 0x50 @ 0x1A0092236, 0x1A009290C\n          number: 0x45 @ 0x1A009219C, 0x1A009282F\n      or:\n        and:\n          number: 0x4D @ 0x1A009220C\n          number: 0x5A @ 0x1A00922C2\nfunction @ 0x1A0092C0C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0092C13, 0x1A0092C3B\n      or:\n        and:\n          number: 0x50 @ 0x1A00930B2\n          number: 0x45 @ 0x1A0093018\n      or:\n        and:\n          number: 0x4D @ 0x1A0093088\n          number: 0x5A @ 0x1A009313E\nfunction @ 0x1A009435C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0094363, 0x1A009438B\n      or:\n        and:\n          number: 0x50 @ 0x1A0094802\n          number: 0x45 @ 0x1A0094768\n      or:\n        and:\n          number: 0x4D @ 0x1A00947D8\n          number: 0x5A @ 0x1A009488E\nfunction @ 0x1A0094B44\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0094B4B, 0x1A0094B73\n      or:\n        and:\n          number: 0x50 @ 0x1A0094FEA\n          number: 0x45 @ 0x1A0094F50\n      or:\n        and:\n          number: 0x4D @ 0x1A0094FC0\n          number: 0x5A @ 0x1A0095076\nfunction @ 0x1A0096FD0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0096FD7, 0x1A0096FFF\n      or:\n        and:\n          number: 0x50 @ 0x1A0097476\n          number: 0x45 @ 0x1A00973DC\n      or:\n        and:\n          number: 0x4D @ 0x1A009744C\n          number: 0x5A @ 0x1A0097502\nfunction @ 0x1A009787C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A0097883, 0x1A00978AB\n      or:\n        and:\n          number: 0x50 @ 0x1A0097D22\n          number: 0x45 @ 0x1A0097C88\n      or:\n        and:\n          number: 0x4D @ 0x1A0097BAC, 0x1A0097CF8\n          number: 0x5A @ 0x1A0097DAE\nfunction @ 0x1A0098274\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A009827B, 0x1A00982A3\n      or:\n        and:\n          number: 0x50 @ 0x1A009871A\n          number: 0x45 @ 0x1A0098680\n      or:\n        and:\n          number: 0x4D @ 0x1A0098596, 0x1A00986F0\n          number: 0x5A @ 0x1A00987A6, 0x1A0098898, 0x1A0099CD0\nfunction @ 0x1A009AC38\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A009AC3F, 0x1A009AC67\n      or:\n        and:\n          number: 0x50 @ 0x1A009B0DE\n          number: 0x45 @ 0x1A009B044\n      or:\n        and:\n          number: 0x4D @ 0x1A009B0B4\n          number: 0x5A @ 0x1A009B16A\nfunction @ 0x1A00A0754\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00A075B, 0x1A00A0783, 0x1A00A0DCE\n      or:\n        and:\n          number: 0x50 @ 0x1A00A0A40, 0x1A00A0C0A\n          number: 0x45 @ 0x1A00A0B70\n      or:\n        and:\n          number: 0x4D @ 0x1A00A0BE0\n          number: 0x5A @ 0x1A00A0C96\nfunction @ 0x1A00A3EE0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00A3EE7, 0x1A00A3F0F\n      or:\n        and:\n          number: 0x50 @ 0x1A00A40EA, 0x1A00A4386\n          number: 0x45 @ 0x1A00A42EC\n      or:\n        and:\n          number: 0x4D @ 0x1A00A435C\n          number: 0x5A @ 0x1A00A4412\nfunction @ 0x1A00A4A2C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00A4A33, 0x1A00A4A5B\n      or:\n        and:\n          number: 0x50 @ 0x1A00A4ED2\n          number: 0x45 @ 0x1A00A4E38\n      or:\n        and:\n          number: 0x4D @ 0x1A00A4EA8\n          number: 0x5A @ 0x1A00A4F5E\nfunction @ 0x1A00A5730\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00A5737, 0x1A00A575F\n      or:\n        and:\n          number: 0x50 @ 0x1A00A5BD6\n          number: 0x45 @ 0x1A00A5B3C\n      or:\n        and:\n          number: 0x4D @ 0x1A00A5BAC\n          number: 0x5A @ 0x1A00A5C62\nfunction @ 0x1A00A699C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00A69A3, 0x1A00A69CB\n      or:\n        and:\n          number: 0x50 @ 0x1A00A6E42\n          number: 0x45 @ 0x1A00A6DA8\n      or:\n        and:\n          number: 0x4D @ 0x1A00A6E18\n          number: 0x5A @ 0x1A00A6ECE\nfunction @ 0x1A00A8680\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00A8687, 0x1A00A86AF\n      or:\n        and:\n          number: 0x50 @ 0x1A00A8B26\n          number: 0x45 @ 0x1A00A8A8C\n      or:\n        and:\n          number: 0x4D @ 0x1A00A8AFC\n          number: 0x5A @ 0x1A00A8BB2\nfunction @ 0x1A00AB03C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00AB043, 0x1A00AB06B\n      or:\n        and:\n          number: 0x50 @ 0x1A00AB4E2\n          number: 0x45 @ 0x1A00AB448\n      or:\n        and:\n          number: 0x4D @ 0x1A00AB4B8\n          number: 0x5A @ 0x1A00AB56E\nfunction @ 0x1A00AD12C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00AD133, 0x1A00AD15B\n      or:\n        and:\n          number: 0x50 @ 0x1A00AD5D2\n          number: 0x45 @ 0x1A00AD538\n      or:\n        and:\n          number: 0x4D @ 0x1A00AD5A8\n          number: 0x5A @ 0x1A00AD65E\nfunction @ 0x1A00AD840\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00AD847, 0x1A00AD86F\n      or:\n        and:\n          number: 0x50 @ 0x1A00ADCE6\n          number: 0x45 @ 0x1A00ADB70, 0x1A00ADC4C\n      or:\n        and:\n          number: 0x4D @ 0x1A00ADCBC\n          number: 0x5A @ 0x1A00ADD72\nfunction @ 0x1A00AF074\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00AF07B, 0x1A00AF0A3\n      or:\n        and:\n          number: 0x50 @ 0x1A00AF51A\n          number: 0x45 @ 0x1A00AF480\n      or:\n        and:\n          number: 0x4D @ 0x1A00AF4F0\n          number: 0x5A @ 0x1A00AF5A6\nfunction @ 0x1A00B1918\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00B191F, 0x1A00B1947\n      or:\n        and:\n          number: 0x50 @ 0x1A00B1DBE\n          number: 0x45 @ 0x1A00B1D24\n      or:\n        and:\n          number: 0x4D @ 0x1A00B1D94\n          number: 0x5A @ 0x1A00B1E4A\nfunction @ 0x1A00B44BC\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00B44C3, 0x1A00B44EB\n      or:\n        and:\n          number: 0x50 @ 0x1A00B4912, 0x1A00B4962\n          number: 0x45 @ 0x1A00B48C8\n      or:\n        and:\n          number: 0x4D @ 0x1A00B4938\n          number: 0x5A @ 0x1A00B49EE\nfunction @ 0x1A00B5C18\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00B5C1F, 0x1A00B5C47\n      or:\n        and:\n          number: 0x50 @ 0x1A00B60BE\n          number: 0x45 @ 0x1A00B6024\n      or:\n        and:\n          number: 0x4D @ 0x1A00B6094\n          number: 0x5A @ 0x1A00B614A\nfunction @ 0x1A00BE4C4\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00BE4CB, 0x1A00BE4F3\n      or:\n        and:\n          number: 0x50 @ 0x1A00BE96A\n          number: 0x45 @ 0x1A00BE8D0\n      or:\n        and:\n          number: 0x4D @ 0x1A00BE940\n          number: 0x5A @ 0x1A00BE9F6\nfunction @ 0x1A00C10FC\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00C1103, 0x1A00C112B\n      or:\n        and:\n          number: 0x50 @ 0x1A00C15A2\n          number: 0x45 @ 0x1A00C1508\n      or:\n        and:\n          number: 0x4D @ 0x1A00C1578\n          number: 0x5A @ 0x1A00C162E, 0x1A00C1758\nfunction @ 0x1A00C3FE0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00C3FE7, 0x1A00C400F\n      or:\n        and:\n          number: 0x50 @ 0x1A00C4486\n          number: 0x45 @ 0x1A00C43EC\n      or:\n        and:\n          number: 0x4D @ 0x1A00C445C\n          number: 0x5A @ 0x1A00C4512\nfunction @ 0x1A00CA330\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00CA337, 0x1A00CA35F\n      or:\n        and:\n          number: 0x50 @ 0x1A00CA7D6\n          number: 0x45 @ 0x1A00CA73C\n      or:\n        and:\n          number: 0x4D @ 0x1A00CA7AC\n          number: 0x5A @ 0x1A00CA862\nfunction @ 0x1A00CCB68\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00CCB6F, 0x1A00CCB97\n      or:\n        and:\n          number: 0x50 @ 0x1A00CD00E\n          number: 0x45 @ 0x1A00CCF74\n      or:\n        and:\n          number: 0x4D @ 0x1A00CCFE4\n          number: 0x5A @ 0x1A00CCEDE, 0x1A00CCF5C, 0x1A00CD09A\nfunction @ 0x1A00D1CC8\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00D1CCF, 0x1A00D1CF7\n      or:\n        and:\n          number: 0x50 @ 0x1A00D216E\n          number: 0x45 @ 0x1A00D20D4\n      or:\n        and:\n          number: 0x4D @ 0x1A00D2144\n          number: 0x5A @ 0x1A00D21FA\nfunction @ 0x1A00D259C\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00D25A3, 0x1A00D25CB\n      or:\n        and:\n          number: 0x50 @ 0x1A00D2A42\n          number: 0x45 @ 0x1A00D29A8\n      or:\n        and:\n          number: 0x4D @ 0x1A00D2A18\n          number: 0x5A @ 0x1A00D2ACE\nfunction @ 0x1A00D5144\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00D514B, 0x1A00D5173\n      or:\n        and:\n          number: 0x50 @ 0x1A00D55EA\n          number: 0x45 @ 0x1A00D5550\n      or:\n        and:\n          number: 0x4D @ 0x1A00D55C0\n          number: 0x5A @ 0x1A00D5676\nfunction @ 0x1A00D69F8\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00D69FF, 0x1A00D6A27\n      or:\n        and:\n          number: 0x50 @ 0x1A00D6E9E\n          number: 0x45 @ 0x1A00D6E04\n      or:\n        and:\n          number: 0x4D @ 0x1A00D6E74\n          number: 0x5A @ 0x1A00D6F2A\nfunction @ 0x1A00D7DB8\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00D7DBF, 0x1A00D7DE7\n      or:\n        and:\n          number: 0x50 @ 0x1A00D825E\n          number: 0x45 @ 0x1A00D81C4\n      or:\n        and:\n          number: 0x4D @ 0x1A00D8234\n          number: 0x5A @ 0x1A00D82EA\nfunction @ 0x1A00D9090\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00D9097, 0x1A00D90BF\n      or:\n        and:\n          number: 0x50 @ 0x1A00D9536\n          number: 0x45 @ 0x1A00D949C\n      or:\n        and:\n          number: 0x4D @ 0x1A00D9112, 0x1A00D950C, 0x1A00D9BC8\n          number: 0x5A @ 0x1A00D95C2\nfunction @ 0x1A00DA2C4\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00DA2CB, 0x1A00DA2F3\n      or:\n        and:\n          number: 0x50 @ 0x1A00DA76A, 0x1A00DAA66\n          number: 0x45 @ 0x1A00DA6D0\n      or:\n        and:\n          number: 0x4D @ 0x1A00DA740\n          number: 0x5A @ 0x1A00DA338, 0x1A00DA7F6\nfunction @ 0x1A00DB454\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1A00DB45B, 0x1A00DB483\n      or:\n        and:\n          number: 0x50 @ 0x1A00DB8FA\n          number: 0x45 @ 0x1A00DB860\n      or:\n        and:\n          number: 0x4D @ 0x1A00DB8D0, 0x1A00DBB4A, 0x1A00DCC0D, 0x1A00DCC2A, and 2 more...\n          number: 0x5A @ 0x1A00DB986, 0x1A00DBEC0, 0x1A00DBF9D\n\nresolve function by parsing PE exports (3 matches)\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x1A0018FB0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x1A0018FB0\n      mnemonic: movzx @ 0x1A00190E8, 0x1A001953D\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x1A0019108, 0x1A00196DB, 0x1A00196E5, 0x1A00196EB, and 3 more...\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x1A0019151, 0x1A0019199, 0x1A001974C\n      3 or more:\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x1A0019330\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x1A00192F4, 0x1A0019820, 0x1A0019825, 0x1A0019833, and 29 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x1A0019379\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x1A0019312\nfunction @ 0x1A00199C0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x1A00199C0\n      mnemonic: movzx @ 0x1A00190E8, 0x1A001953D, 0x1A00199E3\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x1A0019108, 0x1A00196DB, 0x1A00196E5, 0x1A00196EB, and 3 more...\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x1A0019151, 0x1A0019199, 0x1A001974C\n      3 or more:\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x1A0019330\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x1A00192F4, 0x1A0019820, 0x1A0019825, 0x1A0019833, and 29 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x1A0019379\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x1A0019312\nfunction @ 0x1A0019B94\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x1A0019B94\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x1A0019E35, 0x1A0019E45, 0x1A0019E4F, 0x1A0019E57, and 1 more...\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x1A0019EA0, 0x1A0019EAE, 0x1A0019EB6\n      3 or more:\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x1A0019F14, 0x1A0019F20, 0x1A0019F2C, 0x1A0019F38, and 12 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x1A0019E94, 0x1A0019F0C, 0x1A0019F1C, 0x1A0019F28, and 18 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x1A0019CDD, 0x1A0019E90\n\n\n\n"},"hashes":{"md5":"91c49a21332198c2eba50d0d0fa30304","sha1":"b5a78e977ec7d88bb9c890a6055b5a26d11ff706","sha256":"880520a4ef03fd51e8fb31f0ea3b1afe150958b872fe793f34d6a62c3544d848"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 1179</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 208868</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"vi-019f798ddabc77d2976e0d64376\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"91c49a21332198c2eba50d0d0fa30304\",\n        \"sha256\": \"880520a4ef03fd51e8fb31f0ea3b1afe150958b872fe793f34d6a62\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_peb_access__7_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"PEB access (7 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Process Environment\",\n        \"Block [B0001.019]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1A0016574\",\n      \"label\": \"Block 0x1A0016574\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0016574\"\n    },\n    {\n      \"id\": \"cap_contain_loop__352_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (352 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1A0001000\",\n      \"label\": \"Function 0x1A0001000\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0001000\"\n    },\n    {\n      \"id\": \"cap_get_os_version__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"get OS version (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1A001A98C\",\n      \"label\": \"Function 0x1A001A98C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A001A98C\"\n    },\n    {\n      \"id\": \"cap_check_for_peb_ntglobalflag_flag\",\n      \"label\": \"check for PEB NtGlobalFlag flag\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Process Environment\",\n        \"Block NtGlobalFlag [B0001.036]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1A00F3D4C\",\n      \"label\": \"Function 0x1A00F3D4C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00F3D4C\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Process Environment\",\n        \"Block NtGlobalFlag [B0001.036]\"\n      ]\n    },\n    {\n      \"id\": \"cap_execute_anti_debugging_instructions__7_matches_\",\n      \"label\": \"execute anti-debugging instructions (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Anti-debugging\",\n        \"Instructions [B0001.034]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1A00DFF00\",\n      \"label\": \"Function 0x1A00DFF00\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00DFF00\"\n    },\n    {\n      \"id\": \"func_0x1A0001188\",\n      \"label\": \"Function 0x1A0001188\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0001188\"\n    },\n    {\n      \"id\": \"func_0x1A0001678\",\n      \"label\": \"Function 0x1A0001678\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0001678\"\n    },\n    {\n      \"id\": \"func_0x1A00FCCC0\",\n      \"label\": \"Function 0x1A00FCCC0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00FCCC0\"\n    },\n    {\n      \"id\": \"func_0x1A0013B84\",\n      \"label\": \"Function 0x1A0013B84\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0013B84\"\n    },\n    {\n      \"id\": \"func_0x1A00049C0\",\n      \"label\": \"Function 0x1A00049C0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00049C0\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Anti-debugging\",\n        \"Instructions [B0001.034]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"label\": \"contain obfuscated stackstrings (321 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Executable Code Obfuscation::Argument\",\n        \"Obfuscation [B0032.020]\",\n        \"Anti-Static Analysis::Executable Code\",\n        \"Obfuscation::Stack Strings [B0032.017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1A0064C99\",\n      \"label\": \"Block 0x1A0064C99\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0064C99\"\n    },\n    {\n      \"id\": \"bb_0x1A005D2DF\",\n      \"label\": \"Block 0x1A005D2DF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A005D2DF\"\n    },\n    {\n      \"id\": \"bb_0x1A004C7CD\",\n      \"label\": \"Block 0x1A004C7CD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A004C7CD\"\n    },\n    {\n      \"id\": \"bb_0x1A005540B\",\n      \"label\": \"Block 0x1A005540B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A005540B\"\n    },\n    {\n      \"id\": \"bb_0x1A00AFBCB\",\n      \"label\": \"Block 0x1A00AFBCB\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00AFBCB\"\n    },\n    {\n      \"id\": \"bb_0x1A0023999\",\n      \"label\": \"Block 0x1A0023999\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0023999\"\n    },\n    {\n      \"id\": \"bb_0x1A0037910\",\n      \"label\": \"Block 0x1A0037910\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0037910\"\n    },\n    {\n      \"id\": \"bb_0x1A00B8C90\",\n      \"label\": \"Block 0x1A00B8C90\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00B8C90\"\n    },\n    {\n      \"id\": \"bb_0x1A005ACCD\",\n      \"label\": \"Block 0x1A005ACCD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A005ACCD\"\n    },\n    {\n      \"id\": \"bb_0x1A003D449\",\n      \"label\": \"Block 0x1A003D449\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A003D449\"\n    },\n    {\n      \"id\": \"bb_0x1A00A2EA1\",\n      \"label\": \"Block 0x1A00A2EA1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A2EA1\"\n    },\n    {\n      \"id\": \"bb_0x1A003927D\",\n      \"label\": \"Block 0x1A003927D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A003927D\"\n    },\n    {\n      \"id\": \"bb_0x1A0047AD5\",\n      \"label\": \"Block 0x1A0047AD5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0047AD5\"\n    },\n    {\n      \"id\": \"bb_0x1A00B1959\",\n      \"label\": \"Block 0x1A00B1959\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00B1959\"\n    },\n    {\n      \"id\": \"bb_0x1A0036450\",\n      \"label\": \"Block 0x1A0036450\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0036450\"\n    },\n    {\n      \"id\": \"bb_0x1A00A52BC\",\n      \"label\": \"Block 0x1A00A52BC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A52BC\"\n    },\n    {\n      \"id\": \"bb_0x1A00D5185\",\n      \"label\": \"Block 0x1A00D5185\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00D5185\"\n    },\n    {\n      \"id\": \"bb_0x1A00B0AF9\",\n      \"label\": \"Block 0x1A00B0AF9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00B0AF9\"\n    },\n    {\n      \"id\": \"bb_0x1A00C956F\",\n      \"label\": \"Block 0x1A00C956F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00C956F\"\n    },\n    {\n      \"id\": \"bb_0x1A00BD099\",\n      \"label\": \"Block 0x1A00BD099\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00BD099\"\n    },\n    {\n      \"id\": \"bb_0x1A00D2C39\",\n      \"label\": \"Block 0x1A00D2C39\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00D2C39\"\n    },\n    {\n      \"id\": \"bb_0x1A006FDB9\",\n      \"label\": \"Block 0x1A006FDB9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A006FDB9\"\n    },\n    {\n      \"id\": \"bb_0x1A0022D95\",\n      \"label\": \"Block 0x1A0022D95\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0022D95\"\n    },\n    {\n      \"id\": \"bb_0x1A0040F8D\",\n      \"label\": \"Block 0x1A0040F8D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0040F8D\"\n    },\n    {\n      \"id\": \"bb_0x1A00381A9\",\n      \"label\": \"Block 0x1A00381A9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00381A9\"\n    },\n    {\n      \"id\": \"bb_0x1A006D6A4\",\n      \"label\": \"Block 0x1A006D6A4\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A006D6A4\"\n    },\n    {\n      \"id\": \"bb_0x1A00CC9A4\",\n      \"label\": \"Block 0x1A00CC9A4\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00CC9A4\"\n    },\n    {\n      \"id\": \"bb_0x1A0089961\",\n      \"label\": \"Block 0x1A0089961\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0089961\"\n    },\n    {\n      \"id\": \"bb_0x1A00D90D1\",\n      \"label\": \"Block 0x1A00D90D1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00D90D1\"\n    },\n    {\n      \"id\": \"bb_0x1A0038A29\",\n      \"label\": \"Block 0x1A0038A29\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0038A29\"\n    },\n    {\n      \"id\": \"bb_0x1A0043879\",\n      \"label\": \"Block 0x1A0043879\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0043879\"\n    },\n    {\n      \"id\": \"bb_0x1A008AA09\",\n      \"label\": \"Block 0x1A008AA09\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A008AA09\"\n    },\n    {\n      \"id\": \"bb_0x1A0095D51\",\n      \"label\": \"Block 0x1A0095D51\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0095D51\"\n    },\n    {\n      \"id\": \"bb_0x1A006B0B4\",\n      \"label\": \"Block 0x1A006B0B4\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A006B0B4\"\n    },\n    {\n      \"id\": \"bb_0x1A0044528\",\n      \"label\": \"Block 0x1A0044528\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0044528\"\n    },\n    {\n      \"id\": \"bb_0x1A008103B\",\n      \"label\": \"Block 0x1A008103B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A008103B\"\n    },\n    {\n      \"id\": \"bb_0x1A003FDB5\",\n      \"label\": \"Block 0x1A003FDB5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A003FDB5\"\n    },\n    {\n      \"id\": \"bb_0x1A008BA81\",\n      \"label\": \"Block 0x1A008BA81\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A008BA81\"\n    },\n    {\n      \"id\": \"bb_0x1A00496A5\",\n      \"label\": \"Block 0x1A00496A5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00496A5\"\n    },\n    {\n      \"id\": \"bb_0x1A003DAF9\",\n      \"label\": \"Block 0x1A003DAF9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A003DAF9\"\n    },\n    {\n      \"id\": \"bb_0x1A00BE505\",\n      \"label\": \"Block 0x1A00BE505\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00BE505\"\n    },\n    {\n      \"id\": \"bb_0x1A0062361\",\n      \"label\": \"Block 0x1A0062361\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0062361\"\n    },\n    {\n      \"id\": \"bb_0x1A0077CAB\",\n      \"label\": \"Block 0x1A0077CAB\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0077CAB\"\n    },\n    {\n      \"id\": \"bb_0x1A005E710\",\n      \"label\": \"Block 0x1A005E710\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A005E710\"\n    },\n    {\n      \"id\": \"bb_0x1A004CDED\",\n      \"label\": \"Block 0x1A004CDED\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A004CDED\"\n    },\n    {\n      \"id\": \"bb_0x1A00C867B\",\n      \"label\": \"Block 0x1A00C867B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00C867B\"\n    },\n    {\n      \"id\": \"bb_0x1A002A1F9\",\n      \"label\": \"Block 0x1A002A1F9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A002A1F9\"\n    },\n    {\n      \"id\": \"bb_0x1A0060293\",\n      \"label\": \"Block 0x1A0060293\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0060293\"\n    },\n    {\n      \"id\": \"bb_0x1A006709F\",\n      \"label\": \"Block 0x1A006709F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A006709F\"\n    },\n    {\n      \"id\": \"bb_0x1A008F3E1\",\n      \"label\": \"Block 0x1A008F3E1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A008F3E1\"\n    },\n    {\n      \"id\": \"bb_0x1A00853E5\",\n      \"label\": \"Block 0x1A00853E5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00853E5\"\n    },\n    {\n      \"id\": \"bb_0x1A004F067\",\n      \"label\": \"Block 0x1A004F067\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A004F067\"\n    },\n    {\n      \"id\": \"bb_0x1A0037145\",\n      \"label\": \"Block 0x1A0037145\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0037145\"\n    },\n    {\n      \"id\": \"bb_0x1A00A7049\",\n      \"label\": \"Block 0x1A00A7049\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A7049\"\n    },\n    {\n      \"id\": \"bb_0x1A00A1AE1\",\n      \"label\": \"Block 0x1A00A1AE1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A1AE1\"\n    },\n    {\n      \"id\": \"bb_0x1A00A2385\",\n      \"label\": \"Block 0x1A00A2385\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A2385\"\n    },\n    {\n      \"id\": \"bb_0x1A00C113D\",\n      \"label\": \"Block 0x1A00C113D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00C113D\"\n    },\n    {\n      \"id\": \"bb_0x1A00A0795\",\n      \"label\": \"Block 0x1A00A0795\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A0795\"\n    },\n    {\n      \"id\": \"bb_0x1A001E887\",\n      \"label\": \"Block 0x1A001E887\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A001E887\"\n    },\n    {\n      \"id\": \"bb_0x1A00B3701\",\n      \"label\": \"Block 0x1A00B3701\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00B3701\"\n    },\n    {\n      \"id\": \"bb_0x1A0082855\",\n      \"label\": \"Block 0x1A0082855\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0082855\"\n    },\n    {\n      \"id\": \"bb_0x1A009EC25\",\n      \"label\": \"Block 0x1A009EC25\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A009EC25\"\n    },\n    {\n      \"id\": \"bb_0x1A009DCA7\",\n      \"label\": \"Block 0x1A009DCA7\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A009DCA7\"\n    },\n    {\n      \"id\": \"bb_0x1A00D25DD\",\n      \"label\": \"Block 0x1A00D25DD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00D25DD\"\n    },\n    {\n      \"id\": \"bb_0x1A0081508\",\n      \"label\": \"Block 0x1A0081508\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0081508\"\n    },\n    {\n      \"id\": \"bb_0x1A00AC43D\",\n      \"label\": \"Block 0x1A00AC43D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00AC43D\"\n    },\n    {\n      \"id\": \"bb_0x1A00B3CB9\",\n      \"label\": \"Block 0x1A00B3CB9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00B3CB9\"\n    },\n    {\n      \"id\": \"bb_0x1A00907E7\",\n      \"label\": \"Block 0x1A00907E7\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00907E7\"\n    },\n    {\n      \"id\": \"bb_0x1A0075685\",\n      \"label\": \"Block 0x1A0075685\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0075685\"\n    },\n    {\n      \"id\": \"bb_0x1A00B5229\",\n      \"label\": \"Block 0x1A00B5229\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00B5229\"\n    },\n    {\n      \"id\": \"bb_0x1A00577B9\",\n      \"label\": \"Block 0x1A00577B9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00577B9\"\n    },\n    {\n      \"id\": \"bb_0x1A00A86C1\",\n      \"label\": \"Block 0x1A00A86C1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A86C1\"\n    },\n    {\n      \"id\": \"bb_0x1A003CE85\",\n      \"label\": \"Block 0x1A003CE85\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A003CE85\"\n    },\n    {\n      \"id\": \"bb_0x1A0029220\",\n      \"label\": \"Block 0x1A0029220\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0029220\"\n    },\n    {\n      \"id\": \"bb_0x1A00CFF34\",\n      \"label\": \"Block 0x1A00CFF34\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00CFF34\"\n    },\n    {\n      \"id\": \"bb_0x1A007DD79\",\n      \"label\": \"Block 0x1A007DD79\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A007DD79\"\n    },\n    {\n      \"id\": \"bb_0x1A0046BDD\",\n      \"label\": \"Block 0x1A0046BDD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0046BDD\"\n    },\n    {\n      \"id\": \"bb_0x1A009FBC7\",\n      \"label\": \"Block 0x1A009FBC7\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A009FBC7\"\n    },\n    {\n      \"id\": \"bb_0x1A003F079\",\n      \"label\": \"Block 0x1A003F079\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A003F079\"\n    },\n    {\n      \"id\": \"bb_0x1A007E3A5\",\n      \"label\": \"Block 0x1A007E3A5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A007E3A5\"\n    },\n    {\n      \"id\": \"bb_0x1A00485ED\",\n      \"label\": \"Block 0x1A00485ED\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00485ED\"\n    },\n    {\n      \"id\": \"bb_0x1A0067DFC\",\n      \"label\": \"Block 0x1A0067DFC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0067DFC\"\n    },\n    {\n      \"id\": \"bb_0x1A005436D\",\n      \"label\": \"Block 0x1A005436D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A005436D\"\n    },\n    {\n      \"id\": \"bb_0x1A0097011\",\n      \"label\": \"Block 0x1A0097011\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0097011\"\n    },\n    {\n      \"id\": \"bb_0x1A0038FDC\",\n      \"label\": \"Block 0x1A0038FDC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0038FDC\"\n    },\n    {\n      \"id\": \"bb_0x1A004E113\",\n      \"label\": \"Block 0x1A004E113\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A004E113\"\n    },\n    {\n      \"id\": \"bb_0x1A00AB07D\",\n      \"label\": \"Block 0x1A00AB07D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00AB07D\"\n    },\n    {\n      \"id\": \"bb_0x1A003B8D5\",\n      \"label\": \"Block 0x1A003B8D5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A003B8D5\"\n    },\n    {\n      \"id\": \"bb_0x1A008B584\",\n      \"label\": \"Block 0x1A008B584\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A008B584\"\n    },\n    {\n      \"id\": \"bb_0x1A0073A7D\",\n      \"label\": \"Block 0x1A0073A7D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0073A7D\"\n    },\n    {\n      \"id\": \"bb_0x1A0039DF5\",\n      \"label\": \"Block 0x1A0039DF5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0039DF5\"\n    },\n    {\n      \"id\": \"bb_0x1A00CD763\",\n      \"label\": \"Block 0x1A00CD763\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00CD763\"\n    },\n    {\n      \"id\": \"bb_0x1A006157B\",\n      \"label\": \"Block 0x1A006157B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A006157B\"\n    },\n    {\n      \"id\": \"bb_0x1A0033120\",\n      \"label\": \"Block 0x1A0033120\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0033120\"\n    },\n    {\n      \"id\": \"bb_0x1A009E699\",\n      \"label\": \"Block 0x1A009E699\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A009E699\"\n    },\n    {\n      \"id\": \"bb_0x1A004E8CD\",\n      \"label\": \"Block 0x1A004E8CD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A004E8CD\"\n    },\n    {\n      \"id\": \"bb_0x1A00A2C84\",\n      \"label\": \"Block 0x1A00A2C84\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A2C84\"\n    },\n    {\n      \"id\": \"bb_0x1A00D01AC\",\n      \"label\": \"Block 0x1A00D01AC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00D01AC\"\n    },\n    {\n      \"id\": \"bb_0x1A0059915\",\n      \"label\": \"Block 0x1A0059915\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0059915\"\n    },\n    {\n      \"id\": \"bb_0x1A00285D1\",\n      \"label\": \"Block 0x1A00285D1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00285D1\"\n    },\n    {\n      \"id\": \"bb_0x1A0035C9D\",\n      \"label\": \"Block 0x1A0035C9D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0035C9D\"\n    },\n    {\n      \"id\": \"bb_0x1A00435DC\",\n      \"label\": \"Block 0x1A00435DC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00435DC\"\n    },\n    {\n      \"id\": \"bb_0x1A0086344\",\n      \"label\": \"Block 0x1A0086344\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0086344\"\n    },\n    {\n      \"id\": \"bb_0x1A00AA4F9\",\n      \"label\": \"Block 0x1A00AA4F9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00AA4F9\"\n    },\n    {\n      \"id\": \"bb_0x1A00780A5\",\n      \"label\": \"Block 0x1A00780A5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00780A5\"\n    },\n    {\n      \"id\": \"bb_0x1A0044747\",\n      \"label\": \"Block 0x1A0044747\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0044747\"\n    },\n    {\n      \"id\": \"bb_0x1A0088B0F\",\n      \"label\": \"Block 0x1A0088B0F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0088B0F\"\n    },\n    {\n      \"id\": \"bb_0x1A008EA59\",\n      \"label\": \"Block 0x1A008EA59\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A008EA59\"\n    },\n    {\n      \"id\": \"bb_0x1A00BA629\",\n      \"label\": \"Block 0x1A00BA629\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00BA629\"\n    },\n    {\n      \"id\": \"bb_0x1A009C457\",\n      \"label\": \"Block 0x1A009C457\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A009C457\"\n    },\n    {\n      \"id\": \"bb_0x1A00B8F55\",\n      \"label\": \"Block 0x1A00B8F55\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00B8F55\"\n    },\n    {\n      \"id\": \"bb_0x1A0034D4C\",\n      \"label\": \"Block 0x1A0034D4C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0034D4C\"\n    },\n    {\n      \"id\": \"bb_0x1A0082191\",\n      \"label\": \"Block 0x1A0082191\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0082191\"\n    },\n    {\n      \"id\": \"bb_0x1A00B578B\",\n      \"label\": \"Block 0x1A00B578B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00B578B\"\n    },\n    {\n      \"id\": \"bb_0x1A005261B\",\n      \"label\": \"Block 0x1A005261B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A005261B\"\n    },\n    {\n      \"id\": \"bb_0x1A00D3764\",\n      \"label\": \"Block 0x1A00D3764\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00D3764\"\n    },\n    {\n      \"id\": \"bb_0x1A00AF0B5\",\n      \"label\": \"Block 0x1A00AF0B5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00AF0B5\"\n    },\n    {\n      \"id\": \"bb_0x1A009E18B\",\n      \"label\": \"Block 0x1A009E18B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A009E18B\"\n    },\n    {\n      \"id\": \"bb_0x1A0031059\",\n      \"label\": \"Block 0x1A0031059\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0031059\"\n    },\n    {\n      \"id\": \"bb_0x1A0087A19\",\n      \"label\": \"Block 0x1A0087A19\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0087A19\"\n    },\n    {\n      \"id\": \"bb_0x1A007AAE1\",\n      \"label\": \"Block 0x1A007AAE1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A007AAE1\"\n    },\n    {\n      \"id\": \"bb_0x1A004A9D1\",\n      \"label\": \"Block 0x1A004A9D1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A004A9D1\"\n    },\n    {\n      \"id\": \"bb_0x1A001D3A1\",\n      \"label\": \"Block 0x1A001D3A1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A001D3A1\"\n    },\n    {\n      \"id\": \"bb_0x1A0046611\",\n      \"label\": \"Block 0x1A0046611\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0046611\"\n    },\n    {\n      \"id\": \"bb_0x1A003E229\",\n      \"label\": \"Block 0x1A003E229\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A003E229\"\n    },\n    {\n      \"id\": \"bb_0x1A00AAA89\",\n      \"label\": \"Block 0x1A00AAA89\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00AAA89\"\n    },\n    {\n      \"id\": \"bb_0x1A008CDB5\",\n      \"label\": \"Block 0x1A008CDB5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A008CDB5\"\n    },\n    {\n      \"id\": \"bb_0x1A00BB0C9\",\n      \"label\": \"Block 0x1A00BB0C9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00BB0C9\"\n    },\n    {\n      \"id\": \"bb_0x1A003A96D\",\n      \"label\": \"Block 0x1A003A96D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A003A96D\"\n    },\n    {\n      \"id\": \"bb_0x1A0059F85\",\n      \"label\": \"Block 0x1A0059F85\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0059F85\"\n    },\n    {\n      \"id\": \"bb_0x1A00CB7A8\",\n      \"label\": \"Block 0x1A00CB7A8\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00CB7A8\"\n    },\n    {\n      \"id\": \"bb_0x1A00DA305\",\n      \"label\": \"Block 0x1A00DA305\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00DA305\"\n    },\n    {\n      \"id\": \"bb_0x1A00C6C5D\",\n      \"label\": \"Block 0x1A00C6C5D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00C6C5D\"\n    },\n    {\n      \"id\": \"bb_0x1A00D7DF9\",\n      \"label\": \"Block 0x1A00D7DF9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00D7DF9\"\n    },\n    {\n      \"id\": \"bb_0x1A0071ECB\",\n      \"label\": \"Block 0x1A0071ECB\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0071ECB\"\n    },\n    {\n      \"id\": \"bb_0x1A003A395\",\n      \"label\": \"Block 0x1A003A395\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A003A395\"\n    },\n    {\n      \"id\": \"bb_0x1A00B44FD\",\n      \"label\": \"Block 0x1A00B44FD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00B44FD\"\n    },\n    {\n      \"id\": \"bb_0x1A00A6415\",\n      \"label\": \"Block 0x1A00A6415\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A6415\"\n    },\n    {\n      \"id\": \"bb_0x1A00E0828\",\n      \"label\": \"Block 0x1A00E0828\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00E0828\"\n    },\n    {\n      \"id\": \"bb_0x1A00C5709\",\n      \"label\": \"Block 0x1A00C5709\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00C5709\"\n    },\n    {\n      \"id\": \"bb_0x1A0060FD9\",\n      \"label\": \"Block 0x1A0060FD9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0060FD9\"\n    },\n    {\n      \"id\": \"bb_0x1A0048021\",\n      \"label\": \"Block 0x1A0048021\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0048021\"\n    },\n    {\n      \"id\": \"bb_0x1A00A76AD\",\n      \"label\": \"Block 0x1A00A76AD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A76AD\"\n    },\n    {\n      \"id\": \"bb_0x1A00BDDD9\",\n      \"label\": \"Block 0x1A00BDDD9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00BDDD9\"\n    },\n    {\n      \"id\": \"bb_0x1A00BC939\",\n      \"label\": \"Block 0x1A00BC939\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00BC939\"\n    },\n    {\n      \"id\": \"bb_0x1A00C064D\",\n      \"label\": \"Block 0x1A00C064D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00C064D\"\n    },\n    {\n      \"id\": \"bb_0x1A00B73CD\",\n      \"label\": \"Block 0x1A00B73CD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00B73CD\"\n    },\n    {\n      \"id\": \"bb_0x1A00387A8\",\n      \"label\": \"Block 0x1A00387A8\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00387A8\"\n    },\n    {\n      \"id\": \"bb_0x1A00722B9\",\n      \"label\": \"Block 0x1A00722B9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00722B9\"\n    },\n    {\n      \"id\": \"bb_0x1A0021035\",\n      \"label\": \"Block 0x1A0021035\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0021035\"\n    },\n    {\n      \"id\": \"bb_0x1A0035653\",\n      \"label\": \"Block 0x1A0035653\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0035653\"\n    },\n    {\n      \"id\": \"bb_0x1A0081AD9\",\n      \"label\": \"Block 0x1A0081AD9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0081AD9\"\n    },\n    {\n      \"id\": \"bb_0x1A0027075\",\n      \"label\": \"Block 0x1A0027075\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0027075\"\n    },\n    {\n      \"id\": \"bb_0x1A001C561\",\n      \"label\": \"Block 0x1A001C561\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A001C561\"\n    },\n    {\n      \"id\": \"bb_0x1A00254E5\",\n      \"label\": \"Block 0x1A00254E5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00254E5\"\n    },\n    {\n      \"id\": \"bb_0x1A006774D\",\n      \"label\": \"Block 0x1A006774D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A006774D\"\n    },\n    {\n      \"id\": \"bb_0x1A008DBFB\",\n      \"label\": \"Block 0x1A008DBFB\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A008DBFB\"\n    },\n    {\n      \"id\": \"bb_0x1A0091099\",\n      \"label\": \"Block 0x1A0091099\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0091099\"\n    },\n    {\n      \"id\": \"bb_0x1A0027709\",\n      \"label\": \"Block 0x1A0027709\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0027709\"\n    },\n    {\n      \"id\": \"bb_0x1A0099DA7\",\n      \"label\": \"Block 0x1A0099DA7\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0099DA7\"\n    },\n    {\n      \"id\": \"bb_0x1A00248B5\",\n      \"label\": \"Block 0x1A00248B5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00248B5\"\n    },\n    {\n      \"id\": \"bb_0x1A00DB495\",\n      \"label\": \"Block 0x1A00DB495\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00DB495\"\n    },\n    {\n      \"id\": \"bb_0x1A0094B85\",\n      \"label\": \"Block 0x1A0094B85\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0094B85\"\n    },\n    {\n      \"id\": \"bb_0x1A007B729\",\n      \"label\": \"Block 0x1A007B729\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A007B729\"\n    },\n    {\n      \"id\": \"bb_0x1A00405F5\",\n      \"label\": \"Block 0x1A00405F5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00405F5\"\n    },\n    {\n      \"id\": \"bb_0x1A00CCBA9\",\n      \"label\": \"Block 0x1A00CCBA9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00CCBA9\"\n    },\n    {\n      \"id\": \"bb_0x1A007FC59\",\n      \"label\": \"Block 0x1A007FC59\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A007FC59\"\n    },\n    {\n      \"id\": \"bb_0x1A004B8C1\",\n      \"label\": \"Block 0x1A004B8C1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A004B8C1\"\n    },\n    {\n      \"id\": \"bb_0x1A00D4247\",\n      \"label\": \"Block 0x1A00D4247\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00D4247\"\n    },\n    {\n      \"id\": \"bb_0x1A00AE9E0\",\n      \"label\": \"Block 0x1A00AE9E0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00AE9E0\"\n    },\n    {\n      \"id\": \"bb_0x1A008B7F0\",\n      \"label\": \"Block 0x1A008B7F0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A008B7F0\"\n    },\n    {\n      \"id\": \"bb_0x1A0044C75\",\n      \"label\": \"Block 0x1A0044C75\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0044C75\"\n    },\n    {\n      \"id\": \"bb_0x1A00C800D\",\n      \"label\": \"Block 0x1A00C800D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00C800D\"\n    },\n    {\n      \"id\": \"bb_0x1A00520C9\",\n      \"label\": \"Block 0x1A00520C9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00520C9\"\n    },\n    {\n      \"id\": \"bb_0x1A00507E9\",\n      \"label\": \"Block 0x1A00507E9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00507E9\"\n    },\n    {\n      \"id\": \"bb_0x1A007F6F1\",\n      \"label\": \"Block 0x1A007F6F1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A007F6F1\"\n    },\n    {\n      \"id\": \"bb_0x1A00A69DD\",\n      \"label\": \"Block 0x1A00A69DD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A69DD\"\n    },\n    {\n      \"id\": \"bb_0x1A0027EB9\",\n      \"label\": \"Block 0x1A0027EB9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0027EB9\"\n    },\n    {\n      \"id\": \"bb_0x1A00317F1\",\n      \"label\": \"Block 0x1A00317F1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00317F1\"\n    },\n    {\n      \"id\": \"bb_0x1A00D593B\",\n      \"label\": \"Block 0x1A00D593B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00D593B\"\n    },\n    {\n      \"id\": \"bb_0x1A0032481\",\n      \"label\": \"Block 0x1A0032481\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0032481\"\n    },\n    {\n      \"id\": \"bb_0x1A004A0D9\",\n      \"label\": \"Block 0x1A004A0D9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A004A0D9\"\n    },\n    {\n      \"id\": \"bb_0x1A00E816D\",\n      \"label\": \"Block 0x1A00E816D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00E816D\"\n    },\n    {\n      \"id\": \"bb_0x1A009F203\",\n      \"label\": \"Block 0x1A009F203\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A009F203\"\n    },\n    {\n      \"id\": \"bb_0x1A0028BFD\",\n      \"label\": \"Block 0x1A0028BFD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0028BFD\"\n    },\n    {\n      \"id\": \"bb_0x1A00CD29B\",\n      \"label\": \"Block 0x1A00CD29B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00CD29B\"\n    },\n    {\n      \"id\": \"bb_0x1A00C3867\",\n      \"label\": \"Block 0x1A00C3867\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00C3867\"\n    },\n    {\n      \"id\": \"bb_0x1A00227ED\",\n      \"label\": \"Block 0x1A00227ED\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00227ED\"\n    },\n    {\n      \"id\": \"bb_0x1A008702B\",\n      \"label\": \"Block 0x1A008702B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A008702B\"\n    },\n    {\n      \"id\": \"bb_0x1A008FF4F\",\n      \"label\": \"Block 0x1A008FF4F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A008FF4F\"\n    },\n    {\n      \"id\": \"bb_0x1A00C3397\",\n      \"label\": \"Block 0x1A00C3397\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00C3397\"\n    },\n    {\n      \"id\": \"bb_0x1A00B14BC\",\n      \"label\": \"Block 0x1A00B14BC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00B14BC\"\n    },\n    {\n      \"id\": \"bb_0x1A0042395\",\n      \"label\": \"Block 0x1A0042395\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0042395\"\n    },\n    {\n      \"id\": \"bb_0x1A0053995\",\n      \"label\": \"Block 0x1A0053995\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0053995\"\n    },\n    {\n      \"id\": \"bb_0x1A006916D\",\n      \"label\": \"Block 0x1A006916D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A006916D\"\n    },\n    {\n      \"id\": \"bb_0x1A00787CD\",\n      \"label\": \"Block 0x1A00787CD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00787CD\"\n    },\n    {\n      \"id\": \"bb_0x1A004AFB9\",\n      \"label\": \"Block 0x1A004AFB9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A004AFB9\"\n    },\n    {\n      \"id\": \"bb_0x1A00631DD\",\n      \"label\": \"Block 0x1A00631DD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00631DD\"\n    },\n    {\n      \"id\": \"bb_0x1A00E8408\",\n      \"label\": \"Block 0x1A00E8408\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00E8408\"\n    },\n    {\n      \"id\": \"bb_0x1A004907D\",\n      \"label\": \"Block 0x1A004907D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A004907D\"\n    },\n    {\n      \"id\": \"bb_0x1A0058C31\",\n      \"label\": \"Block 0x1A0058C31\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0058C31\"\n    },\n    {\n      \"id\": \"bb_0x1A00D1177\",\n      \"label\": \"Block 0x1A00D1177\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00D1177\"\n    },\n    {\n      \"id\": \"bb_0x1A00B6F60\",\n      \"label\": \"Block 0x1A00B6F60\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00B6F60\"\n    },\n    {\n      \"id\": \"bb_0x1A0075C4D\",\n      \"label\": \"Block 0x1A0075C4D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0075C4D\"\n    },\n    {\n      \"id\": \"bb_0x1A00B5C59\",\n      \"label\": \"Block 0x1A00B5C59\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00B5C59\"\n    },\n    {\n      \"id\": \"bb_0x1A005BD9D\",\n      \"label\": \"Block 0x1A005BD9D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A005BD9D\"\n    },\n    {\n      \"id\": \"bb_0x1A005407C\",\n      \"label\": \"Block 0x1A005407C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A005407C\"\n    },\n    {\n      \"id\": \"bb_0x1A00953C1\",\n      \"label\": \"Block 0x1A00953C1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00953C1\"\n    },\n    {\n      \"id\": \"bb_0x1A00C2739\",\n      \"label\": \"Block 0x1A00C2739\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00C2739\"\n    },\n    {\n      \"id\": \"bb_0x1A003B2D5\",\n      \"label\": \"Block 0x1A003B2D5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A003B2D5\"\n    },\n    {\n      \"id\": \"bb_0x1A005E9C3\",\n      \"label\": \"Block 0x1A005E9C3\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A005E9C3\"\n    },\n    {\n      \"id\": \"bb_0x1A0066219\",\n      \"label\": \"Block 0x1A0066219\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0066219\"\n    },\n    {\n      \"id\": \"bb_0x1A00E880A\",\n      \"label\": \"Block 0x1A00E880A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00E880A\"\n    },\n    {\n      \"id\": \"bb_0x1A00206B5\",\n      \"label\": \"Block 0x1A00206B5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00206B5\"\n    },\n    {\n      \"id\": \"bb_0x1A00B6389\",\n      \"label\": \"Block 0x1A00B6389\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00B6389\"\n    },\n    {\n      \"id\": \"bb_0x1A008A448\",\n      \"label\": \"Block 0x1A008A448\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A008A448\"\n    },\n    {\n      \"id\": \"bb_0x1A00B3191\",\n      \"label\": \"Block 0x1A00B3191\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00B3191\"\n    },\n    {\n      \"id\": \"bb_0x1A006A3F9\",\n      \"label\": \"Block 0x1A006A3F9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A006A3F9\"\n    },\n    {\n      \"id\": \"bb_0x1A0041961\",\n      \"label\": \"Block 0x1A0041961\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0041961\"\n    },\n    {\n      \"id\": \"bb_0x1A00A5044\",\n      \"label\": \"Block 0x1A00A5044\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A5044\"\n    },\n    {\n      \"id\": \"bb_0x1A0084701\",\n      \"label\": \"Block 0x1A0084701\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0084701\"\n    },\n    {\n      \"id\": \"bb_0x1A004C055\",\n      \"label\": \"Block 0x1A004C055\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A004C055\"\n    },\n    {\n      \"id\": \"bb_0x1A006E201\",\n      \"label\": \"Block 0x1A006E201\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A006E201\"\n    },\n    {\n      \"id\": \"bb_0x1A004334C\",\n      \"label\": \"Block 0x1A004334C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A004334C\"\n    },\n    {\n      \"id\": \"bb_0x1A004D435\",\n      \"label\": \"Block 0x1A004D435\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A004D435\"\n    },\n    {\n      \"id\": \"bb_0x1A0053411\",\n      \"label\": \"Block 0x1A0053411\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0053411\"\n    },\n    {\n      \"id\": \"bb_0x1A00368D9\",\n      \"label\": \"Block 0x1A00368D9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00368D9\"\n    },\n    {\n      \"id\": \"bb_0x1A00562AD\",\n      \"label\": \"Block 0x1A00562AD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00562AD\"\n    },\n    {\n      \"id\": \"bb_0x1A00B7B99\",\n      \"label\": \"Block 0x1A00B7B99\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00B7B99\"\n    },\n    {\n      \"id\": \"bb_0x1A00CA371\",\n      \"label\": \"Block 0x1A00CA371\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00CA371\"\n    },\n    {\n      \"id\": \"bb_0x1A00C4021\",\n      \"label\": \"Block 0x1A00C4021\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00C4021\"\n    },\n    {\n      \"id\": \"bb_0x1A0046045\",\n      \"label\": \"Block 0x1A0046045\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0046045\"\n    },\n    {\n      \"id\": \"bb_0x1A003BF01\",\n      \"label\": \"Block 0x1A003BF01\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A003BF01\"\n    },\n    {\n      \"id\": \"bb_0x1A00517EF\",\n      \"label\": \"Block 0x1A00517EF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00517EF\"\n    },\n    {\n      \"id\": \"bb_0x1A007A1D5\",\n      \"label\": \"Block 0x1A007A1D5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A007A1D5\"\n    },\n    {\n      \"id\": \"bb_0x1A006B9F1\",\n      \"label\": \"Block 0x1A006B9F1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A006B9F1\"\n    },\n    {\n      \"id\": \"bb_0x1A005C61D\",\n      \"label\": \"Block 0x1A005C61D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A005C61D\"\n    },\n    {\n      \"id\": \"bb_0x1A00982B5\",\n      \"label\": \"Block 0x1A00982B5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00982B5\"\n    },\n    {\n      \"id\": \"bb_0x1A0045A6D\",\n      \"label\": \"Block 0x1A0045A6D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0045A6D\"\n    },\n    {\n      \"id\": \"bb_0x1A005B805\",\n      \"label\": \"Block 0x1A005B805\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A005B805\"\n    },\n    {\n      \"id\": \"bb_0x1A00978BD\",\n      \"label\": \"Block 0x1A00978BD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00978BD\"\n    },\n    {\n      \"id\": \"bb_0x1A00BB675\",\n      \"label\": \"Block 0x1A00BB675\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00BB675\"\n    },\n    {\n      \"id\": \"bb_0x1A005A711\",\n      \"label\": \"Block 0x1A005A711\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A005A711\"\n    },\n    {\n      \"id\": \"bb_0x1A00D1D09\",\n      \"label\": \"Block 0x1A00D1D09\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00D1D09\"\n    },\n    {\n      \"id\": \"bb_0x1A001F375\",\n      \"label\": \"Block 0x1A001F375\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A001F375\"\n    },\n    {\n      \"id\": \"bb_0x1A006F963\",\n      \"label\": \"Block 0x1A006F963\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A006F963\"\n    },\n    {\n      \"id\": \"bb_0x1A005CB91\",\n      \"label\": \"Block 0x1A005CB91\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A005CB91\"\n    },\n    {\n      \"id\": \"bb_0x1A002DCE5\",\n      \"label\": \"Block 0x1A002DCE5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A002DCE5\"\n    },\n    {\n      \"id\": \"bb_0x1A009439D\",\n      \"label\": \"Block 0x1A009439D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A009439D\"\n    },\n    {\n      \"id\": \"bb_0x1A00A5771\",\n      \"label\": \"Block 0x1A00A5771\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A5771\"\n    },\n    {\n      \"id\": \"bb_0x1A005D7D1\",\n      \"label\": \"Block 0x1A005D7D1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A005D7D1\"\n    },\n    {\n      \"id\": \"bb_0x1A00682BF\",\n      \"label\": \"Block 0x1A00682BF\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00682BF\"\n    },\n    {\n      \"id\": \"bb_0x1A003C63D\",\n      \"label\": \"Block 0x1A003C63D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A003C63D\"\n    },\n    {\n      \"id\": \"bb_0x1A00CC543\",\n      \"label\": \"Block 0x1A00CC543\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00CC543\"\n    },\n    {\n      \"id\": \"bb_0x1A00D4AB1\",\n      \"label\": \"Block 0x1A00D4AB1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00D4AB1\"\n    },\n    {\n      \"id\": \"bb_0x1A00BAE24\",\n      \"label\": \"Block 0x1A00BAE24\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00BAE24\"\n    },\n    {\n      \"id\": \"bb_0x1A00773E5\",\n      \"label\": \"Block 0x1A00773E5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00773E5\"\n    },\n    {\n      \"id\": \"bb_0x1A00697D1\",\n      \"label\": \"Block 0x1A00697D1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00697D1\"\n    },\n    {\n      \"id\": \"bb_0x1A0090367\",\n      \"label\": \"Block 0x1A0090367\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0090367\"\n    },\n    {\n      \"id\": \"bb_0x1A0091DD1\",\n      \"label\": \"Block 0x1A0091DD1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0091DD1\"\n    },\n    {\n      \"id\": \"bb_0x1A0036ED8\",\n      \"label\": \"Block 0x1A0036ED8\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0036ED8\"\n    },\n    {\n      \"id\": \"bb_0x1A006C56D\",\n      \"label\": \"Block 0x1A006C56D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A006C56D\"\n    },\n    {\n      \"id\": \"bb_0x1A0086771\",\n      \"label\": \"Block 0x1A0086771\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0086771\"\n    },\n    {\n      \"id\": \"bb_0x1A00C2CC9\",\n      \"label\": \"Block 0x1A00C2CC9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00C2CC9\"\n    },\n    {\n      \"id\": \"bb_0x1A00347A5\",\n      \"label\": \"Block 0x1A00347A5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00347A5\"\n    },\n    {\n      \"id\": \"bb_0x1A002BCAD\",\n      \"label\": \"Block 0x1A002BCAD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A002BCAD\"\n    },\n    {\n      \"id\": \"bb_0x1A00D3217\",\n      \"label\": \"Block 0x1A00D3217\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00D3217\"\n    },\n    {\n      \"id\": \"bb_0x1A00CE191\",\n      \"label\": \"Block 0x1A00CE191\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00CE191\"\n    },\n    {\n      \"id\": \"bb_0x1A0071C44\",\n      \"label\": \"Block 0x1A0071C44\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0071C44\"\n    },\n    {\n      \"id\": \"bb_0x1A0092C4D\",\n      \"label\": \"Block 0x1A0092C4D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0092C4D\"\n    },\n    {\n      \"id\": \"bb_0x1A00A9C21\",\n      \"label\": \"Block 0x1A00A9C21\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A9C21\"\n    },\n    {\n      \"id\": \"bb_0x1A002F3AD\",\n      \"label\": \"Block 0x1A002F3AD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A002F3AD\"\n    },\n    {\n      \"id\": \"bb_0x1A005B211\",\n      \"label\": \"Block 0x1A005B211\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A005B211\"\n    },\n    {\n      \"id\": \"bb_0x1A0068A3B\",\n      \"label\": \"Block 0x1A0068A3B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0068A3B\"\n    },\n    {\n      \"id\": \"bb_0x1A003E98C\",\n      \"label\": \"Block 0x1A003E98C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A003E98C\"\n    },\n    {\n      \"id\": \"bb_0x1A005854F\",\n      \"label\": \"Block 0x1A005854F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A005854F\"\n    },\n    {\n      \"id\": \"bb_0x1A0091789\",\n      \"label\": \"Block 0x1A0091789\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0091789\"\n    },\n    {\n      \"id\": \"bb_0x1A0032B5D\",\n      \"label\": \"Block 0x1A0032B5D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0032B5D\"\n    },\n    {\n      \"id\": \"bb_0x1A006E89D\",\n      \"label\": \"Block 0x1A006E89D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A006E89D\"\n    },\n    {\n      \"id\": \"bb_0x1A00AD881\",\n      \"label\": \"Block 0x1A00AD881\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00AD881\"\n    },\n    {\n      \"id\": \"bb_0x1A004524D\",\n      \"label\": \"Block 0x1A004524D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A004524D\"\n    },\n    {\n      \"id\": \"bb_0x1A0084DD5\",\n      \"label\": \"Block 0x1A0084DD5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0084DD5\"\n    },\n    {\n      \"id\": \"bb_0x1A009AC79\",\n      \"label\": \"Block 0x1A009AC79\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A009AC79\"\n    },\n    {\n      \"id\": \"bb_0x1A00659C5\",\n      \"label\": \"Block 0x1A00659C5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00659C5\"\n    },\n    {\n      \"id\": \"bb_0x1A00A3F21\",\n      \"label\": \"Block 0x1A00A3F21\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A3F21\"\n    },\n    {\n      \"id\": \"bb_0x1A0076EEC\",\n      \"label\": \"Block 0x1A0076EEC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0076EEC\"\n    },\n    {\n      \"id\": \"bb_0x1A00340F1\",\n      \"label\": \"Block 0x1A00340F1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00340F1\"\n    },\n    {\n      \"id\": \"bb_0x1A00AE3D9\",\n      \"label\": \"Block 0x1A00AE3D9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00AE3D9\"\n    },\n    {\n      \"id\": \"bb_0x1A002AA0F\",\n      \"label\": \"Block 0x1A002AA0F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A002AA0F\"\n    },\n    {\n      \"id\": \"bb_0x1A0042B29\",\n      \"label\": \"Block 0x1A0042B29\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0042B29\"\n    },\n    {\n      \"id\": \"bb_0x1A007EF5F\",\n      \"label\": \"Block 0x1A007EF5F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A007EF5F\"\n    },\n    {\n      \"id\": \"bb_0x1A007D50D\",\n      \"label\": \"Block 0x1A007D50D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A007D50D\"\n    },\n    {\n      \"id\": \"bb_0x1A00AD16D\",\n      \"label\": \"Block 0x1A00AD16D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00AD16D\"\n    },\n    {\n      \"id\": \"bb_0x1A0043F79\",\n      \"label\": \"Block 0x1A0043F79\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0043F79\"\n    },\n    {\n      \"id\": \"bb_0x1A00CF81F\",\n      \"label\": \"Block 0x1A00CF81F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00CF81F\"\n    },\n    {\n      \"id\": \"bb_0x1A008E72C\",\n      \"label\": \"Block 0x1A008E72C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A008E72C\"\n    },\n    {\n      \"id\": \"bb_0x1A0039871\",\n      \"label\": \"Block 0x1A0039871\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0039871\"\n    },\n    {\n      \"id\": \"bb_0x1A008094C\",\n      \"label\": \"Block 0x1A008094C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A008094C\"\n    },\n    {\n      \"id\": \"bb_0x1A0066ADD\",\n      \"label\": \"Block 0x1A0066ADD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0066ADD\"\n    },\n    {\n      \"id\": \"bb_0x1A006B3FD\",\n      \"label\": \"Block 0x1A006B3FD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A006B3FD\"\n    },\n    {\n      \"id\": \"bb_0x1A002624D\",\n      \"label\": \"Block 0x1A002624D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A002624D\"\n    },\n    {\n      \"id\": \"bb_0x1A00C9A1B\",\n      \"label\": \"Block 0x1A00C9A1B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00C9A1B\"\n    },\n    {\n      \"id\": \"bb_0x1A009A6E5\",\n      \"label\": \"Block 0x1A009A6E5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A009A6E5\"\n    },\n    {\n      \"id\": \"bb_0x1A00BC3DB\",\n      \"label\": \"Block 0x1A00BC3DB\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00BC3DB\"\n    },\n    {\n      \"id\": \"bb_0x1A0072DAD\",\n      \"label\": \"Block 0x1A0072DAD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0072DAD\"\n    },\n    {\n      \"id\": \"bb_0x1A008AFE1\",\n      \"label\": \"Block 0x1A008AFE1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A008AFE1\"\n    },\n    {\n      \"id\": \"bb_0x1A00294E0\",\n      \"label\": \"Block 0x1A00294E0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00294E0\"\n    },\n    {\n      \"id\": \"bb_0x1A00475B1\",\n      \"label\": \"Block 0x1A00475B1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00475B1\"\n    },\n    {\n      \"id\": \"bb_0x1A00A8DD8\",\n      \"label\": \"Block 0x1A00A8DD8\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A8DD8\"\n    },\n    {\n      \"id\": \"bb_0x1A006D005\",\n      \"label\": \"Block 0x1A006D005\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A006D005\"\n    },\n    {\n      \"id\": \"bb_0x1A002FC19\",\n      \"label\": \"Block 0x1A002FC19\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A002FC19\"\n    },\n    {\n      \"id\": \"bb_0x1A006DA29\",\n      \"label\": \"Block 0x1A006DA29\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A006DA29\"\n    },\n    {\n      \"id\": \"bb_0x1A00C209D\",\n      \"label\": \"Block 0x1A00C209D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00C209D\"\n    },\n    {\n      \"id\": \"bb_0x1A00D6A39\",\n      \"label\": \"Block 0x1A00D6A39\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00D6A39\"\n    },\n    {\n      \"id\": \"bb_0x1A0071960\",\n      \"label\": \"Block 0x1A0071960\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0071960\"\n    },\n    {\n      \"id\": \"bb_0x1A00836AB\",\n      \"label\": \"Block 0x1A00836AB\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00836AB\"\n    },\n    {\n      \"id\": \"bb_0x1A00A4A6D\",\n      \"label\": \"Block 0x1A00A4A6D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00A4A6D\"\n    },\n    {\n      \"id\": \"bb_0x1A00C5DF9\",\n      \"label\": \"Block 0x1A00C5DF9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00C5DF9\"\n    },\n    {\n      \"id\": \"bb_0x1A0026815\",\n      \"label\": \"Block 0x1A0026815\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A0026815\"\n    },\n    {\n      \"id\": \"bb_0x1A00D0B24\",\n      \"label\": \"Block 0x1A00D0B24\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00D0B24\"\n    },\n    {\n      \"id\": \"cap_encode_data_using_add_xor_sub_operations__2_matches_\",\n      \"label\": \"encode data using ADD XOR SUB operations (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Custom\",\n        \"Algorithm [E1027.m03]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1A0004744\",\n      \"label\": \"Function 0x1A0004744\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0004744\"\n    },\n    {\n      \"id\": \"func_0x1A00EB9B0\",\n      \"label\": \"Function 0x1A00EB9B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00EB9B0\"\n    },\n    {\n      \"id\": \"cap_author_______jakub_jozwiak_mandiant_com\",\n      \"label\": \"author       jakub.jozwiak@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Custom\",\n        \"Algorithm [E1027.m03]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encode_data_using_base64__11_matches_\",\n      \"label\": \"encode data using Base64 (11 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1A00E0B64\",\n      \"label\": \"Function 0x1A00E0B64\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00E0B64\"\n    },\n    {\n      \"id\": \"func_0x1A002620C\",\n      \"label\": \"Function 0x1A002620C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A002620C\"\n    },\n    {\n      \"id\": \"func_0x1A00D0AEC\",\n      \"label\": \"Function 0x1A00D0AEC\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00D0AEC\"\n    },\n    {\n      \"id\": \"func_0x1A00B36C0\",\n      \"label\": \"Function 0x1A00B36C0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00B36C0\"\n    },\n    {\n      \"id\": \"func_0x1A00A0754\",\n      \"label\": \"Function 0x1A00A0754\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00A0754\"\n    },\n    {\n      \"id\": \"func_0x1A00A63D4\",\n      \"label\": \"Function 0x1A00A63D4\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00A63D4\"\n    },\n    {\n      \"id\": \"func_0x1A00227AC\",\n      \"label\": \"Function 0x1A00227AC\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00227AC\"\n    },\n    {\n      \"id\": \"func_0x1A0071C0C\",\n      \"label\": \"Function 0x1A0071C0C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0071C0C\"\n    },\n    {\n      \"id\": \"func_0x1A0036EA0\",\n      \"label\": \"Function 0x1A0036EA0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0036EA0\"\n    },\n    {\n      \"id\": \"func_0x1A001F334\",\n      \"label\": \"Function 0x1A001F334\",\n      \"type\": \"function\",\n      \"address\": \"0x1A001F334\"\n    },\n    {\n      \"id\": \"func_0x1A00254A4\",\n      \"label\": \"Function 0x1A00254A4\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00254A4\"\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_chaskey__2_matches_\",\n      \"label\": \"encrypt data using chaskey (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or\",\n        \"Information::Encryption-Standard Algorithm [E1027.m05]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1A00E3DEC\",\n      \"label\": \"Function 0x1A00E3DEC\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00E3DEC\"\n    },\n    {\n      \"id\": \"cap_author______still_teamt5_org\",\n      \"label\": \"author      still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or\",\n        \"Information::Encryption-Standard Algorithm [E1027.m05]\"\n      ]\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"label\": \"encrypt data using RC4 PRGA (40 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data::RC4 [C0027.009]\",\n        \"Cryptography::Generate\",\n        \"Pseudo-random Sequence::RC4 PRGA [C0021.004]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1A0077C70\",\n      \"label\": \"Function 0x1A0077C70\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0077C70\"\n    },\n    {\n      \"id\": \"func_0x1A00CFEFC\",\n      \"label\": \"Function 0x1A00CFEFC\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00CFEFC\"\n    },\n    {\n      \"id\": \"func_0x1A008FF14\",\n      \"label\": \"Function 0x1A008FF14\",\n      \"type\": \"function\",\n      \"address\": \"0x1A008FF14\"\n    },\n    {\n      \"id\": \"func_0x1A00AA288\",\n      \"label\": \"Function 0x1A00AA288\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00AA288\"\n    },\n    {\n      \"id\": \"func_0x1A004735C\",\n      \"label\": \"Function 0x1A004735C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A004735C\"\n    },\n    {\n      \"id\": \"func_0x1A00376B0\",\n      \"label\": \"Function 0x1A00376B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00376B0\"\n    },\n    {\n      \"id\": \"func_0x1A000BB10\",\n      \"label\": \"Function 0x1A000BB10\",\n      \"type\": \"function\",\n      \"address\": \"0x1A000BB10\"\n    },\n    {\n      \"id\": \"func_0x1A00AE9A8\",\n      \"label\": \"Function 0x1A00AE9A8\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00AE9A8\"\n    },\n    {\n      \"id\": \"func_0x1A00435A4\",\n      \"label\": \"Function 0x1A00435A4\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00435A4\"\n    },\n    {\n      \"id\": \"func_0x1A00B1248\",\n      \"label\": \"Function 0x1A00B1248\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00B1248\"\n    },\n    {\n      \"id\": \"func_0x1A00B792C\",\n      \"label\": \"Function 0x1A00B792C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00B792C\"\n    },\n    {\n      \"id\": \"func_0x1A00DF1FC\",\n      \"label\": \"Function 0x1A00DF1FC\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00DF1FC\"\n    },\n    {\n      \"id\": \"func_0x1A00BF0FC\",\n      \"label\": \"Function 0x1A00BF0FC\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00BF0FC\"\n    },\n    {\n      \"id\": \"func_0x1A006B07C\",\n      \"label\": \"Function 0x1A006B07C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A006B07C\"\n    },\n    {\n      \"id\": \"func_0x1A00814D0\",\n      \"label\": \"Function 0x1A00814D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00814D0\"\n    },\n    {\n      \"id\": \"func_0x1A00291E8\",\n      \"label\": \"Function 0x1A00291E8\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00291E8\"\n    },\n    {\n      \"id\": \"func_0x1A001E84C\",\n      \"label\": \"Function 0x1A001E84C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A001E84C\"\n    },\n    {\n      \"id\": \"func_0x1A009A26C\",\n      \"label\": \"Function 0x1A009A26C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A009A26C\"\n    },\n    {\n      \"id\": \"func_0x1A00FB590\",\n      \"label\": \"Function 0x1A00FB590\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00FB590\"\n    },\n    {\n      \"id\": \"func_0x1A007EF24\",\n      \"label\": \"Function 0x1A007EF24\",\n      \"type\": \"function\",\n      \"address\": \"0x1A007EF24\"\n    },\n    {\n      \"id\": \"func_0x1A002F9D0\",\n      \"label\": \"Function 0x1A002F9D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A002F9D0\"\n    },\n    {\n      \"id\": \"func_0x1A0057370\",\n      \"label\": \"Function 0x1A0057370\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0057370\"\n    },\n    {\n      \"id\": \"func_0x1A005DDBC\",\n      \"label\": \"Function 0x1A005DDBC\",\n      \"type\": \"function\",\n      \"address\": \"0x1A005DDBC\"\n    },\n    {\n      \"id\": \"func_0x1A0054044\",\n      \"label\": \"Function 0x1A0054044\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0054044\"\n    },\n    {\n      \"id\": \"func_0x1A008B54C\",\n      \"label\": \"Function 0x1A008B54C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A008B54C\"\n    },\n    {\n      \"id\": \"func_0x1A00444F0\",\n      \"label\": \"Function 0x1A00444F0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00444F0\"\n    },\n    {\n      \"id\": \"func_0x1A00B6868\",\n      \"label\": \"Function 0x1A00B6868\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00B6868\"\n    },\n    {\n      \"id\": \"func_0x1A00BADEC\",\n      \"label\": \"Function 0x1A00BADEC\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00BADEC\"\n    },\n    {\n      \"id\": \"func_0x1A00B6F28\",\n      \"label\": \"Function 0x1A00B6F28\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00B6F28\"\n    },\n    {\n      \"id\": \"func_0x1A00B1484\",\n      \"label\": \"Function 0x1A00B1484\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00B1484\"\n    },\n    {\n      \"id\": \"func_0x1A0036418\",\n      \"label\": \"Function 0x1A0036418\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0036418\"\n    },\n    {\n      \"id\": \"func_0x1A00A0524\",\n      \"label\": \"Function 0x1A00A0524\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00A0524\"\n    },\n    {\n      \"id\": \"func_0x1A006D66C\",\n      \"label\": \"Function 0x1A006D66C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A006D66C\"\n    },\n    {\n      \"id\": \"func_0x1A005E468\",\n      \"label\": \"Function 0x1A005E468\",\n      \"type\": \"function\",\n      \"address\": \"0x1A005E468\"\n    },\n    {\n      \"id\": \"func_0x1A00BC3A0\",\n      \"label\": \"Function 0x1A00BC3A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00BC3A0\"\n    },\n    {\n      \"id\": \"func_0x1A00CBEE4\",\n      \"label\": \"Function 0x1A00CBEE4\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00CBEE4\"\n    },\n    {\n      \"id\": \"func_0x1A0052F70\",\n      \"label\": \"Function 0x1A0052F70\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0052F70\"\n    },\n    {\n      \"id\": \"func_0x1A0084494\",\n      \"label\": \"Function 0x1A0084494\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0084494\"\n    },\n    {\n      \"id\": \"func_0x1A00CEBB0\",\n      \"label\": \"Function 0x1A00CEBB0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00CEBB0\"\n    },\n    {\n      \"id\": \"func_0x1A0038770\",\n      \"label\": \"Function 0x1A0038770\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0038770\"\n    },\n    {\n      \"id\": \"cap_hash_data_using_fnv\",\n      \"label\": \"hash data using fnv\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::FNV [C0030.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1A001AF38\",\n      \"label\": \"Function 0x1A001AF38\",\n      \"type\": \"function\",\n      \"address\": \"0x1A001AF38\"\n    },\n    {\n      \"id\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author       moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::FNV [C0030.005]\"\n      ]\n    },\n    {\n      \"id\": \"cap_authenticate_hmac__3_matches_\",\n      \"label\": \"authenticate HMAC (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Hashed Message Authentication Code [C0061]\"\n      ]\n    },\n    {\n      \"id\": \"cap_access_peb_ldr_data__2_matches_\",\n      \"label\": \"access PEB ldr_data (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1A00F55CC\",\n      \"label\": \"Block 0x1A00F55CC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00F55CC\"\n    },\n    {\n      \"id\": \"bb_0x1A00DD0F0\",\n      \"label\": \"Block 0x1A00DD0F0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1A00DD0F0\"\n    },\n    {\n      \"id\": \"cap_parse_pe_header__94_matches_\",\n      \"label\": \"parse PE header (94 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1A00B1918\",\n      \"label\": \"Function 0x1A00B1918\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00B1918\"\n    },\n    {\n      \"id\": \"func_0x1A00AD840\",\n      \"label\": \"Function 0x1A00AD840\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00AD840\"\n    },\n    {\n      \"id\": \"func_0x1A0049664\",\n      \"label\": \"Function 0x1A0049664\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0049664\"\n    },\n    {\n      \"id\": \"func_0x1A004E88C\",\n      \"label\": \"Function 0x1A004E88C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A004E88C\"\n    },\n    {\n      \"id\": \"func_0x1A0058BF0\",\n      \"label\": \"Function 0x1A0058BF0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0058BF0\"\n    },\n    {\n      \"id\": \"func_0x1A00199C0\",\n      \"label\": \"Function 0x1A00199C0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00199C0\"\n    },\n    {\n      \"id\": \"func_0x1A006E85C\",\n      \"label\": \"Function 0x1A006E85C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A006E85C\"\n    },\n    {\n      \"id\": \"func_0x1A0072D6C\",\n      \"label\": \"Function 0x1A0072D6C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0072D6C\"\n    },\n    {\n      \"id\": \"func_0x1A002FBD8\",\n      \"label\": \"Function 0x1A002FBD8\",\n      \"type\": \"function\",\n      \"address\": \"0x1A002FBD8\"\n    },\n    {\n      \"id\": \"func_0x1A00A8680\",\n      \"label\": \"Function 0x1A00A8680\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00A8680\"\n    },\n    {\n      \"id\": \"func_0x1A003BEC0\",\n      \"label\": \"Function 0x1A003BEC0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A003BEC0\"\n    },\n    {\n      \"id\": \"func_0x1A00D259C\",\n      \"label\": \"Function 0x1A00D259C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00D259C\"\n    },\n    {\n      \"id\": \"func_0x1A003A92C\",\n      \"label\": \"Function 0x1A003A92C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A003A92C\"\n    },\n    {\n      \"id\": \"func_0x1A0022D54\",\n      \"label\": \"Function 0x1A0022D54\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0022D54\"\n    },\n    {\n      \"id\": \"func_0x1A007B6E8\",\n      \"label\": \"Function 0x1A007B6E8\",\n      \"type\": \"function\",\n      \"address\": \"0x1A007B6E8\"\n    },\n    {\n      \"id\": \"func_0x1A003DAB8\",\n      \"label\": \"Function 0x1A003DAB8\",\n      \"type\": \"function\",\n      \"address\": \"0x1A003DAB8\"\n    },\n    {\n      \"id\": \"func_0x1A00267D4\",\n      \"label\": \"Function 0x1A00267D4\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00267D4\"\n    },\n    {\n      \"id\": \"func_0x1A0091D90\",\n      \"label\": \"Function 0x1A0091D90\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0091D90\"\n    },\n    {\n      \"id\": \"func_0x1A009AC38\",\n      \"label\": \"Function 0x1A009AC38\",\n      \"type\": \"function\",\n      \"address\": \"0x1A009AC38\"\n    },\n    {\n      \"id\": \"func_0x1A005432C\",\n      \"label\": \"Function 0x1A005432C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A005432C\"\n    },\n    {\n      \"id\": \"func_0x1A00340B0\",\n      \"label\": \"Function 0x1A00340B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00340B0\"\n    },\n    {\n      \"id\": \"func_0x1A0027034\",\n      \"label\": \"Function 0x1A0027034\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0027034\"\n    },\n    {\n      \"id\": \"func_0x1A006FD78\",\n      \"label\": \"Function 0x1A006FD78\",\n      \"type\": \"function\",\n      \"address\": \"0x1A006FD78\"\n    },\n    {\n      \"id\": \"func_0x1A0057778\",\n      \"label\": \"Function 0x1A0057778\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0057778\"\n    },\n    {\n      \"id\": \"func_0x1A00D69F8\",\n      \"label\": \"Function 0x1A00D69F8\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00D69F8\"\n    },\n    {\n      \"id\": \"func_0x1A009435C\",\n      \"label\": \"Function 0x1A009435C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A009435C\"\n    },\n    {\n      \"id\": \"func_0x1A00CA330\",\n      \"label\": \"Function 0x1A00CA330\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00CA330\"\n    },\n    {\n      \"id\": \"func_0x1A003D408\",\n      \"label\": \"Function 0x1A003D408\",\n      \"type\": \"function\",\n      \"address\": \"0x1A003D408\"\n    },\n    {\n      \"id\": \"func_0x1A00661D8\",\n      \"label\": \"Function 0x1A00661D8\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00661D8\"\n    },\n    {\n      \"id\": \"func_0x1A00D9090\",\n      \"label\": \"Function 0x1A00D9090\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00D9090\"\n    },\n    {\n      \"id\": \"func_0x1A0089920\",\n      \"label\": \"Function 0x1A0089920\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0089920\"\n    },\n    {\n      \"id\": \"func_0x1A00D7DB8\",\n      \"label\": \"Function 0x1A00D7DB8\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00D7DB8\"\n    },\n    {\n      \"id\": \"func_0x1A0092C0C\",\n      \"label\": \"Function 0x1A0092C0C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0092C0C\"\n    },\n    {\n      \"id\": \"func_0x1A006C52C\",\n      \"label\": \"Function 0x1A006C52C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A006C52C\"\n    },\n    {\n      \"id\": \"func_0x1A00C10FC\",\n      \"label\": \"Function 0x1A00C10FC\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00C10FC\"\n    },\n    {\n      \"id\": \"func_0x1A0018FB0\",\n      \"label\": \"Function 0x1A0018FB0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0018FB0\"\n    },\n    {\n      \"id\": \"func_0x1A003CE44\",\n      \"label\": \"Function 0x1A003CE44\",\n      \"type\": \"function\",\n      \"address\": \"0x1A003CE44\"\n    },\n    {\n      \"id\": \"func_0x1A00AB03C\",\n      \"label\": \"Function 0x1A00AB03C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00AB03C\"\n    },\n    {\n      \"id\": \"func_0x1A00D5144\",\n      \"label\": \"Function 0x1A00D5144\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00D5144\"\n    },\n    {\n      \"id\": \"func_0x1A00DA2C4\",\n      \"label\": \"Function 0x1A00DA2C4\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00DA2C4\"\n    },\n    {\n      \"id\": \"func_0x1A001D360\",\n      \"label\": \"Function 0x1A001D360\",\n      \"type\": \"function\",\n      \"address\": \"0x1A001D360\"\n    },\n    {\n      \"id\": \"func_0x1A0098274\",\n      \"label\": \"Function 0x1A0098274\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0098274\"\n    },\n    {\n      \"id\": \"func_0x1A00A5730\",\n      \"label\": \"Function 0x1A00A5730\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00A5730\"\n    },\n    {\n      \"id\": \"func_0x1A00CCB68\",\n      \"label\": \"Function 0x1A00CCB68\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00CCB68\"\n    },\n    {\n      \"id\": \"func_0x1A007878C\",\n      \"label\": \"Function 0x1A007878C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A007878C\"\n    },\n    {\n      \"id\": \"func_0x1A0040F4C\",\n      \"label\": \"Function 0x1A0040F4C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0040F4C\"\n    },\n    {\n      \"id\": \"func_0x1A00485AC\",\n      \"label\": \"Function 0x1A00485AC\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00485AC\"\n    },\n    {\n      \"id\": \"func_0x1A002DCA4\",\n      \"label\": \"Function 0x1A002DCA4\",\n      \"type\": \"function\",\n      \"address\": \"0x1A002DCA4\"\n    },\n    {\n      \"id\": \"func_0x1A005BD5C\",\n      \"label\": \"Function 0x1A005BD5C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A005BD5C\"\n    },\n    {\n      \"id\": \"func_0x1A00AF074\",\n      \"label\": \"Function 0x1A00AF074\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00AF074\"\n    },\n    {\n      \"id\": \"func_0x1A006D9E8\",\n      \"label\": \"Function 0x1A006D9E8\",\n      \"type\": \"function\",\n      \"address\": \"0x1A006D9E8\"\n    },\n    {\n      \"id\": \"func_0x1A00BE4C4\",\n      \"label\": \"Function 0x1A00BE4C4\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00BE4C4\"\n    },\n    {\n      \"id\": \"func_0x1A006A3B8\",\n      \"label\": \"Function 0x1A006A3B8\",\n      \"type\": \"function\",\n      \"address\": \"0x1A006A3B8\"\n    },\n    {\n      \"id\": \"func_0x1A0042AE8\",\n      \"label\": \"Function 0x1A0042AE8\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0042AE8\"\n    },\n    {\n      \"id\": \"func_0x1A008BA40\",\n      \"label\": \"Function 0x1A008BA40\",\n      \"type\": \"function\",\n      \"address\": \"0x1A008BA40\"\n    },\n    {\n      \"id\": \"func_0x1A009787C\",\n      \"label\": \"Function 0x1A009787C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A009787C\"\n    },\n    {\n      \"id\": \"func_0x1A00A3EE0\",\n      \"label\": \"Function 0x1A00A3EE0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00A3EE0\"\n    },\n    {\n      \"id\": \"func_0x1A0082814\",\n      \"label\": \"Function 0x1A0082814\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0082814\"\n    },\n    {\n      \"id\": \"func_0x1A007AAA0\",\n      \"label\": \"Function 0x1A007AAA0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A007AAA0\"\n    },\n    {\n      \"id\": \"func_0x1A006319C\",\n      \"label\": \"Function 0x1A006319C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A006319C\"\n    },\n    {\n      \"id\": \"func_0x1A0036898\",\n      \"label\": \"Function 0x1A0036898\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0036898\"\n    },\n    {\n      \"id\": \"func_0x1A00AD12C\",\n      \"label\": \"Function 0x1A00AD12C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00AD12C\"\n    },\n    {\n      \"id\": \"func_0x1A0075C0C\",\n      \"label\": \"Function 0x1A0075C0C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0075C0C\"\n    },\n    {\n      \"id\": \"func_0x1A0035C5C\",\n      \"label\": \"Function 0x1A0035C5C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0035C5C\"\n    },\n    {\n      \"id\": \"func_0x1A002BC6C\",\n      \"label\": \"Function 0x1A002BC6C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A002BC6C\"\n    },\n    {\n      \"id\": \"func_0x1A0096FD0\",\n      \"label\": \"Function 0x1A0096FD0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0096FD0\"\n    },\n    {\n      \"id\": \"func_0x1A00B5C18\",\n      \"label\": \"Function 0x1A00B5C18\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00B5C18\"\n    },\n    {\n      \"id\": \"func_0x1A004B880\",\n      \"label\": \"Function 0x1A004B880\",\n      \"type\": \"function\",\n      \"address\": \"0x1A004B880\"\n    },\n    {\n      \"id\": \"func_0x1A0094B44\",\n      \"label\": \"Function 0x1A0094B44\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0094B44\"\n    },\n    {\n      \"id\": \"func_0x1A003F038\",\n      \"label\": \"Function 0x1A003F038\",\n      \"type\": \"function\",\n      \"address\": \"0x1A003F038\"\n    },\n    {\n      \"id\": \"func_0x1A0069790\",\n      \"label\": \"Function 0x1A0069790\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0069790\"\n    },\n    {\n      \"id\": \"func_0x1A00B44BC\",\n      \"label\": \"Function 0x1A00B44BC\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00B44BC\"\n    },\n    {\n      \"id\": \"func_0x1A0073A3C\",\n      \"label\": \"Function 0x1A0073A3C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0073A3C\"\n    },\n    {\n      \"id\": \"func_0x1A00A4A2C\",\n      \"label\": \"Function 0x1A00A4A2C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00A4A2C\"\n    },\n    {\n      \"id\": \"func_0x1A00D1CC8\",\n      \"label\": \"Function 0x1A00D1CC8\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00D1CC8\"\n    },\n    {\n      \"id\": \"func_0x1A0042354\",\n      \"label\": \"Function 0x1A0042354\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0042354\"\n    },\n    {\n      \"id\": \"func_0x1A00C3FE0\",\n      \"label\": \"Function 0x1A00C3FE0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00C3FE0\"\n    },\n    {\n      \"id\": \"func_0x1A0020FF4\",\n      \"label\": \"Function 0x1A0020FF4\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0020FF4\"\n    },\n    {\n      \"id\": \"func_0x1A006B9B0\",\n      \"label\": \"Function 0x1A006B9B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1A006B9B0\"\n    },\n    {\n      \"id\": \"func_0x1A0072278\",\n      \"label\": \"Function 0x1A0072278\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0072278\"\n    },\n    {\n      \"id\": \"func_0x1A0032440\",\n      \"label\": \"Function 0x1A0032440\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0032440\"\n    },\n    {\n      \"id\": \"func_0x1A004903C\",\n      \"label\": \"Function 0x1A004903C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A004903C\"\n    },\n    {\n      \"id\": \"func_0x1A004C014\",\n      \"label\": \"Function 0x1A004C014\",\n      \"type\": \"function\",\n      \"address\": \"0x1A004C014\"\n    },\n    {\n      \"id\": \"func_0x1A0062320\",\n      \"label\": \"Function 0x1A0062320\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0062320\"\n    },\n    {\n      \"id\": \"func_0x1A004A098\",\n      \"label\": \"Function 0x1A004A098\",\n      \"type\": \"function\",\n      \"address\": \"0x1A004A098\"\n    },\n    {\n      \"id\": \"func_0x1A001C520\",\n      \"label\": \"Function 0x1A001C520\",\n      \"type\": \"function\",\n      \"address\": \"0x1A001C520\"\n    },\n    {\n      \"id\": \"func_0x1A00DB454\",\n      \"label\": \"Function 0x1A00DB454\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00DB454\"\n    },\n    {\n      \"id\": \"func_0x1A00A699C\",\n      \"label\": \"Function 0x1A00A699C\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00A699C\"\n    },\n    {\n      \"id\": \"func_0x1A0038168\",\n      \"label\": \"Function 0x1A0038168\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0038168\"\n    },\n    {\n      \"id\": \"func_0x1A00853A4\",\n      \"label\": \"Function 0x1A00853A4\",\n      \"type\": \"function\",\n      \"address\": \"0x1A00853A4\"\n    },\n    {\n      \"id\": \"func_0x1A004AF78\",\n      \"label\": \"Function 0x1A004AF78\",\n      \"type\": \"function\",\n      \"address\": \"0x1A004AF78\"\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports__3_matches_\",\n      \"label\": \"resolve function by parsing PE exports (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1A0019B94\",\n      \"label\": \"Function 0x1A0019B94\",\n      \"type\": \"function\",\n      \"address\": \"0x1A0019B94\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_peb_access__7_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_peb_access__7_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x1A0016574\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__352_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__352_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x1A0001000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_os_version__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x1A001A98C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_peb_ntglobalflag_flag\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_peb_ntglobalflag_flag\",\n      \"target\": \"func_0x1A00F3D4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00F3D4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_execute_anti_debugging_instructions__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_execute_anti_debugging_instructions__7_matches_\",\n      \"target\": \"func_0x1A00DFF00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_execute_anti_debugging_instructions__7_matches_\",\n      \"target\": \"func_0x1A0001188\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_execute_anti_debugging_instructions__7_matches_\",\n      \"target\": \"func_0x1A00F3D4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_execute_anti_debugging_instructions__7_matches_\",\n      \"target\": \"func_0x1A0001678\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_execute_anti_debugging_instructions__7_matches_\",\n      \"target\": \"func_0x1A00FCCC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_execute_anti_debugging_instructions__7_matches_\",\n      \"target\": \"func_0x1A0013B84\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_execute_anti_debugging_instructions__7_matches_\",\n      \"target\": \"func_0x1A00049C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00DFF00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0001188\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00F3D4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0001678\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00FCCC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0013B84\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00049C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0064C99\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A005D2DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A004C7CD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A005540B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00AFBCB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0023999\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0037910\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00B8C90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A005ACCD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A003D449\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A2EA1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A003927D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0047AD5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00B1959\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0036450\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A52BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00D5185\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00B0AF9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00C956F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00BD099\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00D2C39\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A006FDB9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0022D95\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0040F8D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00381A9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A006D6A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00CC9A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0089961\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00D90D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0038A29\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0043879\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A008AA09\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0095D51\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A006B0B4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0044528\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A008103B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A003FDB5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A008BA81\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00496A5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A003DAF9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00BE505\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0062361\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0077CAB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A005E710\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A004CDED\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00C867B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A002A1F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0060293\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A006709F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A008F3E1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00853E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A004F067\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0037145\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A7049\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A1AE1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A2385\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00C113D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A0795\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A001E887\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00B3701\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0082855\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A009EC25\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A009DCA7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00D25DD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0081508\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00AC43D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00B3CB9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00907E7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0075685\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00B5229\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00577B9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A86C1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A003CE85\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0029220\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00CFF34\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A007DD79\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0046BDD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A009FBC7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A003F079\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A007E3A5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00485ED\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0067DFC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A005436D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0097011\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0038FDC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A004E113\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00AB07D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A003B8D5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A008B584\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0073A7D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0039DF5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00CD763\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A006157B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0033120\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A009E699\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A004E8CD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A2C84\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00D01AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0059915\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00285D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0035C9D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00435DC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0086344\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00AA4F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00780A5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0044747\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0088B0F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A008EA59\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00BA629\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A009C457\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00B8F55\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0034D4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0082191\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00B578B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A005261B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00D3764\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00AF0B5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A009E18B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0031059\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0087A19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A007AAE1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A004A9D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A001D3A1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0046611\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A003E229\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00AAA89\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A008CDB5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00BB0C9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A003A96D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0059F85\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00CB7A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00DA305\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00C6C5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00D7DF9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0071ECB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A003A395\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00B44FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A6415\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00E0828\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00C5709\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0060FD9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0048021\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A76AD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00BDDD9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00BC939\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00C064D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00B73CD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00387A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00722B9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0021035\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0035653\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0081AD9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0027075\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A001C561\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00254E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A006774D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A008DBFB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0091099\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0027709\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0099DA7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00248B5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00DB495\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0094B85\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A007B729\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00405F5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00CCBA9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A007FC59\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A004B8C1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00D4247\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00AE9E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A008B7F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0044C75\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00C800D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00520C9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00507E9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A007F6F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A69DD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0027EB9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00317F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00D593B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0032481\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A004A0D9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00E816D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A009F203\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0028BFD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00CD29B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00C3867\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00227ED\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A008702B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A008FF4F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00C3397\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00B14BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0042395\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0053995\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A006916D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00787CD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A004AFB9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00631DD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00E8408\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A004907D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0058C31\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00D1177\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00B6F60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0075C4D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00B5C59\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A005BD9D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A005407C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00953C1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00C2739\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A003B2D5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A005E9C3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0066219\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00E880A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00206B5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00B6389\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A008A448\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00B3191\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A006A3F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0041961\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A5044\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0084701\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A004C055\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A006E201\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A004334C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A004D435\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0053411\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00368D9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00562AD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00B7B99\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00CA371\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00C4021\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0046045\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A003BF01\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00517EF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A007A1D5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A006B9F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A005C61D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00982B5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0045A6D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A005B805\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00978BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00BB675\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A005A711\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00D1D09\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A001F375\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A006F963\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A005CB91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A002DCE5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A009439D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A5771\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A005D7D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00682BF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A003C63D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00CC543\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00D4AB1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00BAE24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00773E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00697D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0090367\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0091DD1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0036ED8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A006C56D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0086771\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00C2CC9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00347A5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A002BCAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00D3217\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00CE191\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0071C44\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0092C4D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A9C21\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A002F3AD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A005B211\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0068A3B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A003E98C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A005854F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0091789\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0032B5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A006E89D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00AD881\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A004524D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0084DD5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A009AC79\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00659C5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A3F21\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0076EEC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00340F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00AE3D9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A002AA0F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0042B29\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A007EF5F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A007D50D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00AD16D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0043F79\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00CF81F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A008E72C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0039871\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A008094C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0066ADD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A006B3FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A002624D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00C9A1B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A009A6E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00BC3DB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0072DAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A008AFE1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00294E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00475B1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A8DD8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A006D005\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A002FC19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A006DA29\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00C209D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00D6A39\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0071960\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00836AB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00A4A6D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00C5DF9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A0026815\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_contain_obfuscated_stackstrings__321_matches_\",\n      \"target\": \"bb_0x1A00D0B24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0064C99\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A005D2DF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A004C7CD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A005540B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00AFBCB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0023999\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0037910\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00B8C90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A005ACCD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A003D449\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A2EA1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A003927D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0047AD5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00B1959\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0036450\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A52BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00D5185\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00B0AF9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00C956F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00BD099\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00D2C39\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A006FDB9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0022D95\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0040F8D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00381A9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A006D6A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00CC9A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0089961\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00D90D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0038A29\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0043879\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A008AA09\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0095D51\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A006B0B4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0044528\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A008103B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A003FDB5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A008BA81\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00496A5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A003DAF9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00BE505\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0062361\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0077CAB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A005E710\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A004CDED\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00C867B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A002A1F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0060293\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A006709F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A008F3E1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00853E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A004F067\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0037145\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A7049\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A1AE1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A2385\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00C113D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A0795\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A001E887\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00B3701\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0082855\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A009EC25\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A009DCA7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00D25DD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0081508\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00AC43D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00B3CB9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00907E7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0075685\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00B5229\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00577B9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A86C1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A003CE85\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0029220\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00CFF34\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A007DD79\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0046BDD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A009FBC7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A003F079\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A007E3A5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00485ED\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0067DFC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A005436D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0097011\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0038FDC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A004E113\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00AB07D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A003B8D5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A008B584\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0073A7D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0039DF5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00CD763\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A006157B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0033120\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A009E699\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A004E8CD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A2C84\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00D01AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0059915\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00285D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0035C9D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00435DC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0086344\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00AA4F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00780A5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0044747\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0088B0F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A008EA59\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00BA629\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A009C457\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00B8F55\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0034D4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0082191\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00B578B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A005261B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00D3764\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00AF0B5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A009E18B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0031059\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0087A19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A007AAE1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A004A9D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A001D3A1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0046611\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A003E229\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00AAA89\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A008CDB5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00BB0C9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A003A96D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0059F85\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00CB7A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00DA305\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00C6C5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00D7DF9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0071ECB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A003A395\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00B44FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A6415\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00E0828\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00C5709\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0060FD9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0048021\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A76AD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00BDDD9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00BC939\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00C064D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00B73CD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00387A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00722B9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0021035\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0035653\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0081AD9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0027075\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A001C561\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00254E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A006774D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A008DBFB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0091099\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0027709\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0099DA7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00248B5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00DB495\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0094B85\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A007B729\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00405F5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00CCBA9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A007FC59\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A004B8C1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00D4247\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00AE9E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A008B7F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0044C75\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00C800D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00520C9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00507E9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A007F6F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A69DD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0027EB9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00317F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00D593B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0032481\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A004A0D9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00E816D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A009F203\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0028BFD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00CD29B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00C3867\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00227ED\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A008702B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A008FF4F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00C3397\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00B14BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0042395\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0053995\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A006916D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00787CD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A004AFB9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00631DD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00E8408\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A004907D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0058C31\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00D1177\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00B6F60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0075C4D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00B5C59\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A005BD9D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A005407C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00953C1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00C2739\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A003B2D5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A005E9C3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0066219\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00E880A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00206B5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00B6389\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A008A448\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00B3191\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A006A3F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0041961\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A5044\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0084701\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A004C055\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A006E201\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A004334C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A004D435\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0053411\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00368D9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00562AD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00B7B99\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00CA371\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00C4021\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0046045\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A003BF01\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00517EF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A007A1D5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A006B9F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A005C61D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00982B5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0045A6D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A005B805\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00978BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00BB675\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A005A711\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00D1D09\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A001F375\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A006F963\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A005CB91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A002DCE5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A009439D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A5771\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A005D7D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00682BF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A003C63D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00CC543\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00D4AB1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00BAE24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00773E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00697D1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0090367\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0091DD1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0036ED8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A006C56D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0086771\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00C2CC9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00347A5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A002BCAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00D3217\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00CE191\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0071C44\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0092C4D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A9C21\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A002F3AD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A005B211\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0068A3B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A003E98C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A005854F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0091789\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0032B5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A006E89D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00AD881\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A004524D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0084DD5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A009AC79\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00659C5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A3F21\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0076EEC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00340F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00AE3D9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A002AA0F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0042B29\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A007EF5F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A007D50D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00AD16D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0043F79\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00CF81F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A008E72C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0039871\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A008094C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0066ADD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A006B3FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A002624D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00C9A1B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A009A6E5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00BC3DB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0072DAD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A008AFE1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00294E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00475B1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A8DD8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A006D005\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A002FC19\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A006DA29\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00C209D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00D6A39\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0071960\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00836AB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00A4A6D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00C5DF9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A0026815\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00D0B24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encode_data_using_add_xor_sub_operations__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_add_xor_sub_operations__2_matches_\",\n      \"target\": \"func_0x1A0004744\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_add_xor_sub_operations__2_matches_\",\n      \"target\": \"func_0x1A00EB9B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______jakub_jozwiak_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______jakub_jozwiak_mandiant_com\",\n      \"target\": \"func_0x1A0004744\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______jakub_jozwiak_mandiant_com\",\n      \"target\": \"func_0x1A00EB9B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encode_data_using_base64__11_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__11_matches_\",\n      \"target\": \"func_0x1A00E0B64\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__11_matches_\",\n      \"target\": \"func_0x1A002620C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__11_matches_\",\n      \"target\": \"func_0x1A00D0AEC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__11_matches_\",\n      \"target\": \"func_0x1A00B36C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__11_matches_\",\n      \"target\": \"func_0x1A00A0754\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__11_matches_\",\n      \"target\": \"func_0x1A00A63D4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__11_matches_\",\n      \"target\": \"func_0x1A00227AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__11_matches_\",\n      \"target\": \"func_0x1A0071C0C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__11_matches_\",\n      \"target\": \"func_0x1A0036EA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__11_matches_\",\n      \"target\": \"func_0x1A001F334\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__11_matches_\",\n      \"target\": \"func_0x1A00254A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1A00E0B64\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1A002620C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1A00D0AEC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1A00B36C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1A00A0754\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1A00A63D4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1A00227AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1A0071C0C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1A0036EA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1A001F334\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1A00254A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_chaskey__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_chaskey__2_matches_\",\n      \"target\": \"func_0x1A00F3D4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_chaskey__2_matches_\",\n      \"target\": \"func_0x1A00E3DEC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______still_teamt5_org\",\n      \"target\": \"func_0x1A00F3D4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______still_teamt5_org\",\n      \"target\": \"func_0x1A00E3DEC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A0077C70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00CFEFC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A008FF14\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00AA288\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A004735C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00376B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A000BB10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00AE9A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00435A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00B1248\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00B792C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00DF1FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00BF0FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A006B07C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00814D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00291E8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A001E84C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A009A26C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00FB590\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A007EF24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A002F9D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A0057370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A005DDBC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A0054044\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A008B54C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00444F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00B6868\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00BADEC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00B6F28\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00B1484\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A0036418\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00A0524\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A006D66C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A005E468\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00BC3A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00CBEE4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A0052F70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A0084494\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A00CEBB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_prga__40_matches_\",\n      \"target\": \"func_0x1A0038770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0077C70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00CFEFC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A008FF14\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00AA288\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A004735C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00376B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A000BB10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00AE9A8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00435A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00B1248\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00B792C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00DF1FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00BF0FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A006B07C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00814D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00291E8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A001E84C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A009A26C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00FB590\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A007EF24\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A002F9D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0057370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A005DDBC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0054044\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A008B54C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00444F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00B6868\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00BADEC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00B6F28\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00B1484\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0036418\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00A0524\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A006D66C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A005E468\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00BC3A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00CBEE4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0052F70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0084494\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00CEBB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0038770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_fnv\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_fnv\",\n      \"target\": \"func_0x1A001AF38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1A001AF38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_authenticate_hmac__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__3_matches_\",\n      \"target\": \"func_0x1A00A0754\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__3_matches_\",\n      \"target\": \"func_0x1A001F334\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac__3_matches_\",\n      \"target\": \"func_0x1A00254A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00A0754\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A001F334\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00254A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_peb_ldr_data__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__2_matches_\",\n      \"target\": \"bb_0x1A00F55CC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_access_peb_ldr_data__2_matches_\",\n      \"target\": \"bb_0x1A00DD0F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00F55CC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1A00DD0F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header__94_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00B1918\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00AD840\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0049664\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A004E88C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0058BF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00199C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A006E85C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0072D6C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A002FBD8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00A8680\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A003BEC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00D259C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A003A92C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0022D54\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A007B6E8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A003DAB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00267D4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0091D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A009AC38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A005432C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00340B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0027034\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A006FD78\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0057778\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00D69F8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A009435C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00CA330\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A003D408\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00661D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00D9090\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0089920\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00D7DB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0092C0C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A006C52C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00C10FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0018FB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A003CE44\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00AB03C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00D5144\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00DA2C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A001D360\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0098274\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00A5730\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00CCB68\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A007878C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0040F4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00485AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A002DCA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A005BD5C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00254A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00AF074\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A006D9E8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00BE4C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A006A3B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0042AE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A008BA40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A009787C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00A3EE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0082814\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A007AAA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A006319C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0036898\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00AD12C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0075C0C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0035C5C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A002BC6C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0096FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00B5C18\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A004B880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0094B44\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A003F038\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0069790\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00B44BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0073A3C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00A4A2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00D1CC8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0042354\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00C3FE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0020FF4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00A0754\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A006B9B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0072278\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0032440\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A004903C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A004C014\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0062320\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A004A098\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A001F334\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A001C520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00DB454\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00A699C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A0038168\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A00853A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header__94_matches_\",\n      \"target\": \"func_0x1A004AF78\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00B1918\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00AD840\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0049664\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A004E88C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0058BF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00199C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A006E85C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0072D6C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A002FBD8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00A8680\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A003BEC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00D259C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A003A92C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0022D54\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A007B6E8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A003DAB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00267D4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0091D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A009AC38\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A005432C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00340B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0027034\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A006FD78\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0057778\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00D69F8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A009435C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00CA330\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A003D408\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00661D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00D9090\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0089920\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00D7DB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0092C0C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A006C52C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00C10FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0018FB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A003CE44\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00AB03C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00D5144\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00DA2C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A001D360\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0098274\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00A5730\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00CCB68\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A007878C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0040F4C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00485AC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A002DCA4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A005BD5C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00254A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00AF074\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A006D9E8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00BE4C4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A006A3B8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0042AE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A008BA40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A009787C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00A3EE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0082814\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A007AAA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A006319C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0036898\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00AD12C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0075C0C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0035C5C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A002BC6C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0096FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00B5C18\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A004B880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0094B44\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A003F038\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0069790\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00B44BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0073A3C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00A4A2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00D1CC8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0042354\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00C3FE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0020FF4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00A0754\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A006B9B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0072278\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0032440\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A004903C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A004C014\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0062320\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A004A098\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A001F334\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A001C520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00DB454\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00A699C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A0038168\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A00853A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1A004AF78\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__3_matches_\",\n      \"target\": \"func_0x1A0019B94\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__3_matches_\",\n      \"target\": \"func_0x1A00199C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__3_matches_\",\n      \"target\": \"func_0x1A0018FB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x1A0019B94\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x1A00199C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x1A0018FB0\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-19 14:19:45.584819\",\n    \"total_functions\": \"1179\",\n    \"total_features\": \"208868\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-19 14:19:51"}
{"_id":{"$oid":"6a5c9254b3bed57e0e7378ad"},"sha256":"e7030756a6f7f4544a8496221b89883f473043e213f4145b07bfb55612cb0615","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"4a5b9ae625f164121aa23910692f6552","sha1":"a7151fda36cad43f044a4e10631f167f0d21e3f7","sha256":"e7030756a6f7f4544a8496221b89883f473043e213f4145b07bfb55612cb0615"}},"timestamp":"2026-07-19 14:31:08"}
{"_id":{"$oid":"6a5c9628b3bed57e0e7378c4"},"sha256":"1e969173c001e524b7ef3a22c0fcb1cc834104c18b64beea1d0a8de14be52087","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"very_verbose":{"success":false,"error":"ERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"}},"outputs":{"normal":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n","very_verbose":"ERROR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n\n\nSTDOUT:\n\n\nSTDERR:\nERROR    capa:                                                    helpers.py:278\n         --------------------------------------------------------               \n         ------------------------                                               \nERROR    capa:  Input file does not appear to be a supported      helpers.py:279\n         file.                                                                  \nERROR    capa:                                                    helpers.py:280\nERROR    capa:  See all supported file formats via capa's help    helpers.py:281\n         output (-h).                                                           \nERROR    capa:  If you don't know the input file type,            helpers.py:282\nERROR    capa:  you can try using the `file` utility to guess it. helpers.py:283\nERROR    capa:                                                    helpers.py:284\n         --------------------------------------------------------               \n         ------------------------                                               \n"},"hashes":{"md5":"1ea6e01c9630479597cc0b581e3ba382","sha1":"3e05751e04a1073bd60386dcb05d3f5bd50a9b9d","sha256":"1e969173c001e524b7ef3a22c0fcb1cc834104c18b64beea1d0a8de14be52087"}},"timestamp":"2026-07-19 14:47:28"}
{"_id":{"$oid":"6a5c9b82b3bed57e0e7378cf"},"sha256":"c9b4047be7c4b7190533db32c67b85fe51c1692cca1d36944ad2f4d554b9320a","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":true,"path":"/tmp/sdm_capa_j00lfpus/rp-019f79b8d2487453a40ae1cad2b6caa4.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_j00lfpus/rp-019f79b8d2487453a40ae1cad2b6caa4.exe_very_verbose.txt"}},"outputs":{"normal":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         packed.                                                                \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Packed samples have often been  common.py:90\n         obfuscated to hide their logic.                                        \nWARNING  capa.capabilities.common:  capa cannot handle obfuscation  common.py:90\n         well using static analysis. This means the results may be              \n         misleading or incomplete.                                              \nWARNING  capa.capabilities.common:  If possible, you should try to  common.py:90\n         unpack this input file before analyzing it with capa.                  \nWARNING  capa.capabilities.common:  Alternatively, run the sample   common.py:90\n         in a supported sandbox and invoke capa against the report              \n         to obtain dynamic analysis results.                                    \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         packer file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"md5                     1c7a02bb53ab156eb200122c93dde12f                        \nsha1                    4b52e8d87ce511b05aa619a782e14f7e6625f37c                \nsha256                  c9b4047be7c4b7190533db32c67b85fe51c1692cca1d36944ad2f4d…\npath                    /home/apogean/projects/malware/windows/all_runs/rp-019f…\ntimestamp               2026-07-19 15:09:39.065923                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIg2h9Vf/rules                                   \nfunction count          4                                                       \nlibrary function count  0                                                       \ntotal feature count     26543                                                   \n\nreference analysis tools strings\nnamespace  anti-analysis\nscope      file         \n\npacked with Themida\nnamespace  anti-analysis/packer/themida\nscope      file                        \n\ndecompress data using aPLib\nnamespace    data-manipulation/compression                  \ndescription  detects decompression function of library aPLib\nscope        function                                       \nmatches      0x906058                                       \n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls\nscope      file                     \n\n\n\n","very_verbose":"md5                     1c7a02bb53ab156eb200122c93dde12f                        \nsha1                    4b52e8d87ce511b05aa619a782e14f7e6625f37c                \nsha256                  c9b4047be7c4b7190533db32c67b85fe51c1692cca1d36944ad2f4d…\npath                    /home/apogean/projects/malware/windows/all_runs/rp-019f…\ntimestamp               2026-07-19 15:10:18.036344                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIcxHi70/rules                                   \nfunction count          4                                                       \nlibrary function count  0                                                       \ntotal feature count     26543                                                   \n\ncontain loop (library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x906058\n  or:\n    characteristic: loop @ 0x906058\n\nreference analysis tools strings\nnamespace   anti-analysis                                                       \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \nmbc         Discovery::Analysis Tool Discovery::Process detection [B0013.001]   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /(?<!\\w)ida?(\\.exe)?$/i\n    - \"IDAT\" @ file+0xA2911, file+0xA491D\n\npacked with Themida\nnamespace   anti-analysis/packer/themida                                        \nauthor      william.ballenthin@mandiant.com                                     \nscope       file                                                                \natt&ck      Defense Evasion::Obfuscated Files or Information::Software Packing  \n            [T1027.002]                                                         \nmbc         Anti-Static Analysis::Software Packing::Themida [F0001.011]         \nreferences  https://www.hexacorn.com/blog/2016/12/15/pe-section-names-re-visite…\nor:\n  section: .themida @ 0x5B4000\n  count(section(        )): 2 or more @ 0x401000, 0x55D000, 0x585000, 0x58A000, and 1 more...\n\ndecompress data using aPLib\nnamespace    data-manipulation/compression                                      \nauthor       @r3c0nst (Frank Boldewin), moritz.raabe@mandiant.com,              \n             cdong49@gatech.edu, still@teamt5.org                               \nscope        function                                                           \nmbc          Data::Decompress Data::aPLib [C0025.003]                           \nreferences   https://ibsensoftware.com/files/aPLib-1.1.1.zip                    \ndescription  detects decompression function of library aPLib                    \nfunction @ 0x906058\n  and: = aP_depack\n    match: contain loop @ 0x906058\n      or:\n        characteristic: loop @ 0x906058\n    instruction:\n      and:\n        mnemonic: cmp @ 0x90614C\n        or:\n          number: 0x7D00 @ 0x90614C\n    instruction:\n      and:\n        mnemonic: cmp @ 0x906168\n        or:\n          number: 0x7F @ 0x906168\n    instruction:\n      and:\n        mnemonic: shl @ 0x906129\n        number: 0x8 @ 0x906129\n    instruction:\n      and:\n        mnemonic: shr @ 0x906182\n        number: 0x1 @ 0x906182\n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls   \nauthor     michael.hunhoff@mandiant.com\nscope      file                        \nsection: .tls @ 0x5A6000\n\n(internal) packer file limitation\nnamespace    internal/limitation/static                                         \nauthor       william.ballenthin@mandiant.com                                    \nscope        file                                                               \ndescription  This sample appears to be packed.                                  \n                                                                                \n             Packed samples have often been obfuscated to hide their logic.     \n             capa cannot handle obfuscation well using static analysis. This    \n             means the results may be misleading or incomplete.                 \n             If possible, you should try to unpack this input file before       \n             analyzing it with capa.                                            \n             Alternatively, run the sample in a supported sandbox and invoke    \n             capa against the report to obtain dynamic analysis results.        \n                                                                                \nor:\n  match: anti-analysis/packer @ global\n    or:\n      section: .themida @ 0x5B4000\n      count(section(        )): 2 or more @ 0x401000, 0x55D000, 0x585000, 0x58A000, and 1 more...\n\n\n\n"},"hashes":{"md5":"1c7a02bb53ab156eb200122c93dde12f","sha1":"4b52e8d87ce511b05aa619a782e14f7e6625f37c","sha256":"c9b4047be7c4b7190533db32c67b85fe51c1692cca1d36944ad2f4d554b9320a"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 4</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 26543</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"rp-019f\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"1c7a02bb53ab156eb200122c93dde12f\",\n        \"sha256\": \"c9b4047be7c4b7190533db32c67b85fe51c1692cca1d36944ad2f4d\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_reference_analysis_tools_strings\",\n      \"label\": \"reference analysis tools strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_packed_with_themida\",\n      \"label\": \"packed with Themida\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Software Packing::Themida [F0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Static Analysis::Software Packing::Themida [F0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_decompress_data_using_aplib\",\n      \"label\": \"decompress data using aPLib\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decompress Data::aPLib [C0025.003]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x906058\",\n      \"label\": \"Function 0x906058\",\n      \"type\": \"function\",\n      \"address\": \"0x906058\"\n    },\n    {\n      \"id\": \"cap_cdong49_gatech_edu__still_teamt5_org\",\n      \"label\": \"cdong49@gatech.edu, still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Decompress Data::aPLib [C0025.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"label\": \"contain a thread local storage (.tls) section\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap__internal__packer_file_limitation\",\n      \"label\": \"(internal) packer file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_analysis_tools_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_packed_with_themida\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_decompress_data_using_aplib\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_decompress_data_using_aplib\",\n      \"target\": \"func_0x906058\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_cdong49_gatech_edu__still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_cdong49_gatech_edu__still_teamt5_org\",\n      \"target\": \"func_0x906058\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal__packer_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-19 15:10:18.036344\",\n    \"total_functions\": \"4\",\n    \"total_features\": \"26543\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-19 15:10:18"}
{"_id":{"$oid":"6a5ca35fb3bed57e0e7378df"},"sha256":"72e3fb64a103033837ee52ff73f5c00b2a8536b363431cd1308e7ce00f26908a","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_boamvfmu/rdls-019f79da669c71719879d09c9105a912.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_boamvfmu/rdls-019f79da669c71719879d09c9105a912.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_boamvfmu/rdls-019f79da669c71719879d09c9105a912.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ ae6c4adaf1a49825d656e1523e0e45a4                                  │\n│ sha1     │ dabbc951f9ef0aa7bbb6870a096bea408d064285                          │\n│ sha256   │ 72e3fb64a103033837ee52ff73f5c00b2a8536b363431cd1308e7ce00f26908a  │\n│ analysis │ static                                                            │\n│ os       │ any                                                               │\n│ format   │ dotnet                                                            │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/rdls-019f79da669… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION      │ Virtualization/Sandbox Evasion::System Checks         │\n│                      │ [T1497.001]                                           │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Virtual Machine Detection [B0009]                 │\n│ DISCOVERY                │ Analysis Tool Discovery::Process detection        │\n│                          │ [B0013.001]                                       │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                              ┃ Namespace                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ reference analysis tools strings        │ anti-analysis                      │\n│ reference anti-VM strings targeting Xen │ anti-analysis/anti-vm/vm-detection │\n│ compiled to the .NET platform           │ runtime/dotnet                     │\n└─────────────────────────────────────────┴────────────────────────────────────┘\n\n","verbose":"md5                     ae6c4adaf1a49825d656e1523e0e45a4                        \nsha1                    dabbc951f9ef0aa7bbb6870a096bea408d064285                \nsha256                  72e3fb64a103033837ee52ff73f5c00b2a8536b363431cd1308e7ce…\npath                    /home/apogean/projects/malware/windows/all_runs/rdls-01…\ntimestamp               2026-07-19 15:43:45.878036                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEICxHkFy/rules                                   \nfunction count          0                                                       \nlibrary function count  0                                                       \ntotal feature count     9448                                                    \n\nreference analysis tools strings\nnamespace  anti-analysis\nscope      file         \n\nreference anti-VM strings targeting Xen\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\ncompiled to the .NET platform\nnamespace  runtime/dotnet\nscope      file          \n\n\n\n","very_verbose":"md5                     ae6c4adaf1a49825d656e1523e0e45a4                        \nsha1                    dabbc951f9ef0aa7bbb6870a096bea408d064285                \nsha256                  72e3fb64a103033837ee52ff73f5c00b2a8536b363431cd1308e7ce…\npath                    /home/apogean/projects/malware/windows/all_runs/rdls-01…\ntimestamp               2026-07-19 15:43:51.700307                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIEVgujV/rules                                   \nfunction count          0                                                       \nlibrary function count  0                                                       \ntotal feature count     9448                                                    \n\nreference analysis tools strings\nnamespace   anti-analysis                                                       \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \nmbc         Discovery::Analysis Tool Discovery::Process detection [B0013.001]   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /(?<!\\w)ida?(\\.exe)?$/i\n    - \"IDAT\" @ file+0x31A41, file+0x51A41, file+0x61A41, file+0x71A41, and 2 more...\n\nreference anti-VM strings targeting Xen\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /^Xen/i\n    - \"xEN!\" @ file+0x702CD\n\n(internal) .NET file limitation\nnamespace    internal/limitation/dynamic                        \nauthor       @v1bh475u                                          \nscope        file                                               \ndescription  This dynamic analysis trace describes a .NET file. \n                                                                \n             capa rules are not yet tuned for the .NET runtime, \n             so its analysis may be incomplete or misleading.   \n                                                                \nor:\n  format: dotnet\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  format: dotnet\n\n\n\n"},"hashes":{"md5":"ae6c4adaf1a49825d656e1523e0e45a4","sha1":"dabbc951f9ef0aa7bbb6870a096bea408d064285","sha256":"72e3fb64a103033837ee52ff73f5c00b2a8536b363431cd1308e7ce00f26908a"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 0</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 9448</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"rdls-01\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"ae6c4adaf1a49825d656e1523e0e45a4\",\n        \"sha256\": \"72e3fb64a103033837ee52ff73f5c00b2a8536b363431cd1308e7ce\",\n        \"arch\": \"i386\",\n        \"os\": \"any\",\n        \"format\": \"dotnet\"\n      }\n    },\n    {\n      \"id\": \"cap_reference_analysis_tools_strings\",\n      \"label\": \"reference analysis tools strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"label\": \"reference anti-VM strings targeting Xen\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal___net_file_limitation\",\n      \"label\": \"(internal) .NET file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author________v1bh475u\",\n      \"label\": \"author       @v1bh475u\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_compiled_to_the__net_platform\",\n      \"label\": \"compiled to the .NET platform\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_analysis_tools_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal___net_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________v1bh475u\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_to_the__net_platform\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-19 15:43:51.700307\",\n    \"total_functions\": \"0\",\n    \"total_features\": \"9448\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-19 15:43:51"}
{"_id":{"$oid":"6a5ca826b3bed57e0e7378f2"},"sha256":"0ab215f9653788c3943cbf7f60470cc02f351e192b34ef673c1fccdc6e3eda0d","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_84k1g8xr/zlib_offset_0x184bd5_7.bin_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_84k1g8xr/zlib_offset_0x184bd5_7.bin_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_84k1g8xr/zlib_offset_0x184bd5_7.bin_very_verbose.txt"}},"outputs":{"normal":"┌───────────┬──────────────────────────────────────────────────────────────────┐\n│ md5       │ 0e675d4a7a5b7ccd69013386793f68eb                                 │\n│ sha1      │ 6e5821ddd8fea6681bda4448816f39984a33596b                         │\n│ sha256    │ bf5ff4603557c9959acec995653d052d9054ad4826df967974efd2f377c723d1 │\n│ analysis  │ static                                                           │\n│ os        │ windows                                                          │\n│ format    │ pe                                                               │\n│ arch      │ amd64                                                            │\n│ path      │ /tmp/sdm_decoded_xojecni2/zlib_offset_0x184bd5_7.bin             │\n└───────────┴──────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic                       ┃ ATT&CK Technique                       ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ EXECUTION                           │ Shared Modules [T1129]                 │\n└─────────────────────────────────────┴────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective              ┃ MBC Behavior                                    ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DATA                       │ Check String [C0019]                            │\n│ PROCESS                    │ Allocate Thread Local Storage [C0040]           │\n│                            │ Set Thread Local Storage Value [C0041]          │\n└────────────────────────────┴─────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                                     ┃ Namespace                   ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ parse credit card information                  │ collection/credit-card      │\n│ get thread local storage value (5 matches)     │ host-interaction/process    │\n│ allocate thread local storage                  │ host-interaction/thread/tls │\n│ set thread local storage value                 │ host-interaction/thread/tls │\n│ link function at runtime on Windows (3         │ linking/runtime-linking     │\n│ matches)                                       │                             │\n└────────────────────────────────────────────────┴─────────────────────────────┘\n\n","verbose":"md5                     0e675d4a7a5b7ccd69013386793f68eb                        \nsha1                    6e5821ddd8fea6681bda4448816f39984a33596b                \nsha256                  bf5ff4603557c9959acec995653d052d9054ad4826df967974efd2f…\npath                    /tmp/sdm_decoded_xojecni2/zlib_offset_0x184bd5_7.bin    \ntimestamp               2026-07-19 16:04:06.636001                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x180000000                                             \nrules                   /tmp/_MEIKktZi8/rules                                   \nfunction count          155                                                     \nlibrary function count  66                                                      \ntotal feature count     10077                                                   \n\nparse credit card information\nnamespace  collection/credit-card\nscope      function              \nmatches    0x1800058A0           \n\nget thread local storage value (5 matches)\nnamespace  host-interaction/process\nscope      function                \nmatches    0x180001890             \n           0x180001930             \n           0x1800048F4             \n           0x18000C3B0             \n           0x18000C5D0             \n\nallocate thread local storage\nnamespace  host-interaction/thread/tls\nscope      function                   \nmatches    0x180004830                \n\nset thread local storage value\nnamespace  host-interaction/thread/tls\nscope      function                   \nmatches    0x180004BF8                \n\nlink function at runtime on Windows (3 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x180004B7A            \n           0x180004B7A            \n           0x180004B7A            \n\n\n\n","very_verbose":"md5                     0e675d4a7a5b7ccd69013386793f68eb                        \nsha1                    6e5821ddd8fea6681bda4448816f39984a33596b                \nsha256                  bf5ff4603557c9959acec995653d052d9054ad4826df967974efd2f…\npath                    /tmp/sdm_decoded_xojecni2/zlib_offset_0x184bd5_7.bin    \ntimestamp               2026-07-19 16:04:13.822309                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x180000000                                             \nrules                   /tmp/_MEIHP9eTT/rules                                   \nfunction count          155                                                     \nlibrary function count  66                                                      \ntotal feature count     10077                                                   \n\ncontain loop (51 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x180001270\n  or:\n    characteristic: loop @ 0x180001270\n\nparse credit card information\nnamespace  collection/credit-card    \nauthor     @_re_fox                  \nscope      function                  \nmbc        Data::Check String [C0019]\nfunction @ 0x1800058A0\n  and:\n    not: = if a function also compares these non-hex characters it's most likely NOT \nparsing CC data\n      and:\n        match: parse credit card information/efff727f6e2f4f8da22050885c920578\n        match: parse credit card information/9d69217cd41f45bda65f68dc58eba594\n        match: parse credit card information/7e601cb3a1fe4ac693b83e4540bae902\n        match: parse credit card information/af277ea9d2704e6a9db43fc05a4d9459\n    3 or more:\n      instruction:\n        and:\n          mnemonic: cmp @ 0x180005B0D\n          number: 0x42 = 'B' (Format code) @ 0x180005B0D\n        and:\n          mnemonic: cmp @ 0x180005C0E\n          number: 0x42 = 'B' (Format code) @ 0x180005C0E\n      instruction:\n        and:\n          mnemonic: cmp @ 0x180005ECC\n          number: 0x44 = 'D' (Format code) @ 0x180005ECC\n        and:\n          mnemonic: cmp @ 0x180005B45\n          number: 0x44 = 'D' (Format code) @ 0x180005B45\n      instruction:\n        and:\n          mnemonic: cmp @ 0x180005C04\n          number: 0x3F = '?' (Track 1 & 2 end sentinel) @ 0x180005C04\n        and:\n          mnemonic: cmp @ 0x180005F9F\n          number: 0x3F = '?' (Track 1 & 2 end sentinel) @ 0x180005F9F\n\nget thread local storage value (5 matches)\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x180001890\n  and:\n    api: TlsGetValue @ 0x1800018F2\nfunction @ 0x180001930\n  and:\n    api: TlsGetValue @ 0x180001992\nfunction @ 0x1800048F4\n  and:\n    api: TlsGetValue @ 0x18000495F\nfunction @ 0x18000C3B0\n  and:\n    api: TlsGetValue @ 0x18000C42C\nfunction @ 0x18000C5D0\n  and:\n    api: TlsGetValue @ 0x18000C42C\n\nallocate thread local storage\nnamespace  host-interaction/thread/tls                   \nauthor     michael.hunhoff@mandiant.com                  \nscope      function                                      \nmbc        Process::Allocate Thread Local Storage [C0040]\nfunction @ 0x180004830\n  or:\n    api: TlsAlloc @ 0x180004871\n\nset thread local storage value\nnamespace  host-interaction/thread/tls                    \nauthor     michael.hunhoff@mandiant.com                   \nscope      function                                       \nmbc        Process::Set Thread Local Storage Value [C0041]\nfunction @ 0x180004BF8\n  and:\n    api: TlsSetValue @ 0x180004C4D\n\nlink function at runtime on Windows (3 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x180004B7A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x180004B7A\ninstruction @ 0x180004B7A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x180004B7A\ninstruction @ 0x180004B7A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x180004B7A\n\n\n\n"},"hashes":{"md5":"0e675d4a7a5b7ccd69013386793f68eb","sha1":"6e5821ddd8fea6681bda4448816f39984a33596b","sha256":"bf5ff4603557c9959acec995653d052d9054ad4826df967974efd2f377c723d1"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 155</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 10077</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"zlib_offset_0x184bd5_7.bin\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"0e675d4a7a5b7ccd69013386793f68eb\",\n        \"sha256\": \"bf5ff4603557c9959acec995653d052d9054ad4826df967974efd2f\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__51_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (51 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x180001270\",\n      \"label\": \"Function 0x180001270\",\n      \"type\": \"function\",\n      \"address\": \"0x180001270\"\n    },\n    {\n      \"id\": \"cap_parse_credit_card_information\",\n      \"label\": \"parse credit card information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Check String [C0019]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1800058A0\",\n      \"label\": \"Function 0x1800058A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1800058A0\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox\",\n      \"label\": \"author     @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Check String [C0019]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_thread_local_storage_value__5_matches_\",\n      \"label\": \"get thread local storage value (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x18000C3B0\",\n      \"label\": \"Function 0x18000C3B0\",\n      \"type\": \"function\",\n      \"address\": \"0x18000C3B0\"\n    },\n    {\n      \"id\": \"func_0x18000C5D0\",\n      \"label\": \"Function 0x18000C5D0\",\n      \"type\": \"function\",\n      \"address\": \"0x18000C5D0\"\n    },\n    {\n      \"id\": \"func_0x180001890\",\n      \"label\": \"Function 0x180001890\",\n      \"type\": \"function\",\n      \"address\": \"0x180001890\"\n    },\n    {\n      \"id\": \"func_0x1800048F4\",\n      \"label\": \"Function 0x1800048F4\",\n      \"type\": \"function\",\n      \"address\": \"0x1800048F4\"\n    },\n    {\n      \"id\": \"func_0x180001930\",\n      \"label\": \"Function 0x180001930\",\n      \"type\": \"function\",\n      \"address\": \"0x180001930\"\n    },\n    {\n      \"id\": \"api_TlsGetValue\",\n      \"label\": \"TlsGetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_allocate_thread_local_storage\",\n      \"label\": \"allocate thread local storage\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Allocate Thread Local Storage [C0040]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180004830\",\n      \"label\": \"Function 0x180004830\",\n      \"type\": \"function\",\n      \"address\": \"0x180004830\"\n    },\n    {\n      \"id\": \"api_TlsAlloc\",\n      \"label\": \"TlsAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_thread_local_storage_value\",\n      \"label\": \"set thread local storage value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Set Thread Local Storage Value [C0041]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180004BF8\",\n      \"label\": \"Function 0x180004BF8\",\n      \"type\": \"function\",\n      \"address\": \"0x180004BF8\"\n    },\n    {\n      \"id\": \"api_TlsSetValue\",\n      \"label\": \"TlsSetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__3_matches_\",\n      \"label\": \"link function at runtime on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__51_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__51_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x180001270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_credit_card_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_credit_card_information\",\n      \"target\": \"func_0x1800058A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox\",\n      \"target\": \"func_0x1800058A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_thread_local_storage_value__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__5_matches_\",\n      \"target\": \"func_0x18000C3B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__5_matches_\",\n      \"target\": \"func_0x18000C5D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__5_matches_\",\n      \"target\": \"func_0x180001890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__5_matches_\",\n      \"target\": \"func_0x1800048F4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value__5_matches_\",\n      \"target\": \"func_0x180001930\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18000C3B0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000C5D0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001890\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800048F4\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001930\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18000C3B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x18000C5D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180001890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1800048F4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180001930\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x18000C3B0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x18000C5D0\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001890\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1800048F4\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001930\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_thread_local_storage\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_thread_local_storage\",\n      \"target\": \"func_0x180004830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180004830\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180004830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180004830\",\n      \"target\": \"api_TlsAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_thread_local_storage_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_thread_local_storage_value\",\n      \"target\": \"func_0x180004BF8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180004BF8\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x180004BF8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180004BF8\",\n      \"target\": \"api_TlsSetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-19 16:04:13.822309\",\n    \"total_functions\": \"155\",\n    \"total_features\": \"10077\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-19 16:04:14"}
{"_id":{"$oid":"6a5cae55b3bed57e0e7378f6"},"sha256":"e632a474347f7e231beff070ce83413f9062dfc361fcdab25e0a3fb67a0326fc","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_muzwawg_/at-019f7a056e6c71f0acf04abd83f619e7.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_muzwawg_/at-019f7a056e6c71f0acf04abd83f619e7.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_muzwawg_/at-019f7a056e6c71f0acf04abd83f619e7.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ f925f96907127bdead9ec8c026f0bf02                                  │\n│ sha1     │ dc03e82adb937f25b1557d9b3016c76cde31b2df                          │\n│ sha256   │ e632a474347f7e231beff070ce83413f9062dfc361fcdab25e0a3fb67a0326fc  │\n│ analysis │ static                                                            │\n│ os       │ any                                                               │\n│ format   │ dotnet                                                            │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/at-019f7a056e6c7… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic                 ┃ ATT&CK Technique                             ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION               │ Reflective Code Loading [T1620]              │\n└───────────────────────────────┴──────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ CRYPTOGRAPHY         │ Generate Pseudo-random Sequence::Use API [C0021.003]  │\n│ DISCOVERY            │ Analysis Tool Discovery::Process detection            │\n│                      │ [B0013.001]                                           │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                                        ┃ Namespace                ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ reference analysis tools strings                  │ anti-analysis            │\n│ generate random numbers in .NET (3 matches)       │ data-manipulation/prng   │\n│ access .NET resource                              │ executable/resource      │\n│ load .NET assembly                                │ load-code/dotnet         │\n│ compiled to the .NET platform                     │ runtime/dotnet           │\n└───────────────────────────────────────────────────┴──────────────────────────┘\n\n","verbose":"md5                     f925f96907127bdead9ec8c026f0bf02                        \nsha1                    dc03e82adb937f25b1557d9b3016c76cde31b2df                \nsha256                  e632a474347f7e231beff070ce83413f9062dfc361fcdab25e0a3fb…\npath                    /home/apogean/projects/malware/windows/all_runs/at-019f…\ntimestamp               2026-07-19 16:30:33.326063                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIlYs3cO/rules                                   \nfunction count          90                                                      \nlibrary function count  0                                                       \ntotal feature count     14309                                                   \n\nreference analysis tools strings\nnamespace  anti-analysis\nscope      file         \n\ngenerate random numbers in .NET (3 matches)\nnamespace  data-manipulation/prng\nscope      function              \nmatches    token(0x6000016)      \n           token(0x600001C)      \n           token(0x600001D)      \n\naccess .NET resource\nnamespace  executable/resource\nscope      function           \nmatches    token(0x6000048)   \n\nload .NET assembly\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x600001F)\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet\nscope      file          \n\n\n\n","very_verbose":"md5                     f925f96907127bdead9ec8c026f0bf02                        \nsha1                    dc03e82adb937f25b1557d9b3016c76cde31b2df                \nsha256                  e632a474347f7e231beff070ce83413f9062dfc361fcdab25e0a3fb…\npath                    /home/apogean/projects/malware/windows/all_runs/at-019f…\ntimestamp               2026-07-19 16:30:36.994198                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    i386                                                    \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIWZoAX6/rules                                   \nfunction count          90                                                      \nlibrary function count  0                                                       \ntotal feature count     14309                                                   \n\nreference analysis tools strings\nnamespace   anti-analysis                                                       \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \nmbc         Discovery::Analysis Tool Discovery::Process detection [B0013.001]   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /(?<!\\w)ida?(\\.exe)?$/i\n    - \"IDAT\" @ file+0x2E95F, file+0x3E95F, file+0x4E95F, file+0x7E95F, and 6 more...\n\ngenerate random numbers in .NET (3 matches)\nnamespace  data-manipulation/prng                                            \nauthor     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com     \nscope      function                                                          \nmbc        Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\nfunction @ token(0x6000016)\n  or:\n    api: System.Random::Next @ token(0x6000016)+0x65, token(0x6000016)+0xEE\nfunction @ token(0x600001C)\n  or:\n    api: System.Random::NextDouble @ token(0x600001C)+0x8B, token(0x600001C)+0xEC, token(0x600001C)+0x29A, \ntoken(0x600001C)+0x451\nfunction @ token(0x600001D)\n  or:\n    api: System.Random::NextDouble @ token(0x600001D)+0x6B\n\naccess .NET resource\nnamespace  executable/resource\nauthor     @mr-tz             \nscope      function           \nfunction @ token(0x6000048)\n  and:\n    format: dotnet\n    or:\n      api: System.Resources.ResourceManager::ctor @ token(0x6000048)+0x1A\n\n(internal) .NET file limitation\nnamespace    internal/limitation/dynamic                        \nauthor       @v1bh475u                                          \nscope        file                                               \ndescription  This dynamic analysis trace describes a .NET file. \n                                                                \n             capa rules are not yet tuned for the .NET runtime, \n             so its analysis may be incomplete or misleading.   \n                                                                \nor:\n  format: dotnet\n\nload .NET assembly\nnamespace  load-code/dotnet                                \nauthor     anushka.virgaonkar@mandiant.com                 \nscope      function                                        \natt&ck     Defense Evasion::Reflective Code Loading [T1620]\nfunction @ token(0x600001F)\n  or:\n    api: System.Reflection.Assembly::Load @ token(0x600001F)+0x1A5\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  format: dotnet\n\n\n\n"},"hashes":{"md5":"f925f96907127bdead9ec8c026f0bf02","sha1":"dc03e82adb937f25b1557d9b3016c76cde31b2df","sha256":"e632a474347f7e231beff070ce83413f9062dfc361fcdab25e0a3fb67a0326fc"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 90</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 14309</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"at-019f\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"f925f96907127bdead9ec8c026f0bf02\",\n        \"sha256\": \"e632a474347f7e231beff070ce83413f9062dfc361fcdab25e0a3fb\",\n        \"arch\": \"i386\",\n        \"os\": \"any\",\n        \"format\": \"dotnet\"\n      }\n    },\n    {\n      \"id\": \"cap_reference_analysis_tools_strings\",\n      \"label\": \"reference analysis tools strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_in__net__3_matches_\",\n      \"label\": \"generate random numbers in .NET (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_System\",\n      \"label\": \"System\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_access__net_resource\",\n      \"label\": \"access .NET resource\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz\",\n      \"label\": \"author     @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap__internal___net_file_limitation\",\n      \"label\": \"(internal) .NET file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author________v1bh475u\",\n      \"label\": \"author       @v1bh475u\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_load__net_assembly\",\n      \"label\": \"load .NET assembly\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_compiled_to_the__net_platform\",\n      \"label\": \"compiled to the .NET platform\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_analysis_tools_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_in__net__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access__net_resource\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal___net_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________v1bh475u\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_load__net_assembly\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_to_the__net_platform\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-19 16:30:36.994198\",\n    \"total_functions\": \"90\",\n    \"total_features\": \"14309\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-19 16:30:37"}
{"_id":{"$oid":"6a5d29cfb3bed57e0e73790f"},"sha256":"db8ce34cefcc83edd0e245844f35373828004706eb41f952ad0c2522e10e4b9c","analysis_data":{"success":true,"results":{"normal":{"success":false,"error":"WARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         compiled with AutoIt.                                                  \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  AutoIt is a freeware BASIC-like common.py:90\n         scripting language designed for automating the Windows                 \n         GUI.                                                                   \nWARNING  capa.capabilities.common:  capa cannot handle AutoIt       common.py:90\n         scripts. This means that the results will be misleading or             \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You may have to analyze the     common.py:90\n         file manually, using a tool like the AutoIt decompiler                 \n         MyAut2Exe.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         autoit file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n"},"verbose":{"success":true,"path":"/tmp/sdm_capa_ahagaped/006_binwalk_AutoIt3.exe.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_ahagaped/006_binwalk_AutoIt3.exe.exe_very_verbose.txt"}},"outputs":{"normal":"ERROR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         compiled with AutoIt.                                                  \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  AutoIt is a freeware BASIC-like common.py:90\n         scripting language designed for automating the Windows                 \n         GUI.                                                                   \nWARNING  capa.capabilities.common:  capa cannot handle AutoIt       common.py:90\n         scripts. This means that the results will be misleading or             \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You may have to analyze the     common.py:90\n         file manually, using a tool like the AutoIt decompiler                 \n         MyAut2Exe.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         autoit file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n\n\nSTDOUT:\n\n\nSTDERR:\nWARNING  capa.capabilities.common:                                  common.py:88\n         ----------------------------------------------------------             \n         ----------------------                                                 \nWARNING  capa.capabilities.common:  This sample appears to be       common.py:90\n         compiled with AutoIt.                                                  \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  AutoIt is a freeware BASIC-like common.py:90\n         scripting language designed for automating the Windows                 \n         GUI.                                                                   \nWARNING  capa.capabilities.common:  capa cannot handle AutoIt       common.py:90\n         scripts. This means that the results will be misleading or             \n         incomplete.                                                            \nWARNING  capa.capabilities.common:  You may have to analyze the     common.py:90\n         file manually, using a tool like the AutoIt decompiler                 \n         MyAut2Exe.                                                             \nWARNING  capa.capabilities.common:                                  common.py:90\nWARNING  capa.capabilities.common:  Identified via rule: (internal) common.py:91\n         autoit file limitation                                                 \nWARNING  capa.capabilities.common:                                  common.py:93\nWARNING  capa.capabilities.common:  Use -v or -vv if you really     common.py:94\n         want to see the capabilities identified by capa.                       \nWARNING  capa.capabilities.common:                                  common.py:95\n         ----------------------------------------------------------             \n         ----------------------                                                 \n","verbose":"md5                     0adb9b817f1df7807576c2d7068dd931                        \nsha1                    4a1b94a9a5113106f40cd8ea724703734d15f118                \nsha256                  98e4f904f7de1644e519d09371b8afcbbf40ff3bd56d76ce4df4847…\npath                    /tmp/sdm_unpack_zgwe7tpi/db8ce34cefcc83edd0e245844f3537…\ntimestamp               2026-07-20 01:39:48.505607                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEItfdLfz/rules                                   \nfunction count          2046                                                    \nlibrary function count  714                                                     \ntotal feature count     116784                                                  \n\ncheck for time delay via QueryPerformanceCounter (4 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    0x46A51A                                       \n           0x46A531                                       \n           0x46B984                                       \n           0x46F1A7                                       \n\ncheck for unmoving mouse cursor (2 matches)\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      function                          \nmatches    0x499928                          \n           0x499ED5                          \n\nlog keystrokes (9 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    0x403205         \n           0x41FC8A         \n           0x462E32         \n           0x463637         \n           0x4642CC         \n           0x46B2C9         \n           0x46BA0B         \n           0x46BB56         \n           0x46BBBB         \n\nlog keystrokes via polling (11 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    0x4019CD         \n           0x41A86C         \n           0x46A54A         \n           0x46A86D         \n           0x46B2C9         \n           0x46B333         \n           0x46B478         \n           0x46B5B6         \n           0x46B796         \n           0x46BB56         \n           0x499ED5         \n\ncapture screenshot\nnamespace  collection/screenshot\nscope      function             \nmatches    0x482EB9             \n\nquery remote server for available data\nnamespace  communication\nscope      basic block  \nmatches    0x47D877     \n\nreceive data (4 matches)\nnamespace    communication                                                     \ndescription  all known techniques for receiving data from a potential C2 server\nscope        function                                                          \nmatches      0x47D7A1                                                          \n             0x47D877                                                          \n             0x481D90                                                          \n             0x4825BD                                                          \n\nsend data (3 matches)\nnamespace    communication                                                 \ndescription  all known techniques for sending data to a potential C2 server\nscope        function                                                      \nmatches      0x47CDD3                                                      \n             0x481F27                                                      \n             0x48295A                                                      \n\nreceive and write data from server to client\nnamespace  communication/c2/file-transfer\nscope      function                      \nmatches    0x47D7A1                      \n\nresolve DNS (3 matches)\nnamespace  communication/dns\nscope      function         \nmatches    0x46E653         \n           0x480EB8         \n           0x481CBE         \n\nconnect network resource\nnamespace    communication/http               \ndescription  connect to disk or print resource\nscope        function                         \nmatches      0x460F6E                         \n\nparse URL\nnamespace  communication/http\nscope      basic block       \nmatches    0x47DA51          \n\nconnect to HTTP server (2 matches)\nnamespace  communication/http/client\nscope      function                 \nmatches    0x47CAA0                 \n           0x47CDD3                 \n\nconnect to URL\nnamespace  communication/http/client\nscope      instruction              \nmatches    0x47CBCF                 \n\ncreate HTTP request\nnamespace  communication/http/client\nscope      function                 \nmatches    0x47D67B                 \n\nread data from Internet (2 matches)\nnamespace  communication/http/client\nscope      function                 \nmatches    0x47D7A1                 \n           0x47D877                 \n\nsend HTTP request\nnamespace  communication/http/client\nscope      function                 \nmatches    0x47CDD3                 \n\nsend ICMP echo request\nnamespace  communication/icmp\nscope      function          \nmatches    0x480EB8          \n\ncreate pipe (2 matches)\nnamespace  communication/named-pipe/create\nscope      function                       \nmatches    0x470D8E                       \n           0x470E63                       \n\nconnect socket\nnamespace    communication/socket                                               \ndescription  Detects socket connection attempts using common APIs or ConnectEx  \n             setup.                                                             \nscope        basic block                                                        \nmatches      0x481AE5                                                           \n\nget socket status\nnamespace  communication/socket\nscope      function            \nmatches    0x483AA6            \n\ninitialize Winsock library (3 matches)\nnamespace  communication/socket\nscope      function            \nmatches    0x46E653            \n           0x480EB8            \n           0x482010            \n\nset socket configuration (3 matches)\nnamespace  communication/socket\nscope      function            \nmatches    0x480EB8            \n           0x482433            \n           0x4839AB            \n\nreceive data on socket (2 matches)\nnamespace  communication/socket/receive\nscope      function                    \nmatches    0x481D90                    \n           0x4825BD                    \n\nsend data on socket (2 matches)\nnamespace  communication/socket/send\nscope      function                 \nmatches    0x481F27                 \n           0x48295A                 \n\nconnect TCP socket\nnamespace  communication/socket/tcp\nscope      function                \nmatches    0x481A15                \n\ncreate TCP socket (2 matches)\nnamespace  communication/socket/tcp\nscope      basic block             \nmatches    0x481A69                \n           0x481BCD                \n\ncreate UDP socket (2 matches)\nnamespace  communication/socket/udp/send\nscope      basic block                  \nmatches    0x4821B4                     \n           0x482433                     \n\nact as TCP client\nnamespace  communication/tcp/client\nscope      function                \nmatches    0x481A15                \n\ncompiled with AutoIt\nnamespace  compiler/autoit\nscope      file           \n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32\nscope      function                        \nmatches    0x482E1E                        \n\nencode data using Base64\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    0x41CBB6                         \n\nencode data using XOR (7 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x469F5F                      \n           0x4728E6                      \n           0x472952                      \n           0x47298C                      \n           0x473201                      \n           0x473475                      \n           0x47E17C                      \n\nhash data using djb2\nnamespace  data-manipulation/hashing/djb2\nscope      function                      \nmatches    0x40829C                      \n\nauthenticate HMAC\nnamespace  data-manipulation/hmac\nscope      function              \nmatches    0x41CBB6              \n\ngenerate random numbers using a Mersenne Twister (4 matches)\nnamespace  data-manipulation/prng/mersenne\nscope      function                       \nmatches    0x472830                       \n           0x472876                       \n           0x4728DA                       \n           0x47291A                       \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x473923           \n\nlist drag and drop files\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x47F45C                  \n\nopen clipboard (2 matches)\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x47F45C                  \n           0x47F6C7                  \n\nread clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x47F45C                  \n\nwrite clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x47F6C7                  \n\ninteract with driver via IOCTL (4 matches)\nnamespace  host-interaction/driver\nscope      instruction            \nmatches    0x46DE05               \n           0x46DE88               \n           0x46DF3B               \n           0x4747AF               \n\nget COMSPEC environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x41E3B3                             \n\nquery environment variable (3 matches)\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x41E3B3                             \n           0x47F84A                             \n           0x487F8F                             \n\nset environment variable (2 matches)\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x43D570                             \n           0x47F8BA                             \n\nget common file path (9 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x403312                    \n           0x403A70                    \n           0x41E3B3                    \n           0x46E753                    \n           0x4738ED                    \n           0x4783F0                    \n           0x47874A                    \n           0x478AEF                    \n           0x48B958                    \n\nset current directory (7 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x403312                    \n           0x403AA3                    \n           0x475E10                    \n           0x47874A                    \n           0x478AEF                    \n           0x479F9F                    \n           0x47A0FA                    \n\ncopy file (3 matches)\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    0x46D6C0                         \n           0x46DA5C                         \n           0x47321B                         \n\ncreate directory (2 matches)\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x46DA81                           \n           0x474678                           \n\ndelete directory (2 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x46F089                           \n           0x474678                           \n\ndelete file (6 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x46D836                           \n           0x46DB69                           \n           0x46F089                           \n           0x47321B                           \n           0x476033                           \n           0x4782F6                           \n\ncheck if file exists (3 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x46DA81                           \n           0x46E387                           \n           0x46E9C5                           \n\nenumerate files on Windows (6 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x46D836                               \n           0x46DB69                               \n           0x4765F1                               \n           0x479F9F                               \n           0x47A0FA                               \n           0x47A488                               \n\nenumerate files recursively (3 matches)\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x479F9F                               \n           0x47A0FA                               \n           0x47A488                               \n\nget file attributes (5 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x46DA81                         \n           0x46E3A5                         \n           0x46E9C5                         \n           0x478940                         \n           0x479FF7                         \n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x48343B                         \n           0x498ECE                         \n\nget file version info\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x46E3D7                         \n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x478940                         \n           0x479FF7                         \n\nmove file (3 matches)\nnamespace  host-interaction/file-system/move\nscope      function                         \nmatches    0x46D6C0                         \n           0x46D836                         \n           0x46EC27                         \n\nread .ini file (4 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x478E39                         \n           0x478EFB                         \n           0x479238                         \n           0x479455                         \n\nread file on Windows (9 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x40653A                         \n           0x40AED0                         \n           0x40B050                         \n           0x43960B                         \n           0x4710AB                         \n           0x472E2B                         \n           0x472F67                         \n           0x48343B                         \n           0x498ECE                         \n\nclear file content\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x478A11                          \n\nwrite file on Windows (7 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x41C08E                          \n           0x46D4BF                          \n           0x470FD1                          \n           0x472FAB                          \n           0x472FF8                          \n           0x47321B                          \n           0x47D7A1                          \n\nenumerate gui resources\nnamespace  host-interaction/gui\nscope      function            \nmatches    0x464A8B            \n\nfind taskbar (3 matches)\nnamespace  host-interaction/gui/taskbar/find\nscope      basic block                      \nmatches    0x45FC52                         \n           0x492C81                         \n           0x492CB5                         \n\nfind graphical window (4 matches)\nnamespace  host-interaction/gui/window/find\nscope      instruction                     \nmatches    0x45FC58                        \n           0x46EF53                        \n           0x492C8B                        \n           0x492CCB                        \n\nget graphical window text (11 matches)\nnamespace  host-interaction/gui/window/get-text\nscope      function                            \nmatches    0x4623BC                            \n           0x463EEA                            \n           0x464453                            \n           0x4651E3                            \n           0x46550C                            \n           0x4664D3                            \n           0x47F32D                            \n           0x492839                            \n           0x4951D2                            \n           0x497A34                            \n           0x497D47                            \n\nhide graphical window (8 matches)\nnamespace  host-interaction/gui/window/hide\nscope      basic block                     \nmatches    0x45FBC0                        \n           0x4831F8                        \n           0x490B89                        \n           0x495B1C                        \n           0x4975F2                        \n           0x498BA7                        \n           0x498C2C                        \n           0x49ABDD                        \n\nget keyboard layout\nnamespace  host-interaction/hardware/keyboard\nscope      function                          \nmatches    0x41E3B3                          \n\nget memory capacity\nnamespace  host-interaction/hardware/memory\nscope      function                        \nmatches    0x41F6D8                        \n\nget disk information (6 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x4747D3                         \n           0x474E1A                         \n           0x4751B2                         \n           0x475280                         \n           0x47534E                         \n           0x475439                         \n\nget disk size (3 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x475B27                         \n           0x475C0A                         \n           0x475CED                         \n\nget storage device properties (2 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x46DDAB                         \n           0x46DE2A                         \n\nprint debug messages\nnamespace  host-interaction/log/debug/write-event\nscope      function                              \nmatches    0x41C08E                              \n\nshutdown system\nnamespace  host-interaction/os\nscope      function           \nmatches    0x46F122           \n\nget hostname (2 matches)\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    0x41E3B3                    \n           0x46E653                    \n\nget system information on Windows\nnamespace  host-interaction/os/info\nscope      function                \nmatches    0x405D78                \n\ncreate process on Windows (6 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x443D42                       \n           0x461C96                       \n           0x461DBE                       \n           0x48B7B2                       \n           0x48BCF9                       \n           0x498AD1                       \n\nallocate or change RWX memory\nnamespace  host-interaction/process/inject\nscope      basic block                    \nmatches    0x48A2B9                       \n\nenumerate processes (2 matches)\nnamespace  host-interaction/process/list\nscope      function                     \nmatches    0x46DC9C                     \n           0x48AFDB                     \n\nacquire debug privileges\nnamespace  host-interaction/process/modify\nscope      basic block                    \nmatches    0x48AAEE                       \n\nmodify access privileges (2 matches)\nnamespace  host-interaction/process/modify\nscope      instruction                    \nmatches    0x461964                       \n           0x461FCA                       \n\nterminate process (3 matches)\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x46F34C                          \n           0x4888B6                          \n           0x48AA41                          \n\nempty the recycle bin\nnamespace  host-interaction/recycle-bin\nscope      function                    \nmatches    0x47838F                    \n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x48C328                 \n           0x48D593                 \n\nquery or enumerate registry value (5 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x40522E                 \n           0x4055F8                 \n           0x460F6E                 \n           0x48C53A                 \n           0x48C7A3                 \n\nset registry value\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x48CD16                        \n\ndelete registry key (2 matches)\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x48BF6D                        \n           0x48D593                        \n\ndelete registry value\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x48BF6D                        \n\nget session user name\nnamespace  host-interaction/session\nscope      function                \nmatches    0x41E3B3                \n\nget token membership\nnamespace  host-interaction/session\nscope      function                \nmatches    0x461EF3                \n\nget token privileges\nnamespace  host-interaction/session\nscope      function                \nmatches    0x4618A4                \n\ncreate thread (5 matches)\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x462093                      \n           0x46EA22                      \n           0x47120E                      \n           0x47120E                      \n           0x47DB7A                      \n\nterminate thread\nnamespace  host-interaction/thread/terminate\nscope      basic block                      \nmatches    0x471244                         \n\nimpersonate user\nnamespace  host-interaction/user\nscope      function             \nmatches    0x461A91             \n\nlink function at runtime on Windows (13 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x405F17               \n           0x406316               \n           0x406350               \n           0x45E73D               \n           0x4333C7               \n           0x4333C7               \n           0x467ADC               \n           0x484A2A               \n           0x48992F               \n           0x48994B               \n           0x489991               \n           0x48C263               \n           0x48D62E               \n\nparse PE header\nnamespace  load-code/pe\nscope      function    \nmatches    0x40B4B0    \n\nresolve function by parsing PE exports (15 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x403AA3    \n           0x408B8A    \n           0x409740    \n           0x40A310    \n           0x40D330    \n           0x4102F0    \n           0x41ABB8    \n           0x41CBB6    \n           0x466E3B    \n           0x468B27    \n           0x476DE8    \n           0x47784B    \n           0x479A66    \n           0x4888B6    \n           0x491952    \n\nexecute shellcode via indirect call\nnamespace  load-code/shellcode\nscope      function           \nmatches    0x489FF3           \n\ncreate shortcut via IShellLink (2 matches)\nnamespace  persistence\nscope      function   \nmatches    0x476178   \n           0x476DE8   \n\n\n\n","very_verbose":"md5                     0adb9b817f1df7807576c2d7068dd931                        \nsha1                    4a1b94a9a5113106f40cd8ea724703734d15f118                \nsha256                  98e4f904f7de1644e519d09371b8afcbbf40ff3bd56d76ce4df4847…\npath                    /tmp/sdm_unpack_zgwe7tpi/db8ce34cefcc83edd0e245844f3537…\ntimestamp               2026-07-20 01:40:48.954838                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEISZoRtQ/rules                                   \nfunction count          2046                                                    \nlibrary function count  714                                                     \ntotal feature count     116784                                                  \n\nallocate memory (2 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x46BC2A in function 0x46BC06\n  or:\n    api: VirtualAllocEx @ 0x46BC57\n\nallocate or change RW memory (library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x46BC2A in function 0x46BC06\n  and:\n    or:\n      match: allocate memory @ 0x46BC2A\n        or:\n          api: VirtualAllocEx @ 0x46BC57\n    or:\n      number: 0x4 = PAGE_READWRITE @ 0x46BC47\n\ncalculate modulo 256 via x86 assembly (9 matches, only showing first match of \nlibrary rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x43719A\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x43719A\n    or:\n      number: 0xFF @ 0x43719A\n\ncontain loop (486 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401212\n  or:\n    characteristic: tight loop @ 0x401293\n\ncreate or open file (13 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x406E80\n  or:\n    api: CreateFile @ 0x406E80\n\ncreate or open registry key (9 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x40522E in function 0x40522E\n  or:\n    api: RegOpenKeyEx @ 0x40534B\n\ndelay execution (37 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x40F25F in function 0x40EE10\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x40F261\n\nget OS version (library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x405D78\n  or:\n    api: GetVersionEx @ 0x405DA7\n\nopen process (7 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org           \nscope   basic block                  \nmbc     Process::Open Process [C0065]\nbasic block @ 0x46BC2A in function 0x46BC06\n  or:\n    api: OpenProcess @ 0x46BC41\n\nwrite process memory (library rule)\nauthor  moritz.raabe@mandiant.com                 \nscope   instruction                               \natt&ck  Defense Evasion::Process Injection [T1055]\ninstruction @ 0x46BD09\n  or:\n    api: WriteProcessMemory @ 0x46BD09\n\ncheck for time delay via QueryPerformanceCounter (4 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection                      \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check     \n           QueryPerformanceCounter [B0001.033]                                  \nfunction @ 0x46A51A\n  and:\n    count(api(QueryPerformanceCounter)): 2 or more @ 0x46B9A0, 0x46B9CF\nfunction @ 0x46A531\n  and:\n    count(api(QueryPerformanceCounter)): 2 or more @ 0x46B9A0, 0x46B9CF\nfunction @ 0x46B984\n  and:\n    count(api(QueryPerformanceCounter)): 2 or more @ 0x46B9A0, 0x46B9CF\nfunction @ 0x46F1A7\n  and:\n    count(api(QueryPerformanceCounter)): 2 or more @ 0x46F1C3, 0x46F1E3\n\ncheck for unmoving mouse cursor (2 matches)\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      BitsOfBinary                                                        \nscope       function                                                            \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::User Activity Based\n            Checks [T1497.002]                                                  \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection::Human User     \n            Check [B0009.012]                                                   \nreferences  https://www.joesecurity.org/blog/5852460122427342172                \nfunction @ 0x499928\n  and:\n    count(api(GetCursorPos)): 2 or more @ 0x499960, 0x4999BD\nfunction @ 0x499ED5\n  and:\n    count(api(GetCursorPos)): 2 or more @ 0x49A378, 0x49A4C7\n\nlog keystrokes (9 matches)\nnamespace  collection/keylog                                \nauthor     moritz.raabe@mandiant.com                        \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nfunction @ 0x403205\n  or:\n    api: MapVirtualKey @ 0x403236, 0x40323E, 0x403249, 0x403254, and 2 more...\nfunction @ 0x41FC8A\n  or:\n    api: AttachThreadInput @ 0x45FCB2, 0x45FCBA, 0x45FCC2, 0x45FD3B, and 2 more...\n    api: MapVirtualKey @ 0x45FCDA, 0x45FCEF, 0x45FCFD, 0x45FD0C\nfunction @ 0x462E32\n  or:\n    api: MapVirtualKey @ 0x462E4D, 0x462E79, 0x462E9F\nfunction @ 0x463637\n  or:\n    api: AttachThreadInput @ 0x463674\nfunction @ 0x4642CC\n  or:\n    api: AttachThreadInput @ 0x4642F4\nfunction @ 0x46B2C9\n  or:\n    api: MapVirtualKey @ 0x46B2F8, 0x46B314\nfunction @ 0x46BA0B\n  or:\n    api: AttachThreadInput @ 0x46BA57, 0x46BA82, 0x46BA94, 0x46BAD9, and 2 more...\nfunction @ 0x46BB56\n  or:\n    api: MapVirtualKey @ 0x46BB8B\nfunction @ 0x46BBBB\n  or:\n    api: MapVirtualKey @ 0x46BBD9\n\nlog keystrokes via polling (11 matches)\nnamespace  collection/keylog                                \nauthor     michael.hunhoff@mandiant.com                     \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nmbc        Collection::Keylogging::Polling [F0002.002]      \nfunction @ 0x4019CD\n  or:\n    api: GetAsyncKeyState @ 0x401A23, 0x401A3D\nfunction @ 0x41A86C\n  or:\n    api: VkKeyScan @ 0x458469, 0x458479, 0x4584C2\nfunction @ 0x46A54A\n  or:\n    api: GetAsyncKeyState @ 0x46A5F3, 0x46A628, 0x46A655, 0x46A67F, and 1 more...\n    api: GetKeyState @ 0x46A60E, 0x46A63D, 0x46A667, 0x46A691, and 1 more...\n    api: GetKeyboardState @ 0x46A572\nfunction @ 0x46A86D\n  or:\n    api: GetAsyncKeyState @ 0x46A979, 0x46A9BF, 0x46A9FC, 0x46AA33, and 1 more...\n    api: GetKeyState @ 0x46A990, 0x46A9D0, 0x46AA0A, 0x46AA41, and 1 more...\n    api: GetKeyboardState @ 0x46A8EE\nfunction @ 0x46B2C9\n  or:\n    api: GetKeyState @ 0x46B2D9\nfunction @ 0x46B333\n  or:\n    api: GetKeyboardState @ 0x46B388\nfunction @ 0x46B478\n  or:\n    api: GetKeyboardState @ 0x46B4CD\nfunction @ 0x46B5B6\n  or:\n    api: GetKeyboardState @ 0x46B60A\nfunction @ 0x46B796\n  or:\n    api: GetKeyboardState @ 0x46B7EA\nfunction @ 0x46BB56\n  or:\n    api: VkKeyScan @ 0x46BB6E\nfunction @ 0x499ED5\n  or:\n    api: GetKeyState @ 0x49A0EA, 0x49A0F7, 0x49A117\n\ncapture screenshot\nnamespace  collection/screenshot                                            \nauthor     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\nscope      function                                                         \natt&ck     Collection::Screen Capture [T1113]                               \nmbc        Collection::Screen Capture::WinAPI [E1113.m01]                   \nfunction @ 0x482EB9\n  or:\n    and:\n      or:\n        api: GetDC @ 0x482F35\n      or:\n        api: GetDIBits @ 0x483009, 0x48302D\n      api: CreateCompatibleDC @ 0x482F51\n      api: CreateCompatibleBitmap @ 0x482F45\n\nquery remote server for available data\nnamespace  communication               \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ 0x47D877 in function 0x47D877\n  or:\n    api: InternetQueryDataAvailable @ 0x47D895\n\nreceive data (4 matches)\nnamespace    communication                                                     \nauthor       william.ballenthin@mandiant.com                                   \nscope        function                                                          \nmbc          Command and Control::C2 Communication::Receive Data [B0030.002]   \ndescription  all known techniques for receiving data from a potential C2 server\nfunction @ 0x47D7A1\n  or:\n    match: read data from Internet @ 0x47D7A1\n      and:\n        or:\n          api: InternetReadFile @ 0x47D7E6\nfunction @ 0x47D877\n  or:\n    match: read data from Internet @ 0x47D877\n      and:\n        or:\n          api: InternetReadFile @ 0x47D8CC\nfunction @ 0x481D90\n  or:\n    match: receive data on socket @ 0x481D90\n      or:\n        api: recv @ 0x481E39\nfunction @ 0x4825BD\n  or:\n    match: receive data on socket @ 0x4825BD\n      or:\n        api: recvfrom @ 0x48273E\n\nsend data (3 matches)\nnamespace    communication                                                 \nauthor       william.ballenthin@mandiant.com, joakim@intezer.com           \nscope        function                                                      \nmbc          Command and Control::C2 Communication::Send Data [B0030.001]  \ndescription  all known techniques for sending data to a potential C2 server\nfunction @ 0x47CDD3\n  or:\n    and:\n      os: windows\n      or:\n        match: send HTTP request @ 0x47CDD3\n          or:\n            and:\n              or:\n                api: HttpOpenRequest @ 0x47CE4D\n                api: InternetConnect @ 0x47CE0D\n              or:\n                api: HttpSendRequest @ 0x47CEB1\nfunction @ 0x481F27\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x481F27\n          or:\n            api: send @ 0x481F5B\nfunction @ 0x48295A\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x48295A\n          or:\n            api: sendto @ 0x482A99\n\ndownload and write a file\nnamespace              communication/c2/file-transfer                           \nmaec/malware-category  downloader                                               \nauthor                 moritz.raabe@mandiant.com                                \nscope                  function                                                 \natt&ck                 Command and Control::Ingress Tool Transfer [T1105]       \nmbc                    Command and Control::C2 Communication::Server to Client  \n                       File Transfer [B0030.003]                                \nfunction @ 0x47D7A1\n  and:\n    match: receive data @ 0x47D7A1\n      or:\n        match: read data from Internet @ 0x47D7A1\n          and:\n            or:\n              api: InternetReadFile @ 0x47D7E6\n    match: host-interaction/file-system/write @ 0x47D7A1\n      or:\n        and:\n          os: windows\n          or:\n            api: _fwrite @ 0x47D802\n            api: fwrite @ 0x47D802\n\nreceive and write data from server to client\nnamespace  communication/c2/file-transfer \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x47D7A1\n  and:\n    match: receive data @ 0x47D7A1\n      or:\n        match: read data from Internet @ 0x47D7A1\n          and:\n            or:\n              api: InternetReadFile @ 0x47D7E6\n    match: host-interaction/file-system/write @ 0x47D7A1\n      or:\n        and:\n          os: windows\n          or:\n            api: _fwrite @ 0x47D802\n            api: fwrite @ 0x47D802\n\nresolve DNS (3 matches)\nnamespace  communication/dns                                                    \nauthor     william.ballenthin@mandiant.com, johnk3r, joakim@intezer.com,        \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::DNS Communication::Resolve [C0011.001]                \nfunction @ 0x46E653\n  or:\n    api: gethostbyname @ 0x46E695\nfunction @ 0x480EB8\n  or:\n    api: gethostbyname @ 0x480F85\nfunction @ 0x481CBE\n  or:\n    api: gethostbyname @ 0x481CED\n\nconnect network resource\nnamespace    communication/http               \nauthor       michael.hunhoff@mandiant.com     \nscope        function                         \ndescription  connect to disk or print resource\nfunction @ 0x460F6E\n  and:\n    or:\n      api: WNetAddConnection2 @ 0x461032\n\nparse URL\nnamespace  communication/http          \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ 0x47DA51 in function 0x47DA51\n  or:\n    api: InternetCrackUrl @ 0x47DA97\n\nconnect to HTTP server (2 matches)\nnamespace  communication/http/client                                       \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \nmbc        Communication::HTTP Communication::Connect to Server [C0002.009]\nfunction @ 0x47CAA0\n  and:\n    api: InternetConnect @ 0x47CADF\nfunction @ 0x47CDD3\n  and:\n    api: InternetConnect @ 0x47CE0D\n\nconnect to URL\nnamespace  communication/http/client                              \nauthor     michael.hunhoff@mandiant.com                           \nscope      instruction                                            \nmbc        Communication::HTTP Communication::Open URL [C0002.004]\ninstruction @ 0x47CBCF\n  and:\n    api: InternetOpenUrl @ 0x47CBCF\n\ncreate HTTP request\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Create Request [C0002.012]\nfunction @ 0x47D67B\n  and:\n    or:\n      api: InternetOpen @ 0x47D6DA\n\nread data from Internet (2 matches)\nnamespace  communication/http/client                                    \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \nmbc        Communication::HTTP Communication::Get Response [C0002.017]  \nfunction @ 0x47D7A1\n  and:\n    or:\n      api: InternetReadFile @ 0x47D7E6\nfunction @ 0x47D877\n  and:\n    or:\n      api: InternetReadFile @ 0x47D8CC\n\nsend HTTP request\nnamespace  communication/http/client                                  \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com    \nscope      function                                                   \nmbc        Communication::HTTP Communication::Send Request [C0002.003]\nfunction @ 0x47CDD3\n  or:\n    and:\n      or:\n        api: HttpOpenRequest @ 0x47CE4D\n        api: InternetConnect @ 0x47CE0D\n      or:\n        api: HttpSendRequest @ 0x47CEB1\n\nsend ICMP echo request\nnamespace   communication/icmp                                         \nauthor      michael.hunhoff@mandiant.com                               \nscope       function                                                   \nmbc         Communication::ICMP Communication::Echo Request [C0014.002]\nreferences  https://docs.microsoft.com/en-us/windows/win32/api/icmpapi/\nfunction @ 0x480EB8\n  and:\n    or:\n      api: IcmpSendEcho @ 0x481023, 0x481042\n    optional:\n      or:\n        api: IcmpCreateFile @ 0x480F93\n      api: IcmpCloseHandle @ 0x481116\n\ncreate pipe (2 matches)\nnamespace  communication/named-pipe/create                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com           \nscope      function                                                          \nmbc        Communication::Interprocess Communication::Create Pipe [C0003.001]\nfunction @ 0x470D8E\n  or:\n    api: CreatePipe @ 0x470DEA\nfunction @ 0x470E63\n  or:\n    api: CreatePipe @ 0x470EBD\n\nconnect socket\nnamespace    communication/socket                                               \nauthor       moritz.raabe@mandiant.com, joakim@intezer.com,                     \n             mrhafizfarhad@gmail.com                                            \nscope        basic block                                                        \ndescription  Detects socket connection attempts using common APIs or ConnectEx  \n             setup.                                                             \nbasic block @ 0x481AE5 in function 0x481A15\n  or:\n    api: connect @ 0x481AEC\n\nget socket status\nnamespace  communication/socket                                              \nauthor     michael.hunhoff@mandiant.com                                      \nscope      function                                                          \natt&ck     Discovery::System Network Configuration Discovery [T1016]         \nmbc        Communication::Socket Communication::Get Socket Status [C0001.012]\nfunction @ 0x483AA6\n  or:\n    api: select @ 0x483AF2\n\ninitialize Winsock library (3 matches)\nnamespace  communication/socket                                                 \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Initialize Winsock Library      \n           [C0001.009]                                                          \nfunction @ 0x46E653\n  or:\n    api: WSAStartup @ 0x46E66E\nfunction @ 0x480EB8\n  or:\n    api: WSAStartup @ 0x480F19\nfunction @ 0x482010\n  or:\n    api: WSAStartup @ 0x48202B\n\nset socket configuration (3 matches)\nnamespace  communication/socket                                              \nauthor     michael.hunhoff@mandiant.com                                      \nscope      function                                                          \nmbc        Communication::Socket Communication::Set Socket Config [C0001.001]\nfunction @ 0x480EB8\n  or:\n    api: ioctlsocket @ 0x480F79\nfunction @ 0x482433\n  or:\n    api: setsockopt @ 0x4824E7\nfunction @ 0x4839AB\n  or:\n    api: ioctlsocket @ 0x4839D7\n\nreceive data on socket (2 matches)\nnamespace  communication/socket/receive                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Receive Data [C0001.006]        \nfunction @ 0x481D90\n  or:\n    api: recv @ 0x481E39\nfunction @ 0x4825BD\n  or:\n    api: recvfrom @ 0x48273E\n\nsend data on socket (2 matches)\nnamespace  communication/socket/send                                            \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Communication::Socket Communication::Send Data [C0001.007]           \nfunction @ 0x481F27\n  or:\n    api: send @ 0x481F5B\nfunction @ 0x48295A\n  or:\n    api: sendto @ 0x482A99\n\nconnect TCP socket\nnamespace  communication/socket/tcp                                             \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           mrhafizfarhad@gmail.com                                              \nscope      function                                                             \nmbc        Communication::Socket Communication::Connect Socket [C0001.004]      \nfunction @ 0x481A15\n  and:\n    match: create TCP socket @ 0x481A69\n      or:\n        and:\n          or:\n            number: 0x6 = IPPROTO_TCP @ 0x481A69\n          number: 0x1 = SOCK_STREAM @ 0x481A6B\n          number: 0x2 = AF_INET @ 0x481A6D\n          or:\n            api: socket @ 0x481A6F\n    match: connect socket @ 0x481AE5\n      or:\n        api: connect @ 0x481AEC\n\ncreate TCP socket (2 matches)\nnamespace   communication/socket/tcp                                            \nauthor      william.ballenthin@mandiant.com, joakim@intezer.com,                \n            anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com       \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create TCP Socket [C0001.011]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ 0x481A69 in function 0x481A15\n  or:\n    and:\n      or:\n        number: 0x6 = IPPROTO_TCP @ 0x481A69\n      number: 0x1 = SOCK_STREAM @ 0x481A6B\n      number: 0x2 = AF_INET @ 0x481A6D\n      or:\n        api: socket @ 0x481A6F\nbasic block @ 0x481BCD in function 0x481B61\n  or:\n    and:\n      or:\n        number: 0x6 = IPPROTO_TCP @ 0x481BCD\n      number: 0x1 = SOCK_STREAM @ 0x481BCF\n      number: 0x2 = AF_INET @ 0x481BD1\n      or:\n        api: socket @ 0x481BD3\n\ncreate UDP socket (2 matches)\nnamespace   communication/socket/udp/send                                       \nauthor      moritz.raabe@mandiant.com, joakim@intezer.com,                      \n            michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create UDP Socket [C0001.010]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ 0x4821B4 in function 0x482163\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x4821B6, 0x4821B8\n      or:\n        number: 0x11 = IPPROTO_UDP @ 0x4821B4\n      or:\n        api: socket @ 0x4821BA\nbasic block @ 0x482433 in function 0x482433\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x482456, 0x482458\n      or:\n        number: 0x11 = IPPROTO_UDP @ 0x482454\n      or:\n        api: socket @ 0x48245A\n\nact as TCP client\nnamespace  communication/tcp/client                                     \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                                     \nmbc        Communication::Socket Communication::TCP Client [C0001.008]  \nfunction @ 0x481A15\n  or:\n    match: connect TCP socket @ 0x481A15\n      and:\n        match: create TCP socket @ 0x481A69\n          or:\n            and:\n              or:\n                number: 0x6 = IPPROTO_TCP @ 0x481A69\n              number: 0x1 = SOCK_STREAM @ 0x481A6B\n              number: 0x2 = AF_INET @ 0x481A6D\n              or:\n                api: socket @ 0x481A6F\n        match: connect socket @ 0x481AE5\n          or:\n            api: connect @ 0x481AEC\n\ncompiled with AutoIt\nnamespace   compiler/autoit                                                     \nauthor      william.ballenthin@mandiant.com                                     \nscope       file                                                                \natt&ck      Execution::Command and Scripting Interpreter [T1059]                \nreferences  https://fumik0.com/2019/03/25/lets-play-with-qulab-an-exotic-malwar…\nor:\n  string: \"AutoIt Error\" @ file+0xD0790\n  string: \"#requireadmin\" @ file+0x9C3D8\n  string: \"#OnAutoItStartRegister\" @ file+0x9C3F4\n  substring: >>>AUTOIT SCRIPT<<<\n    - \">>>AUTOIT SCRIPT<<<\" @ file+0xC6020\n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32 \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \nmbc        Data::Checksum::CRC32 [C0032.001]\nfunction @ 0x482E1E\n  or:\n    bytes: 00000000963007772c610eeeba51099919c46d078ff46a7035a563e9a395649e = crc32_tab @ 0x482E61, 0x482E75, 0x482E84\n\nencode data using Base64\nnamespace  data-manipulation/encoding/base64                                    \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::Base64 [C0026.001]         \nfunction @ 0x41CBB6\n  or:\n    and:\n      mnemonic: shl @ 0x41CDA1, 0x45BDB4, 0x45BE3B, 0x45C01A, and 3 more...\n      mnemonic: shr @ 0x41CBEF, 0x41D019, 0x41D209\n      number: 0x3F = modulo 64 @ 0x41CF64, 0x41CF9F, 0x41D0C3, 0x41D10C, and 6 more...\n      or:\n        number: 0x3D = '=' @ 0x41D2CB, 0x45A177, 0x45A193, 0x45A640, and 4 more...\n      match: contain loop @ 0x41CBB6\n        or:\n          characteristic: loop @ 0x41CBB6\n          characteristic: tight loop @ 0x41CDDC, 0x45ADFF, 0x45AF70, 0x45B926, and 12 more...\n      optional:\n        number: 0x2 @ 0x41CD52, 0x41CE58, 0x41D019, 0x41D034, and 152 more...\n        number: 0x3 @ 0x41CFE5, 0x459F49, 0x45A01F, 0x45A12E, and 4 more...\n        number: 0x4 @ 0x41CFC5, 0x41D90D, 0x459BCF, 0x459DC2, and 24 more...\n        number: 0x6 @ 0x41D265, 0x41D285, 0x41D30D, 0x459CE7, and 8 more...\n        number: 0xF @ 0x41D626, 0x41D8EB, 0x45B51C, 0x45BF01, and 3 more...\n\nencode data using XOR (7 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x469F5F in function 0x469F0D\n  and:\n    characteristic: tight loop @ 0x469F5F\n    characteristic: nzxor @ 0x469F5F\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4728E6 in function 0x4728DA\n  and:\n    characteristic: tight loop @ 0x4728E6\n    characteristic: nzxor @ 0x4728F2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x472952 in function 0x47291A\n  and:\n    characteristic: tight loop @ 0x472952\n    characteristic: nzxor @ 0x472957, 0x472964, 0x472971, 0x472973\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x47298C in function 0x47291A\n  and:\n    characteristic: tight loop @ 0x47298C\n    characteristic: nzxor @ 0x472991, 0x472999, 0x4729AD, 0x4729B1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x473201 in function 0x4731D2\n  and:\n    characteristic: tight loop @ 0x473201\n    characteristic: nzxor @ 0x47320E\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x473475 in function 0x47321B\n  and:\n    characteristic: tight loop @ 0x473475\n    characteristic: nzxor @ 0x473482\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x47E17C in function 0x47E159\n  and:\n    characteristic: tight loop @ 0x47E17C\n    characteristic: nzxor @ 0x47E187\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nhash data using djb2\nnamespace   data-manipulation/hashing/djb2                                      \nauthor      awillia2@cisco.com, still@teamt5.org                                \nscope       function                                                            \nmbc         Data::Non-Cryptographic Hash::djb2 [C0030.006]                      \nreferences  https://twitter.com/r3c0nst/status/1392405576131436546,             \n            http://www.cse.yorku.ca/~oz/hash.html                               \nfunction @ 0x40829C\n  and:\n    instruction:\n      and:\n        mnemonic: mov @ 0x4082AD\n        number: 0x1505 @ 0x4082AD\n    or:\n      instruction:\n        and:\n          number: 0x21 @ 0x4082BA\n          or:\n            mnemonic: imul @ 0x4082BA\n\nauthenticate HMAC\nnamespace   data-manipulation/hmac                                              \nauthor      moritz.raabe@mandiant.com                                           \nscope       function                                                            \nmbc         Cryptography::Hashed Message Authentication Code [C0061]            \nreferences  https://tools.ietf.org/html/rfc2104,                                \n            https://tools.ietf.org/html/rfc4634, https://github.com/ogay/hmac   \nfunction @ 0x41CBB6\n  and:\n    number: 0x36 = inner padding byte value @ 0x45B495, 0x45CB81\n    number: 0x5C = outer padding byte value @ 0x41CF17, 0x41D2D9, 0x41D39A, 0x41D3AD, and 8 more...\n    match: contain loop @ 0x41CBB6\n      or:\n        characteristic: loop @ 0x41CBB6\n        characteristic: tight loop @ 0x41CDDC, 0x45ADFF, 0x45AF70, 0x45B926, and 12 more...\n    count(characteristic(nzxor)): 2 or more @ 0x41CC03, 0x41D217\n    optional: = block size\n      number: 0x40 = MD5, SHA-1, SHA-224, or SHA-256 @ 0x45B600, 0x45B856, 0x45C576\n      number: 0x80 = SHA-384 or SHA-512 @ 0x41CD92, 0x41D6FE, 0x41D759, 0x41D7CB, and 2 more...\n\ngenerate random numbers using a Mersenne Twister (4 matches)\nnamespace  data-manipulation/prng/mersenne                      \nauthor     moritz.raabe@mandiant.com                            \nscope      function                                             \nmbc        Cryptography::Generate Pseudo-random Sequence [C0021]\nfunction @ 0x472830\n  or:\n    number: 0xFF3A58AD @ 0x472856\nfunction @ 0x472876\n  or:\n    number: 0xFF3A58AD @ 0x4728A1\nfunction @ 0x4728DA\n  or:\n    number: 0x6C078965 @ 0x4728F4\nfunction @ 0x47291A\n  or:\n    number: 0x9908B0DF @ 0x47296C, 0x4729A8, 0x4729DF\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x473923\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x47395A\n        api: LockResource @ 0x47397A\n      optional:\n        or:\n          api: FindResourceEx @ 0x47394A\n        api: SizeofResource @ 0x47396B\n\nlist drag and drop files\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ 0x47F45C\n  and:\n    api: DragQueryFile @ 0x47F5D4, 0x47F5F1, 0x47F62F\n    and:\n      api: GetClipboardData @ 0x47F4A0, 0x47F52E, 0x47F5A1\n      number: 0xF = HDROP @ 0x47F593, 0x47F59F\n\nopen clipboard (2 matches)\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ 0x47F45C\n  and:\n    api: OpenClipboard @ 0x47F486\n    optional:\n      api: CloseClipboard @ 0x47F4AC, 0x47F4EE, 0x47F51F, 0x47F58E, and 2 more...\nfunction @ 0x47F6C7\n  and:\n    api: OpenClipboard @ 0x47F6EE, 0x47F7AC\n    optional:\n      api: CloseClipboard @ 0x47F6FA, 0x47F800\n\nread clipboard data\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Collection::Clipboard Data [T1115]                                  \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ 0x47F45C\n  and:\n    optional:\n      match: open clipboard @ 0x47F45C\n        and:\n          api: OpenClipboard @ 0x47F486\n          optional:\n            api: CloseClipboard @ 0x47F4AC, 0x47F4EE, 0x47F51F, 0x47F58E, and 2 more...\n      match: contain loop @ 0x47F45C\n        or:\n          characteristic: tight loop @ 0x47F5E5\n      api: GlobalLock @ 0x47F4E4, 0x47F53F, 0x47F5B2\n      api: GlobalUnlock @ 0x47F519, 0x47F57F, 0x47F650\n    or:\n      basic block:\n        and:\n          api: GetClipboardData @ 0x47F52E\n          optional:\n            number: 0x1 = CF_TEXT @ 0x47F52C\n        and:\n          api: GetClipboardData @ 0x47F4A0\n          optional:\n            number: 0xD = CF_UNICODETEXT @ 0x47F49E\n        and:\n          api: GetClipboardData @ 0x47F5A1\n\nwrite clipboard data\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \nmbc         Impact::Clipboard Modification [E1510]                              \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ 0x47F6C7\n  and:\n    optional:\n      match: open clipboard @ 0x47F6C7\n        and:\n          api: OpenClipboard @ 0x47F6EE, 0x47F7AC\n          optional:\n            api: CloseClipboard @ 0x47F6FA, 0x47F800\n      api: EmptyClipboard @ 0x47F6F4, 0x47F7B2\n    or:\n      api: SetClipboardData @ 0x47F7BB\n\ninteract with driver via IOCTL (4 matches)\nnamespace  host-interaction/driver  \nauthor     moritz.raabe@mandiant.com\nscope      instruction              \ninstruction @ 0x46DE05\n  or:\n    api: DeviceIoControl @ 0x46DE05\ninstruction @ 0x46DE88\n  or:\n    api: DeviceIoControl @ 0x46DE88\ninstruction @ 0x46DF3B\n  or:\n    api: DeviceIoControl @ 0x46DF3B\ninstruction @ 0x4747AF\n  or:\n    api: DeviceIoControl @ 0x4747AF\n\nget COMSPEC environment variable\nnamespace  host-interaction/environment-variable          \nauthor     matthew.williams@mandiant.com                  \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Operating System::Environment Variable [C0034] \nfunction @ 0x41E3B3\n  and:\n    match: query environment variable @ 0x41E3B3\n      or:\n        api: GetEnvironmentVariable @ 0x45EC3D, 0x45EC50, 0x45ECAC, 0x45ECBF, and 4 more...\n    or:\n      string: \"COMSPEC\" @ 0x45EC38\n\nquery environment variable (3 matches)\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x41E3B3\n  or:\n    api: GetEnvironmentVariable @ 0x45EC3D, 0x45EC50, 0x45ECAC, 0x45ECBF, and 4 more...\nfunction @ 0x47F84A\n  or:\n    api: GetEnvironmentVariable @ 0x47F887\nfunction @ 0x487F8F\n  or:\n    api: GetEnvironmentVariable @ 0x488033\n\nset environment variable (2 matches)\nnamespace  host-interaction/environment-variable                           \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \nmbc        Operating System::Environment Variable::Set Variable [C0034.001]\nfunction @ 0x43D570\n  or:\n    api: SetEnvironmentVariable @ 0x43D43C\nfunction @ 0x47F8BA\n  or:\n    api: SetEnvironmentVariable @ 0x47F8FA\n\nget common file path (9 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x403312\n  or:\n    api: GetCurrentDirectory @ 0x403342\nfunction @ 0x403A70\n  or:\n    api: GetCurrentDirectory @ 0x403A8C\nfunction @ 0x41E3B3\n  or:\n    api: GetTempPath @ 0x45EC67\n    api: GetSystemDirectory @ 0x45E77A\n    api: GetWindowsDirectory @ 0x45E70A\n    api: GetCurrentDirectory @ 0x45E961\nfunction @ 0x46E753\n  or:\n    api: SHGetFolderPath @ 0x46E76C\nfunction @ 0x4738ED\n  or:\n    api: GetTempPath @ 0x473905\n    api: GetTempFileName @ 0x47391A\nfunction @ 0x4783F0\n  or:\n    api: SHGetSpecialFolderLocation @ 0x4784E9\nfunction @ 0x47874A\n  or:\n    api: GetCurrentDirectory @ 0x478907\nfunction @ 0x478AEF\n  or:\n    api: GetCurrentDirectory @ 0x478C6A\nfunction @ 0x48B958\n  or:\n    api: GetSystemDirectory @ 0x48BB0F, 0x48BB33\n    api: GetCurrentDirectory @ 0x48BB73, 0x48BB95\n\nset current directory (7 matches)\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x403312\n  or:\n    api: SetCurrentDirectory @ 0x403442, 0x443CCB\nfunction @ 0x403AA3\n  or:\n    api: SetCurrentDirectory @ 0x403C17, 0x403D81\nfunction @ 0x475E10\n  or:\n    api: SetCurrentDirectory @ 0x475E28\nfunction @ 0x47874A\n  or:\n    api: SetCurrentDirectory @ 0x47891B, 0x478971, 0x4789BA, 0x478A0A\nfunction @ 0x478AEF\n  or:\n    api: SetCurrentDirectory @ 0x478C7E, 0x478CB0, 0x478CE6, 0x478CEF\nfunction @ 0x479F9F\n  or:\n    api: SetCurrentDirectory @ 0x47A0A7, 0x47A0C5\nfunction @ 0x47A0FA\n  or:\n    api: SetCurrentDirectory @ 0x47A1ED, 0x47A20B\n\ncopy file (3 matches)\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ 0x46D6C0\n  or:\n    basic block:\n      and:\n        number: 0x2 = FO_COPY @ 0x46D7E2\n        or:\n          api: SHFileOperation @ 0x46D821\nfunction @ 0x46DA5C\n  or:\n    api: CopyFileEx @ 0x46DA72\nfunction @ 0x47321B\n  or:\n    api: CopyFile @ 0x473571\n\ncreate directory (2 matches)\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x46DA81\n  or:\n    api: CreateDirectory @ 0x46DAD9, 0x46DB36\nfunction @ 0x474678\n  or:\n    api: CreateDirectory @ 0x4746F7\n\ndelete directory (2 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ 0x46F089\n  or:\n    api: RemoveDirectory @ 0x46F0C7\nfunction @ 0x474678\n  or:\n    api: RemoveDirectory @ 0x474728\n\ndelete file (6 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x46D836\n  or:\n    api: DeleteFile @ 0x46D99D, 0x46D9CD\nfunction @ 0x46DB69\n  or:\n    api: DeleteFile @ 0x46DC30\nfunction @ 0x46F089\n  or:\n    basic block:\n      and:\n        number: 0x3 = FO_DELETE @ 0x46F0DE\n        or:\n          api: SHFileOperation @ 0x46F114\nfunction @ 0x47321B\n  or:\n    api: DeleteFile @ 0x4734D9, 0x47355B, 0x473582, 0x473594\nfunction @ 0x476033\n  or:\n    api: DeleteFile @ 0x476128\nfunction @ 0x4782F6\n  or:\n    basic block:\n      and:\n        number: 0x3 = FO_DELETE @ 0x478336\n        or:\n          api: SHFileOperation @ 0x47836A\n\ncheck if file exists (3 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x46DA81\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x46DABB\n        instruction:\n          and:\n            mnemonic: cmp @ 0x46DAC1\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x46DAC1\n    basic block:\n      and:\n        api: GetLastError @ 0x46DACA\n        instruction:\n          and:\n            mnemonic: cmp @ 0x46DAD2\n            number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x46DAD2\nfunction @ 0x46E387\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x46E3A6\n        instruction:\n          and:\n            mnemonic: cmp @ 0x46E3AC\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x46E3AC\nfunction @ 0x46E9C5\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x46E9C6\n        instruction:\n          and:\n            mnemonic: cmp @ 0x46E9CC\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x46E9CC\n\nenumerate files on Windows (6 matches)\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ 0x46D836\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x46D8E2\n      or:\n        api: FindNextFile @ 0x46D9F7\n      optional:\n        api: FindClose @ 0x46DA13, 0x46DA24\n        match: contain loop @ 0x46D836\n          or:\n            characteristic: loop @ 0x46D836\nfunction @ 0x46DB69\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x46DBE0\n      or:\n        api: FindNextFile @ 0x46DC41\n      optional:\n        api: FindClose @ 0x46DC58, 0x46DC61\n        match: contain loop @ 0x46DB69\n          or:\n            characteristic: loop @ 0x46DB69\nfunction @ 0x4765F1\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x47661B\n      or:\n        api: FindNextFile @ 0x476671\n      optional:\n        api: FindClose @ 0x4766B9\n        match: contain loop @ 0x4765F1\n          or:\n            characteristic: loop @ 0x4765F1\nfunction @ 0x479F9F\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x479FC0, 0x47A057\n      or:\n        api: FindNextFile @ 0x47A030, 0x47A0CF\n      optional:\n        api: FindClose @ 0x47A03B, 0x47A0DC, 0x47A0EC\n        match: contain loop @ 0x479F9F\n          or:\n            characteristic: loop @ 0x479F9F\n            characteristic: recursive call @ 0x479F9F\nfunction @ 0x47A0FA\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x47A11B, 0x47A19D\n      or:\n        api: FindNextFile @ 0x47A176, 0x47A215\n      optional:\n        api: FindClose @ 0x47A181, 0x47A222, 0x47A232\n        match: contain loop @ 0x47A0FA\n          or:\n            characteristic: loop @ 0x47A0FA\n            characteristic: recursive call @ 0x47A0FA\nfunction @ 0x47A488\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x47A4D5\n      or:\n        api: FindNextFile @ 0x47A5D2\n      optional:\n        api: FindClose @ 0x47A5E8\n        match: contain loop @ 0x47A488\n          or:\n            characteristic: loop @ 0x47A488\n            characteristic: recursive call @ 0x47A488\n\nenumerate files recursively (3 matches)\nnamespace  host-interaction/file-system/files/list        \nauthor     @_re_fox, anushka.virgaonkar@mandiant.com      \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nmbc        Discovery::File and Directory Discovery [E1083]\nfunction @ 0x479F9F\n  and:\n    characteristic: recursive call @ 0x479F9F\n    or:\n      match: enumerate files on Windows @ 0x479F9F\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x479FC0, 0x47A057\n            or:\n              api: FindNextFile @ 0x47A030, 0x47A0CF\n            optional:\n              api: FindClose @ 0x47A03B, 0x47A0DC, 0x47A0EC\n              match: contain loop @ 0x479F9F\n                or:\n                  characteristic: loop @ 0x479F9F\n                  characteristic: recursive call @ 0x479F9F\nfunction @ 0x47A0FA\n  and:\n    characteristic: recursive call @ 0x47A0FA\n    or:\n      match: enumerate files on Windows @ 0x47A0FA\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x47A11B, 0x47A19D\n            or:\n              api: FindNextFile @ 0x47A176, 0x47A215\n            optional:\n              api: FindClose @ 0x47A181, 0x47A222, 0x47A232\n              match: contain loop @ 0x47A0FA\n                or:\n                  characteristic: loop @ 0x47A0FA\n                  characteristic: recursive call @ 0x47A0FA\nfunction @ 0x47A488\n  and:\n    characteristic: recursive call @ 0x47A488\n    or:\n      match: enumerate files on Windows @ 0x47A488\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x47A4D5\n            or:\n              api: FindNextFile @ 0x47A5D2\n            optional:\n              api: FindClose @ 0x47A5E8\n              match: contain loop @ 0x47A488\n                or:\n                  characteristic: loop @ 0x47A488\n                  characteristic: recursive call @ 0x47A488\n\nget file attributes (5 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x46DA81 in function 0x46DA81\n  or:\n    api: GetFileAttributes @ 0x46DABB\nbasic block @ 0x46E3A5 in function 0x46E387\n  or:\n    api: GetFileAttributes @ 0x46E3A6\nbasic block @ 0x46E9C5 in function 0x46E9C5\n  or:\n    api: GetFileAttributes @ 0x46E9C6\nbasic block @ 0x478940 in function 0x47874A\n  or:\n    api: GetFileAttributes @ 0x478945\nbasic block @ 0x479FF7 in function 0x479F9F\n  or:\n    api: GetFileAttributes @ 0x479FFE\n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x48343B\n  or:\n    api: GetFileSize @ 0x4836D2\nfunction @ 0x498ECE\n  or:\n    api: GetFileSize @ 0x498F01\n\nget file version info\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x46E3D7\n  and:\n    or:\n      api: GetFileVersionInfo @ 0x46E40F\n    optional: = retrieve specified version information from the version-information resource\n      api: VerQueryValue @ 0x46E485, 0x46E52F\n      or:\n        api: GetFileVersionInfoSize @ 0x46E3E9\n\nset file attributes (2 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ 0x478940 in function 0x47874A\n  or:\n    api: SetFileAttributes @ 0x47895F\nbasic block @ 0x479FF7 in function 0x479F9F\n  or:\n    api: SetFileAttributes @ 0x47A018\n\nmove file (3 matches)\nnamespace  host-interaction/file-system/move                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Move File [C0063]                         \nfunction @ 0x46D6C0\n  or:\n    api: MoveFile @ 0x46D73F\nfunction @ 0x46D836\n  or:\n    api: MoveFile @ 0x46D9B0\nfunction @ 0x46EC27\n  or:\n    api: MoveFile @ 0x46ECD8\n    basic block:\n      and:\n        number: 0x1 = FO_MOVE @ 0x46EE74\n        or:\n          api: SHFileOperation @ 0x46EE7C\n\nread .ini file (4 matches)\nnamespace  host-interaction/file-system/read     \nauthor     @_re_fox, michael.hunhoff@mandiant.com\nscope      function                              \nmbc        File System::Read File [C0051]        \nfunction @ 0x478E39\n  and:\n    or:\n      api: GetPrivateProfileString @ 0x478EBE\nfunction @ 0x478EFB\n  and:\n    or:\n      api: GetPrivateProfileSection @ 0x478F66\nfunction @ 0x479238\n  and:\n    or:\n      api: GetPrivateProfileSectionNames @ 0x479294\nfunction @ 0x479455\n  and:\n    or:\n      api: GetPrivateProfileSection @ 0x479508, 0x479534\n\nread file on Windows (9 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x40653A\n  or:\n    and:\n      os: windows\n      or:\n        api: fread @ 0x406558\nfunction @ 0x40AED0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x40B01C\nfunction @ 0x40B050\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x40B0AC\nfunction @ 0x43960B\n  or:\n    and:\n      os: windows\n      or:\n        api: _read @ 0x439524\nfunction @ 0x4710AB\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x471103, 0x4711AF\nfunction @ 0x472E2B\n  or:\n    and:\n      os: windows\n      or:\n        api: fread @ 0x472E5B\nfunction @ 0x472F67\n  or:\n    and:\n      os: windows\n      or:\n        api: fread @ 0x472F89\nfunction @ 0x48343B\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x4836B8\n          match: create or open file @ 0x4836BF\n            or:\n              api: CreateFile @ 0x4836BF\n      or:\n        api: ReadFile @ 0x4836F5\nfunction @ 0x498ECE\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x498EEB\n          match: create or open file @ 0x498EF1\n            or:\n              api: CreateFile @ 0x498EF1\n      or:\n        api: ReadFile @ 0x498F36\n\nclear file content\nnamespace  host-interaction/file-system/write\nauthor     jakeperalta7                      \nscope      function                          \nmbc        File System::Writes File [C0052]  \nfunction @ 0x478A11\n  and:\n    api: SetEndOfFile @ 0x478A55\n    not:\n      api: SetFilePointer\n\nwrite file on Windows (7 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x41C08E\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x4590B2\n        api: fwrite @ 0x4590B2\nfunction @ 0x46D4BF\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x46D4E6\nfunction @ 0x470FD1\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x471002\nfunction @ 0x472FAB\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x472FE3\n        api: fwrite @ 0x472FE3\nfunction @ 0x472FF8\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x473011\n        api: fwrite @ 0x473011\nfunction @ 0x47321B\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x4734AB\n        api: fwrite @ 0x4734AB\nfunction @ 0x47D7A1\n  or:\n    and:\n      os: windows\n      or:\n        api: _fwrite @ 0x47D802\n        api: fwrite @ 0x47D802\n\nenumerate gui resources\nnamespace  host-interaction/gui                           \nauthor     johnk3r, anushka.virgaonkar@mandiant.com       \nscope      function                                       \natt&ck     Discovery::Application Window Discovery [T1010]\nfunction @ 0x464A8B\n  or:\n    api: EnumWindows @ 0x465179\n\nfind taskbar (3 matches)\nnamespace  host-interaction/gui/taskbar/find   \nauthor     moritz.raabe@mandiant.com           \nscope      basic block                         \nmbc        Discovery::Taskbar Discovery [B0043]\nbasic block @ 0x45FC52 in function 0x41FC8A\n  and:\n    string: \"Shell_TrayWnd\" @ 0x45FC53\n    match: find graphical window @ 0x45FC58\n      or:\n        api: FindWindow @ 0x45FC58\nbasic block @ 0x492C81 in function 0x492C81\n  and:\n    string: \"Shell_TrayWnd\" @ 0x492C84\n    match: find graphical window @ 0x492C8B\n      or:\n        api: FindWindow @ 0x492C8B\nbasic block @ 0x492CB5 in function 0x492CB5\n  and:\n    string: \"Shell_TrayWnd\" @ 0x492CC4\n    match: find graphical window @ 0x492CCB\n      or:\n        api: FindWindow @ 0x492CCB\n\nfind graphical window (4 matches)\nnamespace  host-interaction/gui/window/find               \nauthor     moritz.raabe@mandiant.com                      \nscope      instruction                                    \natt&ck     Discovery::Application Window Discovery [T1010]\ninstruction @ 0x45FC58\n  or:\n    api: FindWindow @ 0x45FC58\ninstruction @ 0x46EF53\n  or:\n    api: FindWindowEx @ 0x46EF53\ninstruction @ 0x492C8B\n  or:\n    api: FindWindow @ 0x492C8B\ninstruction @ 0x492CCB\n  or:\n    api: FindWindow @ 0x492CCB\n\nget graphical window text (11 matches)\nnamespace  host-interaction/gui/window/get-text           \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \nmbc        Discovery::Application Window Discovery [E1010]\nfunction @ 0x4623BC\n  or:\n    and:\n      or:\n        basic block:\n          and:\n            number: 0xD = WM_GETTEXT @ 0x462425\n            api: SendMessage @ 0x462429\nfunction @ 0x463EEA\n  or:\n    and:\n      api: GetWindowText @ 0x4641EC\nfunction @ 0x464453\n  or:\n    and:\n      or:\n        basic block:\n          and:\n            number: 0xD = WM_GETTEXT @ 0x4644AD\n            api: SendMessage @ 0x4644B2\nfunction @ 0x4651E3\n  or:\n    and:\n      api: GetWindowText @ 0x465269, 0x46532C\nfunction @ 0x46550C\n  or:\n    and:\n      optional:\n        api: IsWindowVisible @ 0x465524\n      or:\n        basic block:\n          and:\n            number: 0xD = WM_GETTEXT @ 0x465574\n            api: SendMessage @ 0x465579\nfunction @ 0x4664D3\n  or:\n    and:\n      api: GetWindowText @ 0x4664FE\nfunction @ 0x47F32D\n  or:\n    and:\n      api: GetWindowText @ 0x47F354\nfunction @ 0x492839\n  or:\n    and:\n      api: GetWindowText @ 0x4929A2\nfunction @ 0x4951D2\n  or:\n    and:\n      api: GetWindowText @ 0x495650, 0x4956B9\nfunction @ 0x497A34\n  or:\n    and:\n      api: GetWindowText @ 0x497C53\nfunction @ 0x497D47\n  or:\n    and:\n      api: GetWindowText @ 0x497EB3\n\nhide graphical window (8 matches)\nnamespace  host-interaction/gui/window/hide                          \nauthor     michael.hunhoff@mandiant.com                              \nscope      basic block                                               \natt&ck     Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\nbasic block @ 0x45FBC0 in function 0x41FBD4\n  and:\n    number: 0x0 = SW_HIDE @ 0x45FBC8\n    api: ShowWindow @ 0x45FBC2\nbasic block @ 0x4831F8 in function 0x48306E\n  and:\n    number: 0x0 = SW_HIDE @ 0x483381, 0x483390\n    api: ShowWindow @ 0x4833F4\nbasic block @ 0x490B89 in function 0x490B61\n  and:\n    number: 0x0 = SW_HIDE @ 0x490B8F\n    api: ShowWindow @ 0x490B93\nbasic block @ 0x495B1C in function 0x495A33\n  and:\n    number: 0x0 = SW_HIDE @ 0x495B22\n    api: ShowWindow @ 0x495B26, 0x495B2C\nbasic block @ 0x4975F2 in function 0x4974D5\n  and:\n    number: 0x0 = SW_HIDE @ 0x4975F2\n    api: ShowWindow @ 0x4975F7\nbasic block @ 0x498BA7 in function 0x498B3A\n  and:\n    number: 0x0 = SW_HIDE @ 0x498BA7\n    api: ShowWindow @ 0x498BAB\nbasic block @ 0x498C2C in function 0x498B3A\n  and:\n    number: 0x0 = SW_HIDE @ 0x498C2C\n    api: ShowWindow @ 0x498C30, 0x498C44\nbasic block @ 0x49ABDD in function 0x49A8E5\n  and:\n    number: 0x0 = SW_HIDE @ 0x49ABDD\n    api: ShowWindow @ 0x49ABE1\n\nget keyboard layout\nnamespace  host-interaction/hardware/keyboard                                   \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Discovery::System Location Discovery::System Language Discovery      \n           [T1614.001]                                                          \nfunction @ 0x41E3B3\n  and:\n    or:\n      api: GetKeyboardLayoutName @ 0x45EB76\n\nget memory capacity\nnamespace  host-interaction/hardware/memory               \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x41F6D8\n  or:\n    api: GlobalMemoryStatusEx @ 0x41F702\n\nget disk information (6 matches)\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ 0x4747D3\n  or:\n    api: GetDriveType @ 0x474930\nfunction @ 0x474E1A\n  or:\n    api: GetDriveType @ 0x47509D\nfunction @ 0x4751B2\n  or:\n    api: GetVolumeInformation @ 0x475217\nfunction @ 0x475280\n  or:\n    api: GetVolumeInformation @ 0x4752E5\nfunction @ 0x47534E\n  or:\n    api: GetVolumeInformation @ 0x4753B6\nfunction @ 0x475439\n  or:\n    api: GetDriveType @ 0x475524\n\nget disk size (3 matches)\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ 0x475B27\n  or:\n    api: GetDiskFreeSpaceEx @ 0x475B92\nfunction @ 0x475C0A\n  or:\n    api: GetDiskFreeSpaceEx @ 0x475C75\nfunction @ 0x475CED\n  or:\n    api: GetDiskFreeSpace @ 0x475D70\n\nget storage device properties (2 matches)\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com                                        \nscope       function                                                            \nreferences  https://docs.microsoft.com/en-us/windows/win32/api/winioctl/ni-wini…\nfunction @ 0x46DDAB\n  and:\n    number: 0x2D1400 = IOCTL_STORAGE_QUERY_PROPERTY @ 0x46DDFF\n    or:\n      match: interact with driver via IOCTL @ 0x46DE05\n        or:\n          api: DeviceIoControl @ 0x46DE05\nfunction @ 0x46DE2A\n  and:\n    number: 0x2D1400 = IOCTL_STORAGE_QUERY_PROPERTY @ 0x46DE82\n    or:\n      match: interact with driver via IOCTL @ 0x46DE88\n        or:\n          api: DeviceIoControl @ 0x46DE88\n\nprint debug messages\nnamespace  host-interaction/log/debug/write-event\nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \nfunction @ 0x41C08E\n  or:\n    api: OutputDebugString @ 0x4590CD\n\nshutdown system\nnamespace  host-interaction/os                   \nauthor     michael.hunhoff@mandiant.com          \nscope      function                              \natt&ck     Impact::System Shutdown/Reboot [T1529]\nfunction @ 0x46F122\n  or:\n    api: ExitWindowsEx @ 0x46F15E\n    api: InitiateSystemShutdownEx @ 0x46F17E\n\nget hostname (2 matches)\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ 0x41E3B3\n  or:\n    api: GetComputerName @ 0x45E6F3\nfunction @ 0x46E653\n  or:\n    api: gethostname @ 0x46E688\n\nget system information on Windows\nnamespace  host-interaction/os/info                       \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com  \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x405D78\n  and:\n    os: windows\n    or:\n      api: GetSystemInfo @ 0x405F51, 0x4450F6\n\ncreate process on Windows (6 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x443D42 in function 0x403312\n  or:\n    api: ShellExecute @ 0x443D5B\nbasic block @ 0x461C96 in function 0x461A91\n  or:\n    api: CreateProcessAsUser @ 0x461CB9\nbasic block @ 0x461DBE in function 0x461D5E\n  or:\n    api: CreateProcessWithLogon @ 0x461DDF\nbasic block @ 0x48B7B2 in function 0x48B6C3\n  or:\n    api: ShellExecuteEx @ 0x48B802\nbasic block @ 0x48BCF9 in function 0x48B958\n  or:\n    api: CreateProcess @ 0x48BD15\nbasic block @ 0x498AD1 in function 0x498AD1\n  or:\n    api: CreateProcess @ 0x498B1E\n\nallocate or change RWX memory\nnamespace  host-interaction/process/inject\nauthor     @mr-tz, mehunhoff@google.com   \nscope      basic block                    \nmbc        Memory::Allocate Memory [C0007]\nbasic block @ 0x48A2B9 in function 0x489FF3\n  or:\n    basic block:\n      and:\n        or:\n          match: allocate memory @ 0x48A2B9\n            or:\n              api: VirtualAlloc @ 0x48A2CD\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x48A2B9\n\nenumerate processes (2 matches)\nnamespace  host-interaction/process/list                                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      function                                                             \natt&ck     Discovery::Process Discovery [T1057], Discovery::Software Discovery  \n           [T1518]                                                              \nfunction @ 0x46DC9C\n  or:\n    and:\n      api: Process32First @ 0x46DCCF\n      api: Process32Next @ 0x46DCEF\n      optional:\n        basic block:\n          and:\n            api: CreateToolhelp32Snapshot @ 0x46DCC1\n            or:\n              number: 0x2 = TH32CS_SNAPPROCESS @ 0x46DCB3\nfunction @ 0x48AFDB\n  or:\n    and:\n      api: Process32First @ 0x48B019\n      api: Process32Next @ 0x48B0FB\n      optional:\n        basic block:\n          and:\n            api: CreateToolhelp32Snapshot @ 0x48B00B\n            or:\n              number: 0x2 = TH32CS_SNAPPROCESS @ 0x48AFF5\n\nacquire debug privileges\nnamespace  host-interaction/process/modify                        \nauthor     william.ballenthin@mandiant.com                        \nscope      basic block                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\nbasic block @ 0x48AAEE in function 0x48AA41\n  and:\n    string: \"SeDebugPrivilege\" @ 0x48AAEE\n\nmodify access privileges (2 matches)\nnamespace  host-interaction/process/modify                        \nauthor     moritz.raabe@mandiant.com                              \nscope      instruction                                            \natt&ck     Privilege Escalation::Access Token Manipulation [T1134]\ninstruction @ 0x461964\n  and:\n    api: AdjustTokenPrivileges @ 0x461964\ninstruction @ 0x461FCA\n  and:\n    api: AdjustTokenPrivileges @ 0x461FCA\n\nterminate process (3 matches)\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x46F34C\n  or:\n    and:\n      optional:\n        match: open process @ 0x46F37C\n          or:\n            api: OpenProcess @ 0x46F390\n      or:\n        api: TerminateProcess @ 0x46F39A\nfunction @ 0x4888B6\n  or:\n    and:\n      or:\n        api: TerminateProcess @ 0x488C59\nfunction @ 0x48AA41\n  or:\n    and:\n      optional:\n        match: open process @ 0x48AAC5, 0x48AB0A\n          or:\n            api: OpenProcess @ 0x48AB12\n          or:\n            api: OpenProcess @ 0x48AACC\n      or:\n        api: TerminateProcess @ 0x48ABC7\n\nempty the recycle bin\nnamespace  host-interaction/recycle-bin\nauthor     moritz.raabe@mandiant.com   \nscope      function                    \nfunction @ 0x47838F\n  or:\n    api: SHEmptyRecycleBin @ 0x4783B3\n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ 0x48C328\n  and:\n    optional:\n      match: create or open registry key @ 0x48C449\n        or:\n          api: RegOpenKeyEx @ 0x48C45F\n    or:\n      api: RegEnumKeyEx @ 0x48C4C2\nfunction @ 0x48D593\n  and:\n    optional:\n      match: create or open registry key @ 0x48D5DE\n        or:\n          api: RegOpenKeyEx @ 0x48D5EC\n    or:\n      api: RegEnumKeyEx @ 0x48D5C3, 0x48D687\n\nquery or enumerate registry value (5 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x40522E\n  and:\n    optional:\n      match: create or open registry key @ 0x40522E\n        or:\n          api: RegOpenKeyEx @ 0x40534B\n    or:\n      api: RegQueryValueEx @ 0x444BD7, 0x444C18\nfunction @ 0x4055F8\n  and:\n    optional:\n      match: create or open registry key @ 0x40560C\n        or:\n          api: RegOpenKeyEx @ 0x40561C\n    or:\n      api: RegQueryValueEx @ 0x40563D\nfunction @ 0x460F6E\n  and:\n    optional:\n      match: create or open registry key @ 0x46105A\n        or:\n          api: RegOpenKeyEx @ 0x46106A\n    or:\n      api: RegQueryValueEx @ 0x461094\nfunction @ 0x48C53A\n  and:\n    optional:\n      match: create or open registry key @ 0x48C66E\n        or:\n          api: RegOpenKeyEx @ 0x48C684\n    or:\n      api: RegEnumValue @ 0x48C6F8\nfunction @ 0x48C7A3\n  and:\n    optional:\n      match: create or open registry key @ 0x48C8F1\n        or:\n          api: RegOpenKeyEx @ 0x48C908\n    or:\n      api: RegQueryValueEx @ 0x48C98B, 0x48CA46, 0x48CAB3, 0x48CB48, and 2 more...\n\nset registry value\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x48CD16\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x48CE80\n          or:\n            api: RegCreateKeyEx @ 0x48CEA3\n      or:\n        api: RegSetValueEx @ 0x48D011, 0x48D120, 0x48D1AC, 0x48D2BF\n\ndelete registry key (2 matches)\nnamespace  host-interaction/registry/delete                                \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\nscope      function                                                        \natt&ck     Defense Evasion::Modify Registry [T1112]                        \nmbc        Operating System::Registry::Delete Registry Key [C0036.002]     \nfunction @ 0x48BF6D\n  and:\n    optional:\n      match: create or open registry key @ 0x48C0BB\n        or:\n          api: RegOpenKeyEx @ 0x48C0D1\n    or:\n      api: RegDeleteKey @ 0x48C281\nfunction @ 0x48D593\n  and:\n    optional:\n      match: create or open registry key @ 0x48D5DE\n        or:\n          api: RegOpenKeyEx @ 0x48D5EC\n    or:\n      api: RegDeleteKey @ 0x48D652\n\ndelete registry value\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ 0x48BF6D\n  and:\n    optional:\n      match: create or open registry key @ 0x48C0BB\n        or:\n          api: RegOpenKeyEx @ 0x48C0D1\n    or:\n      api: RegDeleteValue @ 0x48C169\n\nget session user name\nnamespace  host-interaction/session                                             \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope      function                                                             \natt&ck     Discovery::System Owner/User Discovery [T1033], Discovery::Account   \n           Discovery [T1087]                                                    \nfunction @ 0x41E3B3\n  or:\n    api: GetUserName @ 0x45E60A\n\nget token membership\nnamespace  host-interaction/session                      \nauthor     michael.hunhoff@mandiant.com                  \nscope      function                                      \natt&ck     Discovery::System Owner/User Discovery [T1033]\nfunction @ 0x461EF3\n  and:\n    api: CheckTokenMembership @ 0x461F31\n    optional:\n      api: AllocateAndInitializeSid @ 0x461F1C\n      api: FreeSid @ 0x461F41\n\nget token privileges\nnamespace  host-interaction/session    \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x4618A4\n  and:\n    or:\n      basic block:\n        and:\n          api: GetTokenInformation @ 0x4618F2\n          number: 0x3 = TokenPrivileges @ 0x4618EF\n        and:\n          api: GetTokenInformation @ 0x4618BA\n          number: 0x3 = TokenPrivileges @ 0x4618B7\n\ncreate thread (5 matches)\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x462093 in function 0x462093\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x4620F8\nbasic block @ 0x46EA22 in function 0x46EA02\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthreadex @ 0x46EA47\nbasic block @ 0x47120E in function 0x471295\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x47121B\nbasic block @ 0x47120E in function 0x471295\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x47121B\nbasic block @ 0x47DB7A in function 0x47DB65\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthread @ 0x47DB90\n\nterminate thread\nnamespace  host-interaction/thread/terminate                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \nmbc        Process::Terminate Thread [C0039]                                    \nbasic block @ 0x471244 in function 0x471227\n  or:\n    api: TerminateThread @ 0x471257\n\nimpersonate user\nnamespace  host-interaction/user                                                \nauthor     michael.hunhoff@mandiant.com, 99.elad.levi@gmail.com                 \nscope      function                                                             \natt&ck     Privilege Escalation::Access Token Manipulation::Token               \n           Impersonation/Theft [T1134.001]                                      \nfunction @ 0x461A91\n  or:\n    api: LogonUser @ 0x461B16\n    and:\n      api: LoadUserProfile @ 0x461C73\n\n(internal) autoit file limitation\nnamespace    internal/limitation/static                                         \nauthor       william.ballenthin@mandiant.com                                    \nscope        file                                                               \ndescription  This sample appears to be compiled with AutoIt.                    \n                                                                                \n             AutoIt is a freeware BASIC-like scripting language designed for    \n             automating the Windows GUI.                                        \n             capa cannot handle AutoIt scripts. This means that the results will\n             be misleading or incomplete.                                       \n             You may have to analyze the file manually, using a tool like the   \n             AutoIt decompiler MyAut2Exe.                                       \n                                                                                \nor:\n  match: compiler/autoit @ global\n    or:\n      string: \"AutoIt Error\" @ file+0xD0790\n      string: \"#requireadmin\" @ file+0x9C3D8\n      string: \"#OnAutoItStartRegister\" @ file+0x9C3F4\n      substring: >>>AUTOIT SCRIPT<<<\n        - \">>>AUTOIT SCRIPT<<<\" @ file+0xC6020\n\nlink function at runtime on Windows (13 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x405F17\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x405F17\ninstruction @ 0x406316\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x406316\ninstruction @ 0x406350\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x406350\ninstruction @ 0x4333C7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4333C7\ninstruction @ 0x4333C7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4333C7\ninstruction @ 0x45E73D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x45E73D\ninstruction @ 0x467ADC\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x467ADC\ninstruction @ 0x484A2A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x484A2A\ninstruction @ 0x48992F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x48992F\ninstruction @ 0x48994B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x48994B\ninstruction @ 0x489991\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x489991\ninstruction @ 0x48C263\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x48C263\ninstruction @ 0x48D62E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x48D62E\n\nparse PE header\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x40B4B0\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x40B4E0, 0x40B4F4, 0x40B4FD, 0x40B51F, and 49 more...\n      or:\n        and:\n          number: 0x50 @ 0x450B71\n          number: 0x45 @ 0x40B9ED\n      or:\n        and:\n          number: 0x4D @ 0x40B853\n          number: 0x5A @ 0x40B637, 0x40B690, 0x40BA25\n\nresolve function by parsing PE exports (15 matches)\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x403AA3\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x403AA3\n      mnemonic: movzx @ 0x403CB0, 0x4442BC\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x403BD9, 0x403C09, 0x403C13, 0x403C26, and 4 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x403AFE, 0x403DC6\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x403AB9, 0x403C6A, 0x403E0C, 0x44422B, and 6 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x403AE3, 0x403B9A, 0x44434F, 0x44440F, and 1 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x403CCF, 0x403D55, 0x403D67, 0x444353, and 2 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x403ADF, 0x403C48, 0x403C70, 0x403E08, and 6 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x403C74, 0x403CF1, 0x403D4D, 0x4443E3, and 2 more...\nfunction @ 0x408B8A\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x408B8A\n      mnemonic: movzx @ 0x446766, 0x4469BE\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x408D65, 0x408DBB\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x4468C9, 0x446983\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x408C5B, 0x408CB7, 0x408CEF, 0x408D2C, and 9 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x408B98, 0x408C9E, 0x408DA2, 0x408DB1, and 7 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x408BD6, 0x408BF2, 0x408C67, 0x408D69\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x408D00, 0x4467C4, 0x446893, 0x4468F8, and 2 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x408C85, 0x408CB3, 0x408D8F, 0x408E04, and 2 more...\nfunction @ 0x409740\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x409740\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x409835, 0x409A13, 0x409A69, 0x409B53\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x447357, 0x4473EE, 0x447556, 0x4475AB, and 1 more...\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x4097D3, 0x4099F0, 0x44720D, 0x447232, and 9 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x409839, 0x409A78, 0x44754E\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x409845, 0x409A17, 0x409A29, 0x409A3A, and 6 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x40982D, 0x409AEF, 0x409AF9, 0x409AFD, and 7 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x409841, 0x409964, 0x409A95, 0x409ABD, and 6 more...\nfunction @ 0x40A310\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x40A310\n      mnemonic: movzx @ 0x40A36D, 0x40A38F, 0x40A39D, 0x40A3AF, and 490 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x40A6E8, 0x44A6E0, 0x44A6FB\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x40A800, 0x40AA58, 0x44831B, 0x448327, and 18 more...\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x40A7D7, 0x40AA17, 0x448624, 0x4489BE, and 1 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x448430, 0x448463, 0x448506, 0x448539, and 2 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x40A97D, 0x448F19, 0x448FC0, 0x448FFE, and 14 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x40A98B, 0x448F2B, 0x448F49, 0x448FCA, and 23 more...\nfunction @ 0x40D330\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x40D330\n      mnemonic: movzx @ 0x40D9E2, 0x40DBA6, 0x40DBAD, 0x40DBB6, and 4 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x40D34E, 0x40D3D1, 0x40DD7A, 0x40DDA3, and 3 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x40D3BE, 0x40D941, 0x40DD5A, 0x40DD72, and 4 more...\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x40D4C0, 0x40D4C8, 0x40D4F9, 0x40D587, and 27 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x40D3E1, 0x40D950, 0x40D98F, 0x40DD44, and 4 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x40D495, 0x40D644, 0x40D764, 0x40D7D1, and 16 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x40D4E9, 0x40D5B7, 0x40D64E, 0x40D71D, and 24 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x40D347, 0x40D37A, 0x40D3F1, 0x40D5D0, and 23 more...\nfunction @ 0x4102F0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x4102F0\n      mnemonic: movzx @ 0x4103B0, 0x4103DB, 0x41041B, 0x4105A2, and 30 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x410352\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x410626, 0x41085A, 0x4109AC, 0x4109DC, and 7 more...\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x41034A, 0x410381, 0x410402, 0x410474, and 22 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x410767, 0x4107CF, 0x410811, 0x411260, and 10 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x410342, 0x410365, 0x41040A, 0x4107D6, and 14 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x410688, 0x4106DE, 0x4106E8, 0x410703, and 22 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x410302, 0x410441, 0x410470, 0x4104CA, and 38 more...\nfunction @ 0x41ABB8\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x41ABB8\n      mnemonic: movzx @ 0x41B090, 0x41B0DE, 0x41B11B, 0x41B165, and 2 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x41B02E, 0x41B06E, 0x4589B5\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x41ACD7\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x41B07C, 0x41B0A0, 0x41B0D2, 0x41B0DA, and 11 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x41ABD2, 0x41ABF0, 0x41AFF3, 0x41B12E, and 8 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x41AFE3, 0x41B015, 0x41B055, 0x41B08C, and 8 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x41B02A, 0x41B037, 0x41B067, 0x41B09C, and 12 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x41B019, 0x41B04B, 0x41B14C, 0x45855A, and 11 more...\nfunction @ 0x41CBB6\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x41CBB6\n      mnemonic: movzx @ 0x41CD73, 0x41CD9A, 0x41CDA9, 0x41CDB1, and 128 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x41CE78, 0x45ADDE, 0x45AF44, 0x45BC75\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x45A87A, 0x45BBFB\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x45AB70, 0x45BC35, 0x45BC56, 0x45BC72, and 2 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x459F35, 0x45BB4E, 0x45BDC1, 0x45BE48\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x41CD5B, 0x41D00B, 0x41D041, 0x41D111, and 23 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x459B87, 0x459BC3, 0x459D68, 0x459DB7, and 1 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x459C3C, 0x45AA0D\nfunction @ 0x466E3B\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x466E3B\n      mnemonic: movzx @ 0x467021, 0x467120, 0x46731F, 0x467325\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x466EA7, 0x466ED8, 0x466F3B, 0x467087, and 7 more...\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x466F57\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x466F7A, 0x466F8B, 0x466F9B, 0x466FBF, and 11 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x466E8D, 0x466EAA, 0x466EB4, 0x467167, and 7 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x466ECF, 0x466F08, 0x466F4F, 0x4670E2, and 3 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x466EFD, 0x466F94, 0x4670E6, 0x467178, and 1 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x467056, 0x4670A2, 0x4670EA, 0x467105, and 2 more...\nfunction @ 0x468B27\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x468B27\n      mnemonic: movzx @ 0x468B8F, 0x468BA4, 0x468BE0, 0x468C31, and 8 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x468E07\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x468E68\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x468D18, 0x468FE9\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x468CB1, 0x468D40, 0x468D72\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x468D3A\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x468D1E, 0x468F4B\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x468D34, 0x4690E8\nfunction @ 0x476DE8\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x476DE8\n      mnemonic: movzx @ 0x476E9A, 0x476EB0, 0x476EBC, 0x476EC5\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x476E41, 0x476FBC, 0x476FD3, 0x47721A\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x477143\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x476F6B, 0x476FDF, 0x477028, 0x477074, and 4 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x476E0F, 0x476E6B, 0x476EFE, 0x476F03, and 3 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x477062\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x476F7E, 0x476FFE, 0x477035, 0x477081, and 9 more...\nfunction @ 0x47784B\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x47784B\n      mnemonic: movzx @ 0x4778DF, 0x4778E2\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x4778CB\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x477A80, 0x477B14, 0x477BE0\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x4778B9, 0x4778D7, 0x4778E6, 0x4779DD, and 1 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x477862, 0x477922, 0x47793A, 0x47794F, and 4 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x477960, 0x477978, 0x477AA7, 0x477AEC\nfunction @ 0x479A66\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x479A66\n      mnemonic: movzx @ 0x479B69, 0x479B79, 0x479BA7, 0x479BC0\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x479B24, 0x479F44\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x479ABC\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x479B6D, 0x479BB0, 0x479CA2, 0x479CD9, and 3 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x479BF8, 0x479C06, 0x479C30, 0x479C61, and 4 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x479A8D, 0x479AF4, 0x479C3E, 0x479D46, and 1 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x479BAB, 0x479CBA, 0x479D11, 0x479F24, and 1 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x479CAA, 0x479F38\nfunction @ 0x4888B6\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x4888B6\n      mnemonic: movzx @ 0x4888C2\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x488A29, 0x488CD4\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x488977, 0x488BFA, 0x488C37\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x488927, 0x488959, 0x4889D0, 0x488A11, and 7 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x488AC8, 0x488B4E, 0x488B6C\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x4889F5, 0x488BC8, 0x488BCD, 0x488C10, and 3 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x48896E, 0x4889E5, 0x488A20, 0x488A4E, and 7 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x488A1C, 0x488A2E, 0x488A3A, 0x488AC4, and 2 more...\nfunction @ 0x491952\n  and:\n    os: windows\n    or:\n      mnemonic: movzx @ 0x491B3A, 0x491CF0, 0x491CF6\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x491B6C, 0x491CB4\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x491A54\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x4919DC, 0x4919F4, 0x491A06, 0x491A19, and 6 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x491977, 0x491A02, 0x491AF1\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x49196F, 0x491AA9, 0x491CDC\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x491A96, 0x491AE7, 0x491CC4, 0x491CD2, and 1 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x491983, 0x4919F0, 0x491B0E, 0x491BB0, and 2 more...\n\nexecute shellcode via indirect call\nnamespace  load-code/shellcode            \nauthor     ronnie.salomonsen@mandiant.com \nscope      function                       \nmbc        Memory::Allocate Memory [C0007]\nfunction @ 0x489FF3\n  and:\n    match: allocate or change RWX memory @ 0x48A2B9\n      or:\n        basic block:\n          and:\n            or:\n              match: allocate memory @ 0x48A2B9\n                or:\n                  api: VirtualAlloc @ 0x48A2CD\n            or:\n              number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x48A2B9\n    or:\n      characteristic: indirect call @ 0x48A077, 0x48A0BA\n\ncreate shortcut via IShellLink (2 matches)\nnamespace   persistence                                                         \nauthor      matthew.williams@mandiant.com                                       \nscope       function                                                            \natt&ck      Persistence::Boot or Logon Autostart Execution::Shortcut            \n            Modification [T1547.009]                                            \nreferences  https://docs.microsoft.com/en-us/windows/win32/shell/links#creating…\nfunction @ 0x476178\n  and:\n    offset: 0x50 = psl->SetPath @ 0x47634C, 0x47640A, 0x476438\n    offset: 0x18 = ppf->Save @ 0x4761CC, 0x476204, 0x47629B, 0x4762A0, and 4 more...\n    api: CoCreateInstance @ 0x476308\n    bytes: 0114020000000000c000000000000046 = CLSID_ShellLink @ 0x476303\n    bytes: 0b01000000000000c000000000000046 = IID_IPersistFile @ 0x4764EF\n    or:\n      bytes: f914020000000000c000000000000046 = IID_IShellLinkW @ 0x4762FA\nfunction @ 0x476DE8\n  and:\n    offset: 0x50 = psl->SetPath @ 0x476E30, 0x47704C, 0x477098, 0x4770E4, and 2 more...\n    offset: 0x18 = ppf->Save @ 0x476F7E, 0x476FFE, 0x477035, 0x477081, and 9 more...\n    api: CoCreateInstance @ 0x476FAA\n    bytes: 0114020000000000c000000000000046 = CLSID_ShellLink @ 0x476FA5\n    bytes: 0b01000000000000c000000000000046 = IID_IPersistFile @ 0x476FC1\n    or:\n      bytes: f914020000000000c000000000000046 = IID_IShellLinkW @ 0x476F9E\n\n\n\n"},"hashes":{"md5":"0adb9b817f1df7807576c2d7068dd931","sha1":"4a1b94a9a5113106f40cd8ea724703734d15f118","sha256":"98e4f904f7de1644e519d09371b8afcbbf40ff3bd56d76ce4df48479a4ab884b"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 2046</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 116784</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"db8ce34cefcc83edd0e245844f3537\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"0adb9b817f1df7807576c2d7068dd931\",\n        \"sha256\": \"98e4f904f7de1644e519d09371b8afcbbf40ff3bd56d76ce4df4847\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_allocate_memory__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"allocate memory (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x46BC2A\",\n      \"label\": \"Block 0x46BC2A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46BC2A\"\n    },\n    {\n      \"id\": \"api_VirtualAllocEx\",\n      \"label\": \"VirtualAllocEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_library_rule_\",\n      \"label\": \"library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Modulo [C0058]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_loop__486_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (486 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401212\",\n      \"label\": \"Function 0x401212\",\n      \"type\": \"function\",\n      \"address\": \"0x401212\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__13_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (13 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40522E\",\n      \"label\": \"Block 0x40522E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40522E\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__37_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (37 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40F25F\",\n      \"label\": \"Block 0x40F25F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40F25F\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_open_process__7_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"open process (7 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Open Process [C0065]\"\n      ]\n    },\n    {\n      \"id\": \"api_OpenProcess\",\n      \"label\": \"OpenProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"label\": \"check for time delay via QueryPerformanceCounter (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"QueryPerformanceCounter [B0001.033]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46A51A\",\n      \"label\": \"Function 0x46A51A\",\n      \"type\": \"function\",\n      \"address\": \"0x46A51A\"\n    },\n    {\n      \"id\": \"func_0x46F1A7\",\n      \"label\": \"Function 0x46F1A7\",\n      \"type\": \"function\",\n      \"address\": \"0x46F1A7\"\n    },\n    {\n      \"id\": \"func_0x46A531\",\n      \"label\": \"Function 0x46A531\",\n      \"type\": \"function\",\n      \"address\": \"0x46A531\"\n    },\n    {\n      \"id\": \"func_0x46B984\",\n      \"label\": \"Function 0x46B984\",\n      \"type\": \"function\",\n      \"address\": \"0x46B984\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"QueryPerformanceCounter [B0001.033]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_for_unmoving_mouse_cursor__2_matches_\",\n      \"label\": \"check for unmoving mouse cursor (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection::Human User\",\n        \"Check [B0009.012]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x499ED5\",\n      \"label\": \"Function 0x499ED5\",\n      \"type\": \"function\",\n      \"address\": \"0x499ED5\"\n    },\n    {\n      \"id\": \"func_0x499928\",\n      \"label\": \"Function 0x499928\",\n      \"type\": \"function\",\n      \"address\": \"0x499928\"\n    },\n    {\n      \"id\": \"cap_author______bitsofbinary\",\n      \"label\": \"author      BitsOfBinary\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection::Human User\",\n        \"Check [B0009.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes__9_matches_\",\n      \"label\": \"log keystrokes (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46B2C9\",\n      \"label\": \"Function 0x46B2C9\",\n      \"type\": \"function\",\n      \"address\": \"0x46B2C9\"\n    },\n    {\n      \"id\": \"func_0x46BBBB\",\n      \"label\": \"Function 0x46BBBB\",\n      \"type\": \"function\",\n      \"address\": \"0x46BBBB\"\n    },\n    {\n      \"id\": \"func_0x46BA0B\",\n      \"label\": \"Function 0x46BA0B\",\n      \"type\": \"function\",\n      \"address\": \"0x46BA0B\"\n    },\n    {\n      \"id\": \"func_0x4642CC\",\n      \"label\": \"Function 0x4642CC\",\n      \"type\": \"function\",\n      \"address\": \"0x4642CC\"\n    },\n    {\n      \"id\": \"func_0x462E32\",\n      \"label\": \"Function 0x462E32\",\n      \"type\": \"function\",\n      \"address\": \"0x462E32\"\n    },\n    {\n      \"id\": \"func_0x463637\",\n      \"label\": \"Function 0x463637\",\n      \"type\": \"function\",\n      \"address\": \"0x463637\"\n    },\n    {\n      \"id\": \"func_0x403205\",\n      \"label\": \"Function 0x403205\",\n      \"type\": \"function\",\n      \"address\": \"0x403205\"\n    },\n    {\n      \"id\": \"func_0x46BB56\",\n      \"label\": \"Function 0x46BB56\",\n      \"type\": \"function\",\n      \"address\": \"0x46BB56\"\n    },\n    {\n      \"id\": \"func_0x41FC8A\",\n      \"label\": \"Function 0x41FC8A\",\n      \"type\": \"function\",\n      \"address\": \"0x41FC8A\"\n    },\n    {\n      \"id\": \"api_AttachThreadInput\",\n      \"label\": \"AttachThreadInput\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_MapVirtualKey\",\n      \"label\": \"MapVirtualKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"label\": \"log keystrokes via polling (11 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4019CD\",\n      \"label\": \"Function 0x4019CD\",\n      \"type\": \"function\",\n      \"address\": \"0x4019CD\"\n    },\n    {\n      \"id\": \"func_0x46B5B6\",\n      \"label\": \"Function 0x46B5B6\",\n      \"type\": \"function\",\n      \"address\": \"0x46B5B6\"\n    },\n    {\n      \"id\": \"func_0x46A86D\",\n      \"label\": \"Function 0x46A86D\",\n      \"type\": \"function\",\n      \"address\": \"0x46A86D\"\n    },\n    {\n      \"id\": \"func_0x46B333\",\n      \"label\": \"Function 0x46B333\",\n      \"type\": \"function\",\n      \"address\": \"0x46B333\"\n    },\n    {\n      \"id\": \"func_0x46A54A\",\n      \"label\": \"Function 0x46A54A\",\n      \"type\": \"function\",\n      \"address\": \"0x46A54A\"\n    },\n    {\n      \"id\": \"func_0x41A86C\",\n      \"label\": \"Function 0x41A86C\",\n      \"type\": \"function\",\n      \"address\": \"0x41A86C\"\n    },\n    {\n      \"id\": \"func_0x46B796\",\n      \"label\": \"Function 0x46B796\",\n      \"type\": \"function\",\n      \"address\": \"0x46B796\"\n    },\n    {\n      \"id\": \"func_0x46B478\",\n      \"label\": \"Function 0x46B478\",\n      \"type\": \"function\",\n      \"address\": \"0x46B478\"\n    },\n    {\n      \"id\": \"api_GetKeyState\",\n      \"label\": \"GetKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_VkKeyScan\",\n      \"label\": \"VkKeyScan\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetKeyboardState\",\n      \"label\": \"GetKeyboardState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetAsyncKeyState\",\n      \"label\": \"GetAsyncKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_capture_screenshot\",\n      \"label\": \"capture screenshot\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x482EB9\",\n      \"label\": \"Function 0x482EB9\",\n      \"type\": \"function\",\n      \"address\": \"0x482EB9\"\n    },\n    {\n      \"id\": \"api_GetDIBits\",\n      \"label\": \"GetDIBits\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateCompatibleBitmap\",\n      \"label\": \"CreateCompatibleBitmap\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetDC\",\n      \"label\": \"GetDC\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateCompatibleDC\",\n      \"label\": \"CreateCompatibleDC\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Screen Capture::WinAPI [E1113.m01]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_remote_server_for_available_data\",\n      \"label\": \"query remote server for available data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x47D877\",\n      \"label\": \"Block 0x47D877\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x47D877\"\n    },\n    {\n      \"id\": \"api_InternetQueryDataAvailable\",\n      \"label\": \"InternetQueryDataAvailable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_receive_data__4_matches_\",\n      \"label\": \"receive data (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x481D90\",\n      \"label\": \"Function 0x481D90\",\n      \"type\": \"function\",\n      \"address\": \"0x481D90\"\n    },\n    {\n      \"id\": \"func_0x4825BD\",\n      \"label\": \"Function 0x4825BD\",\n      \"type\": \"function\",\n      \"address\": \"0x4825BD\"\n    },\n    {\n      \"id\": \"func_0x47D877\",\n      \"label\": \"Function 0x47D877\",\n      \"type\": \"function\",\n      \"address\": \"0x47D877\"\n    },\n    {\n      \"id\": \"func_0x47D7A1\",\n      \"label\": \"Function 0x47D7A1\",\n      \"type\": \"function\",\n      \"address\": \"0x47D7A1\"\n    },\n    {\n      \"id\": \"api_InternetReadFile\",\n      \"label\": \"InternetReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_recv\",\n      \"label\": \"recv\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"api_recvfrom\",\n      \"label\": \"recvfrom\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data__3_matches_\",\n      \"label\": \"send data (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x48295A\",\n      \"label\": \"Function 0x48295A\",\n      \"type\": \"function\",\n      \"address\": \"0x48295A\"\n    },\n    {\n      \"id\": \"func_0x47CDD3\",\n      \"label\": \"Function 0x47CDD3\",\n      \"type\": \"function\",\n      \"address\": \"0x47CDD3\"\n    },\n    {\n      \"id\": \"func_0x481F27\",\n      \"label\": \"Function 0x481F27\",\n      \"type\": \"function\",\n      \"address\": \"0x481F27\"\n    },\n    {\n      \"id\": \"api_sendto\",\n      \"label\": \"sendto\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"api_InternetConnect\",\n      \"label\": \"InternetConnect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_HttpOpenRequest\",\n      \"label\": \"HttpOpenRequest\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_send\",\n      \"label\": \"send\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"api_HttpSendRequest\",\n      \"label\": \"HttpSendRequest\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_download_and_write_a_file\",\n      \"label\": \"download and write a file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"downloader\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Server to Client\",\n        \"File Transfer [B0030.003]\"\n      ]\n    },\n    {\n      \"id\": \"api__fwrite\",\n      \"label\": \"_fwrite\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_fwrite\",\n      \"label\": \"fwrite\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_maec_malware_category__downloader\",\n      \"label\": \"maec/malware-category  downloader\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"downloader\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Server to Client\",\n        \"File Transfer [B0030.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_and_write_data_from_server_to_client\",\n      \"label\": \"receive and write data from server to client\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_resolve_dns__3_matches_\",\n      \"label\": \"resolve DNS (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::DNS Communication::Resolve [C0011.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x481CBE\",\n      \"label\": \"Function 0x481CBE\",\n      \"type\": \"function\",\n      \"address\": \"0x481CBE\"\n    },\n    {\n      \"id\": \"func_0x480EB8\",\n      \"label\": \"Function 0x480EB8\",\n      \"type\": \"function\",\n      \"address\": \"0x480EB8\"\n    },\n    {\n      \"id\": \"func_0x46E653\",\n      \"label\": \"Function 0x46E653\",\n      \"type\": \"function\",\n      \"address\": \"0x46E653\"\n    },\n    {\n      \"id\": \"api_gethostbyname\",\n      \"label\": \"gethostbyname\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::DNS Communication::Resolve [C0011.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_network_resource\",\n      \"label\": \"connect network resource\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x460F6E\",\n      \"label\": \"Function 0x460F6E\",\n      \"type\": \"function\",\n      \"address\": \"0x460F6E\"\n    },\n    {\n      \"id\": \"api_WNetAddConnection2\",\n      \"label\": \"WNetAddConnection2\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"label\": \"author       michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_parse_url\",\n      \"label\": \"parse URL\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x47DA51\",\n      \"label\": \"Block 0x47DA51\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x47DA51\"\n    },\n    {\n      \"id\": \"api_InternetCrackUrl\",\n      \"label\": \"InternetCrackUrl\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_connect_to_http_server__2_matches_\",\n      \"label\": \"connect to HTTP server (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Connect to Server [C0002.009]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47CAA0\",\n      \"label\": \"Function 0x47CAA0\",\n      \"type\": \"function\",\n      \"address\": \"0x47CAA0\"\n    },\n    {\n      \"id\": \"cap_connect_to_url\",\n      \"label\": \"connect to URL\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Open URL [C0002.004]\"\n      ]\n    },\n    {\n      \"id\": \"api_InternetOpenUrl\",\n      \"label\": \"InternetOpenUrl\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_create_http_request\",\n      \"label\": \"create HTTP request\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47D67B\",\n      \"label\": \"Function 0x47D67B\",\n      \"type\": \"function\",\n      \"address\": \"0x47D67B\"\n    },\n    {\n      \"id\": \"api_InternetOpen\",\n      \"label\": \"InternetOpen\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Create Request [C0002.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_data_from_internet__2_matches_\",\n      \"label\": \"read data from Internet (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Get Response [C0002.017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_http_request\",\n      \"label\": \"send HTTP request\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Send Request [C0002.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication::Send Request [C0002.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_icmp_echo_request\",\n      \"label\": \"send ICMP echo request\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::ICMP Communication::Echo Request [C0014.002]\"\n      ]\n    },\n    {\n      \"id\": \"api_IcmpSendEcho\",\n      \"label\": \"IcmpSendEcho\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_IcmpCloseHandle\",\n      \"label\": \"IcmpCloseHandle\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_IcmpCreateFile\",\n      \"label\": \"IcmpCreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::ICMP Communication::Echo Request [C0014.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_pipe__2_matches_\",\n      \"label\": \"create pipe (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Interprocess Communication::Create Pipe [C0003.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x470D8E\",\n      \"label\": \"Function 0x470D8E\",\n      \"type\": \"function\",\n      \"address\": \"0x470D8E\"\n    },\n    {\n      \"id\": \"func_0x470E63\",\n      \"label\": \"Function 0x470E63\",\n      \"type\": \"function\",\n      \"address\": \"0x470E63\"\n    },\n    {\n      \"id\": \"api_CreatePipe\",\n      \"label\": \"CreatePipe\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_connect_socket\",\n      \"label\": \"connect socket\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x481AE5\",\n      \"label\": \"Block 0x481AE5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x481AE5\"\n    },\n    {\n      \"id\": \"api_connect\",\n      \"label\": \"connect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_mrhafizfarhad_gmail_com\",\n      \"label\": \"mrhafizfarhad@gmail.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_socket_status\",\n      \"label\": \"get socket status\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Get Socket Status [C0001.012]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x483AA6\",\n      \"label\": \"Function 0x483AA6\",\n      \"type\": \"function\",\n      \"address\": \"0x483AA6\"\n    },\n    {\n      \"id\": \"api_select\",\n      \"label\": \"select\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_initialize_winsock_library__3_matches_\",\n      \"label\": \"initialize Winsock library (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Initialize Winsock Library\",\n        \"[C0001.009]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x482010\",\n      \"label\": \"Function 0x482010\",\n      \"type\": \"function\",\n      \"address\": \"0x482010\"\n    },\n    {\n      \"id\": \"api_WSAStartup\",\n      \"label\": \"WSAStartup\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_socket_configuration__3_matches_\",\n      \"label\": \"set socket configuration (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Set Socket Config [C0001.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4839AB\",\n      \"label\": \"Function 0x4839AB\",\n      \"type\": \"function\",\n      \"address\": \"0x4839AB\"\n    },\n    {\n      \"id\": \"func_0x482433\",\n      \"label\": \"Function 0x482433\",\n      \"type\": \"function\",\n      \"address\": \"0x482433\"\n    },\n    {\n      \"id\": \"api_setsockopt\",\n      \"label\": \"setsockopt\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_ioctlsocket\",\n      \"label\": \"ioctlsocket\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_receive_data_on_socket__2_matches_\",\n      \"label\": \"receive data on socket (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Receive Data [C0001.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data_on_socket__2_matches_\",\n      \"label\": \"send data on socket (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_tcp_socket\",\n      \"label\": \"connect TCP socket\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Connect Socket [C0001.004]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x481A15\",\n      \"label\": \"Function 0x481A15\",\n      \"type\": \"function\",\n      \"address\": \"0x481A15\"\n    },\n    {\n      \"id\": \"api_socket\",\n      \"label\": \"socket\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_tcp_socket__2_matches_\",\n      \"label\": \"create TCP socket (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x481A69\",\n      \"label\": \"Block 0x481A69\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x481A69\"\n    },\n    {\n      \"id\": \"bb_0x481BCD\",\n      \"label\": \"Block 0x481BCD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x481BCD\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create TCP Socket [C0001.011]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_udp_socket__2_matches_\",\n      \"label\": \"create UDP socket (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create UDP Socket [C0001.010]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4821B4\",\n      \"label\": \"Block 0x4821B4\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4821B4\"\n    },\n    {\n      \"id\": \"bb_0x482433\",\n      \"label\": \"Block 0x482433\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x482433\"\n    },\n    {\n      \"id\": \"cap_act_as_tcp_client\",\n      \"label\": \"act as TCP client\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::TCP Client [C0001.008]\"\n      ]\n    },\n    {\n      \"id\": \"cap_compiled_with_autoit\",\n      \"label\": \"compiled with AutoIt\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [T1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [T1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_with_crc32\",\n      \"label\": \"hash data with CRC32\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x482E1E\",\n      \"label\": \"Function 0x482E1E\",\n      \"type\": \"function\",\n      \"address\": \"0x482E1E\"\n    },\n    {\n      \"id\": \"cap_encode_data_using_base64\",\n      \"label\": \"encode data using Base64\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x41CBB6\",\n      \"label\": \"Function 0x41CBB6\",\n      \"type\": \"function\",\n      \"address\": \"0x41CBB6\"\n    },\n    {\n      \"id\": \"cap_hash_data_using_djb2\",\n      \"label\": \"hash data using djb2\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::djb2 [C0030.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40829C\",\n      \"label\": \"Function 0x40829C\",\n      \"type\": \"function\",\n      \"address\": \"0x40829C\"\n    },\n    {\n      \"id\": \"cap_author______awillia2_cisco_com__still_teamt5_org\",\n      \"label\": \"author      awillia2@cisco.com, still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Non-Cryptographic Hash::djb2 [C0030.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_authenticate_hmac\",\n      \"label\": \"authenticate HMAC\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Hashed Message Authentication Code [C0061]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Hashed Message Authentication Code [C0061]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"label\": \"generate random numbers using a Mersenne Twister (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence [C0021]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4728DA\",\n      \"label\": \"Function 0x4728DA\",\n      \"type\": \"function\",\n      \"address\": \"0x4728DA\"\n    },\n    {\n      \"id\": \"func_0x472830\",\n      \"label\": \"Function 0x472830\",\n      \"type\": \"function\",\n      \"address\": \"0x472830\"\n    },\n    {\n      \"id\": \"func_0x47291A\",\n      \"label\": \"Function 0x47291A\",\n      \"type\": \"function\",\n      \"address\": \"0x47291A\"\n    },\n    {\n      \"id\": \"func_0x472876\",\n      \"label\": \"Function 0x472876\",\n      \"type\": \"function\",\n      \"address\": \"0x472876\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x473923\",\n      \"label\": \"Function 0x473923\",\n      \"type\": \"function\",\n      \"address\": \"0x473923\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResourceEx\",\n      \"label\": \"FindResourceEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_list_drag_and_drop_files\",\n      \"label\": \"list drag and drop files\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47F45C\",\n      \"label\": \"Function 0x47F45C\",\n      \"type\": \"function\",\n      \"address\": \"0x47F45C\"\n    },\n    {\n      \"id\": \"api_DragQueryFile\",\n      \"label\": \"DragQueryFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetClipboardData\",\n      \"label\": \"GetClipboardData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_open_clipboard__2_matches_\",\n      \"label\": \"open clipboard (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47F6C7\",\n      \"label\": \"Function 0x47F6C7\",\n      \"type\": \"function\",\n      \"address\": \"0x47F6C7\"\n    },\n    {\n      \"id\": \"api_CloseClipboard\",\n      \"label\": \"CloseClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_OpenClipboard\",\n      \"label\": \"OpenClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_clipboard_data\",\n      \"label\": \"read clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"api_GlobalLock\",\n      \"label\": \"GlobalLock\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GlobalUnlock\",\n      \"label\": \"GlobalUnlock\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_clipboard_data\",\n      \"label\": \"write clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"api_EmptyClipboard\",\n      \"label\": \"EmptyClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SetClipboardData\",\n      \"label\": \"SetClipboardData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_interact_with_driver_via_ioctl__4_matches_\",\n      \"label\": \"interact with driver via IOCTL (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_DeviceIoControl\",\n      \"label\": \"DeviceIoControl\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_comspec_environment_variable\",\n      \"label\": \"get COMSPEC environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable [C0034]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x41E3B3\",\n      \"label\": \"Function 0x41E3B3\",\n      \"type\": \"function\",\n      \"address\": \"0x41E3B3\"\n    },\n    {\n      \"id\": \"api_GetEnvironmentVariable\",\n      \"label\": \"GetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"label\": \"author     matthew.williams@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable [C0034]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable__3_matches_\",\n      \"label\": \"query environment variable (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x487F8F\",\n      \"label\": \"Function 0x487F8F\",\n      \"type\": \"function\",\n      \"address\": \"0x487F8F\"\n    },\n    {\n      \"id\": \"func_0x47F84A\",\n      \"label\": \"Function 0x47F84A\",\n      \"type\": \"function\",\n      \"address\": \"0x47F84A\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_environment_variable__2_matches_\",\n      \"label\": \"set environment variable (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable::Set Variable [C0034.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47F8BA\",\n      \"label\": \"Function 0x47F8BA\",\n      \"type\": \"function\",\n      \"address\": \"0x47F8BA\"\n    },\n    {\n      \"id\": \"func_0x43D570\",\n      \"label\": \"Function 0x43D570\",\n      \"type\": \"function\",\n      \"address\": \"0x43D570\"\n    },\n    {\n      \"id\": \"api_SetEnvironmentVariable\",\n      \"label\": \"SetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__9_matches_\",\n      \"label\": \"get common file path (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x403A70\",\n      \"label\": \"Function 0x403A70\",\n      \"type\": \"function\",\n      \"address\": \"0x403A70\"\n    },\n    {\n      \"id\": \"func_0x478AEF\",\n      \"label\": \"Function 0x478AEF\",\n      \"type\": \"function\",\n      \"address\": \"0x478AEF\"\n    },\n    {\n      \"id\": \"func_0x46E753\",\n      \"label\": \"Function 0x46E753\",\n      \"type\": \"function\",\n      \"address\": \"0x46E753\"\n    },\n    {\n      \"id\": \"func_0x403312\",\n      \"label\": \"Function 0x403312\",\n      \"type\": \"function\",\n      \"address\": \"0x403312\"\n    },\n    {\n      \"id\": \"func_0x48B958\",\n      \"label\": \"Function 0x48B958\",\n      \"type\": \"function\",\n      \"address\": \"0x48B958\"\n    },\n    {\n      \"id\": \"func_0x4738ED\",\n      \"label\": \"Function 0x4738ED\",\n      \"type\": \"function\",\n      \"address\": \"0x4738ED\"\n    },\n    {\n      \"id\": \"func_0x4783F0\",\n      \"label\": \"Function 0x4783F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4783F0\"\n    },\n    {\n      \"id\": \"func_0x47874A\",\n      \"label\": \"Function 0x47874A\",\n      \"type\": \"function\",\n      \"address\": \"0x47874A\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHGetFolderPath\",\n      \"label\": \"SHGetFolderPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetCurrentDirectory\",\n      \"label\": \"GetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempFileName\",\n      \"label\": \"GetTempFileName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHGetSpecialFolderLocation\",\n      \"label\": \"SHGetSpecialFolderLocation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_current_directory__7_matches_\",\n      \"label\": \"set current directory (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x479F9F\",\n      \"label\": \"Function 0x479F9F\",\n      \"type\": \"function\",\n      \"address\": \"0x479F9F\"\n    },\n    {\n      \"id\": \"func_0x403AA3\",\n      \"label\": \"Function 0x403AA3\",\n      \"type\": \"function\",\n      \"address\": \"0x403AA3\"\n    },\n    {\n      \"id\": \"func_0x47A0FA\",\n      \"label\": \"Function 0x47A0FA\",\n      \"type\": \"function\",\n      \"address\": \"0x47A0FA\"\n    },\n    {\n      \"id\": \"func_0x475E10\",\n      \"label\": \"Function 0x475E10\",\n      \"type\": \"function\",\n      \"address\": \"0x475E10\"\n    },\n    {\n      \"id\": \"api_SetCurrentDirectory\",\n      \"label\": \"SetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_copy_file__3_matches_\",\n      \"label\": \"copy file (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46D6C0\",\n      \"label\": \"Function 0x46D6C0\",\n      \"type\": \"function\",\n      \"address\": \"0x46D6C0\"\n    },\n    {\n      \"id\": \"func_0x47321B\",\n      \"label\": \"Function 0x47321B\",\n      \"type\": \"function\",\n      \"address\": \"0x47321B\"\n    },\n    {\n      \"id\": \"func_0x46DA5C\",\n      \"label\": \"Function 0x46DA5C\",\n      \"type\": \"function\",\n      \"address\": \"0x46DA5C\"\n    },\n    {\n      \"id\": \"api_CopyFileEx\",\n      \"label\": \"CopyFileEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CopyFile\",\n      \"label\": \"CopyFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHFileOperation\",\n      \"label\": \"SHFileOperation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_directory__2_matches_\",\n      \"label\": \"create directory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x474678\",\n      \"label\": \"Function 0x474678\",\n      \"type\": \"function\",\n      \"address\": \"0x474678\"\n    },\n    {\n      \"id\": \"func_0x46DA81\",\n      \"label\": \"Function 0x46DA81\",\n      \"type\": \"function\",\n      \"address\": \"0x46DA81\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_delete_directory__2_matches_\",\n      \"label\": \"delete directory (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46F089\",\n      \"label\": \"Function 0x46F089\",\n      \"type\": \"function\",\n      \"address\": \"0x46F089\"\n    },\n    {\n      \"id\": \"api_RemoveDirectory\",\n      \"label\": \"RemoveDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_file__6_matches_\",\n      \"label\": \"delete file (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4782F6\",\n      \"label\": \"Function 0x4782F6\",\n      \"type\": \"function\",\n      \"address\": \"0x4782F6\"\n    },\n    {\n      \"id\": \"func_0x476033\",\n      \"label\": \"Function 0x476033\",\n      \"type\": \"function\",\n      \"address\": \"0x476033\"\n    },\n    {\n      \"id\": \"func_0x46D836\",\n      \"label\": \"Function 0x46D836\",\n      \"type\": \"function\",\n      \"address\": \"0x46D836\"\n    },\n    {\n      \"id\": \"func_0x46DB69\",\n      \"label\": \"Function 0x46DB69\",\n      \"type\": \"function\",\n      \"address\": \"0x46DB69\"\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__3_matches_\",\n      \"label\": \"check if file exists (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46E387\",\n      \"label\": \"Function 0x46E387\",\n      \"type\": \"function\",\n      \"address\": \"0x46E387\"\n    },\n    {\n      \"id\": \"func_0x46E9C5\",\n      \"label\": \"Function 0x46E9C5\",\n      \"type\": \"function\",\n      \"address\": \"0x46E9C5\"\n    },\n    {\n      \"id\": \"api_GetLastError\",\n      \"label\": \"GetLastError\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"label\": \"enumerate files on Windows (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4765F1\",\n      \"label\": \"Function 0x4765F1\",\n      \"type\": \"function\",\n      \"address\": \"0x4765F1\"\n    },\n    {\n      \"id\": \"func_0x47A488\",\n      \"label\": \"Function 0x47A488\",\n      \"type\": \"function\",\n      \"address\": \"0x47A488\"\n    },\n    {\n      \"id\": \"api_FindFirstFile\",\n      \"label\": \"FindFirstFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindClose\",\n      \"label\": \"FindClose\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindNextFile\",\n      \"label\": \"FindNextFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_recursively__3_matches_\",\n      \"label\": \"enumerate files recursively (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     @_re_fox, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes__5_matches_\",\n      \"label\": \"get file attributes (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x478940\",\n      \"label\": \"Block 0x478940\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x478940\"\n    },\n    {\n      \"id\": \"bb_0x46E9C5\",\n      \"label\": \"Block 0x46E9C5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46E9C5\"\n    },\n    {\n      \"id\": \"bb_0x479FF7\",\n      \"label\": \"Block 0x479FF7\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x479FF7\"\n    },\n    {\n      \"id\": \"bb_0x46E3A5\",\n      \"label\": \"Block 0x46E3A5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46E3A5\"\n    },\n    {\n      \"id\": \"bb_0x46DA81\",\n      \"label\": \"Block 0x46DA81\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46DA81\"\n    },\n    {\n      \"id\": \"cap_get_file_size__2_matches_\",\n      \"label\": \"get file size (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x48343B\",\n      \"label\": \"Function 0x48343B\",\n      \"type\": \"function\",\n      \"address\": \"0x48343B\"\n    },\n    {\n      \"id\": \"func_0x498ECE\",\n      \"label\": \"Function 0x498ECE\",\n      \"type\": \"function\",\n      \"address\": \"0x498ECE\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_file_version_info\",\n      \"label\": \"get file version info\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46E3D7\",\n      \"label\": \"Function 0x46E3D7\",\n      \"type\": \"function\",\n      \"address\": \"0x46E3D7\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfo\",\n      \"label\": \"GetFileVersionInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_VerQueryValue\",\n      \"label\": \"VerQueryValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileVersionInfoSize\",\n      \"label\": \"GetFileVersionInfoSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_file_attributes__2_matches_\",\n      \"label\": \"set file attributes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"api_SetFileAttributes\",\n      \"label\": \"SetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_move_file__3_matches_\",\n      \"label\": \"move file (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46EC27\",\n      \"label\": \"Function 0x46EC27\",\n      \"type\": \"function\",\n      \"address\": \"0x46EC27\"\n    },\n    {\n      \"id\": \"api_MoveFile\",\n      \"label\": \"MoveFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read__ini_file__4_matches_\",\n      \"label\": \"read .ini file (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x478E39\",\n      \"label\": \"Function 0x478E39\",\n      \"type\": \"function\",\n      \"address\": \"0x478E39\"\n    },\n    {\n      \"id\": \"func_0x479238\",\n      \"label\": \"Function 0x479238\",\n      \"type\": \"function\",\n      \"address\": \"0x479238\"\n    },\n    {\n      \"id\": \"func_0x479455\",\n      \"label\": \"Function 0x479455\",\n      \"type\": \"function\",\n      \"address\": \"0x479455\"\n    },\n    {\n      \"id\": \"func_0x478EFB\",\n      \"label\": \"Function 0x478EFB\",\n      \"type\": \"function\",\n      \"address\": \"0x478EFB\"\n    },\n    {\n      \"id\": \"api_GetPrivateProfileString\",\n      \"label\": \"GetPrivateProfileString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetPrivateProfileSectionNames\",\n      \"label\": \"GetPrivateProfileSectionNames\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetPrivateProfileSection\",\n      \"label\": \"GetPrivateProfileSection\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     @_re_fox, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__9_matches_\",\n      \"label\": \"read file on Windows (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x43960B\",\n      \"label\": \"Function 0x43960B\",\n      \"type\": \"function\",\n      \"address\": \"0x43960B\"\n    },\n    {\n      \"id\": \"func_0x40653A\",\n      \"label\": \"Function 0x40653A\",\n      \"type\": \"function\",\n      \"address\": \"0x40653A\"\n    },\n    {\n      \"id\": \"func_0x472F67\",\n      \"label\": \"Function 0x472F67\",\n      \"type\": \"function\",\n      \"address\": \"0x472F67\"\n    },\n    {\n      \"id\": \"func_0x40B050\",\n      \"label\": \"Function 0x40B050\",\n      \"type\": \"function\",\n      \"address\": \"0x40B050\"\n    },\n    {\n      \"id\": \"func_0x40AED0\",\n      \"label\": \"Function 0x40AED0\",\n      \"type\": \"function\",\n      \"address\": \"0x40AED0\"\n    },\n    {\n      \"id\": \"func_0x472E2B\",\n      \"label\": \"Function 0x472E2B\",\n      \"type\": \"function\",\n      \"address\": \"0x472E2B\"\n    },\n    {\n      \"id\": \"func_0x4710AB\",\n      \"label\": \"Function 0x4710AB\",\n      \"type\": \"function\",\n      \"address\": \"0x4710AB\"\n    },\n    {\n      \"id\": \"api_fread\",\n      \"label\": \"fread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api__read\",\n      \"label\": \"_read\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"cap_clear_file_content\",\n      \"label\": \"clear file content\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x478A11\",\n      \"label\": \"Function 0x478A11\",\n      \"type\": \"function\",\n      \"address\": \"0x478A11\"\n    },\n    {\n      \"id\": \"api_SetEndOfFile\",\n      \"label\": \"SetEndOfFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SetFilePointer\",\n      \"label\": \"SetFilePointer\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____jakeperalta7\",\n      \"label\": \"author     jakeperalta7\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__7_matches_\",\n      \"label\": \"write file on Windows (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x472FAB\",\n      \"label\": \"Function 0x472FAB\",\n      \"type\": \"function\",\n      \"address\": \"0x472FAB\"\n    },\n    {\n      \"id\": \"func_0x472FF8\",\n      \"label\": \"Function 0x472FF8\",\n      \"type\": \"function\",\n      \"address\": \"0x472FF8\"\n    },\n    {\n      \"id\": \"func_0x46D4BF\",\n      \"label\": \"Function 0x46D4BF\",\n      \"type\": \"function\",\n      \"address\": \"0x46D4BF\"\n    },\n    {\n      \"id\": \"func_0x41C08E\",\n      \"label\": \"Function 0x41C08E\",\n      \"type\": \"function\",\n      \"address\": \"0x41C08E\"\n    },\n    {\n      \"id\": \"func_0x470FD1\",\n      \"label\": \"Function 0x470FD1\",\n      \"type\": \"function\",\n      \"address\": \"0x470FD1\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_gui_resources\",\n      \"label\": \"enumerate gui resources\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x464A8B\",\n      \"label\": \"Function 0x464A8B\",\n      \"type\": \"function\",\n      \"address\": \"0x464A8B\"\n    },\n    {\n      \"id\": \"api_EnumWindows\",\n      \"label\": \"EnumWindows\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     johnk3r, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_find_taskbar__3_matches_\",\n      \"label\": \"find taskbar (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Taskbar Discovery [B0043]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x45FC52\",\n      \"label\": \"Block 0x45FC52\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x45FC52\"\n    },\n    {\n      \"id\": \"bb_0x492CB5\",\n      \"label\": \"Block 0x492CB5\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x492CB5\"\n    },\n    {\n      \"id\": \"bb_0x492C81\",\n      \"label\": \"Block 0x492C81\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x492C81\"\n    },\n    {\n      \"id\": \"api_FindWindow\",\n      \"label\": \"FindWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_find_graphical_window__4_matches_\",\n      \"label\": \"find graphical window (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindWindowEx\",\n      \"label\": \"FindWindowEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_graphical_window_text__11_matches_\",\n      \"label\": \"get graphical window text (11 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x497D47\",\n      \"label\": \"Function 0x497D47\",\n      \"type\": \"function\",\n      \"address\": \"0x497D47\"\n    },\n    {\n      \"id\": \"func_0x4664D3\",\n      \"label\": \"Function 0x4664D3\",\n      \"type\": \"function\",\n      \"address\": \"0x4664D3\"\n    },\n    {\n      \"id\": \"func_0x464453\",\n      \"label\": \"Function 0x464453\",\n      \"type\": \"function\",\n      \"address\": \"0x464453\"\n    },\n    {\n      \"id\": \"func_0x4651E3\",\n      \"label\": \"Function 0x4651E3\",\n      \"type\": \"function\",\n      \"address\": \"0x4651E3\"\n    },\n    {\n      \"id\": \"func_0x492839\",\n      \"label\": \"Function 0x492839\",\n      \"type\": \"function\",\n      \"address\": \"0x492839\"\n    },\n    {\n      \"id\": \"func_0x4951D2\",\n      \"label\": \"Function 0x4951D2\",\n      \"type\": \"function\",\n      \"address\": \"0x4951D2\"\n    },\n    {\n      \"id\": \"func_0x47F32D\",\n      \"label\": \"Function 0x47F32D\",\n      \"type\": \"function\",\n      \"address\": \"0x47F32D\"\n    },\n    {\n      \"id\": \"func_0x46550C\",\n      \"label\": \"Function 0x46550C\",\n      \"type\": \"function\",\n      \"address\": \"0x46550C\"\n    },\n    {\n      \"id\": \"func_0x4623BC\",\n      \"label\": \"Function 0x4623BC\",\n      \"type\": \"function\",\n      \"address\": \"0x4623BC\"\n    },\n    {\n      \"id\": \"func_0x497A34\",\n      \"label\": \"Function 0x497A34\",\n      \"type\": \"function\",\n      \"address\": \"0x497A34\"\n    },\n    {\n      \"id\": \"func_0x463EEA\",\n      \"label\": \"Function 0x463EEA\",\n      \"type\": \"function\",\n      \"address\": \"0x463EEA\"\n    },\n    {\n      \"id\": \"api_SendMessage\",\n      \"label\": \"SendMessage\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_IsWindowVisible\",\n      \"label\": \"IsWindowVisible\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetWindowText\",\n      \"label\": \"GetWindowText\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_hide_graphical_window__8_matches_\",\n      \"label\": \"hide graphical window (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x49ABDD\",\n      \"label\": \"Block 0x49ABDD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x49ABDD\"\n    },\n    {\n      \"id\": \"bb_0x490B89\",\n      \"label\": \"Block 0x490B89\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x490B89\"\n    },\n    {\n      \"id\": \"bb_0x495B1C\",\n      \"label\": \"Block 0x495B1C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x495B1C\"\n    },\n    {\n      \"id\": \"bb_0x45FBC0\",\n      \"label\": \"Block 0x45FBC0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x45FBC0\"\n    },\n    {\n      \"id\": \"bb_0x498BA7\",\n      \"label\": \"Block 0x498BA7\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x498BA7\"\n    },\n    {\n      \"id\": \"bb_0x4975F2\",\n      \"label\": \"Block 0x4975F2\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4975F2\"\n    },\n    {\n      \"id\": \"bb_0x4831F8\",\n      \"label\": \"Block 0x4831F8\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4831F8\"\n    },\n    {\n      \"id\": \"bb_0x498C2C\",\n      \"label\": \"Block 0x498C2C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x498C2C\"\n    },\n    {\n      \"id\": \"api_ShowWindow\",\n      \"label\": \"ShowWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_keyboard_layout\",\n      \"label\": \"get keyboard layout\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery::System Language Discovery\",\n        \"[T1614.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetKeyboardLayoutName\",\n      \"label\": \"GetKeyboardLayoutName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_memory_capacity\",\n      \"label\": \"get memory capacity\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x41F6D8\",\n      \"label\": \"Function 0x41F6D8\",\n      \"type\": \"function\",\n      \"address\": \"0x41F6D8\"\n    },\n    {\n      \"id\": \"api_GlobalMemoryStatusEx\",\n      \"label\": \"GlobalMemoryStatusEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_information__6_matches_\",\n      \"label\": \"get disk information (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x47534E\",\n      \"label\": \"Function 0x47534E\",\n      \"type\": \"function\",\n      \"address\": \"0x47534E\"\n    },\n    {\n      \"id\": \"func_0x4747D3\",\n      \"label\": \"Function 0x4747D3\",\n      \"type\": \"function\",\n      \"address\": \"0x4747D3\"\n    },\n    {\n      \"id\": \"func_0x475280\",\n      \"label\": \"Function 0x475280\",\n      \"type\": \"function\",\n      \"address\": \"0x475280\"\n    },\n    {\n      \"id\": \"func_0x475439\",\n      \"label\": \"Function 0x475439\",\n      \"type\": \"function\",\n      \"address\": \"0x475439\"\n    },\n    {\n      \"id\": \"func_0x474E1A\",\n      \"label\": \"Function 0x474E1A\",\n      \"type\": \"function\",\n      \"address\": \"0x474E1A\"\n    },\n    {\n      \"id\": \"func_0x4751B2\",\n      \"label\": \"Function 0x4751B2\",\n      \"type\": \"function\",\n      \"address\": \"0x4751B2\"\n    },\n    {\n      \"id\": \"api_GetVolumeInformation\",\n      \"label\": \"GetVolumeInformation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetDriveType\",\n      \"label\": \"GetDriveType\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_size__3_matches_\",\n      \"label\": \"get disk size (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x475CED\",\n      \"label\": \"Function 0x475CED\",\n      \"type\": \"function\",\n      \"address\": \"0x475CED\"\n    },\n    {\n      \"id\": \"func_0x475B27\",\n      \"label\": \"Function 0x475B27\",\n      \"type\": \"function\",\n      \"address\": \"0x475B27\"\n    },\n    {\n      \"id\": \"func_0x475C0A\",\n      \"label\": \"Function 0x475C0A\",\n      \"type\": \"function\",\n      \"address\": \"0x475C0A\"\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpace\",\n      \"label\": \"GetDiskFreeSpace\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpaceEx\",\n      \"label\": \"GetDiskFreeSpaceEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_storage_device_properties__2_matches_\",\n      \"label\": \"get storage device properties (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x46DDAB\",\n      \"label\": \"Function 0x46DDAB\",\n      \"type\": \"function\",\n      \"address\": \"0x46DDAB\"\n    },\n    {\n      \"id\": \"func_0x46DE2A\",\n      \"label\": \"Function 0x46DE2A\",\n      \"type\": \"function\",\n      \"address\": \"0x46DE2A\"\n    },\n    {\n      \"id\": \"cap_print_debug_messages\",\n      \"label\": \"print debug messages\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_OutputDebugString\",\n      \"label\": \"OutputDebugString\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_shutdown_system\",\n      \"label\": \"shutdown system\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::System Shutdown/Reboot [T1529]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46F122\",\n      \"label\": \"Function 0x46F122\",\n      \"type\": \"function\",\n      \"address\": \"0x46F122\"\n    },\n    {\n      \"id\": \"api_InitiateSystemShutdownEx\",\n      \"label\": \"InitiateSystemShutdownEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_ExitWindowsEx\",\n      \"label\": \"ExitWindowsEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_hostname__2_matches_\",\n      \"label\": \"get hostname (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_gethostname\",\n      \"label\": \"gethostname\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetComputerName\",\n      \"label\": \"GetComputerName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_system_information_on_windows\",\n      \"label\": \"get system information on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405D78\",\n      \"label\": \"Function 0x405D78\",\n      \"type\": \"function\",\n      \"address\": \"0x405D78\"\n    },\n    {\n      \"id\": \"api_GetSystemInfo\",\n      \"label\": \"GetSystemInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__6_matches_\",\n      \"label\": \"create process on Windows (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x461DBE\",\n      \"label\": \"Block 0x461DBE\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x461DBE\"\n    },\n    {\n      \"id\": \"bb_0x498AD1\",\n      \"label\": \"Block 0x498AD1\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x498AD1\"\n    },\n    {\n      \"id\": \"bb_0x48B7B2\",\n      \"label\": \"Block 0x48B7B2\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x48B7B2\"\n    },\n    {\n      \"id\": \"bb_0x48BCF9\",\n      \"label\": \"Block 0x48BCF9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x48BCF9\"\n    },\n    {\n      \"id\": \"bb_0x443D42\",\n      \"label\": \"Block 0x443D42\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x443D42\"\n    },\n    {\n      \"id\": \"bb_0x461C96\",\n      \"label\": \"Block 0x461C96\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x461C96\"\n    },\n    {\n      \"id\": \"api_CreateProcessAsUser\",\n      \"label\": \"CreateProcessAsUser\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_ShellExecute\",\n      \"label\": \"ShellExecute\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_CreateProcessWithLogon\",\n      \"label\": \"CreateProcessWithLogon\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_ShellExecuteEx\",\n      \"label\": \"ShellExecuteEx\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_allocate_or_change_rwx_memory\",\n      \"label\": \"allocate or change RWX memory\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x48A2B9\",\n      \"label\": \"Block 0x48A2B9\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x48A2B9\"\n    },\n    {\n      \"id\": \"api_VirtualAlloc\",\n      \"label\": \"VirtualAlloc\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"label\": \"author     @mr-tz, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_processes__2_matches_\",\n      \"label\": \"enumerate processes (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Process Discovery [T1057]\",\n        \"Discovery::Software Discovery\",\n        \"[T1518]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46DC9C\",\n      \"label\": \"Function 0x46DC9C\",\n      \"type\": \"function\",\n      \"address\": \"0x46DC9C\"\n    },\n    {\n      \"id\": \"func_0x48AFDB\",\n      \"label\": \"Function 0x48AFDB\",\n      \"type\": \"function\",\n      \"address\": \"0x48AFDB\"\n    },\n    {\n      \"id\": \"api_CreateToolhelp32Snapshot\",\n      \"label\": \"CreateToolhelp32Snapshot\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_Process32First\",\n      \"label\": \"Process32First\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_Process32Next\",\n      \"label\": \"Process32Next\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_acquire_debug_privileges\",\n      \"label\": \"acquire debug privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x48AAEE\",\n      \"label\": \"Block 0x48AAEE\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x48AAEE\"\n    },\n    {\n      \"id\": \"cap_modify_access_privileges__2_matches_\",\n      \"label\": \"modify access privileges (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation [T1134]\"\n      ]\n    },\n    {\n      \"id\": \"api_AdjustTokenPrivileges\",\n      \"label\": \"AdjustTokenPrivileges\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_terminate_process__3_matches_\",\n      \"label\": \"terminate process (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x46F34C\",\n      \"label\": \"Function 0x46F34C\",\n      \"type\": \"function\",\n      \"address\": \"0x46F34C\"\n    },\n    {\n      \"id\": \"func_0x48AA41\",\n      \"label\": \"Function 0x48AA41\",\n      \"type\": \"function\",\n      \"address\": \"0x48AA41\"\n    },\n    {\n      \"id\": \"func_0x4888B6\",\n      \"label\": \"Function 0x4888B6\",\n      \"type\": \"function\",\n      \"address\": \"0x4888B6\"\n    },\n    {\n      \"id\": \"api_TerminateProcess\",\n      \"label\": \"TerminateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_empty_the_recycle_bin\",\n      \"label\": \"empty the recycle bin\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x47838F\",\n      \"label\": \"Function 0x47838F\",\n      \"type\": \"function\",\n      \"address\": \"0x47838F\"\n    },\n    {\n      \"id\": \"api_SHEmptyRecycleBin\",\n      \"label\": \"SHEmptyRecycleBin\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"label\": \"query or enumerate registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x48C328\",\n      \"label\": \"Function 0x48C328\",\n      \"type\": \"function\",\n      \"address\": \"0x48C328\"\n    },\n    {\n      \"id\": \"func_0x48D593\",\n      \"label\": \"Function 0x48D593\",\n      \"type\": \"function\",\n      \"address\": \"0x48D593\"\n    },\n    {\n      \"id\": \"api_RegEnumKeyEx\",\n      \"label\": \"RegEnumKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"label\": \"query or enumerate registry value (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x48C53A\",\n      \"label\": \"Function 0x48C53A\",\n      \"type\": \"function\",\n      \"address\": \"0x48C53A\"\n    },\n    {\n      \"id\": \"func_0x48C7A3\",\n      \"label\": \"Function 0x48C7A3\",\n      \"type\": \"function\",\n      \"address\": \"0x48C7A3\"\n    },\n    {\n      \"id\": \"func_0x40522E\",\n      \"label\": \"Function 0x40522E\",\n      \"type\": \"function\",\n      \"address\": \"0x40522E\"\n    },\n    {\n      \"id\": \"func_0x4055F8\",\n      \"label\": \"Function 0x4055F8\",\n      \"type\": \"function\",\n      \"address\": \"0x4055F8\"\n    },\n    {\n      \"id\": \"api_RegEnumValue\",\n      \"label\": \"RegEnumValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value\",\n      \"label\": \"set registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x48CD16\",\n      \"label\": \"Function 0x48CD16\",\n      \"type\": \"function\",\n      \"address\": \"0x48CD16\"\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"api_RegCreateKeyEx\",\n      \"label\": \"RegCreateKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delete_registry_key__2_matches_\",\n      \"label\": \"delete registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x48BF6D\",\n      \"label\": \"Function 0x48BF6D\",\n      \"type\": \"function\",\n      \"address\": \"0x48BF6D\"\n    },\n    {\n      \"id\": \"api_RegDeleteKey\",\n      \"label\": \"RegDeleteKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_value\",\n      \"label\": \"delete registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"api_RegDeleteValue\",\n      \"label\": \"RegDeleteValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_session_user_name\",\n      \"label\": \"get session user name\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\",\n        \"Discovery::Account\",\n        \"Discovery [T1087]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetUserName\",\n      \"label\": \"GetUserName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_token_membership\",\n      \"label\": \"get token membership\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x461EF3\",\n      \"label\": \"Function 0x461EF3\",\n      \"type\": \"function\",\n      \"address\": \"0x461EF3\"\n    },\n    {\n      \"id\": \"api_CheckTokenMembership\",\n      \"label\": \"CheckTokenMembership\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_AllocateAndInitializeSid\",\n      \"label\": \"AllocateAndInitializeSid\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FreeSid\",\n      \"label\": \"FreeSid\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_token_privileges\",\n      \"label\": \"get token privileges\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x4618A4\",\n      \"label\": \"Function 0x4618A4\",\n      \"type\": \"function\",\n      \"address\": \"0x4618A4\"\n    },\n    {\n      \"id\": \"api_GetTokenInformation\",\n      \"label\": \"GetTokenInformation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_thread__5_matches_\",\n      \"label\": \"create thread (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x47120E\",\n      \"label\": \"Block 0x47120E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x47120E\"\n    },\n    {\n      \"id\": \"bb_0x46EA22\",\n      \"label\": \"Block 0x46EA22\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x46EA22\"\n    },\n    {\n      \"id\": \"bb_0x47DB7A\",\n      \"label\": \"Block 0x47DB7A\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x47DB7A\"\n    },\n    {\n      \"id\": \"bb_0x462093\",\n      \"label\": \"Block 0x462093\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x462093\"\n    },\n    {\n      \"id\": \"api_CreateThread\",\n      \"label\": \"CreateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api__beginthreadex\",\n      \"label\": \"_beginthreadex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api__beginthread\",\n      \"label\": \"_beginthread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_terminate_thread\",\n      \"label\": \"terminate thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Thread [C0039]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x471244\",\n      \"label\": \"Block 0x471244\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x471244\"\n    },\n    {\n      \"id\": \"api_TerminateThread\",\n      \"label\": \"TerminateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_impersonate_user\",\n      \"label\": \"impersonate user\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation::Token\",\n        \"Impersonation/Theft [T1134.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x461A91\",\n      \"label\": \"Function 0x461A91\",\n      \"type\": \"function\",\n      \"address\": \"0x461A91\"\n    },\n    {\n      \"id\": \"api_LogonUser\",\n      \"label\": \"LogonUser\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadUserProfile\",\n      \"label\": \"LoadUserProfile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__99_elad_levi_gmail_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, 99.elad.levi@gmail.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Privilege Escalation::Access Token Manipulation::Token\",\n        \"Impersonation/Theft [T1134.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal__autoit_file_limitation\",\n      \"label\": \"(internal) autoit file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__13_matches_\",\n      \"label\": \"link function at runtime on Windows (13 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header\",\n      \"label\": \"parse PE header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40B4B0\",\n      \"label\": \"Function 0x40B4B0\",\n      \"type\": \"function\",\n      \"address\": \"0x40B4B0\"\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"label\": \"resolve function by parsing PE exports (15 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x47784B\",\n      \"label\": \"Function 0x47784B\",\n      \"type\": \"function\",\n      \"address\": \"0x47784B\"\n    },\n    {\n      \"id\": \"func_0x466E3B\",\n      \"label\": \"Function 0x466E3B\",\n      \"type\": \"function\",\n      \"address\": \"0x466E3B\"\n    },\n    {\n      \"id\": \"func_0x40D330\",\n      \"label\": \"Function 0x40D330\",\n      \"type\": \"function\",\n      \"address\": \"0x40D330\"\n    },\n    {\n      \"id\": \"func_0x409740\",\n      \"label\": \"Function 0x409740\",\n      \"type\": \"function\",\n      \"address\": \"0x409740\"\n    },\n    {\n      \"id\": \"func_0x476DE8\",\n      \"label\": \"Function 0x476DE8\",\n      \"type\": \"function\",\n      \"address\": \"0x476DE8\"\n    },\n    {\n      \"id\": \"func_0x491952\",\n      \"label\": \"Function 0x491952\",\n      \"type\": \"function\",\n      \"address\": \"0x491952\"\n    },\n    {\n      \"id\": \"func_0x468B27\",\n      \"label\": \"Function 0x468B27\",\n      \"type\": \"function\",\n      \"address\": \"0x468B27\"\n    },\n    {\n      \"id\": \"func_0x40A310\",\n      \"label\": \"Function 0x40A310\",\n      \"type\": \"function\",\n      \"address\": \"0x40A310\"\n    },\n    {\n      \"id\": \"func_0x41ABB8\",\n      \"label\": \"Function 0x41ABB8\",\n      \"type\": \"function\",\n      \"address\": \"0x41ABB8\"\n    },\n    {\n      \"id\": \"func_0x479A66\",\n      \"label\": \"Function 0x479A66\",\n      \"type\": \"function\",\n      \"address\": \"0x479A66\"\n    },\n    {\n      \"id\": \"func_0x4102F0\",\n      \"label\": \"Function 0x4102F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4102F0\"\n    },\n    {\n      \"id\": \"func_0x408B8A\",\n      \"label\": \"Function 0x408B8A\",\n      \"type\": \"function\",\n      \"address\": \"0x408B8A\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_execute_shellcode_via_indirect_call\",\n      \"label\": \"execute shellcode via indirect call\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x489FF3\",\n      \"label\": \"Function 0x489FF3\",\n      \"type\": \"function\",\n      \"address\": \"0x489FF3\"\n    },\n    {\n      \"id\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"label\": \"author     ronnie.salomonsen@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_shortcut_via_ishelllink__2_matches_\",\n      \"label\": \"create shortcut via IShellLink (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x476178\",\n      \"label\": \"Function 0x476178\",\n      \"type\": \"function\",\n      \"address\": \"0x476178\"\n    },\n    {\n      \"id\": \"api_CoCreateInstance\",\n      \"label\": \"CoCreateInstance\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_memory__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_memory__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x46BC2A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__486_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__486_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401212\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__13_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x40522E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__37_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__37_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x40F25F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_process__7_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_process__7_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x46BC2A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"target\": \"func_0x46A51A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"target\": \"func_0x46F1A7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"target\": \"func_0x46A531\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_queryperformancecounter__4_matches_\",\n      \"target\": \"func_0x46B984\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46A51A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46F1A7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46A531\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46B984\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_unmoving_mouse_cursor__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_unmoving_mouse_cursor__2_matches_\",\n      \"target\": \"func_0x499ED5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_unmoving_mouse_cursor__2_matches_\",\n      \"target\": \"func_0x499928\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______bitsofbinary\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______bitsofbinary\",\n      \"target\": \"func_0x499ED5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______bitsofbinary\",\n      \"target\": \"func_0x499928\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x46B2C9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x46BBBB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x46BA0B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x4642CC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x462E32\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x463637\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x403205\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x46BB56\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__9_matches_\",\n      \"target\": \"func_0x41FC8A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46B2C9\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BBBB\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BA0B\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4642CC\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x462E32\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463637\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403205\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BB56\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41FC8A\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B2C9\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BBBB\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BA0B\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4642CC\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x462E32\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463637\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403205\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BB56\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41FC8A\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46B2C9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46BBBB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46BA0B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4642CC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x462E32\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x463637\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x403205\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46BB56\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x41FC8A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46B2C9\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BBBB\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BA0B\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4642CC\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x462E32\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463637\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403205\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BB56\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41FC8A\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B2C9\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BBBB\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BA0B\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4642CC\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x462E32\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463637\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403205\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BB56\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41FC8A\",\n      \"target\": \"api_MapVirtualKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46B2C9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x499ED5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x4019CD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46B5B6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46A86D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46B333\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46A54A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x41A86C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46BB56\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46B796\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__11_matches_\",\n      \"target\": \"func_0x46B478\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46B2C9\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499ED5\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4019CD\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B5B6\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A86D\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B333\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A54A\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41A86C\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BB56\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B796\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B478\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B2C9\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499ED5\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4019CD\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B5B6\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A86D\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B333\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A54A\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41A86C\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BB56\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B796\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B478\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B2C9\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499ED5\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4019CD\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B5B6\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A86D\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B333\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A54A\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41A86C\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BB56\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B796\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B478\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B2C9\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499ED5\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4019CD\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B5B6\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A86D\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B333\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A54A\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41A86C\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BB56\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B796\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B478\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46B2C9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x499ED5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4019CD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46B5B6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46A86D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46B333\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46A54A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x41A86C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46BB56\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46B796\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46B478\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46B2C9\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499ED5\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4019CD\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B5B6\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A86D\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B333\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A54A\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41A86C\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BB56\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B796\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B478\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B2C9\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499ED5\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4019CD\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B5B6\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A86D\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B333\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A54A\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41A86C\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BB56\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B796\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B478\",\n      \"target\": \"api_VkKeyScan\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B2C9\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499ED5\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4019CD\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B5B6\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A86D\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B333\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A54A\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41A86C\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BB56\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B796\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B478\",\n      \"target\": \"api_GetKeyboardState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B2C9\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x499ED5\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4019CD\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B5B6\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A86D\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B333\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46A54A\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41A86C\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46BB56\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B796\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46B478\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_capture_screenshot\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_capture_screenshot\",\n      \"target\": \"func_0x482EB9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x482EB9\",\n      \"target\": \"api_GetDIBits\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482EB9\",\n      \"target\": \"api_CreateCompatibleBitmap\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482EB9\",\n      \"target\": \"api_GetDC\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482EB9\",\n      \"target\": \"api_CreateCompatibleDC\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com____re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x482EB9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x482EB9\",\n      \"target\": \"api_GetDIBits\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482EB9\",\n      \"target\": \"api_CreateCompatibleBitmap\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482EB9\",\n      \"target\": \"api_GetDC\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482EB9\",\n      \"target\": \"api_CreateCompatibleDC\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_remote_server_for_available_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_remote_server_for_available_data\",\n      \"target\": \"bb_0x47D877\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x47D877\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data__4_matches_\",\n      \"target\": \"func_0x481D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__4_matches_\",\n      \"target\": \"func_0x4825BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__4_matches_\",\n      \"target\": \"func_0x47D877\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__4_matches_\",\n      \"target\": \"func_0x47D7A1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481D90\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4825BD\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D877\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481D90\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4825BD\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D877\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481D90\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4825BD\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D877\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x481D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x4825BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x47D877\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x47D7A1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481D90\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4825BD\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D877\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481D90\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4825BD\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D877\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481D90\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4825BD\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D877\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data__3_matches_\",\n      \"target\": \"func_0x48295A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__3_matches_\",\n      \"target\": \"func_0x47CDD3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__3_matches_\",\n      \"target\": \"func_0x481F27\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48295A\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F27\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48295A\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F27\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48295A\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F27\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48295A\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F27\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48295A\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F27\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x48295A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x47CDD3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x481F27\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48295A\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F27\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48295A\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F27\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48295A\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F27\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48295A\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F27\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48295A\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F27\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_download_and_write_a_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_download_and_write_a_file\",\n      \"target\": \"func_0x47D7A1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_maec_malware_category__downloader\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_maec_malware_category__downloader\",\n      \"target\": \"func_0x47D7A1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_and_write_data_from_server_to_client\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_and_write_data_from_server_to_client\",\n      \"target\": \"func_0x47D7A1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x47D7A1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_dns__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_dns__3_matches_\",\n      \"target\": \"func_0x481CBE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_dns__3_matches_\",\n      \"target\": \"func_0x480EB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_dns__3_matches_\",\n      \"target\": \"func_0x46E653\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481CBE\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480EB8\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E653\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x481CBE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x480EB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E653\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481CBE\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480EB8\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E653\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_network_resource\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_network_resource\",\n      \"target\": \"func_0x460F6E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x460F6E\",\n      \"target\": \"api_WNetAddConnection2\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x460F6E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x460F6E\",\n      \"target\": \"api_WNetAddConnection2\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_url\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_url\",\n      \"target\": \"bb_0x47DA51\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x47DA51\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_to_http_server__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_to_http_server__2_matches_\",\n      \"target\": \"func_0x47CAA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_to_http_server__2_matches_\",\n      \"target\": \"func_0x47CDD3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CAA0\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47CAA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47CDD3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CAA0\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_to_url\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_http_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_http_request\",\n      \"target\": \"func_0x47D67B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47D67B\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47D67B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47D67B\",\n      \"target\": \"api_InternetOpen\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_data_from_internet__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__2_matches_\",\n      \"target\": \"func_0x47D877\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_data_from_internet__2_matches_\",\n      \"target\": \"func_0x47D7A1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47D877\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47D877\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47D7A1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47D877\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_InternetReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_http_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_http_request\",\n      \"target\": \"func_0x47CDD3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47CDD3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_HttpOpenRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_HttpSendRequest\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47CDD3\",\n      \"target\": \"api_InternetConnect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_icmp_echo_request\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_icmp_echo_request\",\n      \"target\": \"func_0x480EB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480EB8\",\n      \"target\": \"api_IcmpSendEcho\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480EB8\",\n      \"target\": \"api_IcmpCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480EB8\",\n      \"target\": \"api_IcmpCreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x480EB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480EB8\",\n      \"target\": \"api_IcmpSendEcho\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480EB8\",\n      \"target\": \"api_IcmpCloseHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480EB8\",\n      \"target\": \"api_IcmpCreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_pipe__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_pipe__2_matches_\",\n      \"target\": \"func_0x470D8E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_pipe__2_matches_\",\n      \"target\": \"func_0x470E63\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x470D8E\",\n      \"target\": \"api_CreatePipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470E63\",\n      \"target\": \"api_CreatePipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x470D8E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x470E63\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x470D8E\",\n      \"target\": \"api_CreatePipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470E63\",\n      \"target\": \"api_CreatePipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_socket\",\n      \"target\": \"bb_0x481AE5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mrhafizfarhad_gmail_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x481AE5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_socket_status\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_socket_status\",\n      \"target\": \"func_0x483AA6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x483AA6\",\n      \"target\": \"api_select\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x483AA6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x483AA6\",\n      \"target\": \"api_select\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_initialize_winsock_library__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_initialize_winsock_library__3_matches_\",\n      \"target\": \"func_0x482010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_initialize_winsock_library__3_matches_\",\n      \"target\": \"func_0x480EB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_initialize_winsock_library__3_matches_\",\n      \"target\": \"func_0x46E653\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x482010\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480EB8\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E653\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x482010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x480EB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E653\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x482010\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480EB8\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E653\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_socket_configuration__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__3_matches_\",\n      \"target\": \"func_0x480EB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__3_matches_\",\n      \"target\": \"func_0x4839AB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__3_matches_\",\n      \"target\": \"func_0x482433\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480EB8\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4839AB\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482433\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480EB8\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4839AB\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482433\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x480EB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4839AB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x482433\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x480EB8\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4839AB\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482433\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x480EB8\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4839AB\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x482433\",\n      \"target\": \"api_ioctlsocket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data_on_socket__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__2_matches_\",\n      \"target\": \"func_0x481D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__2_matches_\",\n      \"target\": \"func_0x4825BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481D90\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4825BD\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481D90\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4825BD\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x481D90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4825BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481D90\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4825BD\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481D90\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4825BD\",\n      \"target\": \"api_recvfrom\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data_on_socket__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__2_matches_\",\n      \"target\": \"func_0x48295A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__2_matches_\",\n      \"target\": \"func_0x481F27\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48295A\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F27\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48295A\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F27\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48295A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x481F27\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48295A\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F27\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48295A\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481F27\",\n      \"target\": \"api_sendto\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_tcp_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_tcp_socket\",\n      \"target\": \"func_0x481A15\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481A15\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481A15\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"func_0x481A15\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481A15\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481A15\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_tcp_socket__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__2_matches_\",\n      \"target\": \"bb_0x481A69\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_tcp_socket__2_matches_\",\n      \"target\": \"bb_0x481BCD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x481A69\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x481BCD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_udp_socket__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__2_matches_\",\n      \"target\": \"bb_0x4821B4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket__2_matches_\",\n      \"target\": \"bb_0x482433\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4821B4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x482433\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_act_as_tcp_client\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_act_as_tcp_client\",\n      \"target\": \"func_0x481A15\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481A15\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481A15\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x481A15\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x481A15\",\n      \"target\": \"api_connect\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x481A15\",\n      \"target\": \"api_socket\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_with_autoit\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_crc32\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_with_crc32\",\n      \"target\": \"func_0x482E1E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x482E1E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encode_data_using_base64\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64\",\n      \"target\": \"func_0x41CBB6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x41CBB6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_using_djb2\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_using_djb2\",\n      \"target\": \"func_0x40829C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______awillia2_cisco_com__still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______awillia2_cisco_com__still_teamt5_org\",\n      \"target\": \"func_0x40829C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_authenticate_hmac\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac\",\n      \"target\": \"func_0x41CBB6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x41CBB6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"target\": \"func_0x4728DA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"target\": \"func_0x472830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"target\": \"func_0x47291A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_generate_random_numbers_using_a_mersenne_twister__4_matches_\",\n      \"target\": \"func_0x472876\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4728DA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x472830\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x47291A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x472876\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x473923\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x473923\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473923\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473923\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473923\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x473923\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x473923\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473923\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473923\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x473923\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_list_drag_and_drop_files\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_list_drag_and_drop_files\",\n      \"target\": \"func_0x47F45C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_DragQueryFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_GetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47F45C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_DragQueryFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_GetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_clipboard__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_clipboard__2_matches_\",\n      \"target\": \"func_0x47F6C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_open_clipboard__2_matches_\",\n      \"target\": \"func_0x47F45C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47F6C7\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F6C7\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47F6C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47F45C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47F6C7\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F6C7\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_clipboard_data\",\n      \"target\": \"func_0x47F45C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_GlobalLock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_GlobalUnlock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_GetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47F45C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_GlobalLock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_GlobalUnlock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F45C\",\n      \"target\": \"api_GetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_clipboard_data\",\n      \"target\": \"func_0x47F6C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47F6C7\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F6C7\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F6C7\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F6C7\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47F6C7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47F6C7\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F6C7\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F6C7\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F6C7\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_interact_with_driver_via_ioctl__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_comspec_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_comspec_environment_variable\",\n      \"target\": \"func_0x41E3B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____matthew_williams_mandiant_com\",\n      \"target\": \"func_0x41E3B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__3_matches_\",\n      \"target\": \"func_0x487F8F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__3_matches_\",\n      \"target\": \"func_0x41E3B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__3_matches_\",\n      \"target\": \"func_0x47F84A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x487F8F\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F84A\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x487F8F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x41E3B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x47F84A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x487F8F\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F84A\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_environment_variable__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_environment_variable__2_matches_\",\n      \"target\": \"func_0x47F8BA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_environment_variable__2_matches_\",\n      \"target\": \"func_0x43D570\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47F8BA\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43D570\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47F8BA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x43D570\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47F8BA\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43D570\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x403A70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x478AEF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x46E753\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x403312\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x48B958\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x4738ED\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x4783F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x41E3B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__9_matches_\",\n      \"target\": \"func_0x47874A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403A70\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478AEF\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E753\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403312\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B958\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4738ED\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783F0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47874A\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403A70\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478AEF\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E753\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403312\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B958\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4738ED\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783F0\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47874A\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403A70\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478AEF\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E753\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403312\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B958\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4738ED\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783F0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47874A\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403A70\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478AEF\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E753\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403312\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B958\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4738ED\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783F0\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47874A\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403A70\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478AEF\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E753\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403312\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B958\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4738ED\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783F0\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47874A\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403A70\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478AEF\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E753\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403312\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B958\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4738ED\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783F0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47874A\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403A70\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478AEF\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E753\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403312\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B958\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4738ED\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783F0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47874A\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403A70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x478AEF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46E753\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x403312\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48B958\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4738ED\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4783F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41E3B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47874A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x403A70\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478AEF\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E753\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403312\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B958\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4738ED\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783F0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47874A\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403A70\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478AEF\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E753\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403312\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B958\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4738ED\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783F0\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47874A\",\n      \"target\": \"api_SHGetFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403A70\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478AEF\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E753\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403312\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B958\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4738ED\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783F0\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47874A\",\n      \"target\": \"api_GetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403A70\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478AEF\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E753\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403312\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B958\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4738ED\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783F0\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47874A\",\n      \"target\": \"api_GetTempFileName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403A70\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478AEF\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E753\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403312\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B958\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4738ED\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783F0\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47874A\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403A70\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478AEF\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E753\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403312\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B958\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4738ED\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783F0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47874A\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403A70\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478AEF\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E753\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403312\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48B958\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4738ED\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4783F0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47874A\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_current_directory__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x478AEF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x479F9F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x403AA3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x403312\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x47A0FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x475E10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_current_directory__7_matches_\",\n      \"target\": \"func_0x47874A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x478AEF\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479F9F\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403AA3\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403312\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0FA\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475E10\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47874A\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x478AEF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x479F9F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403AA3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403312\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47A0FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x475E10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47874A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x478AEF\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479F9F\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403AA3\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403312\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0FA\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475E10\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47874A\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_copy_file__3_matches_\",\n      \"target\": \"func_0x46D6C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_copy_file__3_matches_\",\n      \"target\": \"func_0x47321B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_copy_file__3_matches_\",\n      \"target\": \"func_0x46DA5C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46D6C0\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47321B\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DA5C\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D6C0\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47321B\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DA5C\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D6C0\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47321B\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DA5C\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D6C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47321B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46DA5C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46D6C0\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47321B\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DA5C\",\n      \"target\": \"api_CopyFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D6C0\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47321B\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DA5C\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D6C0\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47321B\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DA5C\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory__2_matches_\",\n      \"target\": \"func_0x474678\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_directory__2_matches_\",\n      \"target\": \"func_0x46DA81\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x474678\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DA81\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x474678\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46DA81\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x474678\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DA81\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_directory__2_matches_\",\n      \"target\": \"func_0x474678\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_directory__2_matches_\",\n      \"target\": \"func_0x46F089\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x474678\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46F089\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x474678\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46F089\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x474678\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46F089\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x4782F6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x47321B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x46F089\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x476033\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x46D836\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__6_matches_\",\n      \"target\": \"func_0x46DB69\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4782F6\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47321B\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46F089\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476033\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D836\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB69\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4782F6\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47321B\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46F089\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476033\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D836\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB69\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4782F6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x47321B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46F089\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x476033\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D836\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46DB69\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4782F6\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47321B\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46F089\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476033\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D836\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB69\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4782F6\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47321B\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46F089\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476033\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D836\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB69\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x46E387\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x46DA81\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__3_matches_\",\n      \"target\": \"func_0x46E9C5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46E387\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DA81\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E9C5\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E387\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DA81\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E9C5\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E387\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46DA81\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46E9C5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46E387\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DA81\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E9C5\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E387\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DA81\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E9C5\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x479F9F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x4765F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x47A488\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x46D836\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x47A0FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows__6_matches_\",\n      \"target\": \"func_0x46DB69\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x479F9F\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4765F1\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A488\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D836\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0FA\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB69\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479F9F\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4765F1\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A488\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D836\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0FA\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB69\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479F9F\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4765F1\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A488\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D836\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0FA\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB69\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x479F9F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4765F1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47A488\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46D836\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47A0FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46DB69\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x479F9F\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4765F1\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A488\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D836\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0FA\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB69\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479F9F\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4765F1\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A488\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D836\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0FA\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB69\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479F9F\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4765F1\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A488\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D836\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0FA\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DB69\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_recursively__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively__3_matches_\",\n      \"target\": \"func_0x47A488\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively__3_matches_\",\n      \"target\": \"func_0x479F9F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively__3_matches_\",\n      \"target\": \"func_0x47A0FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47A488\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479F9F\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0FA\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A488\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479F9F\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0FA\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A488\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479F9F\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0FA\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47A488\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x479F9F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47A0FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47A488\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479F9F\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0FA\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A488\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479F9F\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0FA\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A488\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479F9F\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47A0FA\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x478940\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x46E9C5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x479FF7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x46E3A5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x46DA81\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x478940\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x46E9C5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x479FF7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x46E3A5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x46DA81\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x48343B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x498ECE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48343B\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498ECE\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48343B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x498ECE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48343B\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498ECE\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_version_info\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_version_info\",\n      \"target\": \"func_0x46E3D7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46E3D7\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E3D7\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E3D7\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46E3D7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46E3D7\",\n      \"target\": \"api_GetFileVersionInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E3D7\",\n      \"target\": \"api_VerQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E3D7\",\n      \"target\": \"api_GetFileVersionInfoSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__2_matches_\",\n      \"target\": \"bb_0x479FF7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__2_matches_\",\n      \"target\": \"bb_0x478940\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x479FF7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x478940\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_move_file__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_move_file__3_matches_\",\n      \"target\": \"func_0x46D6C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__3_matches_\",\n      \"target\": \"func_0x46EC27\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__3_matches_\",\n      \"target\": \"func_0x46D836\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46D6C0\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EC27\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D836\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D6C0\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EC27\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D836\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D6C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46EC27\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46D836\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46D6C0\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EC27\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D836\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D6C0\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46EC27\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D836\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read__ini_file__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__4_matches_\",\n      \"target\": \"func_0x478E39\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__4_matches_\",\n      \"target\": \"func_0x479238\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__4_matches_\",\n      \"target\": \"func_0x479455\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read__ini_file__4_matches_\",\n      \"target\": \"func_0x478EFB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x478E39\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479238\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479455\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478EFB\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478E39\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479238\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479455\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478EFB\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478E39\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479238\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479455\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478EFB\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x478E39\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x479238\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x479455\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x478EFB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x478E39\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479238\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479455\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478EFB\",\n      \"target\": \"api_GetPrivateProfileString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478E39\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479238\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479455\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478EFB\",\n      \"target\": \"api_GetPrivateProfileSectionNames\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478E39\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479238\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x479455\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478EFB\",\n      \"target\": \"api_GetPrivateProfileSection\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x43960B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x40653A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x472F67\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x40B050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x48343B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x40AED0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x498ECE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x472E2B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__9_matches_\",\n      \"target\": \"func_0x4710AB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x43960B\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40653A\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F67\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B050\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48343B\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AED0\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498ECE\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472E2B\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4710AB\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43960B\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40653A\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F67\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B050\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48343B\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AED0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498ECE\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472E2B\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4710AB\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43960B\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40653A\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F67\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B050\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48343B\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AED0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498ECE\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472E2B\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4710AB\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43960B\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40653A\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F67\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B050\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48343B\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AED0\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498ECE\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472E2B\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4710AB\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x43960B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40653A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472F67\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40B050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48343B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40AED0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x498ECE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472E2B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4710AB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x43960B\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40653A\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F67\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B050\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48343B\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AED0\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498ECE\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472E2B\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4710AB\",\n      \"target\": \"api_fread\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43960B\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40653A\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F67\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B050\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48343B\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AED0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498ECE\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472E2B\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4710AB\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43960B\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40653A\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F67\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B050\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48343B\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AED0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498ECE\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472E2B\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4710AB\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x43960B\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40653A\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472F67\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40B050\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48343B\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40AED0\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x498ECE\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472E2B\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4710AB\",\n      \"target\": \"api__read\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_clear_file_content\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_clear_file_content\",\n      \"target\": \"func_0x478A11\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x478A11\",\n      \"target\": \"api_SetEndOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478A11\",\n      \"target\": \"api_SetFilePointer\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____jakeperalta7\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____jakeperalta7\",\n      \"target\": \"func_0x478A11\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x478A11\",\n      \"target\": \"api_SetEndOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x478A11\",\n      \"target\": \"api_SetFilePointer\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x47321B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x472FAB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x472FF8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x46D4BF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x47D7A1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x41C08E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__7_matches_\",\n      \"target\": \"func_0x470FD1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47321B\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472FAB\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472FF8\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D4BF\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41C08E\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470FD1\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47321B\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472FAB\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472FF8\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D4BF\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41C08E\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470FD1\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47321B\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472FAB\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472FF8\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D4BF\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41C08E\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470FD1\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47321B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472FAB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x472FF8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46D4BF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47D7A1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41C08E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x470FD1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47321B\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472FAB\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472FF8\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D4BF\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41C08E\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470FD1\",\n      \"target\": \"api__fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47321B\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472FAB\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472FF8\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D4BF\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41C08E\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470FD1\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47321B\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472FAB\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x472FF8\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46D4BF\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47D7A1\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41C08E\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x470FD1\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_gui_resources\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_gui_resources\",\n      \"target\": \"func_0x464A8B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x464A8B\",\n      \"target\": \"api_EnumWindows\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x464A8B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x464A8B\",\n      \"target\": \"api_EnumWindows\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_taskbar__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_find_taskbar__3_matches_\",\n      \"target\": \"bb_0x45FC52\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_find_taskbar__3_matches_\",\n      \"target\": \"bb_0x492CB5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_find_taskbar__3_matches_\",\n      \"target\": \"bb_0x492C81\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x45FC52\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x492CB5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x492C81\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_graphical_window__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_graphical_window_text__11_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x497D47\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x4664D3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x464453\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x4651E3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x492839\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x4951D2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x47F32D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x46550C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x4623BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x497A34\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__11_matches_\",\n      \"target\": \"func_0x463EEA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x497D47\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4664D3\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x464453\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4651E3\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x492839\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4951D2\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F32D\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46550C\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4623BC\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x497A34\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463EEA\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x497D47\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4664D3\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x464453\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4651E3\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x492839\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4951D2\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F32D\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46550C\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4623BC\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x497A34\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463EEA\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x497D47\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4664D3\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x464453\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4651E3\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x492839\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4951D2\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F32D\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46550C\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4623BC\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x497A34\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463EEA\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x497D47\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4664D3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x464453\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4651E3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x492839\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4951D2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x47F32D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x46550C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4623BC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x497A34\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x463EEA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x497D47\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4664D3\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x464453\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4651E3\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x492839\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4951D2\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F32D\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46550C\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4623BC\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x497A34\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463EEA\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x497D47\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4664D3\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x464453\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4651E3\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x492839\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4951D2\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F32D\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46550C\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4623BC\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x497A34\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463EEA\",\n      \"target\": \"api_IsWindowVisible\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x497D47\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4664D3\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x464453\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4651E3\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x492839\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4951D2\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47F32D\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46550C\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4623BC\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x497A34\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x463EEA\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hide_graphical_window__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x49ABDD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x490B89\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x495B1C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x45FBC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x498BA7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x4975F2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x4831F8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window__8_matches_\",\n      \"target\": \"bb_0x498C2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x49ABDD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x490B89\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x495B1C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x45FBC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x498BA7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4975F2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4831F8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x498C2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_keyboard_layout\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_keyboard_layout\",\n      \"target\": \"func_0x41E3B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetKeyboardLayoutName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x41E3B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetKeyboardLayoutName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_memory_capacity\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_memory_capacity\",\n      \"target\": \"func_0x41F6D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41F6D8\",\n      \"target\": \"api_GlobalMemoryStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x41F6D8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41F6D8\",\n      \"target\": \"api_GlobalMemoryStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x47534E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x4747D3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x475280\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x475439\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x474E1A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x4751B2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47534E\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4747D3\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475280\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475439\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474E1A\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4751B2\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47534E\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4747D3\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475280\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475439\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474E1A\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4751B2\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x47534E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4747D3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x475280\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x475439\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x474E1A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4751B2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47534E\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4747D3\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475280\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475439\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474E1A\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4751B2\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x47534E\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4747D3\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475280\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475439\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x474E1A\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4751B2\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_size__3_matches_\",\n      \"target\": \"func_0x475CED\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_size__3_matches_\",\n      \"target\": \"func_0x475B27\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_size__3_matches_\",\n      \"target\": \"func_0x475C0A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x475CED\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475B27\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475C0A\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475CED\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475B27\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475C0A\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x475CED\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x475B27\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x475C0A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x475CED\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475B27\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475C0A\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475CED\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475B27\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x475C0A\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_storage_device_properties__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_storage_device_properties__2_matches_\",\n      \"target\": \"func_0x46DDAB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_storage_device_properties__2_matches_\",\n      \"target\": \"func_0x46DE2A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46DDAB\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE2A\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46DDAB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46DE2A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46DDAB\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DE2A\",\n      \"target\": \"api_DeviceIoControl\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_print_debug_messages\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_print_debug_messages\",\n      \"target\": \"func_0x41C08E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41C08E\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x41C08E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41C08E\",\n      \"target\": \"api_OutputDebugString\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_shutdown_system\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_shutdown_system\",\n      \"target\": \"func_0x46F122\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46F122\",\n      \"target\": \"api_InitiateSystemShutdownEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46F122\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46F122\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46F122\",\n      \"target\": \"api_InitiateSystemShutdownEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46F122\",\n      \"target\": \"api_ExitWindowsEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_hostname__2_matches_\",\n      \"target\": \"func_0x41E3B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_hostname__2_matches_\",\n      \"target\": \"func_0x46E653\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_gethostname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E653\",\n      \"target\": \"api_gethostname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E653\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41E3B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46E653\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_gethostname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E653\",\n      \"target\": \"api_gethostname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46E653\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_system_information_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_system_information_on_windows\",\n      \"target\": \"func_0x405D78\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405D78\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x405D78\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405D78\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x461DBE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x498AD1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x48B7B2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x48BCF9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x443D42\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__6_matches_\",\n      \"target\": \"bb_0x461C96\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x461DBE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x498AD1\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x48B7B2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x48BCF9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x443D42\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x461C96\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_or_change_rwx_memory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory\",\n      \"target\": \"bb_0x48A2B9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x48A2B9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_processes__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_processes__2_matches_\",\n      \"target\": \"func_0x46DC9C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_processes__2_matches_\",\n      \"target\": \"func_0x48AFDB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46DC9C\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AFDB\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DC9C\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AFDB\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DC9C\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AFDB\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x46DC9C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x48AFDB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46DC9C\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AFDB\",\n      \"target\": \"api_CreateToolhelp32Snapshot\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DC9C\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AFDB\",\n      \"target\": \"api_Process32First\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46DC9C\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AFDB\",\n      \"target\": \"api_Process32Next\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_acquire_debug_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_acquire_debug_privileges\",\n      \"target\": \"bb_0x48AAEE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"bb_0x48AAEE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_modify_access_privileges__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process__3_matches_\",\n      \"target\": \"func_0x46F34C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__3_matches_\",\n      \"target\": \"func_0x48AA41\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__3_matches_\",\n      \"target\": \"func_0x4888B6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46F34C\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AA41\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4888B6\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46F34C\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AA41\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4888B6\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x46F34C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48AA41\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4888B6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x46F34C\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AA41\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4888B6\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x46F34C\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48AA41\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4888B6\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_empty_the_recycle_bin\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_empty_the_recycle_bin\",\n      \"target\": \"func_0x47838F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47838F\",\n      \"target\": \"api_SHEmptyRecycleBin\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x47838F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x47838F\",\n      \"target\": \"api_SHEmptyRecycleBin\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"target\": \"func_0x48C328\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"target\": \"func_0x48D593\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48C328\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48D593\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C328\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48D593\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x48C328\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x48D593\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48C328\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48D593\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C328\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48D593\",\n      \"target\": \"api_RegEnumKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x460F6E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x48C53A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x48C7A3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x40522E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x4055F8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x460F6E\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C53A\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C7A3\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40522E\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4055F8\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x460F6E\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C53A\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C7A3\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40522E\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4055F8\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x460F6E\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C53A\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C7A3\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40522E\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4055F8\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x460F6E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48C53A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48C7A3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40522E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4055F8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x460F6E\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C53A\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C7A3\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40522E\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4055F8\",\n      \"target\": \"api_RegEnumValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x460F6E\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C53A\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C7A3\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40522E\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4055F8\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x460F6E\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C53A\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48C7A3\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40522E\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4055F8\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value\",\n      \"target\": \"func_0x48CD16\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48CD16\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48CD16\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x48CD16\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48CD16\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48CD16\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key__2_matches_\",\n      \"target\": \"func_0x48BF6D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key__2_matches_\",\n      \"target\": \"func_0x48D593\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48BF6D\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48D593\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BF6D\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48D593\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x48BF6D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x48D593\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48BF6D\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48D593\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BF6D\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48D593\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value\",\n      \"target\": \"func_0x48BF6D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48BF6D\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BF6D\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x48BF6D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x48BF6D\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x48BF6D\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_user_name\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_session_user_name\",\n      \"target\": \"func_0x41E3B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetUserName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x41E3B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x41E3B3\",\n      \"target\": \"api_GetUserName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_token_membership\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_token_membership\",\n      \"target\": \"func_0x461EF3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x461EF3\",\n      \"target\": \"api_CheckTokenMembership\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461EF3\",\n      \"target\": \"api_AllocateAndInitializeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461EF3\",\n      \"target\": \"api_FreeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x461EF3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x461EF3\",\n      \"target\": \"api_CheckTokenMembership\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461EF3\",\n      \"target\": \"api_AllocateAndInitializeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461EF3\",\n      \"target\": \"api_FreeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_token_privileges\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_token_privileges\",\n      \"target\": \"func_0x4618A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4618A4\",\n      \"target\": \"api_GetTokenInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4618A4\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4618A4\",\n      \"target\": \"api_GetTokenInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread__5_matches_\",\n      \"target\": \"bb_0x47120E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__5_matches_\",\n      \"target\": \"bb_0x46EA22\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__5_matches_\",\n      \"target\": \"bb_0x47DB7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__5_matches_\",\n      \"target\": \"bb_0x462093\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x47120E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x46EA22\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x47DB7A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x462093\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_thread\",\n      \"target\": \"bb_0x471244\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x471244\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_impersonate_user\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_impersonate_user\",\n      \"target\": \"func_0x461A91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x461A91\",\n      \"target\": \"api_LogonUser\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461A91\",\n      \"target\": \"api_LoadUserProfile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__99_elad_levi_gmail_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__99_elad_levi_gmail_com\",\n      \"target\": \"func_0x461A91\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x461A91\",\n      \"target\": \"api_LogonUser\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x461A91\",\n      \"target\": \"api_LoadUserProfile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal__autoit_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__13_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header\",\n      \"target\": \"func_0x40B4B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x40B4B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x41CBB6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x403AA3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x47784B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x466E3B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x40D330\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x409740\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x476DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x491952\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x468B27\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x40A310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x41ABB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x479A66\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x4888B6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x4102F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__15_matches_\",\n      \"target\": \"func_0x408B8A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x41CBB6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x403AA3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x47784B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x466E3B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x40D330\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x409740\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x476DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x491952\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x468B27\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x40A310\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x41ABB8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x479A66\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x4888B6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x4102F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x408B8A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_execute_shellcode_via_indirect_call\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_execute_shellcode_via_indirect_call\",\n      \"target\": \"func_0x489FF3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x489FF3\",\n      \"target\": \"api_VirtualAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____ronnie_salomonsen_mandiant_com\",\n      \"target\": \"func_0x489FF3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x489FF3\",\n      \"target\": \"api_VirtualAlloc\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_shortcut_via_ishelllink__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_shortcut_via_ishelllink__2_matches_\",\n      \"target\": \"func_0x476DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_shortcut_via_ishelllink__2_matches_\",\n      \"target\": \"func_0x476178\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x476DE8\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476178\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______matthew_williams_mandiant_com\",\n      \"target\": \"func_0x476DE8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______matthew_williams_mandiant_com\",\n      \"target\": \"func_0x476178\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x476DE8\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x476178\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-20 01:40:48.954838\",\n    \"total_functions\": \"2046\",\n    \"total_features\": \"116784\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-20 01:40:53"}
{"_id":{"$oid":"6a5e02c1b3bed57e0e737923"},"sha256":"7132a14099e6824598c5899dea19a4b8f4d89683bb01774b402674da1d4fee2f","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_jfs0h8ak/7132a14099e6824598c5899dea19a4b8f4d89683bb01774b402674da1d4fee2f-019f7f40e152738285f788f229f71fb9.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_jfs0h8ak/7132a14099e6824598c5899dea19a4b8f4d89683bb01774b402674da1d4fee2f-019f7f40e152738285f788f229f71fb9.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_jfs0h8ak/7132a14099e6824598c5899dea19a4b8f4d89683bb01774b402674da1d4fee2f-019f7f40e152738285f788f229f71fb9.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 584e516edb5fc2b79960940b18cd65b5                                  │\n│ sha1     │ 4ad57334dee1fafb11f25b63df07a64370153ea7                          │\n│ sha256   │ 7132a14099e6824598c5899dea19a4b8f4d89683bb01774b402674da1d4fee2f  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ amd64                                                             │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/7132a14099e68245… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic                       ┃ ATT&CK Technique                       ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ EXECUTION                           │ Shared Modules [T1129]                 │\n└─────────────────────────────────────┴────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective                ┃ MBC Behavior                                  ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ EXECUTION                    │ Install Additional Program [B0023]            │\n│ FILE SYSTEM                  │ Writes File [C0052]                           │\n│ PROCESS                      │ Create Process [C0017]                        │\n│                              │ Terminate Process [C0018]                     │\n└──────────────────────────────┴───────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                              ┃ Namespace                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ extract resource via kernel32 functions │ executable/resource                │\n│ contain an embedded PE file             │ executable/subfile/pe              │\n│ write file on Windows                   │ host-interaction/file-system/write │\n│ create process on Windows               │ host-interaction/process/create    │\n│ terminate process                       │ host-interaction/process/terminate │\n│ link function at runtime on Windows (5  │ linking/runtime-linking            │\n│ matches)                                │                                    │\n│ link many functions at runtime          │ linking/runtime-linking            │\n└─────────────────────────────────────────┴────────────────────────────────────┘\n\n","verbose":"md5                     584e516edb5fc2b79960940b18cd65b5                        \nsha1                    4ad57334dee1fafb11f25b63df07a64370153ea7                \nsha256                  7132a14099e6824598c5899dea19a4b8f4d89683bb01774b402674d…\npath                    /home/apogean/projects/malware/windows/all_runs/7132a14…\ntimestamp               2026-07-20 17:00:32.630009                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x180000000                                             \nrules                   /tmp/_MEI9ZiJTf/rules                                   \nfunction count          29                                                      \nlibrary function count  170                                                     \ntotal feature count     15974                                                   \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x180001014        \n\ncontain an embedded PE file\nnamespace  executable/subfile/pe\nscope      file                 \n\nwrite file on Windows\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x180001014                       \n\ncreate process on Windows\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x1800010F8                    \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x180007DAF                       \n\nlink function at runtime on Windows (5 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x180007F31            \n           0x180007F5A            \n           0x180007F7A            \n           0x180007F9A            \n           0x180007FC2            \n\nlink many functions at runtime\nnamespace  linking/runtime-linking\nscope      function               \nmatches    0x180007ED0            \n\n\n\n","very_verbose":"md5                     584e516edb5fc2b79960940b18cd65b5                        \nsha1                    4ad57334dee1fafb11f25b63df07a64370153ea7                \nsha256                  7132a14099e6824598c5899dea19a4b8f4d89683bb01774b402674d…\npath                    /home/apogean/projects/malware/windows/all_runs/7132a14…\ntimestamp               2026-07-20 17:00:48.438270                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x180000000                                             \nrules                   /tmp/_MEI7rBl8o/rules                                   \nfunction count          29                                                      \nlibrary function count  170                                                     \ntotal feature count     15974                                                   \n\ncontain loop (4 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x1800018FC\n  or:\n    characteristic: loop @ 0x1800018FC\n\ncreate or open file (library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x1800010AF\n  or:\n    api: CreateFile @ 0x1800010AF\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x180001014\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x180001055\n        api: LockResource @ 0x180001063\n      optional:\n        or:\n          api: FindResource @ 0x180001036\n        api: SizeofResource @ 0x18000107B\n\ncontain an embedded PE file\nnamespace  executable/subfile/pe                        \nauthor     moritz.raabe@mandiant.com                    \nscope      file                                         \nmbc        Execution::Install Additional Program [B0023]\nor:\n  count(characteristic(embedded pe)): 1 or more @ file+0xC8A8, file+0x178C8, file+0x1B928, file+0x3E94C\n\nwrite file on Windows\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x180001014\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x18000109D\n            number: 0x2 = FILE_WRITE_DATA @ 0x18000108D\n            match: create or open file @ 0x1800010AF\n              or:\n                api: CreateFile @ 0x1800010AF\n      or:\n        api: WriteFile @ 0x1800010D3\n\ncreate process on Windows\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x1800010F8 in function 0x1800010F8\n  or:\n    api: CreateProcess @ 0x180001178\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x180007DAF\n  or:\n    and:\n      or:\n        api: TerminateProcess @ 0x180007E44\n\nlink function at runtime on Windows (5 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x180007F31\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x180007F31\ninstruction @ 0x180007F5A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x180007F5A\ninstruction @ 0x180007F7A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x180007F7A\ninstruction @ 0x180007F9A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x180007F9A\ninstruction @ 0x180007FC2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x180007FC2\n\nlink many functions at runtime\nnamespace  linking/runtime-linking                      \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com\nscope      function                                     \natt&ck     Execution::Shared Modules [T1129]            \nfunction @ 0x180007ED0\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x180007F31, 0x180007F5A, 0x180007F7A, 0x180007F9A, and 1 more...\n\n\n\n"},"hashes":{"md5":"584e516edb5fc2b79960940b18cd65b5","sha1":"4ad57334dee1fafb11f25b63df07a64370153ea7","sha256":"7132a14099e6824598c5899dea19a4b8f4d89683bb01774b402674da1d4fee2f"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 29</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 15974</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"7132a14\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"584e516edb5fc2b79960940b18cd65b5\",\n        \"sha256\": \"7132a14099e6824598c5899dea19a4b8f4d89683bb01774b402674d\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__4_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (4 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1800018FC\",\n      \"label\": \"Function 0x1800018FC\",\n      \"type\": \"function\",\n      \"address\": \"0x1800018FC\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x180001014\",\n      \"label\": \"Function 0x180001014\",\n      \"type\": \"function\",\n      \"address\": \"0x180001014\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_contain_an_embedded_pe_file\",\n      \"label\": \"contain an embedded PE file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows\",\n      \"label\": \"write file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows\",\n      \"label\": \"create process on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1800010F8\",\n      \"label\": \"Block 0x1800010F8\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1800010F8\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180007DAF\",\n      \"label\": \"Function 0x180007DAF\",\n      \"type\": \"function\",\n      \"address\": \"0x180007DAF\"\n    },\n    {\n      \"id\": \"api_TerminateProcess\",\n      \"label\": \"TerminateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__5_matches_\",\n      \"label\": \"link function at runtime on Windows (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_many_functions_at_runtime\",\n      \"label\": \"link many functions at runtime\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180007ED0\",\n      \"label\": \"Function 0x180007ED0\",\n      \"type\": \"function\",\n      \"address\": \"0x180007ED0\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__4_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__4_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x1800018FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x180001014\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x180001014\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_an_embedded_pe_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows\",\n      \"target\": \"func_0x180001014\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x180001014\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x180001014\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows\",\n      \"target\": \"bb_0x1800010F8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1800010F8\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x180007DAF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180007DAF\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x180007DAF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x180007DAF\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_many_functions_at_runtime\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime\",\n      \"target\": \"func_0x180007ED0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x180007ED0\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-20 17:00:48.438270\",\n    \"total_functions\": \"29\",\n    \"total_features\": \"15974\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-20 17:00:49"}
{"_id":{"$oid":"6a5e07a1b3bed57e0e737934"},"sha256":"f191f756996a14a11e5445fa7103d302efd510cf2fbf920e6c0c8ed51d512e36","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_ncn41vz2/everything-019f7f42fecc7c41a55dd70b4a72446e.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_ncn41vz2/everything-019f7f42fecc7c41a55dd70b4a72446e.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_ncn41vz2/everything-019f7f42fecc7c41a55dd70b4a72446e.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 464df9e59802fb4d6f4a0c743a5ded94                                  │\n│ sha1     │ 2aaa17b0aceb7d017c47ea0110de97e29d920ace                          │\n│ sha256   │ f191f756996a14a11e5445fa7103d302efd510cf2fbf920e6c0c8ed51d512e36  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ amd64                                                             │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/everything-019f7… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Clipboard Data [T1115]                                │\n│                      │ Input Capture::Keylogging [T1056.001]                 │\n│                      │ Video Capture [T1125]                                 │\n│ DEFENSE EVASION      │ Hide Artifacts::Hidden Window [T1564.003]             │\n│                      │ Modify Registry [T1112]                               │\n│                      │ Obfuscated Files or Information [T1027]               │\n│                      │ Virtualization/Sandbox Evasion::User Activity Based   │\n│                      │ Checks [T1497.002]                                    │\n│ DISCOVERY            │ Account Discovery [T1087]                             │\n│                      │ Application Window Discovery [T1010]                  │\n│                      │ File and Directory Discovery [T1083]                  │\n│                      │ Query Registry [T1012]                                │\n│                      │ System Information Discovery [T1082]                  │\n│                      │ System Location Discovery [T1614]                     │\n│                      │ System Location Discovery::System Language Discovery  │\n│                      │ [T1614.001]                                           │\n│                      │ System Network Configuration Discovery [T1016]        │\n│                      │ System Owner/User Discovery [T1033]                   │\n│ EXECUTION            │ Command and Scripting Interpreter [T1059]             │\n│                      │ Shared Modules [T1129]                                │\n│                      │ System Services::Service Execution [T1569.002]        │\n│ IMPACT               │ Service Stop [T1489]                                  │\n│ PERSISTENCE          │ Boot or Logon Autostart Execution::Registry Run Keys  │\n│                      │ / Startup Folder [T1547.001]                          │\n│                      │ Create or Modify System Process::Windows Service      │\n│                      │ [T1543.003]                                           │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Conditional Execution::Runs as Service            │\n│                          │ [B0025.007]                                       │\n│                          │ Debugger Detection::Software Breakpoints          │\n│                          │ [B0001.025]                                       │\n│                          │ Debugger Detection::Timing/Delay Check            │\n│                          │ GetTickCount [B0001.032]                          │\n│                          │ Virtual Machine Detection::Human User Check       │\n│                          │ [B0009.012]                                       │\n│ COLLECTION               │ Keylogging::Polling [F0002.002]                   │\n│ COMMAND AND CONTROL      │ C2 Communication::Receive Data [B0030.002]        │\n│                          │ C2 Communication::Send Data [B0030.001]           │\n│ COMMUNICATION            │ DNS Communication::Resolve [C0011.001]            │\n│                          │ HTTP Communication [C0002]                        │\n│                          │ Interprocess Communication::Connect Pipe          │\n│                          │ [C0003.002]                                       │\n│                          │ Interprocess Communication::Create Pipe           │\n│                          │ [C0003.001]                                       │\n│                          │ Socket Communication::Create UDP Socket           │\n│                          │ [C0001.010]                                       │\n│                          │ Socket Communication::Initialize Winsock Library  │\n│                          │ [C0001.009]                                       │\n│                          │ Socket Communication::Receive Data [C0001.006]    │\n│                          │ Socket Communication::Send Data [C0001.007]       │\n│                          │ Socket Communication::Set Socket Config           │\n│                          │ [C0001.001]                                       │\n│ CRYPTOGRAPHY             │ Encrypt Data::RC4 [C0027.009]                     │\n│                          │ Encryption Key::RC4 KSA [C0028.002]               │\n│                          │ Hashed Message Authentication Code [C0061]        │\n│ DATA                     │ Check String [C0019]                              │\n│                          │ Encode Data::Base64 [C0026.001]                   │\n│                          │ Encode Data::XOR [C0026.002]                      │\n│ DEFENSE EVASION          │ Obfuscated Files or                               │\n│                          │ Information::Encoding-Standard Algorithm          │\n│                          │ [E1027.m02]                                       │\n│                          │ Obfuscated Files or                               │\n│                          │ Information::Encryption-Standard Algorithm        │\n│                          │ [E1027.m05]                                       │\n│ DISCOVERY                │ Application Window Discovery [E1010]              │\n│                          │ Code Discovery::Enumerate PE Sections [B0046.001] │\n│                          │ File and Directory Discovery [E1083]              │\n│                          │ File and Directory Discovery::Log File            │\n│                          │ [E1083.m01]                                       │\n│                          │ System Information Discovery [E1082]              │\n│ EXECUTION                │ Command and Scripting Interpreter [E1059]         │\n│ FILE SYSTEM              │ Copy File [C0045]                                 │\n│                          │ Create Directory [C0046]                          │\n│                          │ Delete Directory [C0048]                          │\n│                          │ Delete File [C0047]                               │\n│                          │ Get File Attributes [C0049]                       │\n│                          │ Move File [C0063]                                 │\n│                          │ Read File [C0051]                                 │\n│                          │ Writes File [C0052]                               │\n│ IMPACT                   │ Clipboard Modification [E1510]                    │\n│ OPERATING SYSTEM         │ Registry::Delete Registry Key [C0036.002]         │\n│                          │ Registry::Delete Registry Value [C0036.007]       │\n│                          │ Registry::Query Registry Key [C0036.005]          │\n│                          │ Registry::Query Registry Value [C0036.006]        │\n│                          │ Registry::Set Registry Key [C0036.001]            │\n│                          │ Wallpaper [C0035]                                 │\n│ PERSISTENCE              │ Registry Run Keys / Startup Folder [F0012]        │\n│ PROCESS                  │ Check Mutex [C0043]                               │\n│                          │ Create Mutex [C0042]                              │\n│                          │ Create Process [C0017]                            │\n│                          │ Create Thread [C0038]                             │\n│                          │ Terminate Process [C0018]                         │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ check for software breakpoints (2     │ anti-analysis/anti-debugging/debugg… │\n│ matches)                              │                                      │\n│ check for time delay via GetTickCount │ anti-analysis/anti-debugging/debugg… │\n│ (11 matches)                          │                                      │\n│ check for unmoving mouse cursor       │ anti-analysis/anti-vm/vm-detection   │\n│ get geographical location (9 matches) │ collection                           │\n│ parse credit card information         │ collection/credit-card               │\n│ log keystrokes (3 matches)            │ collection/keylog                    │\n│ log keystrokes via polling (6         │ collection/keylog                    │\n│ matches)                              │                                      │\n│ capture webcam image                  │ collection/webcam                    │\n│ receive data (4 matches)              │ communication                        │\n│ send data (4 matches)                 │ communication                        │\n│ resolve DNS                           │ communication/dns                    │\n│ reference HTTP User-Agent string      │ communication/http                   │\n│ connect pipe                          │ communication/named-pipe/connect     │\n│ create pipe                           │ communication/named-pipe/create      │\n│ connect socket (3 matches)            │ communication/socket                 │\n│ get socket information (3 matches)    │ communication/socket                 │\n│ initialize Winsock library (3         │ communication/socket                 │\n│ matches)                              │                                      │\n│ set socket configuration (6 matches)  │ communication/socket                 │\n│ create UDP socket                     │ communication/socket/udp/send        │\n│ encode data using Base64 (2 matches)  │ data-manipulation/encoding/base64    │\n│ encode data using XOR (3 matches)     │ data-manipulation/encoding/xor       │\n│ encrypt data using RC4 KSA (2         │ data-manipulation/encryption/rc4     │\n│ matches)                              │                                      │\n│ encrypt data using speck              │ data-manipulation/encryption/speck   │\n│ authenticate HMAC                     │ data-manipulation/hmac               │\n│ contains PDB path                     │ executable/pe/pdb                    │\n│ extract resource via kernel32         │ executable/resource                  │\n│ functions                             │                                      │\n│ accept command line arguments (6      │ host-interaction/cli                 │\n│ matches)                              │                                      │\n│ read clipboard data                   │ host-interaction/clipboard           │\n│ write clipboard data (4 matches)      │ host-interaction/clipboard           │\n│ query environment variable (2         │ host-interaction/environment-variab… │\n│ matches)                              │                                      │\n│ get common file path (4 matches)      │ host-interaction/file-system         │\n│ get file system object information    │ host-interaction/file-system         │\n│ copy file                             │ host-interaction/file-system/copy    │\n│ create directory                      │ host-interaction/file-system/create  │\n│ delete directory (3 matches)          │ host-interaction/file-system/delete  │\n│ delete file (5 matches)               │ host-interaction/file-system/delete  │\n│ check if file exists (8 matches)      │ host-interaction/file-system/exists  │\n│ get file attributes (5 matches)       │ host-interaction/file-system/meta    │\n│ get file size (2 matches)             │ host-interaction/file-system/meta    │\n│ move file (4 matches)                 │ host-interaction/file-system/move    │\n│ read file on Windows (25 matches)     │ host-interaction/file-system/read    │\n│ write file on Windows (9 matches)     │ host-interaction/file-system/write   │\n│ enumerate gui resources               │ host-interaction/gui                 │\n│ set application hook (4 matches)      │ host-interaction/gui                 │\n│ change the wallpaper                  │ host-interaction/gui/session         │\n│ find graphical window                 │ host-interaction/gui/window/find     │\n│ get graphical window text (7 matches) │ host-interaction/gui/window/get-text │\n│ hide graphical window                 │ host-interaction/gui/window/hide     │\n│ get keyboard layout (2 matches)       │ host-interaction/hardware/keyboard   │\n│ get disk information (6 matches)      │ host-interaction/hardware/storage    │\n│ get disk size                         │ host-interaction/hardware/storage    │\n│ get volume information via IOCTL (2   │ host-interaction/hardware/storage    │\n│ matches)                              │                                      │\n│ access the Windows event log          │ host-interaction/log/winevt/access   │\n│ check mutex on Windows                │ host-interaction/mutex               │\n│ get local IPv4 addresses (3 matches)  │ host-interaction/network/address     │\n│ get hostname                          │ host-interaction/os/hostname         │\n│ get system information on Windows     │ host-interaction/os/info             │\n│ create process on Windows (2 matches) │ host-interaction/process/create      │\n│ terminate process (7 matches)         │ host-interaction/process/terminate   │\n│ query or enumerate registry key (2    │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ query or enumerate registry value (5  │ host-interaction/registry            │\n│ matches)                              │                                      │\n│ set registry value (2 matches)        │ host-interaction/registry/create     │\n│ delete registry key (2 matches)       │ host-interaction/registry/delete     │\n│ delete registry value                 │ host-interaction/registry/delete     │\n│ run as service                        │ host-interaction/service             │\n│ create service (2 matches)            │ host-interaction/service/create      │\n│ delete service (2 matches)            │ host-interaction/service/delete      │\n│ start service (2 matches)             │ host-interaction/service/start       │\n│ stop service (4 matches)              │ host-interaction/service/stop        │\n│ get session user name                 │ host-interaction/session             │\n│ create thread                         │ host-interaction/thread/create       │\n│ link function at runtime on Windows   │ linking/runtime-linking              │\n│ (98 matches)                          │                                      │\n│ link many functions at runtime (2     │ linking/runtime-linking              │\n│ matches)                              │                                      │\n│ enumerate PE sections (2 matches)     │ load-code/pe                         │\n│ parse PE header                       │ load-code/pe                         │\n│ resolve function by parsing PE        │ load-code/pe                         │\n│ exports (7 matches)                   │                                      │\n│ persist via Run registry key (3       │ persistence/registry/run             │\n│ matches)                              │                                      │\n│ persist via Windows service (2        │ persistence/service                  │\n│ matches)                              │                                      │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     464df9e59802fb4d6f4a0c743a5ded94                        \nsha1                    2aaa17b0aceb7d017c47ea0110de97e29d920ace                \nsha256                  f191f756996a14a11e5445fa7103d302efd510cf2fbf920e6c0c8ed…\npath                    /home/apogean/projects/malware/windows/all_runs/everyth…\ntimestamp               2026-07-20 17:01:39.424680                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x140000000                                             \nrules                   /tmp/_MEII7OVH2/rules                                   \nfunction count          2689                                                    \nlibrary function count  97                                                      \ntotal feature count     234849                                                  \n\ncheck for software breakpoints (2 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    0x1400674A0                                    \n           0x1400F5490                                    \n\ncheck for time delay via GetTickCount (11 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection\nscope      function                                       \nmatches    0x140048C20                                    \n           0x14004EC40                                    \n           0x14004FB70                                    \n           0x1400CE930                                    \n           0x1400EC2E0                                    \n           0x1400ECAF0                                    \n           0x1400EEFC0                                    \n           0x1400F0200                                    \n           0x1400F5050                                    \n           0x140106BB0                                    \n           0x14010D5A0                                    \n\ncheck for unmoving mouse cursor\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      function                          \nmatches    0x140141050                       \n\nget geographical location (9 matches)\nnamespace  collection \nscope      function   \nmatches    0x14005EEB0\n           0x1400DC370\n           0x1400DC3B0\n           0x14010F6C0\n           0x14010F780\n           0x140111260\n           0x14017ADD0\n           0x14017D070\n           0x1401B0A00\n\nparse credit card information\nnamespace  collection/credit-card\nscope      function              \nmatches    0x14018D880           \n\nlog keystrokes (3 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    0x1400E19A0      \n           0x1400F5390      \n           0x14015DFB0      \n\nlog keystrokes via polling (6 matches)\nnamespace  collection/keylog\nscope      function         \nmatches    0x1400CC320      \n           0x1400DA590      \n           0x1400DFED0      \n           0x1400E1B00      \n           0x1400F8C10      \n           0x1401001F0      \n\ncapture webcam image\nnamespace  collection/webcam\nscope      function         \nmatches    0x140142A30      \n\nreceive data (4 matches)\nnamespace    communication                                                     \ndescription  all known techniques for receiving data from a potential C2 server\nscope        function                                                          \nmatches      0x1400B74E0                                                       \n             0x1400B90C0                                                       \n             0x1400BCA70                                                       \n             0x1400C8B20                                                       \n\nsend data (4 matches)\nnamespace    communication                                                 \ndescription  all known techniques for sending data to a potential C2 server\nscope        function                                                      \nmatches      0x1400B6780                                                   \n             0x1400B7E80                                                   \n             0x1400B95B0                                                   \n             0x1400C27F0                                                   \n\nresolve DNS\nnamespace  communication/dns\nscope      function         \nmatches    0x1400DB440      \n\nreference HTTP User-Agent string\nnamespace  communication/http\nscope      function          \nmatches    0x14016C930       \n\nconnect pipe\nnamespace  communication/named-pipe/connect\nscope      function                        \nmatches    0x1400F0BE0                     \n\ncreate pipe\nnamespace  communication/named-pipe/create\nscope      function                       \nmatches    0x1400F0BE0                    \n\nconnect socket (3 matches)\nnamespace    communication/socket                                               \ndescription  Detects socket connection attempts using common APIs or ConnectEx  \n             setup.                                                             \nscope        basic block                                                        \nmatches      0x1400B78B3                                                        \n             0x1400BB924                                                        \n             0x1400BBB42                                                        \n\nget socket information (3 matches)\nnamespace  communication/socket\nscope      function            \nmatches    0x1400B9880         \n           0x1400B9FD0         \n           0x1400BB6C0         \n\ninitialize Winsock library (3 matches)\nnamespace  communication/socket\nscope      function            \nmatches    0x1400B7AF0         \n           0x1400BD1E0         \n           0x1400C8F10         \n\nset socket configuration (6 matches)\nnamespace  communication/socket\nscope      function            \nmatches    0x1400B77C0         \n           0x1400B9880         \n           0x1400B9FD0         \n           0x1400BB890         \n           0x1400BCD00         \n           0x1400C8D50         \n\nreceive data on socket (4 matches)\nnamespace  communication/socket/receive\nscope      function                    \nmatches    0x1400B74E0                 \n           0x1400B90C0                 \n           0x1400BCA70                 \n           0x1400C8B20                 \n\nsend data on socket (4 matches)\nnamespace  communication/socket/send\nscope      function                 \nmatches    0x1400B6780              \n           0x1400B7E80              \n           0x1400B95B0              \n           0x1400C27F0              \n\ncreate UDP socket\nnamespace  communication/socket/udp/send\nscope      basic block                  \nmatches    0x1400B9880                  \n\nencode data using Base64 (2 matches)\nnamespace  data-manipulation/encoding/base64\nscope      function                         \nmatches    0x1401899D0                      \n           0x14018D880                      \n\nencode data using XOR (3 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x1400B46C0                   \n           0x140163724                   \n           0x140181A30                   \n\nencrypt data using RC4 KSA (2 matches)\nnamespace  data-manipulation/encryption/rc4\nscope      function                        \nmatches    0x14010D8C0                     \n           0x140123C80                     \n\nencrypt data using speck\nnamespace  data-manipulation/encryption/speck\nscope      function                          \nmatches    0x14018D880                       \n\nauthenticate HMAC\nnamespace  data-manipulation/hmac\nscope      function              \nmatches    0x14018D880           \n\ncontains PDB path\nnamespace  executable/pe/pdb\nscope      file             \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x1400C79B0        \n\naccept command line arguments (6 matches)\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x140006010         \n           0x1400B4020         \n           0x1400CE620         \n           0x1400CF020         \n           0x1400CF8C0         \n           0x1401AB000         \n\nopen clipboard (6 matches)\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x1400D8AA0               \n           0x1400F8450               \n           0x140102050               \n           0x140104520               \n           0x1401046A0               \n           0x140106BB0               \n\nread clipboard data\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x140106BB0               \n\nwrite clipboard data (4 matches)\nnamespace  host-interaction/clipboard\nscope      function                  \nmatches    0x1400D8AA0               \n           0x140102050               \n           0x140104520               \n           0x1401046A0               \n\ninteract with driver via IOCTL (32 matches)\nnamespace  host-interaction/driver\nscope      instruction            \nmatches    0x14005003A            \n           0x140057DAE            \n           0x140057F7A            \n           0x1400B337A            \n           0x1400B34C4            \n           0x1400B351A            \n           0x1400CFEDB            \n           0x1400CFF8D            \n           0x1400D0721            \n           0x1400CFD1D            \n           0x1400CFEDB            \n           0x1400CFF8D            \n           0x1400D0721            \n           0x1400D84FB            \n           0x1400D947D            \n           0x1400D953B            \n           0x1400D9622            \n           0x1400DBE20            \n           0x1400DFCCD            \n           0x1400E03E3            \n           0x1400E0464            \n           0x1400E04F4            \n           0x1400E0573            \n           0x1400E0605            \n           0x1400E0698            \n           0x1400E0739            \n           0x1400E07C8            \n           0x1400E0852            \n           0x1400E5F6D            \n           0x1400EF1C6            \n           0x1400EF9F2            \n           0x1400F04B5            \n\nquery environment variable (2 matches)\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x1400E0A40                          \n           0x1401AE2A0                          \n\nget common file path (4 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x1400B44E0                 \n           0x1400D9990                 \n           0x1400E0230                 \n           0x1400E08B0                 \n\nget file system object information\nnamespace  host-interaction/file-system\nscope      basic block                 \nmatches    0x1400DB18C                 \n\ncopy file\nnamespace  host-interaction/file-system/copy\nscope      function                         \nmatches    0x1400CC920                      \n\ncreate directory\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x1400D5860                        \n\ndelete directory (3 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x1400D5430                        \n           0x1400D5610                        \n           0x1400D7B50                        \n\ndelete file (5 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x1400D5430                        \n           0x1400D5610                        \n           0x1400D7AC0                        \n           0x1400D8840                        \n           0x140165280                        \n\ncheck if file exists (8 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x1400D5550                        \n           0x1400D5770                        \n           0x1400D5860                        \n           0x1400D72F0                        \n           0x1400D8350                        \n           0x1400D83D0                        \n           0x1400D8440                        \n           0x1400DBC10                        \n\nget file attributes (5 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x1400D5894                      \n           0x1400D72F0                      \n           0x1400D8350                      \n           0x1400D83D0                      \n           0x1400D8463                      \n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x1400D78D0                      \n           0x1400DBC10                      \n\nmove file (4 matches)\nnamespace  host-interaction/file-system/move\nscope      function                         \nmatches    0x1400D5610                      \n           0x140109640                      \n           0x14013C810                      \n           0x14013CC30                      \n\nread file on Windows (25 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x140004610                      \n           0x140004770                      \n           0x1400048C0                      \n           0x140004D80                      \n           0x140004ED0                      \n           0x1400B3660                      \n           0x1400B8F10                      \n           0x1400BE010                      \n           0x1400BE0F0                      \n           0x1400BE1E0                      \n           0x1400BE4D0                      \n           0x1400BE570                      \n           0x1400C2DC0                      \n           0x1400CB5B0                      \n           0x1400CFA70                      \n           0x1400CFD90                      \n           0x1400CFE80                      \n           0x1400D13A0                      \n           0x1400DBC10                      \n           0x1400DC9B0                      \n           0x1400E5550                      \n           0x1400E5D50                      \n           0x1400EA6D0                      \n           0x1400F0070                      \n           0x14017B500                      \n\nwrite file on Windows (9 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x1400B3B20                       \n           0x1400D54C0                       \n           0x1400EA560                       \n           0x1400EE1D0                       \n           0x1400EE370                       \n           0x1400EE440                       \n           0x1400EE680                       \n           0x1401AC870                       \n           0x1401ACAB0                       \n\nenumerate gui resources\nnamespace  host-interaction/gui\nscope      function            \nmatches    0x1401048B0         \n\nset application hook (4 matches)\nnamespace  host-interaction/gui\nscope      instruction         \nmatches    0x1400CF5E6         \n           0x1400CF7BF         \n           0x1400CF5E6         \n           0x1400CF7BF         \n\nchange the wallpaper\nnamespace  host-interaction/gui/session\nscope      basic block                 \nmatches    0x14013D52F                 \n\nfind graphical window\nnamespace  host-interaction/gui/window/find\nscope      instruction                     \nmatches    0x1400D81AC                     \n\nget graphical window text (7 matches)\nnamespace  host-interaction/gui/window/get-text\nscope      function                            \nmatches    0x1400D96C0                         \n           0x1400D9770                         \n           0x14015CFD0                         \n           0x1401632A0                         \n           0x140163900                         \n           0x140163B70                         \n           0x140165280                         \n\nhide graphical window\nnamespace  host-interaction/gui/window/hide\nscope      basic block                     \nmatches    0x140102610                     \n\nget keyboard layout (2 matches)\nnamespace  host-interaction/hardware/keyboard\nscope      function                          \nmatches    0x1400CC320                       \n           0x1400DC3B0                       \n\nget disk information (6 matches)\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x1400D2A60                      \n           0x1400D7010                      \n           0x1400D8100                      \n           0x1400D91B0                      \n           0x1400DC080                      \n           0x1400E6E80                      \n\nget disk size\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x1400D7270                      \n\nget volume information via IOCTL (2 matches)\nnamespace  host-interaction/hardware/storage\nscope      basic block                      \nmatches    0x1400CFE80                      \n           0x1400CFE80                      \n\naccess the Windows event log\nnamespace  host-interaction/log/winevt/access\nscope      function                          \nmatches    0x1400B4190                       \n\ncheck mutex on Windows\nnamespace  host-interaction/mutex\nscope      function              \nmatches    0x1400CE930           \n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex\nscope      instruction           \nmatches    0x1400CEA39           \n\nget local IPv4 addresses (3 matches)\nnamespace  host-interaction/network/address\nscope      function                        \nmatches    0x1400B9880                     \n           0x1400B9FD0                     \n           0x1400BB6C0                     \n\nget hostname\nnamespace  host-interaction/os/hostname\nscope      function                    \nmatches    0x1400D6F40                 \n\nget system information on Windows\nnamespace  host-interaction/os/info\nscope      function                \nmatches    0x1400E4260             \n\ncreate process on Windows (2 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x1400D7D15                    \n           0x1400E3562                    \n\nterminate process (7 matches)\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x1400B4190                       \n           0x1400CCA90                       \n           0x1400CD290                       \n           0x1400EC810                       \n           0x1400ECD90                       \n           0x1401AB3A7                       \n           0x1401AC760                       \n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x1400DA6F0              \n           0x140110070              \n\nquery or enumerate registry value (5 matches)\nnamespace  host-interaction/registry\nscope      function                 \nmatches    0x1400DA9A0              \n           0x1400DAB40              \n           0x1400DAC60              \n           0x1400DCB00              \n           0x140110070              \n\nset registry value (2 matches)\nnamespace  host-interaction/registry/create\nscope      function                        \nmatches    0x1400E24D0                     \n           0x1400E2610                     \n\ndelete registry key (2 matches)\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x1400DA6F0                     \n           0x1400DA820                     \n\ndelete registry value\nnamespace  host-interaction/registry/delete\nscope      function                        \nmatches    0x1400E2720                     \n\nrun as service\nnamespace  host-interaction/service\nscope      file                    \n\ncreate service (2 matches)\nnamespace  host-interaction/service/create\nscope      function                       \nmatches    0x140005A50                    \n           0x1400ECFE0                    \n\ndelete service (2 matches)\nnamespace  host-interaction/service/delete\nscope      function                       \nmatches    0x1400056D0                    \n           0x1400EC810                    \n\nstart service (2 matches)\nnamespace  host-interaction/service/start\nscope      function                      \nmatches    0x140005820                   \n           0x1400ECAF0                   \n\nstop service (4 matches)\nnamespace  host-interaction/service/stop\nscope      function                     \nmatches    0x1400056D0                  \n           0x140005930                  \n           0x1400EC810                  \n           0x1400ECD90                  \n\nget session user name\nnamespace  host-interaction/session\nscope      function                \nmatches    0x1400D6FA0             \n\ncreate thread\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x1401AAC4D                   \n\nlink function at runtime on Windows (98 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x1400E2F03            \n           0x1400E2FE5            \n           0x1400E433E            \n           0x1400E4367            \n           0x1400E4390            \n           0x1400E43B9            \n           0x1400E43E2            \n           0x1400E440B            \n           0x1400E4434            \n           0x1400E445D            \n           0x1400E4486            \n           0x1400E44AF            \n           0x1400E44D8            \n           0x1400E4501            \n           0x1400E452A            \n           0x1400E4553            \n           0x1400E457C            \n           0x1400E45A5            \n           0x1400E45CE            \n           0x1400E45F7            \n           0x1400E4620            \n           0x1400E4649            \n           0x1400E4672            \n           0x1400E469B            \n           0x1400E46C4            \n           0x1400E4724            \n           0x1400E474D            \n           0x1400E4776            \n           0x1400E479F            \n           0x1400E47C8            \n           0x1400E47F1            \n           0x1400E481A            \n           0x1400E4843            \n           0x1400E486C            \n           0x1400E48AD            \n           0x1400E48D4            \n           0x1400E48FD            \n           0x1400E4926            \n           0x1400E494D            \n           0x1400E4976            \n           0x1400E499F            \n           0x1400E49C8            \n           0x1400E49F1            \n           0x1400E4A1A            \n           0x1400E4A43            \n           0x1400E4A96            \n           0x1400E4AB2            \n           0x1400E4AF3            \n           0x1400E4B1C            \n           0x1400E4B45            \n           0x1400E4B6E            \n           0x1400E4B97            \n           0x1400E4BC0            \n           0x1400E4BFD            \n           0x1400E4C3E            \n           0x1400E4C67            \n           0x1400E4C90            \n           0x1400E4CB9            \n           0x1400E4CE2            \n           0x1400E4D0B            \n           0x1400E4D34            \n           0x1400E4D5D            \n           0x1400E4D86            \n           0x1400E4DAF            \n           0x1400E4DD8            \n           0x1400E4E15            \n           0x1400E4E3E            \n           0x1400E4E7B            \n           0x1400E4EA4            \n           0x1400E4EE5            \n           0x1400E4F0E            \n           0x1400E4F37            \n           0x1400E4F60            \n           0x1400E4F89            \n           0x1400E4FB2            \n           0x1400E4FDB            \n           0x1400E5004            \n           0x1400E502D            \n           0x1400E5056            \n           0x1400E5093            \n           0x1400E50D0            \n           0x14013EA25            \n           0x14016C9AB            \n           0x14016C9BE            \n           0x14016C9D1            \n           0x14016C9E4            \n           0x1401AB4F8            \n           0x1401AB5D8            \n           0x1401AB6B8            \n           0x1401AB7D8            \n           0x1401AB7F0            \n           0x1401AB6B8            \n           0x1401AF192            \n           0x1401AF44E            \n           0x1401AF476            \n           0x1401AF495            \n           0x1401AF4E3            \n           0x1401AF507            \n\nlink many functions at runtime (2 matches)\nnamespace  linking/runtime-linking\nscope      function               \nmatches    0x1400E4260            \n           0x1401AF3F0            \n\nenumerate PE sections (2 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x1400D0820 \n           0x1400D13A0 \n\nparse PE header\nnamespace  load-code/pe\nscope      function    \nmatches    0x1401AB000 \n\nresolve function by parsing PE exports (7 matches)\nnamespace  load-code/pe\nscope      function    \nmatches    0x140009FD0 \n           0x140011870 \n           0x140029EE0 \n           0x1400B18B0 \n           0x1400BF5A0 \n           0x14016A420 \n           0x140183590 \n\npersist via Run registry key (3 matches)\nnamespace  persistence/registry/run\nscope      function                \nmatches    0x140144390             \n           0x140149760             \n           0x14014D500             \n\npersist via Windows service (2 matches)\nnamespace  persistence/service\nscope      function           \nmatches    0x140005A50        \n           0x1400ECFE0        \n\n\n\n","very_verbose":"md5                     464df9e59802fb4d6f4a0c743a5ded94                        \nsha1                    2aaa17b0aceb7d017c47ea0110de97e29d920ace                \nsha256                  f191f756996a14a11e5445fa7103d302efd510cf2fbf920e6c0c8ed…\npath                    /home/apogean/projects/malware/windows/all_runs/everyth…\ntimestamp               2026-07-20 17:03:45.576871                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x140000000                                             \nrules                   /tmp/_MEIKEGd13/rules                                   \nfunction count          2689                                                    \nlibrary function count  97                                                      \ntotal feature count     234849                                                  \n\nallocate memory (library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x1400CF9B0 in function 0x1400CF9B0\n  or:\n    api: VirtualAlloc @ 0x1400CF9CA\n\nallocate or change RW memory (library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x1400CF9B0 in function 0x1400CF9B0\n  and:\n    or:\n      match: allocate memory @ 0x1400CF9B0\n        or:\n          api: VirtualAlloc @ 0x1400CF9CA\n    or:\n      number: 0x4 = PAGE_READWRITE @ 0x1400CF9BC\n\ncontain loop (1286 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x1400013E0\n  or:\n    characteristic: tight loop @ 0x140001400\n\ncreate or open file (8 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x1400B457A\n  or:\n    api: CreateFile @ 0x1400B457A\n\ncreate or open registry key (10 matches, only showing first match of library \nrule)\nauthor  michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope   basic block                                                             \nmbc     Operating System::Registry::Create Registry Key [C0036.004], Operating  \n        System::Registry::Open Registry Key [C0036.003]                         \nbasic block @ 0x1400DA6F0 in function 0x1400DA6F0\n  or:\n    api: RegOpenKeyEx @ 0x1400DA73C\n\ndelay execution (46 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x140010C9E in function 0x140010BA0\n  or:\n    and:\n      os: windows\n      or:\n        api: WaitForSingleObject @ 0x140010CA6\n\nget OS version (2 matches, only showing first match of library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x1400E4260\n  or:\n    api: GetVersionEx @ 0x1400E4295\n\nget service handle (12 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x1400056D0\n  or:\n    api: OpenService @ 0x140005707, 0x140005741\n\nopen process (10 matches, only showing first match of library rule)\nauthor  0x534a@mailbox.org           \nscope   basic block                  \nmbc     Process::Open Process [C0065]\nbasic block @ 0x1400CCAC0 in function 0x1400CCA90\n  or:\n    api: OpenProcess @ 0x1400CCAD1\n\ncheck for software breakpoints (2 matches)\nnamespace   anti-analysis/anti-debugging/debugger-detection                     \nauthor      michael.hunhoff@mandiant.com                                        \nscope       function                                                            \nmbc         Anti-Behavioral Analysis::Debugger Detection::Software Breakpoints  \n            [B0001.025]                                                         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\n            https://anti-debug.checkpoint.com/techniques/assembly.html          \nfunction @ 0x1400674A0\n  and:\n    match: contain loop @ 0x1400674A0\n      or:\n        characteristic: loop @ 0x1400674A0\n        characteristic: tight loop @ 0x140069620, 0x140069660, 0x1400697C0, 0x1400697D2, and 2 more...\n    or:\n      and: = INT3 (long form)\n        instruction:\n          and:\n            mnemonic: cmp @ 0x140069B62\n            number: 0xCD = INT3 (long form byte 1) @ 0x140069B62\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1400676A4\n            number: 0x3 = INT3 (long form byte 2) @ 0x1400676A4\n          and:\n            mnemonic: cmp @ 0x140067EC4\n            number: 0x3 = INT3 (long form byte 2) @ 0x140067EC4\n          and:\n            mnemonic: cmp @ 0x14006866B\n            number: 0x3 = INT3 (long form byte 2) @ 0x14006866B\n          and:\n            mnemonic: cmp @ 0x14006806E\n            number: 0x3 = INT3 (long form byte 2) @ 0x14006806E\n          and:\n            mnemonic: cmp @ 0x140067AB4\n            number: 0x3 = INT3 (long form byte 2) @ 0x140067AB4\n          and:\n            mnemonic: cmp @ 0x140067C5E\n            number: 0x3 = INT3 (long form byte 2) @ 0x140067C5E\n          and:\n            mnemonic: cmp @ 0x14006831B\n            number: 0x3 = INT3 (long form byte 2) @ 0x14006831B\n          and:\n            mnemonic: cmp @ 0x14006783E\n            number: 0x3 = INT3 (long form byte 2) @ 0x14006783E\nfunction @ 0x1400F5490\n  and:\n    match: contain loop @ 0x1400F5490\n      or:\n        characteristic: tight loop @ 0x1400F56A2\n    or:\n      and: = INT3 (long form)\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1400F58AA\n            number: 0xCD = INT3 (long form byte 1) @ 0x1400F58AA\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1400F5857\n            number: 0x3 = INT3 (long form byte 2) @ 0x1400F5857\n\ncheck for time delay via GetTickCount (11 matches)\nnamespace  anti-analysis/anti-debugging/debugger-detection                      \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check     \n           GetTickCount [B0001.032]                                             \nfunction @ 0x140048C20\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x140048C29, 0x140048C65\n        mnemonic: cmp @ 0x140048C67\n      and:\n        mnemonic: sub @ 0x140048D73\n        mnemonic: cmp @ 0x140048D75\n    count(api(GetTickCount)): 2 or more @ 0x140048C57, 0x140048C5F, 0x140048D6D\nfunction @ 0x14004EC40\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x14004ED30\n        mnemonic: cmp @ 0x14004ED33\n      and:\n        mnemonic: sub @ 0x14004F0B6\n        mnemonic: cmp @ 0x14004F0CE\n    count(api(GetTickCount)): 2 or more @ 0x14004ED2A, 0x14004F38F\nfunction @ 0x14004FB70\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x14004FB73\n        mnemonic: cmp @ 0x14004FB7A\n      and:\n        mnemonic: sub @ 0x140050582\n        mnemonic: cmp @ 0x140050585\n      and:\n        mnemonic: sub @ 0x14004FF47\n        mnemonic: cmp @ 0x14004FF4A\n    count(api(GetTickCount)): 2 or more @ 0x14004FC03, 0x14004FCE8, 0x14004FEC9, 0x140050071, and 10 more...\nfunction @ 0x1400CE930\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x1400CE940, 0x1400CE969\n        mnemonic: cmp @ 0x1400CE96B\n      and:\n        mnemonic: sub @ 0x1400CEA98\n        mnemonic: cmp @ 0x1400CEA9A\n    count(api(GetTickCount)): 2 or more @ 0x1400CE95B, 0x1400CE963, 0x1400CEA92\nfunction @ 0x1400EC2E0\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x1400EC425\n        mnemonic: cmp @ 0x1400EC427\n    count(api(GetTickCount)): 2 or more @ 0x1400EC35B, 0x1400EC3B7, 0x1400EC41F\nfunction @ 0x1400ECAF0\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x1400ECCCC\n        mnemonic: cmp @ 0x1400ECCCE\n      and:\n        mnemonic: sub @ 0x1400ECC82\n        mnemonic: cmp @ 0x1400ECC84\n    count(api(GetTickCount)): 2 or more @ 0x1400ECC74, 0x1400ECC7C, 0x1400ECCC6\nfunction @ 0x1400EEFC0\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x1400EEFD0\n        mnemonic: cmp @ 0x1400EEFF8\n      and:\n        mnemonic: sub @ 0x1400EF5B9\n        mnemonic: cmp @ 0x1400EF5CA\n      and:\n        mnemonic: sub @ 0x1400EF659\n        mnemonic: cmp @ 0x1400EF66A\n    count(api(GetTickCount)): 2 or more @ 0x1400EF8BD, 0x1400EF90C\nfunction @ 0x1400F0200\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x1400F0210\n        mnemonic: cmp @ 0x1400F023B\n      and:\n        mnemonic: sub @ 0x1400F0265\n        mnemonic: cmp @ 0x1400F0268\n      and:\n        mnemonic: sub @ 0x1400F0555\n        mnemonic: cmp @ 0x1400F0558\n    count(api(GetTickCount)): 2 or more @ 0x1400F022F, 0x1400F02C4, 0x1400F05B4\nfunction @ 0x1400F5050\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x1400F50DC\n        mnemonic: cmp @ 0x1400F50E2\n    count(api(GetTickCount)): 2 or more @ 0x1400F50AF, 0x1400F50C3\nfunction @ 0x140106BB0\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x140107074\n        mnemonic: cmp @ 0x140107077\n      and:\n        mnemonic: sub @ 0x140106F33\n        mnemonic: cmp @ 0x140106F38\n      and:\n        mnemonic: sub @ 0x140106F21\n        mnemonic: cmp @ 0x140106F24\n      and:\n        mnemonic: sub @ 0x140106BBD\n        mnemonic: cmp @ 0x140106BE7\n      and:\n        mnemonic: sub @ 0x1401070BC\n        mnemonic: cmp @ 0x1401070C1\n      and:\n        mnemonic: sub @ 0x1401070AA\n        mnemonic: cmp @ 0x1401070AD\n      and:\n        mnemonic: sub @ 0x140106E3B\n        mnemonic: cmp @ 0x140106E3E\n      and:\n        mnemonic: sub @ 0x140106F01\n        mnemonic: cmp @ 0x140106F06\n      and:\n        mnemonic: sub @ 0x140106EEB\n        mnemonic: cmp @ 0x140106EEE\n      and:\n        mnemonic: sub @ 0x14010708A\n        mnemonic: cmp @ 0x14010708F\n    count(api(GetTickCount)): 2 or more @ 0x140106E35, 0x140107019\nfunction @ 0x14010D5A0\n  and:\n    basic block:\n      and:\n        mnemonic: sub @ 0x14010D5D8\n        mnemonic: cmp @ 0x14010D5DE\n    count(api(GetTickCount)): 2 or more @ 0x14010D5B4, 0x14010D5D0\n\ncheck for unmoving mouse cursor\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      BitsOfBinary                                                        \nscope       function                                                            \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::User Activity Based\n            Checks [T1497.002]                                                  \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection::Human User     \n            Check [B0009.012]                                                   \nreferences  https://www.joesecurity.org/blog/5852460122427342172                \nfunction @ 0x140141050\n  and:\n    count(api(GetCursorPos)): 2 or more @ 0x140141E92, 0x140141F69, 0x1401422ED, 0x140142433\n\nget geographical location (9 matches)\nnamespace  collection                                  \nauthor     moritz.raabe, michael.hunhoff@mandiant.com  \nscope      function                                    \natt&ck     Discovery::System Location Discovery [T1614]\nfunction @ 0x14005EEB0\n  or:\n    api: GetLocaleInfo @ 0x14005F5E5, 0x14006049D, 0x1400606CD\nfunction @ 0x1400DC370\n  or:\n    api: GetLocaleInfo @ 0x1400DC383\nfunction @ 0x1400DC3B0\n  or:\n    api: GetLocaleInfo @ 0x1400DC438\nfunction @ 0x14010F6C0\n  or:\n    api: GetLocaleInfo @ 0x14010F6FA\nfunction @ 0x14010F780\n  or:\n    api: GetLocaleInfo @ 0x14010F85B, 0x14010F8E3, 0x14010F955\nfunction @ 0x140111260\n  or:\n    api: GetLocaleInfo @ 0x1401112A9\nfunction @ 0x14017ADD0\n  or:\n    api: GetLocaleInfo @ 0x14017AE0D, 0x14017AE30, 0x14017AE5E\nfunction @ 0x14017D070\n  or:\n    api: GetLocaleInfo @ 0x14017D163\nfunction @ 0x1401B0A00\n  or:\n    api: GetLocaleInfo @ 0x1401B0A28\n\nparse credit card information\nnamespace  collection/credit-card    \nauthor     @_re_fox                  \nscope      function                  \nmbc        Data::Check String [C0019]\nfunction @ 0x14018D880\n  and:\n    not: = if a function also compares these non-hex characters it's most likely NOT \nparsing CC data\n      and:\n        match: parse credit card information/efff727f6e2f4f8da22050885c920578\n    3 or more:\n      instruction:\n        and:\n          mnemonic: cmp @ 0x14018E777\n          number: 0x5E = '^' (Track 1 separator) @ 0x14018E777\n        and:\n          mnemonic: cmp @ 0x14018E387\n          number: 0x5E = '^' (Track 1 separator) @ 0x14018E387\n      instruction:\n        and:\n          mnemonic: cmp @ 0x1401915B0\n          number: 0x3D = '=' (Track 2 separator) @ 0x1401915B0\n        and:\n          mnemonic: cmp @ 0x1401917F1\n          number: 0x3D = '=' (Track 2 separator) @ 0x1401917F1\n        and:\n          mnemonic: cmp @ 0x14018E5F2\n          number: 0x3D = '=' (Track 2 separator) @ 0x14018E5F2\n        and:\n          mnemonic: cmp @ 0x14018F1D5\n          number: 0x3D = '=' (Track 2 separator) @ 0x14018F1D5\n        and:\n          mnemonic: cmp @ 0x140190F89\n          number: 0x3D = '=' (Track 2 separator) @ 0x140190F89\n        and:\n          mnemonic: cmp @ 0x140190F99\n          number: 0x3D = '=' (Track 2 separator) @ 0x140190F99\n        and:\n          mnemonic: cmp @ 0x14018E2AB\n          number: 0x3D = '=' (Track 2 separator) @ 0x14018E2AB\n      instruction:\n        and:\n          mnemonic: cmp @ 0x14018FB02\n          number: 0x3F = '?' (Track 1 & 2 end sentinel) @ 0x14018FB02\n        and:\n          mnemonic: cmp @ 0x140190F25\n          number: 0x3F = '?' (Track 1 & 2 end sentinel) @ 0x140190F25\n        and:\n          mnemonic: cmp @ 0x140191538\n          number: 0x3F = '?' (Track 1 & 2 end sentinel) @ 0x140191538\n        and:\n          mnemonic: cmp @ 0x140190E3C\n          number: 0x3F = '?' (Track 1 & 2 end sentinel) @ 0x140190E3C\n        and:\n          mnemonic: cmp @ 0x140190A7D\n          number: 0x3F = '?' (Track 1 & 2 end sentinel) @ 0x140190A7D\n        and:\n          mnemonic: cmp @ 0x14018DECE\n          number: 0x3F = '?' (Track 1 & 2 end sentinel) @ 0x14018DECE\n        and:\n          mnemonic: cmp @ 0x140190F7F\n          number: 0x3F = '?' (Track 1 & 2 end sentinel) @ 0x140190F7F\n\nlog keystrokes (3 matches)\nnamespace  collection/keylog                                \nauthor     moritz.raabe@mandiant.com                        \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nfunction @ 0x1400E19A0\n  or:\n    api: AttachThreadInput @ 0x1400E1A34, 0x1400E1A4A\nfunction @ 0x1400F5390\n  or:\n    api: AttachThreadInput @ 0x1400E1A34, 0x1400E1A4A\nfunction @ 0x14015DFB0\n  or:\n    api: AttachThreadInput @ 0x1400E1A34, 0x1400E1A4A\n\nlog keystrokes via polling (6 matches)\nnamespace  collection/keylog                                \nauthor     michael.hunhoff@mandiant.com                     \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nmbc        Collection::Keylogging::Polling [F0002.002]      \nfunction @ 0x1400CC320\n  or:\n    api: GetKeyNameText @ 0x1400CC3C9\nfunction @ 0x1400DA590\n  or:\n    api: GetKeyState @ 0x1400DA594\nfunction @ 0x1400DFED0\n  or:\n    api: GetKeyState @ 0x1400DFEDB, 0x1400DFEF1, 0x1400DFF04\nfunction @ 0x1400E1B00\n  or:\n    api: GetKeyState @ 0x1400E1B0B, 0x1400E1B21, 0x1400E1B34, 0x1400E1B47, and 1 more...\nfunction @ 0x1400F8C10\n  or:\n    api: GetAsyncKeyState @ 0x1400F8C27\nfunction @ 0x1401001F0\n  or:\n    api: GetAsyncKeyState @ 0x1401003FE, 0x140100452, 0x1401004AA, 0x1401004F3, and 2 more...\n\ncapture webcam image\nnamespace  collection/webcam                \nauthor     johnk3r                          \nscope      function                         \natt&ck     Collection::Video Capture [T1125]\nfunction @ 0x140142A30\n  or:\n    basic block:\n      and:\n        api: SendMessage @ 0x140142BCE\n        number: 0x419 = WM_CAP_FILE_SAVEDIB @ 0x140142B92\n      and:\n        api: SendMessage @ 0x140142AD8\n        number: 0x419 = WM_CAP_FILE_SAVEDIB @ 0x140142ADE\n\nreceive data (4 matches)\nnamespace    communication                                                     \nauthor       william.ballenthin@mandiant.com                                   \nscope        function                                                          \nmbc          Command and Control::C2 Communication::Receive Data [B0030.002]   \ndescription  all known techniques for receiving data from a potential C2 server\nfunction @ 0x1400B74E0\n  or:\n    match: receive data on socket @ 0x1400B74E0\n      or:\n        api: recv @ 0x1400B758E\nfunction @ 0x1400B90C0\n  or:\n    match: receive data on socket @ 0x1400B90C0\n      or:\n        api: recv @ 0x1400B9157\nfunction @ 0x1400BCA70\n  or:\n    match: receive data on socket @ 0x1400BCA70\n      or:\n        api: recv @ 0x1400BCB1F\nfunction @ 0x1400C8B20\n  or:\n    match: receive data on socket @ 0x1400C8B20\n      or:\n        api: recv @ 0x1400C8B9C\n\nsend data (4 matches)\nnamespace    communication                                                 \nauthor       william.ballenthin@mandiant.com, joakim@intezer.com           \nscope        function                                                      \nmbc          Command and Control::C2 Communication::Send Data [B0030.001]  \ndescription  all known techniques for sending data to a potential C2 server\nfunction @ 0x1400B6780\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x1400B6780\n          or:\n            api: send @ 0x1400B67D5\nfunction @ 0x1400B7E80\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x1400B7E80\n          or:\n            api: send @ 0x1400B7ED2\nfunction @ 0x1400B95B0\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x1400B95B0\n          or:\n            api: send @ 0x1400B9618, 0x1400B970D\nfunction @ 0x1400C27F0\n  or:\n    and:\n      os: windows\n      or:\n        match: send data on socket @ 0x1400C27F0\n          or:\n            api: send @ 0x1400C2846, 0x1400C28F9\n\nresolve DNS\nnamespace  communication/dns                                                    \nauthor     william.ballenthin@mandiant.com, johnk3r, joakim@intezer.com,        \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::DNS Communication::Resolve [C0011.001]                \nfunction @ 0x1400DB440\n  or:\n    api: gethostbyname @ 0x1400DB4AB\n\nreference HTTP User-Agent string\nnamespace   communication/http                                                  \nauthor      @mr-tz                                                              \nscope       function                                                            \nmbc         Communication::HTTP Communication [C0002]                           \nreferences  https://www.useragents.me/,                                         \n            https://www.whatismybrowser.com/guides/the-latest-user-agent/       \nfunction @ 0x14016C930\n  or:\n    substring: Mozilla/5.0\n      - \"Mozilla/5.0 (compatible; Everything/%s; +https://www.voidtools.com/update/)\" @ 0x14016CA50\n\nconnect pipe\nnamespace  communication/named-pipe/connect                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com            \nscope      function                                                           \nmbc        Communication::Interprocess Communication::Connect Pipe [C0003.002]\nfunction @ 0x1400F0BE0\n  or:\n    api: ConnectNamedPipe @ 0x1400F125C\n\ncreate pipe\nnamespace  communication/named-pipe/create                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com           \nscope      function                                                          \nmbc        Communication::Interprocess Communication::Create Pipe [C0003.001]\nfunction @ 0x1400F0BE0\n  or:\n    api: CreateNamedPipe @ 0x1400F11E8, 0x1400F1222\n\nconnect socket (3 matches)\nnamespace    communication/socket                                               \nauthor       moritz.raabe@mandiant.com, joakim@intezer.com,                     \n             mrhafizfarhad@gmail.com                                            \nscope        basic block                                                        \ndescription  Detects socket connection attempts using common APIs or ConnectEx  \n             setup.                                                             \nbasic block @ 0x1400B78B3 in function 0x1400B77C0\n  or:\n    api: connect @ 0x1400B7921\nbasic block @ 0x1400BB924 in function 0x1400BB890\n  or:\n    api: connect @ 0x1400BB996\nbasic block @ 0x1400BBB42 in function 0x1400BB890\n  or:\n    api: connect @ 0x1400BBB56\n\nget socket information (3 matches)\nnamespace  communication/socket                                     \nauthor     michael.hunhoff@mandiant.com                             \nscope      function                                                 \natt&ck     Discovery::System Network Configuration Discovery [T1016]\nfunction @ 0x1400B9880\n  or:\n    api: getsockname @ 0x1400B99AE\nfunction @ 0x1400B9FD0\n  or:\n    api: getsockname @ 0x1400BA0D9, 0x1400BA110\nfunction @ 0x1400BB6C0\n  or:\n    api: getsockname @ 0x1400BB7F2\n\ninitialize Winsock library (3 matches)\nnamespace  communication/socket                                                 \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Initialize Winsock Library      \n           [C0001.009]                                                          \nfunction @ 0x1400B7AF0\n  or:\n    api: WSAStartup @ 0x1400B7D0E\nfunction @ 0x1400BD1E0\n  or:\n    api: WSAStartup @ 0x1400BD239\nfunction @ 0x1400C8F10\n  or:\n    api: WSAStartup @ 0x1400C8F69\n\nset socket configuration (6 matches)\nnamespace  communication/socket                                              \nauthor     michael.hunhoff@mandiant.com                                      \nscope      function                                                          \nmbc        Communication::Socket Communication::Set Socket Config [C0001.001]\nfunction @ 0x1400B77C0\n  or:\n    api: setsockopt @ 0x1400B78D6\nfunction @ 0x1400B9880\n  or:\n    api: setsockopt @ 0x1400B98FE\nfunction @ 0x1400B9FD0\n  or:\n    api: setsockopt @ 0x1400BA040\nfunction @ 0x1400BB890\n  or:\n    api: setsockopt @ 0x1400BB947, 0x1400BBA6C\nfunction @ 0x1400BCD00\n  or:\n    api: setsockopt @ 0x1400BCEED, 0x1400BD05F\nfunction @ 0x1400C8D50\n  or:\n    api: setsockopt @ 0x1400C8E3F\n\nreceive data on socket (4 matches)\nnamespace  communication/socket/receive                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \nmbc        Communication::Socket Communication::Receive Data [C0001.006]        \nfunction @ 0x1400B74E0\n  or:\n    api: recv @ 0x1400B758E\nfunction @ 0x1400B90C0\n  or:\n    api: recv @ 0x1400B9157\nfunction @ 0x1400BCA70\n  or:\n    api: recv @ 0x1400BCB1F\nfunction @ 0x1400C8B20\n  or:\n    api: recv @ 0x1400C8B9C\n\nsend data on socket (4 matches)\nnamespace  communication/socket/send                                            \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Communication::Socket Communication::Send Data [C0001.007]           \nfunction @ 0x1400B6780\n  or:\n    api: send @ 0x1400B67D5\nfunction @ 0x1400B7E80\n  or:\n    api: send @ 0x1400B7ED2\nfunction @ 0x1400B95B0\n  or:\n    api: send @ 0x1400B9618, 0x1400B970D\nfunction @ 0x1400C27F0\n  or:\n    api: send @ 0x1400C2846, 0x1400C28F9\n\ncreate UDP socket\nnamespace   communication/socket/udp/send                                       \nauthor      moritz.raabe@mandiant.com, joakim@intezer.com,                      \n            michael.hunhoff@mandiant.com                                        \nscope       basic block                                                         \nmbc         Communication::Socket Communication::Create UDP Socket [C0001.010]  \nreferences  https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-win…\n            https://man7.org/linux/man-pages/man2/socket.2.html                 \nbasic block @ 0x1400B9880 in function 0x1400B9880\n  or:\n    and:\n      number: 0x2 = AF_INET @ 0x1400B98B3\n      or:\n        number: 0x0 = protocol (default) @ 0x1400B98A7\n      or:\n        api: socket @ 0x1400B98C4\n\nencode data using Base64 (2 matches)\nnamespace  data-manipulation/encoding/base64                                    \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::Base64 [C0026.001]         \nfunction @ 0x1401899D0\n  or:\n    and:\n      mnemonic: shl @ 0x140189A3B, 0x140189A62, 0x140189A6A, 0x140189A93, and 15 more...\n      mnemonic: shr @ 0x140189A09\n      number: 0x3F = modulo 64 @ 0x140189A38, 0x140189A5C, 0x140189A5F, 0x140189A8D, and 11 more...\n      or:\n        number: 0x3D = '=' @ 0x140189DB5, 0x140189ED5\n      match: contain loop @ 0x1401899D0\n        or:\n          characteristic: loop @ 0x1401899D0\n          characteristic: tight loop @ 0x14018A1A3\n      optional:\n        number: 0x2 @ 0x140189A02, 0x140189A73, 0x140189CF4, 0x140189E84, and 7 more...\n        number: 0x3 @ 0x140189AB0, 0x140189AC6, 0x14018A261\n        number: 0x4 @ 0x140189AB9, 0x140189AF9, 0x140189C1C, 0x140189C4D, and 3 more...\n        number: 0x6 @ 0x140189A3B, 0x140189A62, 0x140189A93, 0x140189A9F, and 7 more...\n        number: 0xF @ 0x140189A58, 0x140189DDA\nfunction @ 0x14018D880\n  or:\n    and:\n      mnemonic: shl @ 0x14018DC2E, 0x14018DD63, 0x14018DFA7, 0x14018E4C1, and 50 more...\n      mnemonic: shr @ 0x14018D8E9, 0x14018D932, 0x14018E12D, 0x140191947, and 2 more...\n      number: 0x3F = modulo 64 @ 0x14018DD5D, 0x14018DECE, 0x14018E4B6, 0x14018E4CC, and 35 more...\n      or:\n        number: 0x3D = '=' @ 0x14018E2AB, 0x14018E5F2, 0x14018F1D5, 0x140190F89, and 5 more...\n      match: contain loop @ 0x14018D880\n        or:\n          characteristic: loop @ 0x14018D880\n          characteristic: tight loop @ 0x14018DB10, 0x14018DB80, 0x14018DCD0, 0x14018DDA0, and 29 more...\n      optional:\n        number: 0x2 @ 0x14018E06A, 0x14018E0C4, 0x14018E12D, 0x14018E4DE, and 53 more...\n        number: 0x3 @ 0x14018E343, 0x14018E369, 0x14018E37D, 0x14018E505, and 33 more...\n        number: 0x4 @ 0x14018DC7C, 0x14018E015, 0x14018E410, 0x14018E520, and 20 more...\n        number: 0x6 @ 0x14018DD63, 0x14018E198, 0x14018E20C, 0x14018E4C1, and 30 more...\n        number: 0xF @ 0x14018E4DB, 0x14018F075, 0x14018F59D, 0x14018FC51, and 7 more...\n\nencode data using XOR (3 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x1400B46C0 in function 0x1400B46A0\n  and:\n    characteristic: tight loop @ 0x1400B46C0\n    characteristic: nzxor @ 0x1400B46D1\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x140163724 in function 0x140163600\n  and:\n    characteristic: tight loop @ 0x140163724\n    characteristic: nzxor @ 0x140163724\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x140181A30 in function 0x140181A10\n  and:\n    characteristic: tight loop @ 0x140181A30\n    characteristic: nzxor @ 0x140181A44, 0x140181A4B\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nencrypt data using RC4 KSA (2 matches)\nnamespace  data-manipulation/encryption/rc4                                     \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Cryptography::Encrypt Data::RC4 [C0027.009], Cryptography::Encryption\n           Key::RC4 KSA [C0028.002]                                             \nfunction @ 0x14010D8C0\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x14010E3E0\n          or:\n            number: 0xFF @ 0x14010E3F8\n        and: = initialize S\n          characteristic: tight loop @ 0x14010E3A3\n          or:\n            number: 0xFF @ 0x14010E3BF\n        and: = initialize S\n          characteristic: tight loop @ 0x14010E460\n          or:\n            number: 0xFF @ 0x14010E464, 0x14010E47C, 0x14010E48B, 0x14010E4AA, and 2 more...\n      or: = modulo 256\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x14010E460, 0x14010E496, 0x14010E4C4\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: idiv @ 0x14010E3AE, 0x14010E3EC\nfunction @ 0x140123C80\n  or:\n    and:\n      basic block:\n        and: = initialize S\n          characteristic: tight loop @ 0x140124900\n          or:\n            number: 0xFF @ 0x140124900\n        and: = initialize S\n          characteristic: tight loop @ 0x140125420\n          or:\n            number: 0xFF @ 0x140125420\n        and: = initialize S\n          characteristic: tight loop @ 0x140125580\n          or:\n            number: 0xFF @ 0x140125580\n        and: = initialize S\n          characteristic: tight loop @ 0x1401254C0\n          or:\n            number: 0xFF @ 0x1401254C0\n        and: = initialize S\n          characteristic: tight loop @ 0x1401259D0\n          or:\n            number: 0xFF @ 0x1401259D0\n      or: = modulo 256\n        basic block:\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x140125A70, 0x140125A7F, 0x140125A8C\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n          and: = modulo via zero-extended mov from 8-bit register\n            count(mnemonic(movzx)): 2 or more @ 0x140125ACF, 0x140125ADE, 0x140125AED\n            not:\n              or:\n                mnemonic: shl\n                mnemonic: rol\n                characteristic: nzxor\n      or: = modulo key length\n        mnemonic: idiv @ 0x140123DA9, 0x140123F88, 0x140123FB5, 0x14012406B, and 5 more...\n\nencrypt data using speck\nnamespace   data-manipulation/encryption/speck                                  \nauthor      still@teamt5.org                                                    \nscope       function                                                            \natt&ck      Defense Evasion::Obfuscated Files or Information [T1027]            \nmbc         Defense Evasion::Obfuscated Files or                                \n            Information::Encryption-Standard Algorithm [E1027.m05]              \nreferences  https://github.com/maxmouchet/gfc/blob/8d818b0fe2023c92cbf8d7eb8967…\n            https://github.com/TheWover/donut/blob/47758d787209dd1744f58c140102…\nfunction @ 0x14018D880\n  and:\n    match: contain loop @ 0x14018D880\n      or:\n        characteristic: loop @ 0x14018D880\n        characteristic: tight loop @ 0x14018DB10, 0x14018DB80, 0x14018DCD0, 0x14018DDA0, and 29 more...\n    instruction:\n      and:\n        mnemonic: cmp @ 0x14018EB68\n        or:\n          number: 0x1A = encryption loop @ 0x14018EB68\n      and:\n        mnemonic: cmp @ 0x140191A62\n        or:\n          number: 0x1A = encryption loop @ 0x140191A62\n      and:\n        mnemonic: cmp @ 0x140191B45\n        or:\n          number: 0x1B = encryption loop @ 0x140191B45\n    instruction:\n      and:\n        mnemonic: cmp @ 0x140190EF2\n        or:\n          number: 0x3 = master key copy loop @ 0x140190EF2\n      and:\n        mnemonic: cmp @ 0x1401929E5\n        or:\n          number: 0x4 = master key copy loop @ 0x1401929E5\n    count(characteristic(nzxor)): 2 or more @ 0x14018D95D, 0x140191E1E\n    2 or more:\n      mnemonic: shl @ 0x14018DC2E, 0x14018DD63, 0x14018DFA7, 0x14018E4C1, and 50 more...\n      mnemonic: imul @ 0x14018FE47, 0x14018FE4B, 0x140190008, 0x140190019\n\nauthenticate HMAC\nnamespace   data-manipulation/hmac                                              \nauthor      moritz.raabe@mandiant.com                                           \nscope       function                                                            \nmbc         Cryptography::Hashed Message Authentication Code [C0061]            \nreferences  https://tools.ietf.org/html/rfc2104,                                \n            https://tools.ietf.org/html/rfc4634, https://github.com/ogay/hmac   \nfunction @ 0x14018D880\n  and:\n    number: 0x36 = inner padding byte value @ 0x14019312B\n    number: 0x5C = outer padding byte value @ 0x14018DBE0, 0x14018E2C0, 0x14018E32F, 0x14018E5AC, and 13 more...\n    match: contain loop @ 0x14018D880\n      or:\n        characteristic: loop @ 0x14018D880\n        characteristic: tight loop @ 0x14018DB10, 0x14018DB80, 0x14018DCD0, 0x14018DDA0, and 29 more...\n    count(characteristic(nzxor)): 2 or more @ 0x14018D95D, 0x140191E1E\n    optional: = block size\n      number: 0x40 = MD5, SHA-1, SHA-224, or SHA-256 @ 0x14018E188, 0x14018EC0E, 0x14018EC53, 0x14018EFDA, and 1 more...\n      number: 0x80 = SHA-384 or SHA-512 @ 0x14018DCC2, 0x14018DCEE, 0x14018DE7B, 0x14018DE91, and 8 more...\n\ncontains PDB path\nnamespace  executable/pe/pdb        \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nregex: /:\\\\.*\\.pdb/\n  - \"c:\\\\dev\\\\Everything-1.4\\\\x64\\\\Release\\\\Everything.pdb\" @ file+0x1EAAA0\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x1400C79B0\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x1400C7A69\n        api: LockResource @ 0x1400C7A86\n      optional:\n        or:\n          api: FindResource @ 0x1400C7A32\n        api: SizeofResource @ 0x1400C7A4E\n        api: FreeResource @ 0x1400C7C07\n\naccept command line arguments (6 matches)\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x140006010\n  or:\n    api: GetCommandLine @ 0x140006049\nfunction @ 0x1400B4020\n  or:\n    api: GetCommandLine @ 0x1400B40E8\nfunction @ 0x1400CE620\n  or:\n    api: GetCommandLine @ 0x1400CE706\nfunction @ 0x1400CF020\n  or:\n    api: GetCommandLine @ 0x1400CF0A6\nfunction @ 0x1400CF8C0\n  or:\n    api: GetCommandLine @ 0x1400CF0A6\nfunction @ 0x1401AB000\n  or:\n    api: GetCommandLine @ 0x1401AB1E6\n\nopen clipboard (6 matches)\nnamespace  host-interaction/clipboard        \nauthor     michael.hunhoff@mandiant.com      \nscope      function                          \natt&ck     Collection::Clipboard Data [T1115]\nfunction @ 0x1400D8AA0\n  and:\n    api: OpenClipboard @ 0x1400D8ABE\n    optional:\n      api: CloseClipboard @ 0x1400D8BA3\nfunction @ 0x1400F8450\n  and:\n    api: OpenClipboard @ 0x1400F84B3\n    optional:\n      api: CloseClipboard @ 0x1400F84C3\nfunction @ 0x140102050\n  and:\n    api: OpenClipboard @ 0x14010211A, 0x1401021AC\n    optional:\n      api: CloseClipboard @ 0x140102138, 0x1401021CA\nfunction @ 0x140104520\n  and:\n    api: OpenClipboard @ 0x140104597\n    optional:\n      api: CloseClipboard @ 0x140104605\nfunction @ 0x1401046A0\n  and:\n    api: OpenClipboard @ 0x1401046DB\n    optional:\n      api: CloseClipboard @ 0x1401047B8, 0x1401047C8\nfunction @ 0x140106BB0\n  and:\n    api: OpenClipboard @ 0x14010715B\n    optional:\n      api: CloseClipboard @ 0x14010734B\n\nread clipboard data\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Collection::Clipboard Data [T1115]                                  \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ 0x140106BB0\n  and:\n    optional:\n      match: open clipboard @ 0x140106BB0\n        and:\n          api: OpenClipboard @ 0x14010715B\n          optional:\n            api: CloseClipboard @ 0x14010734B\n      match: contain loop @ 0x140106BB0\n        or:\n          characteristic: loop @ 0x140106BB0\n      api: GlobalLock @ 0x140107183, 0x1401072BF\n      api: GlobalUnlock @ 0x1401071C2, 0x14010724E, 0x140107345\n    or:\n      basic block:\n        and:\n          api: GetClipboardData @ 0x14010716C\n          optional:\n            number: 0xD = CF_UNICODETEXT @ 0x140107169\n        and:\n          api: GetClipboardData @ 0x1401072AA\n\nwrite clipboard data (4 matches)\nnamespace   host-interaction/clipboard                                          \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \nmbc         Impact::Clipboard Modification [E1510]                              \nreferences  https://learn.microsoft.com/en-us/windows/win32/dataxchg/using-the-…\nfunction @ 0x1400D8AA0\n  and:\n    optional:\n      match: open clipboard @ 0x1400D8AA0\n        and:\n          api: OpenClipboard @ 0x1400D8ABE\n          optional:\n            api: CloseClipboard @ 0x1400D8BA3\n      api: EmptyClipboard @ 0x1400D8AD4\n    or:\n      api: SetClipboardData @ 0x1400D8B44, 0x1400D8B9D\nfunction @ 0x140102050\n  and:\n    optional:\n      match: open clipboard @ 0x140102050\n        and:\n          api: OpenClipboard @ 0x14010211A, 0x1401021AC\n          optional:\n            api: CloseClipboard @ 0x140102138, 0x1401021CA\n      api: EmptyClipboard @ 0x140102124, 0x1401021B6\n    or:\n      api: SetClipboardData @ 0x140102132, 0x1401021C4\nfunction @ 0x140104520\n  and:\n    optional:\n      match: open clipboard @ 0x140104520\n        and:\n          api: OpenClipboard @ 0x140104597\n          optional:\n            api: CloseClipboard @ 0x140104605\n      api: EmptyClipboard @ 0x1401045A1\n    or:\n      api: SetClipboardData @ 0x1401045BC, 0x1401045FA\nfunction @ 0x1401046A0\n  and:\n    optional:\n      match: open clipboard @ 0x1401046A0\n        and:\n          api: OpenClipboard @ 0x1401046DB\n          optional:\n            api: CloseClipboard @ 0x1401047B8, 0x1401047C8\n      api: EmptyClipboard @ 0x1401046E9\n    or:\n      api: SetClipboardData @ 0x140104704, 0x140104740, 0x1401047AD\n\ninteract with driver via IOCTL (32 matches)\nnamespace  host-interaction/driver  \nauthor     moritz.raabe@mandiant.com\nscope      instruction              \ninstruction @ 0x14005003A\n  or:\n    api: DeviceIoControl @ 0x14005003A\ninstruction @ 0x140057DAE\n  or:\n    api: DeviceIoControl @ 0x140057DAE\ninstruction @ 0x140057F7A\n  or:\n    api: DeviceIoControl @ 0x140057F7A\ninstruction @ 0x1400B337A\n  or:\n    api: DeviceIoControl @ 0x1400B337A\ninstruction @ 0x1400B34C4\n  or:\n    api: DeviceIoControl @ 0x1400B34C4\ninstruction @ 0x1400B351A\n  or:\n    api: DeviceIoControl @ 0x1400B351A\ninstruction @ 0x1400CFD1D\n  or:\n    api: DeviceIoControl @ 0x1400CFD1D\ninstruction @ 0x1400CFEDB\n  or:\n    api: DeviceIoControl @ 0x1400CFEDB\ninstruction @ 0x1400CFEDB\n  or:\n    api: DeviceIoControl @ 0x1400CFEDB\ninstruction @ 0x1400CFF8D\n  or:\n    api: DeviceIoControl @ 0x1400CFF8D\ninstruction @ 0x1400CFF8D\n  or:\n    api: DeviceIoControl @ 0x1400CFF8D\ninstruction @ 0x1400D0721\n  or:\n    api: DeviceIoControl @ 0x1400D0721\ninstruction @ 0x1400D0721\n  or:\n    api: DeviceIoControl @ 0x1400D0721\ninstruction @ 0x1400D84FB\n  or:\n    api: DeviceIoControl @ 0x1400D84FB\ninstruction @ 0x1400D947D\n  or:\n    api: DeviceIoControl @ 0x1400D947D\ninstruction @ 0x1400D953B\n  or:\n    api: DeviceIoControl @ 0x1400D953B\ninstruction @ 0x1400D9622\n  or:\n    api: DeviceIoControl @ 0x1400D9622\ninstruction @ 0x1400DBE20\n  or:\n    api: DeviceIoControl @ 0x1400DBE20\ninstruction @ 0x1400DFCCD\n  or:\n    api: DeviceIoControl @ 0x1400DFCCD\ninstruction @ 0x1400E03E3\n  or:\n    api: DeviceIoControl @ 0x1400E03E3\ninstruction @ 0x1400E0464\n  or:\n    api: DeviceIoControl @ 0x1400E0464\ninstruction @ 0x1400E04F4\n  or:\n    api: DeviceIoControl @ 0x1400E04F4\ninstruction @ 0x1400E0573\n  or:\n    api: DeviceIoControl @ 0x1400E0573\ninstruction @ 0x1400E0605\n  or:\n    api: DeviceIoControl @ 0x1400E0605\ninstruction @ 0x1400E0698\n  or:\n    api: DeviceIoControl @ 0x1400E0698\ninstruction @ 0x1400E0739\n  or:\n    api: DeviceIoControl @ 0x1400E0739\ninstruction @ 0x1400E07C8\n  or:\n    api: DeviceIoControl @ 0x1400E07C8\ninstruction @ 0x1400E0852\n  or:\n    api: DeviceIoControl @ 0x1400E0852\ninstruction @ 0x1400E5F6D\n  or:\n    api: DeviceIoControl @ 0x1400E5F6D\ninstruction @ 0x1400EF1C6\n  or:\n    api: DeviceIoControl @ 0x1400EF1C6\ninstruction @ 0x1400EF9F2\n  or:\n    api: DeviceIoControl @ 0x1400EF9F2\ninstruction @ 0x1400F04B5\n  or:\n    api: DeviceIoControl @ 0x1400F04B5\n\nquery environment variable (2 matches)\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x1400E0A40\n  or:\n    api: ExpandEnvironmentStrings @ 0x1400E0AF6, 0x1400E0B34\nfunction @ 0x1401AE2A0\n  or:\n    api: GetEnvironmentStrings @ 0x1401AE2B9, 0x1401AE2E8, 0x1401AE2FC, 0x1401AE3E9\n\nget common file path (4 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x1400B44E0\n  or:\n    api: GetTempPath @ 0x1400B4522\nfunction @ 0x1400D9990\n  or:\n    api: SHGetSpecialFolderLocation @ 0x1400D99BB\nfunction @ 0x1400E0230\n  or:\n    api: GetSystemDirectory @ 0x1400E02A9\nfunction @ 0x1400E08B0\n  or:\n    api: GetWindowsDirectory @ 0x1400E095B, 0x1400E0990\n\nget file system object information\nnamespace  host-interaction/file-system                   \nauthor     michael.hunhoff@mandiant.com                   \nscope      basic block                                    \natt&ck     Discovery::File and Directory Discovery [T1083]\nbasic block @ 0x1400DB18C in function 0x1400DB150\n  or:\n    api: SHGetFileInfo @ 0x1400DB1A0\n\ncopy file\nnamespace  host-interaction/file-system/copy                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Copy File [C0045]                         \nfunction @ 0x1400CC920\n  or:\n    api: CopyFile @ 0x1400CC9F3\n\ncreate directory\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x1400D5860\n  or:\n    api: CreateDirectory @ 0x1400D58EE, 0x1400D590D\n\ndelete directory (3 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ 0x1400D5430\n  or:\n    api: RemoveDirectory @ 0x1400D5474\nfunction @ 0x1400D5610\n  or:\n    api: RemoveDirectory @ 0x1400D56C6\nfunction @ 0x1400D7B50\n  or:\n    api: RemoveDirectory @ 0x1400D7B8A\n\ndelete file (5 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x1400D5430\n  or:\n    api: DeleteFile @ 0x1400D547C\nfunction @ 0x1400D5610\n  or:\n    api: DeleteFile @ 0x1400D56CE\nfunction @ 0x1400D7AC0\n  or:\n    api: DeleteFile @ 0x1400D7AFA\nfunction @ 0x1400D8840\n  or:\n    basic block:\n      and:\n        number: 0x3 = FO_DELETE @ 0x1400D886C\n        or:\n          api: SHFileOperation @ 0x1400D889D\nfunction @ 0x140165280\n  or:\n    basic block:\n      and:\n        number: 0x3 = FO_DELETE @ 0x1401657BF\n        or:\n          api: SHFileOperation @ 0x140165820\n\ncheck if file exists (8 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x1400D5550\n  or:\n    basic block:\n      and:\n        api: GetLastError @ 0x1400D55CE\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1400D55D4\n            number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x1400D55D4\nfunction @ 0x1400D5770\n  or:\n    basic block:\n      and:\n        api: GetLastError @ 0x1400D580B\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1400D5811\n            number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x1400D5811\nfunction @ 0x1400D5860\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x1400D58A9\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1400D58AF\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x1400D58AF\nfunction @ 0x1400D72F0\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x1400D731C\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1400D7322\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x1400D7322\nfunction @ 0x1400D8350\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x1400D838A\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1400D839C\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x1400D839C\nfunction @ 0x1400D83D0\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x1400D840A\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1400D841E\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x1400D841E\nfunction @ 0x1400D8440\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x1400D847F\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1400D8491\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x1400D8491\nfunction @ 0x1400DBC10\n  or:\n    basic block:\n      and:\n        api: GetLastError @ 0x1400DBCA9\n        instruction:\n          and:\n            mnemonic: cmp @ 0x1400DBCAF\n            number: 0x2 = ERROR_FILE_NOT_FOUND @ 0x1400DBCAF\n\nget file attributes (5 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x1400D5894 in function 0x1400D5860\n  or:\n    api: GetFileAttributes @ 0x1400D58A9\nbasic block @ 0x1400D72F0 in function 0x1400D72F0\n  or:\n    api: GetFileAttributes @ 0x1400D731C\nbasic block @ 0x1400D8350 in function 0x1400D8350\n  or:\n    api: GetFileAttributes @ 0x1400D838A\nbasic block @ 0x1400D83D0 in function 0x1400D83D0\n  or:\n    api: GetFileAttributes @ 0x1400D840A\nbasic block @ 0x1400D8463 in function 0x1400D8440\n  or:\n    api: GetFileAttributes @ 0x1400D847F\n\nget file size (2 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x1400D78D0\n  or:\n    api: GetFileSize @ 0x1400D78DD\nfunction @ 0x1400DBC10\n  or:\n    api: GetFileSize @ 0x1400DBCDC\n\nmove file (4 matches)\nnamespace  host-interaction/file-system/move                      \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Move File [C0063]                         \nfunction @ 0x1400D5610\n  or:\n    api: MoveFile @ 0x1400D56E1\n    api: MoveFileEx @ 0x1400D568D\nfunction @ 0x140109640\n  or:\n    basic block:\n      and:\n        number: 0x1 = FO_MOVE @ 0x140109DAE\n        or:\n          api: SHFileOperation @ 0x140109DC7\nfunction @ 0x14013C810\n  or:\n    basic block:\n      and:\n        number: 0x1 = FO_MOVE @ 0x140109DAE\n        or:\n          api: SHFileOperation @ 0x140109DC7\nfunction @ 0x14013CC30\n  or:\n    basic block:\n      and:\n        number: 0x1 = FO_MOVE @ 0x140109DAE\n        or:\n          api: SHFileOperation @ 0x140109DC7\n\nread file on Windows (25 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x140004610\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x14000467D\nfunction @ 0x140004770\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400047C4\nfunction @ 0x1400048C0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x140004914\nfunction @ 0x140004D80\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x140004DD4\nfunction @ 0x140004ED0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x140004DD4\nfunction @ 0x1400B3660\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400D025B\nfunction @ 0x1400B8F10\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400B8F9E\nfunction @ 0x1400BE010\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400BE08B\nfunction @ 0x1400BE0F0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400BE13E\nfunction @ 0x1400BE1E0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400BE21B\nfunction @ 0x1400BE4D0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400BE50B\nfunction @ 0x1400BE570\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400BE5F7\nfunction @ 0x1400C2DC0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400C2EF7\nfunction @ 0x1400CB5B0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400CB690, 0x1400CB6E0, 0x1400CB74B, 0x1400CBBD8\nfunction @ 0x1400CFA70\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400CFAD3\nfunction @ 0x1400CFD90\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400CFDD3\nfunction @ 0x1400CFE80\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400D025B\nfunction @ 0x1400D13A0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400D1C93\nfunction @ 0x1400DBC10\n  or:\n    and:\n      os: windows\n      optional:\n        and:\n          number: 0x80000000 = GENERIC_READ @ 0x1400DBC76\n          match: create or open file @ 0x1400DBC90\n            or:\n              api: CreateFile @ 0x1400DBC90\n      or:\n        api: ReadFile @ 0x1400DBD6F\nfunction @ 0x1400DC9B0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400DC9FD\nfunction @ 0x1400E5550\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400E555D\nfunction @ 0x1400E5D50\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400E5DAA\nfunction @ 0x1400EA6D0\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400EA817\nfunction @ 0x1400F0070\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x1400F00DF\nfunction @ 0x14017B500\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x14017B58F\n\nwrite file on Windows (9 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x1400B3B20\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x1400B3D07\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x1400B3DB0\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x1400B3C87\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x1400B3E68\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x1400B3F05\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x1400B3F47\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x1400B3C2F\n          or:\n            number: 0x2 = FILE_WRITE_DATA @ 0x1400B3DDF\n      or:\n        api: WriteFile @ 0x1400B3C06, 0x1400B3C6A, 0x1400B3C92, 0x1400B3F31, and 1 more...\nfunction @ 0x1400D54C0\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x1400D550C\nfunction @ 0x1400EA560\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x1400EA5F9\nfunction @ 0x1400EE1D0\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x1400EE261\nfunction @ 0x1400EE370\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x1400EE261\nfunction @ 0x1400EE440\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x1400EE261\nfunction @ 0x1400EE680\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x1400EE261\nfunction @ 0x1401AC870\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x1401ACA8F\nfunction @ 0x1401ACAB0\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x1401ACB7C\n\nenumerate gui resources\nnamespace  host-interaction/gui                           \nauthor     johnk3r, anushka.virgaonkar@mandiant.com       \nscope      function                                       \natt&ck     Discovery::Application Window Discovery [T1010]\nfunction @ 0x1401048B0\n  or:\n    api: EnumWindows @ 0x1401048C9\n\nset application hook (4 matches)\nnamespace  host-interaction/gui        \nauthor     michael.hunhoff@mandiant.com\nscope      instruction                 \ninstruction @ 0x1400CF5E6\n  or:\n    api: SetWindowsHookEx @ 0x1400CF5E6\ninstruction @ 0x1400CF5E6\n  or:\n    api: SetWindowsHookEx @ 0x1400CF5E6\ninstruction @ 0x1400CF7BF\n  or:\n    api: UnhookWindowsHookEx @ 0x1400CF7BF\ninstruction @ 0x1400CF7BF\n  or:\n    api: UnhookWindowsHookEx @ 0x1400CF7BF\n\nchange the wallpaper\nnamespace  host-interaction/gui/session       \nauthor     @_re_fox                           \nscope      basic block                        \nmbc        Operating System::Wallpaper [C0035]\nbasic block @ 0x14013D52F in function 0x14013D4D0\n  and:\n    api: SystemParametersInfo @ 0x14013D54C\n    number: 0x14 = SPI_SETDESKWALLPAPER @ 0x14013D57B\n    number: 0x3 = SPIF_SENDWININICHANGE | SPIF_UPDATEINIFILE @ 0x14013D565\n\nfind graphical window\nnamespace  host-interaction/gui/window/find               \nauthor     moritz.raabe@mandiant.com                      \nscope      instruction                                    \natt&ck     Discovery::Application Window Discovery [T1010]\ninstruction @ 0x1400D81AC\n  or:\n    api: FindWindow @ 0x1400D81AC\n\nget graphical window text (7 matches)\nnamespace  host-interaction/gui/window/get-text           \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \nmbc        Discovery::Application Window Discovery [E1010]\nfunction @ 0x1400D96C0\n  or:\n    and:\n      api: GetWindowText @ 0x1400D971E\nfunction @ 0x1400D9770\n  or:\n    and:\n      api: GetWindowText @ 0x1400D97D4\nfunction @ 0x14015CFD0\n  or:\n    and:\n      or:\n        basic block:\n          and:\n            number: 0xD = WM_GETTEXT @ 0x14015DBE5\n            api: SendMessage @ 0x14015D4FC, 0x14015D584, 0x14015D609, 0x14015D68E, and 15 more...\nfunction @ 0x1401632A0\n  or:\n    and:\n      or:\n        basic block:\n          and:\n            number: 0xD = WM_GETTEXT @ 0x140163310\n            api: SendMessage @ 0x1401632EE, 0x14016331D\nfunction @ 0x140163900\n  or:\n    and:\n      api: GetWindowText @ 0x1401639C5\nfunction @ 0x140163B70\n  or:\n    and:\n      api: GetWindowText @ 0x140163C25\nfunction @ 0x140165280\n  or:\n    and:\n      or:\n        basic block:\n          and:\n            number: 0xD = WM_GETTEXT @ 0x140166D6E\n            api: SendMessage @ 0x140166D43, 0x140166D76\n          and:\n            number: 0xD = WM_GETTEXT @ 0x14016576A\n            api: SendMessage @ 0x140165748, 0x140165772\n          and:\n            number: 0xD = WM_GETTEXT @ 0x140166C8A\n            api: SendMessage @ 0x140166C5F, 0x140166C92\n\nhide graphical window\nnamespace  host-interaction/gui/window/hide                          \nauthor     michael.hunhoff@mandiant.com                              \nscope      basic block                                               \natt&ck     Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\nbasic block @ 0x140102610 in function 0x140102610\n  and:\n    number: 0x0 = SW_HIDE @ 0x140102641\n    api: ShowWindow @ 0x140102633\n\nget keyboard layout (2 matches)\nnamespace  host-interaction/hardware/keyboard                                   \nauthor     michael.hunhoff@mandiant.com                                         \nscope      function                                                             \natt&ck     Discovery::System Location Discovery::System Language Discovery      \n           [T1614.001]                                                          \nfunction @ 0x1400CC320\n  and:\n    or:\n      api: GetKeyboardLayout @ 0x1400CC368\nfunction @ 0x1400DC3B0\n  and:\n    optional:\n      api: GetLocaleInfo @ 0x1400DC438\n    or:\n      api: GetKeyboardLayoutList @ 0x1400DC3C6, 0x1400DC3F2\n\nget disk information (6 matches)\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ 0x1400D2A60\n  or:\n    api: QueryDosDevice @ 0x1400D318C\nfunction @ 0x1400D7010\n  or:\n    api: GetVolumeInformation @ 0x1400D70D1\nfunction @ 0x1400D8100\n  or:\n    api: GetDriveType @ 0x1400D813A\nfunction @ 0x1400D91B0\n  or:\n    api: GetDriveType @ 0x1400D92A3\n    api: GetVolumeInformation @ 0x1400D9237\nfunction @ 0x1400DC080\n  or:\n    api: QueryDosDevice @ 0x1400DC107\nfunction @ 0x1400E6E80\n  or:\n    api: QueryDosDevice @ 0x1400E757C\n\nget disk size\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ 0x1400D7270\n  or:\n    api: GetDiskFreeSpace @ 0x1400D729D\n\nget volume information via IOCTL (2 matches)\nnamespace   host-interaction/hardware/storage                                   \nauthor      william.ballenthin@mandiant.com                                     \nscope       basic block                                                         \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-…\nbasic block @ 0x1400CFE80 in function 0x1400CFE80\n  and:\n    number: 0x90064 = FSCTL_GET_NTFS_VOLUME_DATA @ 0x1400CFEC6\n    or:\n      match: interact with driver via IOCTL @ 0x1400CFEDB\n        or:\n          api: DeviceIoControl @ 0x1400CFEDB\nbasic block @ 0x1400CFE80 in function 0x1400CFE80\n  and:\n    number: 0x90064 = FSCTL_GET_NTFS_VOLUME_DATA @ 0x1400CFEC6\n    or:\n      match: interact with driver via IOCTL @ 0x1400CFEDB\n        or:\n          api: DeviceIoControl @ 0x1400CFEDB\n\naccess the Windows event log\nnamespace  host-interaction/log/winevt/access                           \nauthor     moritz.raabe@mandiant.com                                    \nscope      function                                                     \nmbc        Discovery::File and Directory Discovery::Log File [E1083.m01]\nfunction @ 0x1400B4190\n  or:\n    api: ReportEvent @ 0x1400B4296\n\ncheck mutex on Windows\nnamespace  host-interaction/mutex                         \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      function                                       \nmbc        Process::Check Mutex [C0043]                   \nfunction @ 0x1400CE930\n  or:\n    and:\n      match: create or open mutex on Windows @ 0x1400CEA39\n        or:\n          api: CreateMutex @ 0x1400CEA39\n      or:\n        basic block:\n          and:\n            api: GetLastError @ 0x1400CEA46\n            or:\n              number: 0xB7 = ERROR_ALREADY_EXISTS @ 0x1400CEA5B\n\ncreate or open mutex on Windows\nnamespace  host-interaction/mutex                                               \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com,          \n           mehunhoff@google.com                                                 \nscope      instruction                                                          \nmbc        Process::Create Mutex [C0042]                                        \ninstruction @ 0x1400CEA39\n  or:\n    api: CreateMutex @ 0x1400CEA39\n\nget local IPv4 addresses (3 matches)\nnamespace  host-interaction/network/address                                   \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com, mehunhoff@google.com\nscope      function                                                           \natt&ck     Discovery::System Network Configuration Discovery [T1016]          \nfunction @ 0x1400B9880\n  or:\n    api: getsockname @ 0x1400B99AE\nfunction @ 0x1400B9FD0\n  or:\n    api: getsockname @ 0x1400BA0D9, 0x1400BA110\nfunction @ 0x1400BB6C0\n  or:\n    api: getsockname @ 0x1400BB7F2\n\nget hostname\nnamespace  host-interaction/os/hostname                                         \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com,                       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Information Discovery [T1082]                      \nmbc        Discovery::System Information Discovery [E1082]                      \nfunction @ 0x1400D6F40\n  or:\n    api: GetComputerName @ 0x1400D6F6F\n\nget system information on Windows\nnamespace  host-interaction/os/info                       \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com  \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x1400E4260\n  and:\n    os: windows\n    or:\n      api: GetSystemInfo @ 0x1400E42C2\n\ncreate process on Windows (2 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x1400D7D15 in function 0x1400D7BE0\n  or:\n    api: ShellExecuteEx @ 0x1400D7E95\nbasic block @ 0x1400E3562 in function 0x1400E3410\n  or:\n    api: ShellExecuteEx @ 0x1400E36EA\n\nterminate process (7 matches)\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x1400B4190\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x1400B431F\nfunction @ 0x1400CCA90\n  or:\n    and:\n      optional:\n        match: open process @ 0x1400CCAC0\n          or:\n            api: OpenProcess @ 0x1400CCAD1\n      or:\n        api: TerminateProcess @ 0x1400CCB07\nfunction @ 0x1400CD290\n  or:\n    and:\n      optional:\n        match: open process @ 0x1400CD6E9, 0x1400CD82F\n          or:\n            api: OpenProcess @ 0x1400CD6F5\n          or:\n            api: OpenProcess @ 0x1400CD83B\n      or:\n        api: TerminateProcess @ 0x1400CD72B, 0x1400CD871\nfunction @ 0x1400EC810\n  or:\n    and:\n      optional:\n        match: open process @ 0x1400EC957, 0x1400EC971\n          or:\n            api: OpenProcess @ 0x1400EC97D\n          or:\n            api: OpenProcess @ 0x1400EC963\n      or:\n        api: TerminateProcess @ 0x1400EC9B5\nfunction @ 0x1400ECD90\n  or:\n    and:\n      optional:\n        match: open process @ 0x1400ECF03, 0x1400ECF1D\n          or:\n            api: OpenProcess @ 0x1400ECF0F\n          or:\n            api: OpenProcess @ 0x1400ECF29\n      or:\n        api: TerminateProcess @ 0x1400ECF61\nfunction @ 0x1401AB3A7\n  or:\n    and:\n      or:\n        api: TerminateProcess @ 0x1401AB43C\nfunction @ 0x1401AC760\n  or:\n    and:\n      or:\n        api: TerminateProcess @ 0x1401AC843\n\nquery or enumerate registry key (2 matches)\nnamespace  host-interaction/registry                                 \nauthor     michael.hunhoff@mandiant.com                              \nscope      function                                                  \natt&ck     Discovery::Query Registry [T1012]                         \nmbc        Operating System::Registry::Query Registry Key [C0036.005]\nfunction @ 0x1400DA6F0\n  and:\n    optional:\n      match: create or open registry key @ 0x1400DA6F0\n        or:\n          api: RegOpenKeyEx @ 0x1400DA73C\n    or:\n      api: RegEnumKey @ 0x1400DA75C, 0x1400DA797\nfunction @ 0x140110070\n  and:\n    or:\n      api: RegEnumKey @ 0x14011010A, 0x140110271\n\nquery or enumerate registry value (5 matches)\nnamespace  host-interaction/registry                                            \nauthor     william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com,       \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::Query Registry [T1012]                                    \nmbc        Operating System::Registry::Query Registry Value [C0036.006]         \nfunction @ 0x1400DA9A0\n  and:\n    optional:\n      match: create or open registry key @ 0x1400DA9A0\n        or:\n          api: RegOpenKeyEx @ 0x1400DAA09\n    or:\n      api: RegQueryValueEx @ 0x1400DAA9F\nfunction @ 0x1400DAB40\n  and:\n    or:\n      api: SHRegGetUSValue @ 0x1400DABE8\nfunction @ 0x1400DAC60\n  and:\n    or:\n      api: SHRegGetUSValue @ 0x1400DAD03\nfunction @ 0x1400DCB00\n  and:\n    optional:\n      match: create or open registry key @ 0x1400DCB00\n        or:\n          api: RegOpenKeyEx @ 0x1400DCB71\n    or:\n      api: RegQueryValueEx @ 0x1400DCBE5\nfunction @ 0x140110070\n  and:\n    or:\n      api: RegQueryValue @ 0x14011015B, 0x14011019C\n\nset registry value (2 matches)\nnamespace  host-interaction/registry/create                        \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com \nscope      function                                                \nmbc        Operating System::Registry::Set Registry Key [C0036.001]\nfunction @ 0x1400E24D0\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x1400E24D0\n          or:\n            api: RegCreateKeyEx @ 0x1400E2543\n      or:\n        api: RegSetValueEx @ 0x1400E25CE\nfunction @ 0x1400E2610\n  or:\n    and:\n      optional:\n        match: create or open registry key @ 0x1400E2610\n          or:\n            api: RegCreateKeyEx @ 0x1400E2683\n      or:\n        api: RegSetValueEx @ 0x1400E26E9\n\ndelete registry key (2 matches)\nnamespace  host-interaction/registry/delete                                \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\nscope      function                                                        \natt&ck     Defense Evasion::Modify Registry [T1112]                        \nmbc        Operating System::Registry::Delete Registry Key [C0036.002]     \nfunction @ 0x1400DA6F0\n  and:\n    optional:\n      match: create or open registry key @ 0x1400DA6F0\n        or:\n          api: RegOpenKeyEx @ 0x1400DA73C\n    or:\n      api: RegDeleteKey @ 0x1400DA7E2\nfunction @ 0x1400DA820\n  and:\n    or:\n      api: RegDeleteKey @ 0x1400DA8A7\n\ndelete registry value\nnamespace  host-interaction/registry/delete                             \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Defense Evasion::Modify Registry [T1112]                     \nmbc        Operating System::Registry::Delete Registry Value [C0036.007]\nfunction @ 0x1400E2720\n  and:\n    optional:\n      match: create or open registry key @ 0x1400E2780\n        or:\n          api: RegOpenKeyEx @ 0x1400E27B7\n    or:\n      api: RegDeleteValue @ 0x1400E27E0\n\nrun as service\nnamespace  host-interaction/service                                             \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com              \nscope      file                                                                 \nmbc        Anti-Behavioral Analysis::Conditional Execution::Runs as Service     \n           [B0025.007]                                                          \nor:\n  function:\n    or:\n      api: RegisterServiceCtrlHandler @ 0x1400055CE\n    or:\n      api: StartServiceCtrlDispatcher @ 0x1400F1903\n    or:\n      api: StartServiceCtrlDispatcher @ 0x1400056B1\n\ncreate service (2 matches)\nnamespace  host-interaction/service/create                                      \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003], Execution::System Services::Service Execution           \n           [T1569.002]                                                          \nfunction @ 0x140005A50\n  and:\n    api: CreateService @ 0x140005B43\n    optional:\n      api: OpenSCManager @ 0x140005A78\nfunction @ 0x1400ECFE0\n  and:\n    api: CreateService @ 0x1400ED1F3\n    optional:\n      api: OpenSCManager @ 0x1400ED033, 0x1400ED297\n\ndelete service (2 matches)\nnamespace  host-interaction/service/delete                                      \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003]                                                          \nfunction @ 0x1400056D0\n  and:\n    api: DeleteService @ 0x140005752\n    optional:\n      match: get service handle @ 0x1400056D0\n        or:\n          api: OpenService @ 0x140005707, 0x140005741\nfunction @ 0x1400EC810\n  and:\n    api: DeleteService @ 0x1400EC9F7\n    optional:\n      match: get service handle @ 0x1400EC810\n        or:\n          api: OpenService @ 0x1400EC904, 0x1400EC921, 0x1400EC9DE\n\nstart service (2 matches)\nnamespace  host-interaction/service/start                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003]                                                          \nfunction @ 0x140005820\n  and:\n    api: StartService @ 0x14000586B\n    optional:\n      match: get service handle @ 0x140005820\n        or:\n          api: OpenService @ 0x140005855\nfunction @ 0x1400ECAF0\n  and:\n    api: StartService @ 0x1400ECBEE\n    optional:\n      match: get service handle @ 0x1400ECAF0\n        or:\n          api: OpenService @ 0x1400ECBCC, 0x1400ECC66\n\nstop service (4 matches)\nnamespace  host-interaction/service/stop                                        \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003], Impact::Service Stop [T1489]                            \nfunction @ 0x1400056D0\n  and:\n    optional:\n      match: get service handle @ 0x1400056D0\n        or:\n          api: OpenService @ 0x140005707, 0x140005741\n    or:\n      basic block:\n        and:\n          number: 0x1 = SERVICE_CONTROL_STOP @ 0x14000571A\n          or:\n            api: ControlService @ 0x140005722\nfunction @ 0x140005930\n  and:\n    optional:\n      match: get service handle @ 0x140005930\n        or:\n          api: OpenService @ 0x140005967\n    or:\n      basic block:\n        and:\n          number: 0x1 = SERVICE_CONTROL_STOP @ 0x14000597A\n          or:\n            api: ControlService @ 0x140005982\nfunction @ 0x1400EC810\n  and:\n    optional:\n      match: get service handle @ 0x1400EC810\n        or:\n          api: OpenService @ 0x1400EC904, 0x1400EC921, 0x1400EC9DE\n    or:\n      basic block:\n        and:\n          number: 0x1 = SERVICE_CONTROL_STOP @ 0x1400EC98B\n          or:\n            api: ControlService @ 0x1400EC993\nfunction @ 0x1400ECD90\n  and:\n    optional:\n      match: get service handle @ 0x1400ECD90\n        or:\n          api: OpenService @ 0x1400ECE82, 0x1400ECE9F\n    or:\n      basic block:\n        and:\n          number: 0x1 = SERVICE_CONTROL_STOP @ 0x1400ECF37\n          or:\n            api: ControlService @ 0x1400ECF3F\n\nget session user name\nnamespace  host-interaction/session                                             \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com           \nscope      function                                                             \natt&ck     Discovery::System Owner/User Discovery [T1033], Discovery::Account   \n           Discovery [T1087]                                                    \nfunction @ 0x1400D6FA0\n  or:\n    api: GetUserName @ 0x1400D6FD5\n\ncreate thread\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x1401AAC4D in function 0x1401AABE0\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x1401AACA5\n\nlink function at runtime on Windows (98 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x1400E2F03\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E2F03\ninstruction @ 0x1400E2FE5\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E2FE5\ninstruction @ 0x1400E433E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E433E\ninstruction @ 0x1400E4367\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4367\ninstruction @ 0x1400E4390\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4390\ninstruction @ 0x1400E43B9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E43B9\ninstruction @ 0x1400E43E2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E43E2\ninstruction @ 0x1400E440B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E440B\ninstruction @ 0x1400E4434\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4434\ninstruction @ 0x1400E445D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E445D\ninstruction @ 0x1400E4486\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4486\ninstruction @ 0x1400E44AF\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E44AF\ninstruction @ 0x1400E44D8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E44D8\ninstruction @ 0x1400E4501\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4501\ninstruction @ 0x1400E452A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E452A\ninstruction @ 0x1400E4553\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4553\ninstruction @ 0x1400E457C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E457C\ninstruction @ 0x1400E45A5\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E45A5\ninstruction @ 0x1400E45CE\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E45CE\ninstruction @ 0x1400E45F7\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E45F7\ninstruction @ 0x1400E4620\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4620\ninstruction @ 0x1400E4649\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4649\ninstruction @ 0x1400E4672\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4672\ninstruction @ 0x1400E469B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E469B\ninstruction @ 0x1400E46C4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E46C4\ninstruction @ 0x1400E4724\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4724\ninstruction @ 0x1400E474D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E474D\ninstruction @ 0x1400E4776\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4776\ninstruction @ 0x1400E479F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E479F\ninstruction @ 0x1400E47C8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E47C8\ninstruction @ 0x1400E47F1\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E47F1\ninstruction @ 0x1400E481A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E481A\ninstruction @ 0x1400E4843\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4843\ninstruction @ 0x1400E486C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E486C\ninstruction @ 0x1400E48AD\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E48AD\ninstruction @ 0x1400E48D4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E48D4\ninstruction @ 0x1400E48FD\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E48FD\ninstruction @ 0x1400E4926\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4926\ninstruction @ 0x1400E494D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E494D\ninstruction @ 0x1400E4976\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4976\ninstruction @ 0x1400E499F\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E499F\ninstruction @ 0x1400E49C8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E49C8\ninstruction @ 0x1400E49F1\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E49F1\ninstruction @ 0x1400E4A1A\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4A1A\ninstruction @ 0x1400E4A43\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4A43\ninstruction @ 0x1400E4A96\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4A96\ninstruction @ 0x1400E4AB2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4AB2\ninstruction @ 0x1400E4AF3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4AF3\ninstruction @ 0x1400E4B1C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4B1C\ninstruction @ 0x1400E4B45\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4B45\ninstruction @ 0x1400E4B6E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4B6E\ninstruction @ 0x1400E4B97\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4B97\ninstruction @ 0x1400E4BC0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4BC0\ninstruction @ 0x1400E4BFD\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4BFD\ninstruction @ 0x1400E4C3E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4C3E\ninstruction @ 0x1400E4C67\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4C67\ninstruction @ 0x1400E4C90\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4C90\ninstruction @ 0x1400E4CB9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4CB9\ninstruction @ 0x1400E4CE2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4CE2\ninstruction @ 0x1400E4D0B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4D0B\ninstruction @ 0x1400E4D34\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4D34\ninstruction @ 0x1400E4D5D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4D5D\ninstruction @ 0x1400E4D86\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4D86\ninstruction @ 0x1400E4DAF\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4DAF\ninstruction @ 0x1400E4DD8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4DD8\ninstruction @ 0x1400E4E15\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4E15\ninstruction @ 0x1400E4E3E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4E3E\ninstruction @ 0x1400E4E7B\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4E7B\ninstruction @ 0x1400E4EA4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4EA4\ninstruction @ 0x1400E4EE5\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4EE5\ninstruction @ 0x1400E4F0E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4F0E\ninstruction @ 0x1400E4F37\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4F37\ninstruction @ 0x1400E4F60\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4F60\ninstruction @ 0x1400E4F89\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4F89\ninstruction @ 0x1400E4FB2\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4FB2\ninstruction @ 0x1400E4FDB\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E4FDB\ninstruction @ 0x1400E5004\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E5004\ninstruction @ 0x1400E502D\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E502D\ninstruction @ 0x1400E5056\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E5056\ninstruction @ 0x1400E5093\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E5093\ninstruction @ 0x1400E50D0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1400E50D0\ninstruction @ 0x14013EA25\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x14013EA25\ninstruction @ 0x14016C9AB\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x14016C9AB\ninstruction @ 0x14016C9BE\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x14016C9BE\ninstruction @ 0x14016C9D1\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x14016C9D1\ninstruction @ 0x14016C9E4\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x14016C9E4\ninstruction @ 0x1401AB4F8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1401AB4F8\ninstruction @ 0x1401AB5D8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1401AB5D8\ninstruction @ 0x1401AB6B8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1401AB6B8\ninstruction @ 0x1401AB6B8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1401AB6B8\ninstruction @ 0x1401AB7D8\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1401AB7D8\ninstruction @ 0x1401AB7F0\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1401AB7F0\ninstruction @ 0x1401AF192\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1401AF192\ninstruction @ 0x1401AF44E\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1401AF44E\ninstruction @ 0x1401AF476\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1401AF476\ninstruction @ 0x1401AF495\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1401AF495\ninstruction @ 0x1401AF4E3\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1401AF4E3\ninstruction @ 0x1401AF507\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x1401AF507\n\nlink many functions at runtime (2 matches)\nnamespace  linking/runtime-linking                      \nauthor     moritz.raabe@mandiant.com, joakim@intezer.com\nscope      function                                     \natt&ck     Execution::Shared Modules [T1129]            \nfunction @ 0x1400E4260\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x1400E433E, 0x1400E4367, 0x1400E4390, 0x1400E43B9, and 75 more...\nfunction @ 0x1401AF3F0\n  or:\n    count(match(link function at runtime on Windows)): 5 or more @ 0x1401AF44E, 0x1401AF476, 0x1401AF495, 0x1401AF4E3, and 1 more...\n\nenumerate PE sections (2 matches)\nnamespace   load-code/pe                                                        \nauthor      @Ana06, @mr-tz                                                      \nscope       function                                                            \nmbc         Discovery::Code Discovery::Enumerate PE Sections [B0046.001]        \nreferences  https://0x00sec.org/t/reflective-dll-injection/3080,                \n            https://www.ired.team/offensive-security/code-injection-process-inj…\nfunction @ 0x1400D0820\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x1400D0900\n        or:\n          mnemonic: movzx @ 0x1400D0900\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x1400D09FB\n        or:\n          mnemonic: movzx @ 0x1400D09FB\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x1400D0943\n              or:\n                mnemonic: movzx @ 0x1400D0943\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x1400D08A1, 0x1400D08AE, 0x1400D0965\n    count(basic block): 3 or more @ 0x1400D0820, 0x1400D0829, 0x1400D0870, 0x1400D0880, and 143 more...\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x1400D0943, 0x1400D0B21, 0x1400D0CAC, 0x1400D0E53\n      operand[1].offset: 0x10 = IMAGE_SECTION_HEADER.SizeOfRawData @ 0x1400D0921, 0x1400D0C68, 0x1400D11B4, 0x1400D1288\nfunction @ 0x1400D13A0\n  and:\n    os: windows\n    instruction:\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x1400D1653\n        or:\n          mnemonic: movzx @ 0x1400D1653\n      and:\n        operand[1].offset: 0x6 = IMAGE_NT_HEADERS.FileHeader.NumberOfSections @ 0x1400D1564\n        or:\n          mnemonic: movzx @ 0x1400D1564\n    basic block:\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x1400D16F1\n              or:\n                mnemonic: movzx @ 0x1400D16F1\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x1400D1693\n              or:\n                mnemonic: movzx @ 0x1400D1693\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x1400D16B3\n      or:\n        and: = IMAGE_FIRST_SECTION(nt_header)\n          instruction:\n            and:\n              operand[1].offset: 0x14 = IMAGE_NT_HEADERS.FileHeader.SizeOfOptionalHeader @ 0x1400D141B\n              or:\n                mnemonic: mov @ 0x1400D141B\n          operand[1].offset: 0x18 = FileHeader.SizeOfOptionalHeader @ 0x1400D1428\n    count(basic block): 3 or more @ 0x1400D13A0, 0x1400D13D1, 0x1400D13DB, 0x1400D13E5, and 148 more...\n    not:\n      characteristic: nzxor\n    2 or more:\n      operand[1].offset: 0xC = IMAGE_SECTION_HEADER.VirtualAddress @ 0x1400D178F\n      operand[1].offset: 0x14 = IMAGE_SECTION_HEADER.PointerToRawData @ 0x1400D141B, 0x1400D1693, 0x1400D16F1, 0x1400D23E0\n      operand[1].offset: 0x10 = IMAGE_SECTION_HEADER.SizeOfRawData @ 0x1400D14B6, 0x1400D152B, 0x1400D1673, 0x1400D1845, and 12 more...\n\nparse PE header\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x1401AB000\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x1401AB041, 0x1401AB0C6, 0x1401AB0F8, 0x1401AB114, and 5 more...\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x1401AB114\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x1401AB0F8\n\nresolve function by parsing PE exports (7 matches)\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x140009FD0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x140009FD0\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x14000A071, 0x14000A184\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x14000A119, 0x14000A213\n      3 or more:\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x14000A0BA, 0x14000A178, 0x14000A1C5\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x14000A0D5, 0x14000A173, 0x14000A1AF\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x14000A1C2\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x14000A1B7\nfunction @ 0x140011870\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x140011870\n      mnemonic: movzx @ 0x140011B5A, 0x140011B6B, 0x140011BB9, 0x140011E53\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x140011E53\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x140011A9B\n      3 or more:\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x140012182\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x1400119D0, 0x140011BF5, 0x140011C67, 0x140011D11, and 8 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x1400118C4, 0x140011C59, 0x140011D7E, 0x14001218A\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x140011D7A, 0x140012053, 0x14001247B\nfunction @ 0x140029EE0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x140029EE0\n      mnemonic: movzx @ 0x14002A10F, 0x14002A121, 0x14002A143, 0x14002A146, and 11 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x14002A30C, 0x14002A32C, 0x14002A391, 0x14002A41B, and 12 more...\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x14002A48F\n      3 or more:\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x140029EEA, 0x14002A060, 0x14002A092, 0x14002A202, and 7 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x140029EE5, 0x14002A0F8, 0x14002A10B, 0x14002A11D, and 19 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x14002A1D0, 0x14002A43A\nfunction @ 0x1400B18B0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x1400B18B0\n      mnemonic: movzx @ 0x1400B196C, 0x1400B23A6, 0x1400B2A12, 0x1400B2A1F\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x1400B24BD, 0x1400B256E, 0x1400B2664, 0x1400B26E5\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x1400B191A, 0x1400B27A8, 0x1400B2C3C, 0x1400B2C75\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x1400B1A87, 0x1400B1AE7, 0x1400B1B8C, 0x1400B1BDC, and 2 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x1400B263C\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x1400B2C36\nfunction @ 0x1400BF5A0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x1400BF5A0\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x1400BF5D7, 0x1400BF84C, 0x1400BF876, 0x1400BFAC5\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x1400BF71F\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x1400BF815, 0x1400BF993\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x1400BF727, 0x1400BF7B5\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x1400BF734, 0x1400BF826, 0x1400BF954, 0x1400BF972\nfunction @ 0x14016A420\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x14016A420\n      mnemonic: movzx @ 0x14016A47F, 0x14016AB3D, 0x14016AB56\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x14016AB6D, 0x14016AC2A\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x14016A743, 0x14016A776\n      3 or more:\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x14016A5D2, 0x14016A618, 0x14016A643, 0x14016A697, and 11 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x14016AB56, 0x14016AC5A\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x14016AC0D\nfunction @ 0x140183590\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x140183590\n      mnemonic: movzx @ 0x1401837E1, 0x1401837E4, 0x1401837FC, 0x140183803, and 284 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x140183D63, 0x140184378, 0x140185A52\n      or:\n        and:\n          arch: amd64\n          offset: 0x88 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x1401835B9, 0x1401863FB\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x140183A36, 0x140184238, 0x140185192\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x140183B77, 0x1401842B8, 0x140185512\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x14018359A, 0x140183B25, 0x140184298, 0x1401846A4, and 1 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x140183595, 0x140183A81, 0x140184258, 0x140185272\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x140183AD3, 0x140184278, 0x140185352\n\npersist via Run registry key (3 matches)\nnamespace  persistence/registry/run                                             \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com                      \nscope      function                                                             \natt&ck     Persistence::Boot or Logon Autostart Execution::Registry Run Keys /  \n           Startup Folder [T1547.001]                                           \nmbc        Persistence::Registry Run Keys / Startup Folder [F0012]              \nfunction @ 0x140144390\n  and:\n    or:\n      number: 0x80000002 = HKEY_LOCAL_MACHINE @ 0x1401443CE\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\" @ 0x1401443C7\nfunction @ 0x140149760\n  and:\n    or:\n      number: 0x80000002 = HKEY_LOCAL_MACHINE @ 0x140149772, 0x1401497A6, 0x1401497CC\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\" @ 0x14014976B\nfunction @ 0x14014D500\n  and:\n    or:\n      number: 0x80000002 = HKEY_LOCAL_MACHINE @ 0x14014D527, 0x14014D55B, 0x14014D581, 0x14014D63D, and 2 more...\n    or:\n      regex: /Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run/i\n        - \"SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\" @ 0x14014D520, 0x14014D636\n\npersist via Windows service (2 matches)\nnamespace  persistence/service                                                  \nauthor     moritz.raabe@mandiant.com                                            \nscope      function                                                             \natt&ck     Persistence::Create or Modify System Process::Windows Service        \n           [T1543.003], Execution::System Services::Service Execution           \n           [T1569.002]                                                          \nfunction @ 0x140005A50\n  or:\n    and:\n      or:\n        basic block:\n          and:\n            number: 0x2 = SERVICE_AUTO_START @ 0x140005B1E, 0x140005B33\n            api: CreateService @ 0x140005B43\nfunction @ 0x1400ECFE0\n  or:\n    and:\n      or:\n        basic block:\n          and:\n            number: 0x2 = SERVICE_AUTO_START @ 0x1400ED1DA, 0x1400ED1E3\n            api: CreateService @ 0x1400ED1F3\n\n\n\n"},"hashes":{"md5":"464df9e59802fb4d6f4a0c743a5ded94","sha1":"2aaa17b0aceb7d017c47ea0110de97e29d920ace","sha256":"f191f756996a14a11e5445fa7103d302efd510cf2fbf920e6c0c8ed51d512e36"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 2689</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 234849</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"everyth\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"464df9e59802fb4d6f4a0c743a5ded94\",\n        \"sha256\": \"f191f756996a14a11e5445fa7103d302efd510cf2fbf920e6c0c8ed\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__1286_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (1286 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1400013E0\",\n      \"label\": \"Function 0x1400013E0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400013E0\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__8_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (8 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_rule_\",\n      \"label\": \"rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Create Registry Key [C0036.004]\",\n        \"Operating\",\n        \"System::Registry::Open Registry Key [C0036.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1400DA6F0\",\n      \"label\": \"Block 0x1400DA6F0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400DA6F0\"\n    },\n    {\n      \"id\": \"api_RegOpenKeyEx\",\n      \"label\": \"RegOpenKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delay_execution__46_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (46 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x140010C9E\",\n      \"label\": \"Block 0x140010C9E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140010C9E\"\n    },\n    {\n      \"id\": \"api_WaitForSingleObject\",\n      \"label\": \"WaitForSingleObject\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_os_version__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"get OS version (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1400E4260\",\n      \"label\": \"Function 0x1400E4260\",\n      \"type\": \"function\",\n      \"address\": \"0x1400E4260\"\n    },\n    {\n      \"id\": \"api_GetVersionEx\",\n      \"label\": \"GetVersionEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_service_handle__12_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"get service handle (12 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1400056D0\",\n      \"label\": \"Function 0x1400056D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400056D0\"\n    },\n    {\n      \"id\": \"api_OpenService\",\n      \"label\": \"OpenService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_open_process__10_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"open process (10 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Open Process [C0065]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1400CCAC0\",\n      \"label\": \"Block 0x1400CCAC0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400CCAC0\"\n    },\n    {\n      \"id\": \"api_OpenProcess\",\n      \"label\": \"OpenProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_check_for_software_breakpoints__2_matches_\",\n      \"label\": \"check for software breakpoints (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Software Breakpoints\",\n        \"[B0001.025]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400F5490\",\n      \"label\": \"Function 0x1400F5490\",\n      \"type\": \"function\",\n      \"address\": \"0x1400F5490\"\n    },\n    {\n      \"id\": \"func_0x1400674A0\",\n      \"label\": \"Function 0x1400674A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400674A0\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Software Breakpoints\",\n        \"[B0001.025]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_for_time_delay_via_gettickcount__11_matches_\",\n      \"label\": \"check for time delay via GetTickCount (11 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"GetTickCount [B0001.032]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400ECAF0\",\n      \"label\": \"Function 0x1400ECAF0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400ECAF0\"\n    },\n    {\n      \"id\": \"func_0x140048C20\",\n      \"label\": \"Function 0x140048C20\",\n      \"type\": \"function\",\n      \"address\": \"0x140048C20\"\n    },\n    {\n      \"id\": \"func_0x1400EEFC0\",\n      \"label\": \"Function 0x1400EEFC0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400EEFC0\"\n    },\n    {\n      \"id\": \"func_0x14004FB70\",\n      \"label\": \"Function 0x14004FB70\",\n      \"type\": \"function\",\n      \"address\": \"0x14004FB70\"\n    },\n    {\n      \"id\": \"func_0x140106BB0\",\n      \"label\": \"Function 0x140106BB0\",\n      \"type\": \"function\",\n      \"address\": \"0x140106BB0\"\n    },\n    {\n      \"id\": \"func_0x1400EC2E0\",\n      \"label\": \"Function 0x1400EC2E0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400EC2E0\"\n    },\n    {\n      \"id\": \"func_0x1400CE930\",\n      \"label\": \"Function 0x1400CE930\",\n      \"type\": \"function\",\n      \"address\": \"0x1400CE930\"\n    },\n    {\n      \"id\": \"func_0x1400F0200\",\n      \"label\": \"Function 0x1400F0200\",\n      \"type\": \"function\",\n      \"address\": \"0x1400F0200\"\n    },\n    {\n      \"id\": \"func_0x14010D5A0\",\n      \"label\": \"Function 0x14010D5A0\",\n      \"type\": \"function\",\n      \"address\": \"0x14010D5A0\"\n    },\n    {\n      \"id\": \"func_0x1400F5050\",\n      \"label\": \"Function 0x1400F5050\",\n      \"type\": \"function\",\n      \"address\": \"0x1400F5050\"\n    },\n    {\n      \"id\": \"func_0x14004EC40\",\n      \"label\": \"Function 0x14004EC40\",\n      \"type\": \"function\",\n      \"address\": \"0x14004EC40\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check\",\n        \"GetTickCount [B0001.032]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_for_unmoving_mouse_cursor\",\n      \"label\": \"check for unmoving mouse cursor\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection::Human User\",\n        \"Check [B0009.012]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140141050\",\n      \"label\": \"Function 0x140141050\",\n      \"type\": \"function\",\n      \"address\": \"0x140141050\"\n    },\n    {\n      \"id\": \"cap_author______bitsofbinary\",\n      \"label\": \"author      BitsOfBinary\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection::Human User\",\n        \"Check [B0009.012]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_geographical_location__9_matches_\",\n      \"label\": \"get geographical location (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400DC3B0\",\n      \"label\": \"Function 0x1400DC3B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400DC3B0\"\n    },\n    {\n      \"id\": \"func_0x140111260\",\n      \"label\": \"Function 0x140111260\",\n      \"type\": \"function\",\n      \"address\": \"0x140111260\"\n    },\n    {\n      \"id\": \"func_0x1400DC370\",\n      \"label\": \"Function 0x1400DC370\",\n      \"type\": \"function\",\n      \"address\": \"0x1400DC370\"\n    },\n    {\n      \"id\": \"func_0x14010F6C0\",\n      \"label\": \"Function 0x14010F6C0\",\n      \"type\": \"function\",\n      \"address\": \"0x14010F6C0\"\n    },\n    {\n      \"id\": \"func_0x14005EEB0\",\n      \"label\": \"Function 0x14005EEB0\",\n      \"type\": \"function\",\n      \"address\": \"0x14005EEB0\"\n    },\n    {\n      \"id\": \"func_0x1401B0A00\",\n      \"label\": \"Function 0x1401B0A00\",\n      \"type\": \"function\",\n      \"address\": \"0x1401B0A00\"\n    },\n    {\n      \"id\": \"func_0x14010F780\",\n      \"label\": \"Function 0x14010F780\",\n      \"type\": \"function\",\n      \"address\": \"0x14010F780\"\n    },\n    {\n      \"id\": \"func_0x14017D070\",\n      \"label\": \"Function 0x14017D070\",\n      \"type\": \"function\",\n      \"address\": \"0x14017D070\"\n    },\n    {\n      \"id\": \"func_0x14017ADD0\",\n      \"label\": \"Function 0x14017ADD0\",\n      \"type\": \"function\",\n      \"address\": \"0x14017ADD0\"\n    },\n    {\n      \"id\": \"api_GetLocaleInfo\",\n      \"label\": \"GetLocaleInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_credit_card_information\",\n      \"label\": \"parse credit card information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Check String [C0019]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14018D880\",\n      \"label\": \"Function 0x14018D880\",\n      \"type\": \"function\",\n      \"address\": \"0x14018D880\"\n    },\n    {\n      \"id\": \"cap_author_______re_fox\",\n      \"label\": \"author     @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Check String [C0019]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes__3_matches_\",\n      \"label\": \"log keystrokes (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400E19A0\",\n      \"label\": \"Function 0x1400E19A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400E19A0\"\n    },\n    {\n      \"id\": \"func_0x14015DFB0\",\n      \"label\": \"Function 0x14015DFB0\",\n      \"type\": \"function\",\n      \"address\": \"0x14015DFB0\"\n    },\n    {\n      \"id\": \"func_0x1400F5390\",\n      \"label\": \"Function 0x1400F5390\",\n      \"type\": \"function\",\n      \"address\": \"0x1400F5390\"\n    },\n    {\n      \"id\": \"api_AttachThreadInput\",\n      \"label\": \"AttachThreadInput\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Input Capture::Keylogging [T1056.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_polling__6_matches_\",\n      \"label\": \"log keystrokes via polling (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400E1B00\",\n      \"label\": \"Function 0x1400E1B00\",\n      \"type\": \"function\",\n      \"address\": \"0x1400E1B00\"\n    },\n    {\n      \"id\": \"func_0x1400DFED0\",\n      \"label\": \"Function 0x1400DFED0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400DFED0\"\n    },\n    {\n      \"id\": \"func_0x1400DA590\",\n      \"label\": \"Function 0x1400DA590\",\n      \"type\": \"function\",\n      \"address\": \"0x1400DA590\"\n    },\n    {\n      \"id\": \"func_0x1401001F0\",\n      \"label\": \"Function 0x1401001F0\",\n      \"type\": \"function\",\n      \"address\": \"0x1401001F0\"\n    },\n    {\n      \"id\": \"func_0x1400F8C10\",\n      \"label\": \"Function 0x1400F8C10\",\n      \"type\": \"function\",\n      \"address\": \"0x1400F8C10\"\n    },\n    {\n      \"id\": \"func_0x1400CC320\",\n      \"label\": \"Function 0x1400CC320\",\n      \"type\": \"function\",\n      \"address\": \"0x1400CC320\"\n    },\n    {\n      \"id\": \"api_GetAsyncKeyState\",\n      \"label\": \"GetAsyncKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetKeyNameText\",\n      \"label\": \"GetKeyNameText\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetKeyState\",\n      \"label\": \"GetKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_capture_webcam_image\",\n      \"label\": \"capture webcam image\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Video Capture [T1125]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140142A30\",\n      \"label\": \"Function 0x140142A30\",\n      \"type\": \"function\",\n      \"address\": \"0x140142A30\"\n    },\n    {\n      \"id\": \"api_SendMessage\",\n      \"label\": \"SendMessage\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____johnk3r\",\n      \"label\": \"author     johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Video Capture [T1125]\"\n      ]\n    },\n    {\n      \"id\": \"cap_receive_data__4_matches_\",\n      \"label\": \"receive data (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400C8B20\",\n      \"label\": \"Function 0x1400C8B20\",\n      \"type\": \"function\",\n      \"address\": \"0x1400C8B20\"\n    },\n    {\n      \"id\": \"func_0x1400B74E0\",\n      \"label\": \"Function 0x1400B74E0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400B74E0\"\n    },\n    {\n      \"id\": \"func_0x1400B90C0\",\n      \"label\": \"Function 0x1400B90C0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400B90C0\"\n    },\n    {\n      \"id\": \"func_0x1400BCA70\",\n      \"label\": \"Function 0x1400BCA70\",\n      \"type\": \"function\",\n      \"address\": \"0x1400BCA70\"\n    },\n    {\n      \"id\": \"api_recv\",\n      \"label\": \"recv\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Receive Data [B0030.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data__4_matches_\",\n      \"label\": \"send data (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400B7E80\",\n      \"label\": \"Function 0x1400B7E80\",\n      \"type\": \"function\",\n      \"address\": \"0x1400B7E80\"\n    },\n    {\n      \"id\": \"func_0x1400C27F0\",\n      \"label\": \"Function 0x1400C27F0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400C27F0\"\n    },\n    {\n      \"id\": \"func_0x1400B95B0\",\n      \"label\": \"Function 0x1400B95B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400B95B0\"\n    },\n    {\n      \"id\": \"func_0x1400B6780\",\n      \"label\": \"Function 0x1400B6780\",\n      \"type\": \"function\",\n      \"address\": \"0x1400B6780\"\n    },\n    {\n      \"id\": \"api_send\",\n      \"label\": \"send\",\n      \"type\": \"api\",\n      \"category\": \"network\"\n    },\n    {\n      \"id\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author       william.ballenthin@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Command and Control::C2 Communication::Send Data [B0030.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_resolve_dns\",\n      \"label\": \"resolve DNS\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::DNS Communication::Resolve [C0011.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400DB440\",\n      \"label\": \"Function 0x1400DB440\",\n      \"type\": \"function\",\n      \"address\": \"0x1400DB440\"\n    },\n    {\n      \"id\": \"api_gethostbyname\",\n      \"label\": \"gethostbyname\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_michael_hunhoff_mandiant_com\",\n      \"label\": \"michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::DNS Communication::Resolve [C0011.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_http_user_agent_string\",\n      \"label\": \"reference HTTP User-Agent string\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication [C0002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14016C930\",\n      \"label\": \"Function 0x14016C930\",\n      \"type\": \"function\",\n      \"address\": \"0x14016C930\"\n    },\n    {\n      \"id\": \"cap_author_______mr_tz\",\n      \"label\": \"author      @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::HTTP Communication [C0002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_connect_pipe\",\n      \"label\": \"connect pipe\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Interprocess Communication::Connect Pipe [C0003.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400F0BE0\",\n      \"label\": \"Function 0x1400F0BE0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400F0BE0\"\n    },\n    {\n      \"id\": \"api_ConnectNamedPipe\",\n      \"label\": \"ConnectNamedPipe\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Interprocess Communication::Connect Pipe [C0003.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_pipe\",\n      \"label\": \"create pipe\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Interprocess Communication::Create Pipe [C0003.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateNamedPipe\",\n      \"label\": \"CreateNamedPipe\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_connect_socket__3_matches_\",\n      \"label\": \"connect socket (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x1400BB924\",\n      \"label\": \"Block 0x1400BB924\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400BB924\"\n    },\n    {\n      \"id\": \"bb_0x1400BBB42\",\n      \"label\": \"Block 0x1400BBB42\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400BBB42\"\n    },\n    {\n      \"id\": \"bb_0x1400B78B3\",\n      \"label\": \"Block 0x1400B78B3\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400B78B3\"\n    },\n    {\n      \"id\": \"api_connect\",\n      \"label\": \"connect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_mrhafizfarhad_gmail_com\",\n      \"label\": \"mrhafizfarhad@gmail.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_get_socket_information__3_matches_\",\n      \"label\": \"get socket information (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Network Configuration Discovery [T1016]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400B9FD0\",\n      \"label\": \"Function 0x1400B9FD0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400B9FD0\"\n    },\n    {\n      \"id\": \"func_0x1400B9880\",\n      \"label\": \"Function 0x1400B9880\",\n      \"type\": \"function\",\n      \"address\": \"0x1400B9880\"\n    },\n    {\n      \"id\": \"func_0x1400BB6C0\",\n      \"label\": \"Function 0x1400BB6C0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400BB6C0\"\n    },\n    {\n      \"id\": \"api_getsockname\",\n      \"label\": \"getsockname\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_initialize_winsock_library__3_matches_\",\n      \"label\": \"initialize Winsock library (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Initialize Winsock Library\",\n        \"[C0001.009]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400C8F10\",\n      \"label\": \"Function 0x1400C8F10\",\n      \"type\": \"function\",\n      \"address\": \"0x1400C8F10\"\n    },\n    {\n      \"id\": \"func_0x1400B7AF0\",\n      \"label\": \"Function 0x1400B7AF0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400B7AF0\"\n    },\n    {\n      \"id\": \"func_0x1400BD1E0\",\n      \"label\": \"Function 0x1400BD1E0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400BD1E0\"\n    },\n    {\n      \"id\": \"api_WSAStartup\",\n      \"label\": \"WSAStartup\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_socket_configuration__6_matches_\",\n      \"label\": \"set socket configuration (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Set Socket Config [C0001.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400B77C0\",\n      \"label\": \"Function 0x1400B77C0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400B77C0\"\n    },\n    {\n      \"id\": \"func_0x1400BB890\",\n      \"label\": \"Function 0x1400BB890\",\n      \"type\": \"function\",\n      \"address\": \"0x1400BB890\"\n    },\n    {\n      \"id\": \"func_0x1400BCD00\",\n      \"label\": \"Function 0x1400BCD00\",\n      \"type\": \"function\",\n      \"address\": \"0x1400BCD00\"\n    },\n    {\n      \"id\": \"func_0x1400C8D50\",\n      \"label\": \"Function 0x1400C8D50\",\n      \"type\": \"function\",\n      \"address\": \"0x1400C8D50\"\n    },\n    {\n      \"id\": \"api_setsockopt\",\n      \"label\": \"setsockopt\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_receive_data_on_socket__4_matches_\",\n      \"label\": \"receive data on socket (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Receive Data [C0001.006]\"\n      ]\n    },\n    {\n      \"id\": \"cap_send_data_on_socket__4_matches_\",\n      \"label\": \"send data on socket (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Send Data [C0001.007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_udp_socket\",\n      \"label\": \"create UDP socket\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Communication::Socket Communication::Create UDP Socket [C0001.010]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1400B9880\",\n      \"label\": \"Block 0x1400B9880\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400B9880\"\n    },\n    {\n      \"id\": \"api_socket\",\n      \"label\": \"socket\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_encode_data_using_base64__2_matches_\",\n      \"label\": \"encode data using Base64 (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or Information::Encoding-Standard\",\n        \"Algorithm [E1027.m02]\",\n        \"Data::Encode Data::Base64 [C0026.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1401899D0\",\n      \"label\": \"Function 0x1401899D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1401899D0\"\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_rc4_ksa__2_matches_\",\n      \"label\": \"encrypt data using RC4 KSA (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Encrypt Data::RC4 [C0027.009]\",\n        \"Cryptography::Encryption\",\n        \"Key::RC4 KSA [C0028.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140123C80\",\n      \"label\": \"Function 0x140123C80\",\n      \"type\": \"function\",\n      \"address\": \"0x140123C80\"\n    },\n    {\n      \"id\": \"func_0x14010D8C0\",\n      \"label\": \"Function 0x14010D8C0\",\n      \"type\": \"function\",\n      \"address\": \"0x14010D8C0\"\n    },\n    {\n      \"id\": \"cap_encrypt_data_using_speck\",\n      \"label\": \"encrypt data using speck\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or\",\n        \"Information::Encryption-Standard Algorithm [E1027.m05]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______still_teamt5_org\",\n      \"label\": \"author      still@teamt5.org\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Obfuscated Files or\",\n        \"Information::Encryption-Standard Algorithm [E1027.m05]\"\n      ]\n    },\n    {\n      \"id\": \"cap_authenticate_hmac\",\n      \"label\": \"authenticate HMAC\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Hashed Message Authentication Code [C0061]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Hashed Message Authentication Code [C0061]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contains_pdb_path\",\n      \"label\": \"contains PDB path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x1400C79B0\",\n      \"label\": \"Function 0x1400C79B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400C79B0\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FreeResource\",\n      \"label\": \"FreeResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResource\",\n      \"label\": \"FindResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments__6_matches_\",\n      \"label\": \"accept command line arguments (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1401AB000\",\n      \"label\": \"Function 0x1401AB000\",\n      \"type\": \"function\",\n      \"address\": \"0x1401AB000\"\n    },\n    {\n      \"id\": \"func_0x1400CE620\",\n      \"label\": \"Function 0x1400CE620\",\n      \"type\": \"function\",\n      \"address\": \"0x1400CE620\"\n    },\n    {\n      \"id\": \"func_0x140006010\",\n      \"label\": \"Function 0x140006010\",\n      \"type\": \"function\",\n      \"address\": \"0x140006010\"\n    },\n    {\n      \"id\": \"func_0x1400B4020\",\n      \"label\": \"Function 0x1400B4020\",\n      \"type\": \"function\",\n      \"address\": \"0x1400B4020\"\n    },\n    {\n      \"id\": \"func_0x1400CF8C0\",\n      \"label\": \"Function 0x1400CF8C0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400CF8C0\"\n    },\n    {\n      \"id\": \"func_0x1400CF020\",\n      \"label\": \"Function 0x1400CF020\",\n      \"type\": \"function\",\n      \"address\": \"0x1400CF020\"\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_open_clipboard__6_matches_\",\n      \"label\": \"open clipboard (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400F8450\",\n      \"label\": \"Function 0x1400F8450\",\n      \"type\": \"function\",\n      \"address\": \"0x1400F8450\"\n    },\n    {\n      \"id\": \"func_0x1401046A0\",\n      \"label\": \"Function 0x1401046A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1401046A0\"\n    },\n    {\n      \"id\": \"func_0x140102050\",\n      \"label\": \"Function 0x140102050\",\n      \"type\": \"function\",\n      \"address\": \"0x140102050\"\n    },\n    {\n      \"id\": \"func_0x140104520\",\n      \"label\": \"Function 0x140104520\",\n      \"type\": \"function\",\n      \"address\": \"0x140104520\"\n    },\n    {\n      \"id\": \"func_0x1400D8AA0\",\n      \"label\": \"Function 0x1400D8AA0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D8AA0\"\n    },\n    {\n      \"id\": \"api_CloseClipboard\",\n      \"label\": \"CloseClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_OpenClipboard\",\n      \"label\": \"OpenClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_clipboard_data\",\n      \"label\": \"read clipboard data\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"api_GlobalLock\",\n      \"label\": \"GlobalLock\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GlobalUnlock\",\n      \"label\": \"GlobalUnlock\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetClipboardData\",\n      \"label\": \"GetClipboardData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Clipboard Data [T1115]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_clipboard_data__4_matches_\",\n      \"label\": \"write clipboard data (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Impact::Clipboard Modification [E1510]\"\n      ]\n    },\n    {\n      \"id\": \"api_SetClipboardData\",\n      \"label\": \"SetClipboardData\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_EmptyClipboard\",\n      \"label\": \"EmptyClipboard\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_interact_with_driver_via_ioctl__32_matches_\",\n      \"label\": \"interact with driver via IOCTL (32 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_DeviceIoControl\",\n      \"label\": \"DeviceIoControl\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_environment_variable__2_matches_\",\n      \"label\": \"query environment variable (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1401AE2A0\",\n      \"label\": \"Function 0x1401AE2A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1401AE2A0\"\n    },\n    {\n      \"id\": \"func_0x1400E0A40\",\n      \"label\": \"Function 0x1400E0A40\",\n      \"type\": \"function\",\n      \"address\": \"0x1400E0A40\"\n    },\n    {\n      \"id\": \"api_ExpandEnvironmentStrings\",\n      \"label\": \"ExpandEnvironmentStrings\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetEnvironmentStrings\",\n      \"label\": \"GetEnvironmentStrings\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_common_file_path__4_matches_\",\n      \"label\": \"get common file path (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400E0230\",\n      \"label\": \"Function 0x1400E0230\",\n      \"type\": \"function\",\n      \"address\": \"0x1400E0230\"\n    },\n    {\n      \"id\": \"func_0x1400D9990\",\n      \"label\": \"Function 0x1400D9990\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D9990\"\n    },\n    {\n      \"id\": \"func_0x1400E08B0\",\n      \"label\": \"Function 0x1400E08B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400E08B0\"\n    },\n    {\n      \"id\": \"func_0x1400B44E0\",\n      \"label\": \"Function 0x1400B44E0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400B44E0\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHGetSpecialFolderLocation\",\n      \"label\": \"SHGetSpecialFolderLocation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_file_system_object_information\",\n      \"label\": \"get file system object information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1400DB18C\",\n      \"label\": \"Block 0x1400DB18C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400DB18C\"\n    },\n    {\n      \"id\": \"api_SHGetFileInfo\",\n      \"label\": \"SHGetFileInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_copy_file\",\n      \"label\": \"copy file\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Copy File [C0045]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400CC920\",\n      \"label\": \"Function 0x1400CC920\",\n      \"type\": \"function\",\n      \"address\": \"0x1400CC920\"\n    },\n    {\n      \"id\": \"api_CopyFile\",\n      \"label\": \"CopyFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_directory\",\n      \"label\": \"create directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400D5860\",\n      \"label\": \"Function 0x1400D5860\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D5860\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_delete_directory__3_matches_\",\n      \"label\": \"delete directory (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400D5430\",\n      \"label\": \"Function 0x1400D5430\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D5430\"\n    },\n    {\n      \"id\": \"func_0x1400D5610\",\n      \"label\": \"Function 0x1400D5610\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D5610\"\n    },\n    {\n      \"id\": \"func_0x1400D7B50\",\n      \"label\": \"Function 0x1400D7B50\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D7B50\"\n    },\n    {\n      \"id\": \"api_RemoveDirectory\",\n      \"label\": \"RemoveDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_file__5_matches_\",\n      \"label\": \"delete file (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400D8840\",\n      \"label\": \"Function 0x1400D8840\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D8840\"\n    },\n    {\n      \"id\": \"func_0x1400D7AC0\",\n      \"label\": \"Function 0x1400D7AC0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D7AC0\"\n    },\n    {\n      \"id\": \"func_0x140165280\",\n      \"label\": \"Function 0x140165280\",\n      \"type\": \"function\",\n      \"address\": \"0x140165280\"\n    },\n    {\n      \"id\": \"api_SHFileOperation\",\n      \"label\": \"SHFileOperation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__8_matches_\",\n      \"label\": \"check if file exists (8 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400DBC10\",\n      \"label\": \"Function 0x1400DBC10\",\n      \"type\": \"function\",\n      \"address\": \"0x1400DBC10\"\n    },\n    {\n      \"id\": \"func_0x1400D83D0\",\n      \"label\": \"Function 0x1400D83D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D83D0\"\n    },\n    {\n      \"id\": \"func_0x1400D8440\",\n      \"label\": \"Function 0x1400D8440\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D8440\"\n    },\n    {\n      \"id\": \"func_0x1400D8350\",\n      \"label\": \"Function 0x1400D8350\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D8350\"\n    },\n    {\n      \"id\": \"func_0x1400D5550\",\n      \"label\": \"Function 0x1400D5550\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D5550\"\n    },\n    {\n      \"id\": \"func_0x1400D72F0\",\n      \"label\": \"Function 0x1400D72F0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D72F0\"\n    },\n    {\n      \"id\": \"func_0x1400D5770\",\n      \"label\": \"Function 0x1400D5770\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D5770\"\n    },\n    {\n      \"id\": \"api_GetLastError\",\n      \"label\": \"GetLastError\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_get_file_attributes__5_matches_\",\n      \"label\": \"get file attributes (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1400D5894\",\n      \"label\": \"Block 0x1400D5894\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400D5894\"\n    },\n    {\n      \"id\": \"bb_0x1400D83D0\",\n      \"label\": \"Block 0x1400D83D0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400D83D0\"\n    },\n    {\n      \"id\": \"bb_0x1400D8463\",\n      \"label\": \"Block 0x1400D8463\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400D8463\"\n    },\n    {\n      \"id\": \"bb_0x1400D8350\",\n      \"label\": \"Block 0x1400D8350\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400D8350\"\n    },\n    {\n      \"id\": \"bb_0x1400D72F0\",\n      \"label\": \"Block 0x1400D72F0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400D72F0\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size__2_matches_\",\n      \"label\": \"get file size (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400D78D0\",\n      \"label\": \"Function 0x1400D78D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D78D0\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_move_file__4_matches_\",\n      \"label\": \"move file (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Move File [C0063]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x14013CC30\",\n      \"label\": \"Function 0x14013CC30\",\n      \"type\": \"function\",\n      \"address\": \"0x14013CC30\"\n    },\n    {\n      \"id\": \"func_0x140109640\",\n      \"label\": \"Function 0x140109640\",\n      \"type\": \"function\",\n      \"address\": \"0x140109640\"\n    },\n    {\n      \"id\": \"func_0x14013C810\",\n      \"label\": \"Function 0x14013C810\",\n      \"type\": \"function\",\n      \"address\": \"0x14013C810\"\n    },\n    {\n      \"id\": \"api_MoveFileEx\",\n      \"label\": \"MoveFileEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_MoveFile\",\n      \"label\": \"MoveFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__25_matches_\",\n      \"label\": \"read file on Windows (25 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400BE4D0\",\n      \"label\": \"Function 0x1400BE4D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400BE4D0\"\n    },\n    {\n      \"id\": \"func_0x140004770\",\n      \"label\": \"Function 0x140004770\",\n      \"type\": \"function\",\n      \"address\": \"0x140004770\"\n    },\n    {\n      \"id\": \"func_0x1400E5550\",\n      \"label\": \"Function 0x1400E5550\",\n      \"type\": \"function\",\n      \"address\": \"0x1400E5550\"\n    },\n    {\n      \"id\": \"func_0x1400B8F10\",\n      \"label\": \"Function 0x1400B8F10\",\n      \"type\": \"function\",\n      \"address\": \"0x1400B8F10\"\n    },\n    {\n      \"id\": \"func_0x1400CFE80\",\n      \"label\": \"Function 0x1400CFE80\",\n      \"type\": \"function\",\n      \"address\": \"0x1400CFE80\"\n    },\n    {\n      \"id\": \"func_0x1400BE0F0\",\n      \"label\": \"Function 0x1400BE0F0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400BE0F0\"\n    },\n    {\n      \"id\": \"func_0x1400CFD90\",\n      \"label\": \"Function 0x1400CFD90\",\n      \"type\": \"function\",\n      \"address\": \"0x1400CFD90\"\n    },\n    {\n      \"id\": \"func_0x140004ED0\",\n      \"label\": \"Function 0x140004ED0\",\n      \"type\": \"function\",\n      \"address\": \"0x140004ED0\"\n    },\n    {\n      \"id\": \"func_0x1400EA6D0\",\n      \"label\": \"Function 0x1400EA6D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400EA6D0\"\n    },\n    {\n      \"id\": \"func_0x1400BE1E0\",\n      \"label\": \"Function 0x1400BE1E0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400BE1E0\"\n    },\n    {\n      \"id\": \"func_0x1400D13A0\",\n      \"label\": \"Function 0x1400D13A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D13A0\"\n    },\n    {\n      \"id\": \"func_0x140004D80\",\n      \"label\": \"Function 0x140004D80\",\n      \"type\": \"function\",\n      \"address\": \"0x140004D80\"\n    },\n    {\n      \"id\": \"func_0x14017B500\",\n      \"label\": \"Function 0x14017B500\",\n      \"type\": \"function\",\n      \"address\": \"0x14017B500\"\n    },\n    {\n      \"id\": \"func_0x1400E5D50\",\n      \"label\": \"Function 0x1400E5D50\",\n      \"type\": \"function\",\n      \"address\": \"0x1400E5D50\"\n    },\n    {\n      \"id\": \"func_0x1400CB5B0\",\n      \"label\": \"Function 0x1400CB5B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400CB5B0\"\n    },\n    {\n      \"id\": \"func_0x1400BE570\",\n      \"label\": \"Function 0x1400BE570\",\n      \"type\": \"function\",\n      \"address\": \"0x1400BE570\"\n    },\n    {\n      \"id\": \"func_0x1400CFA70\",\n      \"label\": \"Function 0x1400CFA70\",\n      \"type\": \"function\",\n      \"address\": \"0x1400CFA70\"\n    },\n    {\n      \"id\": \"func_0x140004610\",\n      \"label\": \"Function 0x140004610\",\n      \"type\": \"function\",\n      \"address\": \"0x140004610\"\n    },\n    {\n      \"id\": \"func_0x1400B3660\",\n      \"label\": \"Function 0x1400B3660\",\n      \"type\": \"function\",\n      \"address\": \"0x1400B3660\"\n    },\n    {\n      \"id\": \"func_0x1400BE010\",\n      \"label\": \"Function 0x1400BE010\",\n      \"type\": \"function\",\n      \"address\": \"0x1400BE010\"\n    },\n    {\n      \"id\": \"func_0x1400048C0\",\n      \"label\": \"Function 0x1400048C0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400048C0\"\n    },\n    {\n      \"id\": \"func_0x1400DC9B0\",\n      \"label\": \"Function 0x1400DC9B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400DC9B0\"\n    },\n    {\n      \"id\": \"func_0x1400F0070\",\n      \"label\": \"Function 0x1400F0070\",\n      \"type\": \"function\",\n      \"address\": \"0x1400F0070\"\n    },\n    {\n      \"id\": \"func_0x1400C2DC0\",\n      \"label\": \"Function 0x1400C2DC0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400C2DC0\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__9_matches_\",\n      \"label\": \"write file on Windows (9 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400D54C0\",\n      \"label\": \"Function 0x1400D54C0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D54C0\"\n    },\n    {\n      \"id\": \"func_0x1400B3B20\",\n      \"label\": \"Function 0x1400B3B20\",\n      \"type\": \"function\",\n      \"address\": \"0x1400B3B20\"\n    },\n    {\n      \"id\": \"func_0x1401AC870\",\n      \"label\": \"Function 0x1401AC870\",\n      \"type\": \"function\",\n      \"address\": \"0x1401AC870\"\n    },\n    {\n      \"id\": \"func_0x1400EA560\",\n      \"label\": \"Function 0x1400EA560\",\n      \"type\": \"function\",\n      \"address\": \"0x1400EA560\"\n    },\n    {\n      \"id\": \"func_0x1400EE1D0\",\n      \"label\": \"Function 0x1400EE1D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400EE1D0\"\n    },\n    {\n      \"id\": \"func_0x1401ACAB0\",\n      \"label\": \"Function 0x1401ACAB0\",\n      \"type\": \"function\",\n      \"address\": \"0x1401ACAB0\"\n    },\n    {\n      \"id\": \"func_0x1400EE440\",\n      \"label\": \"Function 0x1400EE440\",\n      \"type\": \"function\",\n      \"address\": \"0x1400EE440\"\n    },\n    {\n      \"id\": \"func_0x1400EE680\",\n      \"label\": \"Function 0x1400EE680\",\n      \"type\": \"function\",\n      \"address\": \"0x1400EE680\"\n    },\n    {\n      \"id\": \"func_0x1400EE370\",\n      \"label\": \"Function 0x1400EE370\",\n      \"type\": \"function\",\n      \"address\": \"0x1400EE370\"\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_gui_resources\",\n      \"label\": \"enumerate gui resources\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1401048B0\",\n      \"label\": \"Function 0x1401048B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1401048B0\"\n    },\n    {\n      \"id\": \"api_EnumWindows\",\n      \"label\": \"EnumWindows\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     johnk3r, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_application_hook__4_matches_\",\n      \"label\": \"set application hook (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_SetWindowsHookEx\",\n      \"label\": \"SetWindowsHookEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_UnhookWindowsHookEx\",\n      \"label\": \"UnhookWindowsHookEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_change_the_wallpaper\",\n      \"label\": \"change the wallpaper\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Wallpaper [C0035]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x14013D52F\",\n      \"label\": \"Block 0x14013D52F\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x14013D52F\"\n    },\n    {\n      \"id\": \"api_SystemParametersInfo\",\n      \"label\": \"SystemParametersInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_find_graphical_window\",\n      \"label\": \"find graphical window\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [T1010]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindWindow\",\n      \"label\": \"FindWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_graphical_window_text__7_matches_\",\n      \"label\": \"get graphical window text (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400D96C0\",\n      \"label\": \"Function 0x1400D96C0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D96C0\"\n    },\n    {\n      \"id\": \"func_0x140163B70\",\n      \"label\": \"Function 0x140163B70\",\n      \"type\": \"function\",\n      \"address\": \"0x140163B70\"\n    },\n    {\n      \"id\": \"func_0x1401632A0\",\n      \"label\": \"Function 0x1401632A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1401632A0\"\n    },\n    {\n      \"id\": \"func_0x140163900\",\n      \"label\": \"Function 0x140163900\",\n      \"type\": \"function\",\n      \"address\": \"0x140163900\"\n    },\n    {\n      \"id\": \"func_0x1400D9770\",\n      \"label\": \"Function 0x1400D9770\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D9770\"\n    },\n    {\n      \"id\": \"func_0x14015CFD0\",\n      \"label\": \"Function 0x14015CFD0\",\n      \"type\": \"function\",\n      \"address\": \"0x14015CFD0\"\n    },\n    {\n      \"id\": \"api_GetWindowText\",\n      \"label\": \"GetWindowText\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_hide_graphical_window\",\n      \"label\": \"hide graphical window\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Hide Artifacts::Hidden Window [T1564.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x140102610\",\n      \"label\": \"Block 0x140102610\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x140102610\"\n    },\n    {\n      \"id\": \"api_ShowWindow\",\n      \"label\": \"ShowWindow\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_keyboard_layout__2_matches_\",\n      \"label\": \"get keyboard layout (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery::System Language Discovery\",\n        \"[T1614.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetKeyboardLayoutList\",\n      \"label\": \"GetKeyboardLayoutList\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetKeyboardLayout\",\n      \"label\": \"GetKeyboardLayout\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_information__6_matches_\",\n      \"label\": \"get disk information (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400DC080\",\n      \"label\": \"Function 0x1400DC080\",\n      \"type\": \"function\",\n      \"address\": \"0x1400DC080\"\n    },\n    {\n      \"id\": \"func_0x1400D2A60\",\n      \"label\": \"Function 0x1400D2A60\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D2A60\"\n    },\n    {\n      \"id\": \"func_0x1400D7010\",\n      \"label\": \"Function 0x1400D7010\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D7010\"\n    },\n    {\n      \"id\": \"func_0x1400D8100\",\n      \"label\": \"Function 0x1400D8100\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D8100\"\n    },\n    {\n      \"id\": \"func_0x1400D91B0\",\n      \"label\": \"Function 0x1400D91B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D91B0\"\n    },\n    {\n      \"id\": \"func_0x1400E6E80\",\n      \"label\": \"Function 0x1400E6E80\",\n      \"type\": \"function\",\n      \"address\": \"0x1400E6E80\"\n    },\n    {\n      \"id\": \"api_GetVolumeInformation\",\n      \"label\": \"GetVolumeInformation\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetDriveType\",\n      \"label\": \"GetDriveType\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_QueryDosDevice\",\n      \"label\": \"QueryDosDevice\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_size\",\n      \"label\": \"get disk size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400D7270\",\n      \"label\": \"Function 0x1400D7270\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D7270\"\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpace\",\n      \"label\": \"GetDiskFreeSpace\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_volume_information_via_ioctl__2_matches_\",\n      \"label\": \"get volume information via IOCTL (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1400CFE80\",\n      \"label\": \"Block 0x1400CFE80\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400CFE80\"\n    },\n    {\n      \"id\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"label\": \"author      william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_access_the_windows_event_log\",\n      \"label\": \"access the Windows event log\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery::Log File [E1083.m01]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400B4190\",\n      \"label\": \"Function 0x1400B4190\",\n      \"type\": \"function\",\n      \"address\": \"0x1400B4190\"\n    },\n    {\n      \"id\": \"api_ReportEvent\",\n      \"label\": \"ReportEvent\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_check_mutex_on_windows\",\n      \"label\": \"check mutex on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Check Mutex [C0043]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateMutex\",\n      \"label\": \"CreateMutex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Check Mutex [C0043]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_or_open_mutex_on_windows\",\n      \"label\": \"create or open mutex on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_mehunhoff_google_com\",\n      \"label\": \"mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Mutex [C0042]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_local_ipv4_addresses__3_matches_\",\n      \"label\": \"get local IPv4 addresses (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Network Configuration Discovery [T1016]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Network Configuration Discovery [T1016]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_hostname\",\n      \"label\": \"get hostname\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400D6F40\",\n      \"label\": \"Function 0x1400D6F40\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D6F40\"\n    },\n    {\n      \"id\": \"api_GetComputerName\",\n      \"label\": \"GetComputerName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_system_information_on_windows\",\n      \"label\": \"get system information on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetSystemInfo\",\n      \"label\": \"GetSystemInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, joakim@intezer.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__2_matches_\",\n      \"label\": \"create process on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1400E3562\",\n      \"label\": \"Block 0x1400E3562\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400E3562\"\n    },\n    {\n      \"id\": \"bb_0x1400D7D15\",\n      \"label\": \"Block 0x1400D7D15\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1400D7D15\"\n    },\n    {\n      \"id\": \"api_ShellExecuteEx\",\n      \"label\": \"ShellExecuteEx\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_terminate_process__7_matches_\",\n      \"label\": \"terminate process (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1401AB3A7\",\n      \"label\": \"Function 0x1401AB3A7\",\n      \"type\": \"function\",\n      \"address\": \"0x1401AB3A7\"\n    },\n    {\n      \"id\": \"func_0x1400EC810\",\n      \"label\": \"Function 0x1400EC810\",\n      \"type\": \"function\",\n      \"address\": \"0x1400EC810\"\n    },\n    {\n      \"id\": \"func_0x1400ECD90\",\n      \"label\": \"Function 0x1400ECD90\",\n      \"type\": \"function\",\n      \"address\": \"0x1400ECD90\"\n    },\n    {\n      \"id\": \"func_0x1401AC760\",\n      \"label\": \"Function 0x1401AC760\",\n      \"type\": \"function\",\n      \"address\": \"0x1401AC760\"\n    },\n    {\n      \"id\": \"func_0x1400CCA90\",\n      \"label\": \"Function 0x1400CCA90\",\n      \"type\": \"function\",\n      \"address\": \"0x1400CCA90\"\n    },\n    {\n      \"id\": \"func_0x1400CD290\",\n      \"label\": \"Function 0x1400CD290\",\n      \"type\": \"function\",\n      \"address\": \"0x1400CD290\"\n    },\n    {\n      \"id\": \"api_TerminateProcess\",\n      \"label\": \"TerminateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_ExitProcess\",\n      \"label\": \"ExitProcess\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"label\": \"query or enumerate registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Key [C0036.005]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140110070\",\n      \"label\": \"Function 0x140110070\",\n      \"type\": \"function\",\n      \"address\": \"0x140110070\"\n    },\n    {\n      \"id\": \"func_0x1400DA6F0\",\n      \"label\": \"Function 0x1400DA6F0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400DA6F0\"\n    },\n    {\n      \"id\": \"api_RegEnumKey\",\n      \"label\": \"RegEnumKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"label\": \"query or enumerate registry value (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Query Registry Value [C0036.006]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400DAB40\",\n      \"label\": \"Function 0x1400DAB40\",\n      \"type\": \"function\",\n      \"address\": \"0x1400DAB40\"\n    },\n    {\n      \"id\": \"func_0x1400DAC60\",\n      \"label\": \"Function 0x1400DAC60\",\n      \"type\": \"function\",\n      \"address\": \"0x1400DAC60\"\n    },\n    {\n      \"id\": \"func_0x1400DCB00\",\n      \"label\": \"Function 0x1400DCB00\",\n      \"type\": \"function\",\n      \"address\": \"0x1400DCB00\"\n    },\n    {\n      \"id\": \"func_0x1400DA9A0\",\n      \"label\": \"Function 0x1400DA9A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400DA9A0\"\n    },\n    {\n      \"id\": \"api_RegQueryValueEx\",\n      \"label\": \"RegQueryValueEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHRegGetUSValue\",\n      \"label\": \"SHRegGetUSValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegQueryValue\",\n      \"label\": \"RegQueryValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_registry_value__2_matches_\",\n      \"label\": \"set registry value (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Set Registry Key [C0036.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400E24D0\",\n      \"label\": \"Function 0x1400E24D0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400E24D0\"\n    },\n    {\n      \"id\": \"func_0x1400E2610\",\n      \"label\": \"Function 0x1400E2610\",\n      \"type\": \"function\",\n      \"address\": \"0x1400E2610\"\n    },\n    {\n      \"id\": \"api_RegCreateKeyEx\",\n      \"label\": \"RegCreateKeyEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"api_RegSetValueEx\",\n      \"label\": \"RegSetValueEx\",\n      \"type\": \"api\",\n      \"category\": \"registry\"\n    },\n    {\n      \"id\": \"cap_delete_registry_key__2_matches_\",\n      \"label\": \"delete registry key (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400DA820\",\n      \"label\": \"Function 0x1400DA820\",\n      \"type\": \"function\",\n      \"address\": \"0x1400DA820\"\n    },\n    {\n      \"id\": \"api_RegDeleteKey\",\n      \"label\": \"RegDeleteKey\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Key [C0036.002]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_registry_value\",\n      \"label\": \"delete registry value\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Registry::Delete Registry Value [C0036.007]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400E2720\",\n      \"label\": \"Function 0x1400E2720\",\n      \"type\": \"function\",\n      \"address\": \"0x1400E2720\"\n    },\n    {\n      \"id\": \"api_RegDeleteValue\",\n      \"label\": \"RegDeleteValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_run_as_service\",\n      \"label\": \"run as service\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Conditional Execution::Runs as Service\",\n        \"[B0025.007]\"\n      ]\n    },\n    {\n      \"id\": \"api_StartServiceCtrlDispatcher\",\n      \"label\": \"StartServiceCtrlDispatcher\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_RegisterServiceCtrlHandler\",\n      \"label\": \"RegisterServiceCtrlHandler\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_service__2_matches_\",\n      \"label\": \"create service (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\",\n        \"Execution::System Services::Service Execution\",\n        \"[T1569.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400ECFE0\",\n      \"label\": \"Function 0x1400ECFE0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400ECFE0\"\n    },\n    {\n      \"id\": \"func_0x140005A50\",\n      \"label\": \"Function 0x140005A50\",\n      \"type\": \"function\",\n      \"address\": \"0x140005A50\"\n    },\n    {\n      \"id\": \"api_CreateService\",\n      \"label\": \"CreateService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_OpenSCManager\",\n      \"label\": \"OpenSCManager\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_service__2_matches_\",\n      \"label\": \"delete service (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_DeleteService\",\n      \"label\": \"DeleteService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_start_service__2_matches_\",\n      \"label\": \"start service (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140005820\",\n      \"label\": \"Function 0x140005820\",\n      \"type\": \"function\",\n      \"address\": \"0x140005820\"\n    },\n    {\n      \"id\": \"api_StartService\",\n      \"label\": \"StartService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_stop_service__4_matches_\",\n      \"label\": \"stop service (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\",\n        \"Impact::Service Stop [T1489]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140005930\",\n      \"label\": \"Function 0x140005930\",\n      \"type\": \"function\",\n      \"address\": \"0x140005930\"\n    },\n    {\n      \"id\": \"api_ControlService\",\n      \"label\": \"ControlService\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_session_user_name\",\n      \"label\": \"get session user name\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\",\n        \"Discovery::Account\",\n        \"Discovery [T1087]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400D6FA0\",\n      \"label\": \"Function 0x1400D6FA0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D6FA0\"\n    },\n    {\n      \"id\": \"api_GetUserName\",\n      \"label\": \"GetUserName\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_thread\",\n      \"label\": \"create thread\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x1401AAC4D\",\n      \"label\": \"Block 0x1401AAC4D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x1401AAC4D\"\n    },\n    {\n      \"id\": \"api_CreateThread\",\n      \"label\": \"CreateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__98_matches_\",\n      \"label\": \"link function at runtime on Windows (98 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_link_many_functions_at_runtime__2_matches_\",\n      \"label\": \"link many functions at runtime (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1401AF3F0\",\n      \"label\": \"Function 0x1401AF3F0\",\n      \"type\": \"function\",\n      \"address\": \"0x1401AF3F0\"\n    },\n    {\n      \"id\": \"cap_enumerate_pe_sections__2_matches_\",\n      \"label\": \"enumerate PE sections (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x1400D0820\",\n      \"label\": \"Function 0x1400D0820\",\n      \"type\": \"function\",\n      \"address\": \"0x1400D0820\"\n    },\n    {\n      \"id\": \"cap_author_______ana06___mr_tz\",\n      \"label\": \"author      @Ana06, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Code Discovery::Enumerate PE Sections [B0046.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_parse_pe_header\",\n      \"label\": \"parse PE header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports__7_matches_\",\n      \"label\": \"resolve function by parsing PE exports (7 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x140011870\",\n      \"label\": \"Function 0x140011870\",\n      \"type\": \"function\",\n      \"address\": \"0x140011870\"\n    },\n    {\n      \"id\": \"func_0x140183590\",\n      \"label\": \"Function 0x140183590\",\n      \"type\": \"function\",\n      \"address\": \"0x140183590\"\n    },\n    {\n      \"id\": \"func_0x14016A420\",\n      \"label\": \"Function 0x14016A420\",\n      \"type\": \"function\",\n      \"address\": \"0x14016A420\"\n    },\n    {\n      \"id\": \"func_0x140009FD0\",\n      \"label\": \"Function 0x140009FD0\",\n      \"type\": \"function\",\n      \"address\": \"0x140009FD0\"\n    },\n    {\n      \"id\": \"func_0x140029EE0\",\n      \"label\": \"Function 0x140029EE0\",\n      \"type\": \"function\",\n      \"address\": \"0x140029EE0\"\n    },\n    {\n      \"id\": \"func_0x1400BF5A0\",\n      \"label\": \"Function 0x1400BF5A0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400BF5A0\"\n    },\n    {\n      \"id\": \"func_0x1400B18B0\",\n      \"label\": \"Function 0x1400B18B0\",\n      \"type\": \"function\",\n      \"address\": \"0x1400B18B0\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_persist_via_run_registry_key__3_matches_\",\n      \"label\": \"persist via Run registry key (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Registry Run Keys / Startup Folder [F0012]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x140144390\",\n      \"label\": \"Function 0x140144390\",\n      \"type\": \"function\",\n      \"address\": \"0x140144390\"\n    },\n    {\n      \"id\": \"func_0x14014D500\",\n      \"label\": \"Function 0x14014D500\",\n      \"type\": \"function\",\n      \"address\": \"0x14014D500\"\n    },\n    {\n      \"id\": \"func_0x140149760\",\n      \"label\": \"Function 0x140149760\",\n      \"type\": \"function\",\n      \"address\": \"0x140149760\"\n    },\n    {\n      \"id\": \"cap_persist_via_windows_service__2_matches_\",\n      \"label\": \"persist via Windows service (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Create or Modify System Process::Windows Service\",\n        \"[T1543.003]\",\n        \"Execution::System Services::Service Execution\",\n        \"[T1569.002]\"\n      ]\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__1286_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__1286_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x1400013E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__8_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_rule_\",\n      \"target\": \"bb_0x1400DA6F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__46_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__46_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x140010C9E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_os_version__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_os_version__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x1400E4260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400E4260\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_service_handle__12_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_service_handle__12_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x1400056D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400056D0\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_process__10_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_process__10_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x1400CCAC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_software_breakpoints__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_software_breakpoints__2_matches_\",\n      \"target\": \"func_0x1400F5490\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_software_breakpoints__2_matches_\",\n      \"target\": \"func_0x1400674A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400F5490\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400674A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_time_delay_via_gettickcount__11_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount__11_matches_\",\n      \"target\": \"func_0x1400ECAF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount__11_matches_\",\n      \"target\": \"func_0x140048C20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount__11_matches_\",\n      \"target\": \"func_0x1400EEFC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount__11_matches_\",\n      \"target\": \"func_0x14004FB70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount__11_matches_\",\n      \"target\": \"func_0x140106BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount__11_matches_\",\n      \"target\": \"func_0x1400EC2E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount__11_matches_\",\n      \"target\": \"func_0x1400CE930\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount__11_matches_\",\n      \"target\": \"func_0x1400F0200\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount__11_matches_\",\n      \"target\": \"func_0x14010D5A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount__11_matches_\",\n      \"target\": \"func_0x1400F5050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_for_time_delay_via_gettickcount__11_matches_\",\n      \"target\": \"func_0x14004EC40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400ECAF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140048C20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400EEFC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14004FB70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140106BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400EC2E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400CE930\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400F0200\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14010D5A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400F5050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14004EC40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_for_unmoving_mouse_cursor\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_for_unmoving_mouse_cursor\",\n      \"target\": \"func_0x140141050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______bitsofbinary\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______bitsofbinary\",\n      \"target\": \"func_0x140141050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_geographical_location__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__9_matches_\",\n      \"target\": \"func_0x1400DC3B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__9_matches_\",\n      \"target\": \"func_0x140111260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__9_matches_\",\n      \"target\": \"func_0x1400DC370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__9_matches_\",\n      \"target\": \"func_0x14010F6C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__9_matches_\",\n      \"target\": \"func_0x14005EEB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__9_matches_\",\n      \"target\": \"func_0x1401B0A00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__9_matches_\",\n      \"target\": \"func_0x14010F780\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__9_matches_\",\n      \"target\": \"func_0x14017D070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location__9_matches_\",\n      \"target\": \"func_0x14017ADD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400DC3B0\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140111260\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DC370\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14010F6C0\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14005EEB0\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401B0A00\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14010F780\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14017D070\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14017ADD0\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400DC3B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140111260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400DC370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14010F6C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14005EEB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1401B0A00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14010F780\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14017D070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14017ADD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400DC3B0\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140111260\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DC370\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14010F6C0\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14005EEB0\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401B0A00\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14010F780\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14017D070\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14017ADD0\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_credit_card_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_credit_card_information\",\n      \"target\": \"func_0x14018D880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox\",\n      \"target\": \"func_0x14018D880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__3_matches_\",\n      \"target\": \"func_0x1400E19A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__3_matches_\",\n      \"target\": \"func_0x14015DFB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes__3_matches_\",\n      \"target\": \"func_0x1400F5390\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400E19A0\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14015DFB0\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400F5390\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400E19A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x14015DFB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400F5390\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400E19A0\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14015DFB0\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400F5390\",\n      \"target\": \"api_AttachThreadInput\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_polling__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__6_matches_\",\n      \"target\": \"func_0x1400E1B00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__6_matches_\",\n      \"target\": \"func_0x1400DFED0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__6_matches_\",\n      \"target\": \"func_0x1400DA590\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__6_matches_\",\n      \"target\": \"func_0x1401001F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__6_matches_\",\n      \"target\": \"func_0x1400F8C10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling__6_matches_\",\n      \"target\": \"func_0x1400CC320\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400E1B00\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DFED0\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA590\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401001F0\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400F8C10\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CC320\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E1B00\",\n      \"target\": \"api_GetKeyNameText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DFED0\",\n      \"target\": \"api_GetKeyNameText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA590\",\n      \"target\": \"api_GetKeyNameText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401001F0\",\n      \"target\": \"api_GetKeyNameText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400F8C10\",\n      \"target\": \"api_GetKeyNameText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CC320\",\n      \"target\": \"api_GetKeyNameText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E1B00\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DFED0\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA590\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401001F0\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400F8C10\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CC320\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400E1B00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400DFED0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400DA590\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1401001F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400F8C10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400CC320\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400E1B00\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DFED0\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA590\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401001F0\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400F8C10\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CC320\",\n      \"target\": \"api_GetAsyncKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E1B00\",\n      \"target\": \"api_GetKeyNameText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DFED0\",\n      \"target\": \"api_GetKeyNameText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA590\",\n      \"target\": \"api_GetKeyNameText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401001F0\",\n      \"target\": \"api_GetKeyNameText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400F8C10\",\n      \"target\": \"api_GetKeyNameText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CC320\",\n      \"target\": \"api_GetKeyNameText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E1B00\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DFED0\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA590\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401001F0\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400F8C10\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CC320\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_capture_webcam_image\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_capture_webcam_image\",\n      \"target\": \"func_0x140142A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140142A30\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____johnk3r\",\n      \"target\": \"func_0x140142A30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140142A30\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data__4_matches_\",\n      \"target\": \"func_0x1400C8B20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__4_matches_\",\n      \"target\": \"func_0x1400B74E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__4_matches_\",\n      \"target\": \"func_0x1400B90C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data__4_matches_\",\n      \"target\": \"func_0x1400BCA70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400C8B20\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B74E0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B90C0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BCA70\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x1400C8B20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x1400B74E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x1400B90C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x1400BCA70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400C8B20\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B74E0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B90C0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BCA70\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data__4_matches_\",\n      \"target\": \"func_0x1400B7E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__4_matches_\",\n      \"target\": \"func_0x1400C27F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__4_matches_\",\n      \"target\": \"func_0x1400B95B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data__4_matches_\",\n      \"target\": \"func_0x1400B6780\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400B7E80\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C27F0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B95B0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B6780\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x1400B7E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x1400C27F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x1400B95B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______william_ballenthin_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x1400B6780\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400B7E80\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C27F0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B95B0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B6780\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_dns\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_dns\",\n      \"target\": \"func_0x1400DB440\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400DB440\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400DB440\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400DB440\",\n      \"target\": \"api_gethostbyname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_http_user_agent_string\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_reference_http_user_agent_string\",\n      \"target\": \"func_0x14016C930\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______mr_tz\",\n      \"target\": \"func_0x14016C930\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_pipe\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_pipe\",\n      \"target\": \"func_0x1400F0BE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400F0BE0\",\n      \"target\": \"api_ConnectNamedPipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400F0BE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400F0BE0\",\n      \"target\": \"api_ConnectNamedPipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_pipe\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_pipe\",\n      \"target\": \"func_0x1400F0BE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400F0BE0\",\n      \"target\": \"api_CreateNamedPipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400F0BE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400F0BE0\",\n      \"target\": \"api_CreateNamedPipe\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_connect_socket__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_connect_socket__3_matches_\",\n      \"target\": \"bb_0x1400BB924\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_socket__3_matches_\",\n      \"target\": \"bb_0x1400BBB42\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_connect_socket__3_matches_\",\n      \"target\": \"bb_0x1400B78B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mrhafizfarhad_gmail_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x1400BB924\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x1400BBB42\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_mrhafizfarhad_gmail_com\",\n      \"target\": \"bb_0x1400B78B3\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_socket_information__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_socket_information__3_matches_\",\n      \"target\": \"func_0x1400B9FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_socket_information__3_matches_\",\n      \"target\": \"func_0x1400B9880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_socket_information__3_matches_\",\n      \"target\": \"func_0x1400BB6C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400B9FD0\",\n      \"target\": \"api_getsockname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B9880\",\n      \"target\": \"api_getsockname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BB6C0\",\n      \"target\": \"api_getsockname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400B9FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400B9880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400BB6C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400B9FD0\",\n      \"target\": \"api_getsockname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B9880\",\n      \"target\": \"api_getsockname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BB6C0\",\n      \"target\": \"api_getsockname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_initialize_winsock_library__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_initialize_winsock_library__3_matches_\",\n      \"target\": \"func_0x1400C8F10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_initialize_winsock_library__3_matches_\",\n      \"target\": \"func_0x1400B7AF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_initialize_winsock_library__3_matches_\",\n      \"target\": \"func_0x1400BD1E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400C8F10\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B7AF0\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BD1E0\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400C8F10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400B7AF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400BD1E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400C8F10\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B7AF0\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BD1E0\",\n      \"target\": \"api_WSAStartup\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_socket_configuration__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__6_matches_\",\n      \"target\": \"func_0x1400B77C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__6_matches_\",\n      \"target\": \"func_0x1400B9FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__6_matches_\",\n      \"target\": \"func_0x1400B9880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__6_matches_\",\n      \"target\": \"func_0x1400BB890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__6_matches_\",\n      \"target\": \"func_0x1400BCD00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_socket_configuration__6_matches_\",\n      \"target\": \"func_0x1400C8D50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400B77C0\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B9FD0\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B9880\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BB890\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BCD00\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C8D50\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400B77C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400B9FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400B9880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400BB890\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400BCD00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400C8D50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400B77C0\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B9FD0\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B9880\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BB890\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BCD00\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C8D50\",\n      \"target\": \"api_setsockopt\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_receive_data_on_socket__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__4_matches_\",\n      \"target\": \"func_0x1400C8B20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__4_matches_\",\n      \"target\": \"func_0x1400B74E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__4_matches_\",\n      \"target\": \"func_0x1400B90C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_receive_data_on_socket__4_matches_\",\n      \"target\": \"func_0x1400BCA70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400C8B20\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B74E0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B90C0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BCA70\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400C8B20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400B74E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400B90C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400BCA70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400C8B20\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B74E0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B90C0\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BCA70\",\n      \"target\": \"api_recv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_send_data_on_socket__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__4_matches_\",\n      \"target\": \"func_0x1400B7E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__4_matches_\",\n      \"target\": \"func_0x1400C27F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__4_matches_\",\n      \"target\": \"func_0x1400B95B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_send_data_on_socket__4_matches_\",\n      \"target\": \"func_0x1400B6780\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400B7E80\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C27F0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B95B0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B6780\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400B7E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400C27F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400B95B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400B6780\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400B7E80\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C27F0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B95B0\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B6780\",\n      \"target\": \"api_send\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_udp_socket\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_udp_socket\",\n      \"target\": \"bb_0x1400B9880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x1400B9880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encode_data_using_base64__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__2_matches_\",\n      \"target\": \"func_0x14018D880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encode_data_using_base64__2_matches_\",\n      \"target\": \"func_0x1401899D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14018D880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1401899D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_rc4_ksa__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__2_matches_\",\n      \"target\": \"func_0x140123C80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_rc4_ksa__2_matches_\",\n      \"target\": \"func_0x14010D8C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140123C80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x14010D8C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_encrypt_data_using_speck\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_encrypt_data_using_speck\",\n      \"target\": \"func_0x14018D880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______still_teamt5_org\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______still_teamt5_org\",\n      \"target\": \"func_0x14018D880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_authenticate_hmac\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_authenticate_hmac\",\n      \"target\": \"func_0x14018D880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x14018D880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contains_pdb_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x1400C79B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400C79B0\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C79B0\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C79B0\",\n      \"target\": \"api_FreeResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C79B0\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C79B0\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x1400C79B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400C79B0\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C79B0\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C79B0\",\n      \"target\": \"api_FreeResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C79B0\",\n      \"target\": \"api_FindResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C79B0\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__6_matches_\",\n      \"target\": \"func_0x1401AB000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__6_matches_\",\n      \"target\": \"func_0x1400CE620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__6_matches_\",\n      \"target\": \"func_0x140006010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__6_matches_\",\n      \"target\": \"func_0x1400B4020\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__6_matches_\",\n      \"target\": \"func_0x1400CF8C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__6_matches_\",\n      \"target\": \"func_0x1400CF020\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1401AB000\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CE620\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006010\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B4020\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CF8C0\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CF020\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1401AB000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400CE620\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140006010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400B4020\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400CF8C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400CF020\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1401AB000\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CE620\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140006010\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B4020\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CF8C0\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CF020\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_open_clipboard__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_open_clipboard__6_matches_\",\n      \"target\": \"func_0x1400F8450\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_open_clipboard__6_matches_\",\n      \"target\": \"func_0x1401046A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_open_clipboard__6_matches_\",\n      \"target\": \"func_0x140106BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_open_clipboard__6_matches_\",\n      \"target\": \"func_0x140102050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_open_clipboard__6_matches_\",\n      \"target\": \"func_0x140104520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_open_clipboard__6_matches_\",\n      \"target\": \"func_0x1400D8AA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400F8450\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401046A0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140106BB0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140102050\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140104520\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8AA0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400F8450\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401046A0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140106BB0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140102050\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140104520\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8AA0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400F8450\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1401046A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140106BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140102050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140104520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D8AA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400F8450\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401046A0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140106BB0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140102050\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140104520\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8AA0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400F8450\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401046A0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140106BB0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140102050\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140104520\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8AA0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_clipboard_data\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_clipboard_data\",\n      \"target\": \"func_0x140106BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140106BB0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140106BB0\",\n      \"target\": \"api_GlobalLock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140106BB0\",\n      \"target\": \"api_GlobalUnlock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140106BB0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140106BB0\",\n      \"target\": \"api_GetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140106BB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140106BB0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140106BB0\",\n      \"target\": \"api_GlobalLock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140106BB0\",\n      \"target\": \"api_GlobalUnlock\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140106BB0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140106BB0\",\n      \"target\": \"api_GetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_clipboard_data__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_clipboard_data__4_matches_\",\n      \"target\": \"func_0x140104520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_clipboard_data__4_matches_\",\n      \"target\": \"func_0x1400D8AA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_clipboard_data__4_matches_\",\n      \"target\": \"func_0x1401046A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_clipboard_data__4_matches_\",\n      \"target\": \"func_0x140102050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140104520\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8AA0\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401046A0\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140102050\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140104520\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8AA0\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401046A0\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140102050\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140104520\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8AA0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401046A0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140102050\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140104520\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8AA0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401046A0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140102050\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140104520\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D8AA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1401046A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140102050\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140104520\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8AA0\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401046A0\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140102050\",\n      \"target\": \"api_SetClipboardData\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140104520\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8AA0\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401046A0\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140102050\",\n      \"target\": \"api_EmptyClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140104520\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8AA0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401046A0\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140102050\",\n      \"target\": \"api_CloseClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140104520\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8AA0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401046A0\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140102050\",\n      \"target\": \"api_OpenClipboard\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_interact_with_driver_via_ioctl__32_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__2_matches_\",\n      \"target\": \"func_0x1401AE2A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__2_matches_\",\n      \"target\": \"func_0x1400E0A40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1401AE2A0\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E0A40\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401AE2A0\",\n      \"target\": \"api_GetEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E0A40\",\n      \"target\": \"api_GetEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x1401AE2A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x1400E0A40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1401AE2A0\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E0A40\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401AE2A0\",\n      \"target\": \"api_GetEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E0A40\",\n      \"target\": \"api_GetEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__4_matches_\",\n      \"target\": \"func_0x1400E0230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__4_matches_\",\n      \"target\": \"func_0x1400D9990\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__4_matches_\",\n      \"target\": \"func_0x1400E08B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__4_matches_\",\n      \"target\": \"func_0x1400B44E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400E0230\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D9990\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E08B0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B44E0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E0230\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D9990\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E08B0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B44E0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E0230\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D9990\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E08B0\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B44E0\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E0230\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D9990\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E08B0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B44E0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400E0230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D9990\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400E08B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400B44E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400E0230\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D9990\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E08B0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B44E0\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E0230\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D9990\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E08B0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B44E0\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E0230\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D9990\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E08B0\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B44E0\",\n      \"target\": \"api_SHGetSpecialFolderLocation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E0230\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D9990\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E08B0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B44E0\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_system_object_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_system_object_information\",\n      \"target\": \"bb_0x1400DB18C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x1400DB18C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_copy_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_copy_file\",\n      \"target\": \"func_0x1400CC920\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400CC920\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400CC920\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400CC920\",\n      \"target\": \"api_CopyFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory\",\n      \"target\": \"func_0x1400D5860\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D5860\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D5860\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D5860\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_directory__3_matches_\",\n      \"target\": \"func_0x1400D5430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_directory__3_matches_\",\n      \"target\": \"func_0x1400D5610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_directory__3_matches_\",\n      \"target\": \"func_0x1400D7B50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D5430\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5610\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D7B50\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D5430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D5610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D7B50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D5430\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5610\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D7B50\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__5_matches_\",\n      \"target\": \"func_0x1400D8840\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__5_matches_\",\n      \"target\": \"func_0x1400D7AC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__5_matches_\",\n      \"target\": \"func_0x140165280\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__5_matches_\",\n      \"target\": \"func_0x1400D5430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__5_matches_\",\n      \"target\": \"func_0x1400D5610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D8840\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D7AC0\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140165280\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5430\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5610\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8840\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D7AC0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140165280\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5430\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5610\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D8840\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D7AC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140165280\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D5430\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D5610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D8840\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D7AC0\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140165280\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5430\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5610\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8840\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D7AC0\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140165280\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5430\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5610\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__8_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__8_matches_\",\n      \"target\": \"func_0x1400D5860\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__8_matches_\",\n      \"target\": \"func_0x1400DBC10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__8_matches_\",\n      \"target\": \"func_0x1400D83D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__8_matches_\",\n      \"target\": \"func_0x1400D8440\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__8_matches_\",\n      \"target\": \"func_0x1400D8350\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__8_matches_\",\n      \"target\": \"func_0x1400D5550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__8_matches_\",\n      \"target\": \"func_0x1400D72F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__8_matches_\",\n      \"target\": \"func_0x1400D5770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D5860\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DBC10\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D83D0\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8440\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8350\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5550\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D72F0\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5770\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5860\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DBC10\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D83D0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8440\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8350\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5550\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D72F0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5770\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D5860\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400DBC10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D83D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D8440\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D8350\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D5550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D72F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D5770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D5860\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DBC10\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D83D0\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8440\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8350\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5550\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D72F0\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5770\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5860\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DBC10\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D83D0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8440\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8350\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5550\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D72F0\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5770\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x1400D5894\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x1400D83D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x1400D8463\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x1400D8350\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__5_matches_\",\n      \"target\": \"bb_0x1400D72F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x1400D5894\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x1400D83D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x1400D8463\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x1400D8350\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x1400D72F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x1400DBC10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_size__2_matches_\",\n      \"target\": \"func_0x1400D78D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400DBC10\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D78D0\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400DBC10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D78D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400DBC10\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D78D0\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_move_file__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_move_file__4_matches_\",\n      \"target\": \"func_0x14013CC30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__4_matches_\",\n      \"target\": \"func_0x140109640\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__4_matches_\",\n      \"target\": \"func_0x1400D5610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_move_file__4_matches_\",\n      \"target\": \"func_0x14013C810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14013CC30\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140109640\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5610\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14013C810\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14013CC30\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140109640\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5610\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14013C810\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14013CC30\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140109640\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5610\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14013C810\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14013CC30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140109640\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400D5610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x14013C810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x14013CC30\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140109640\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5610\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14013C810\",\n      \"target\": \"api_SHFileOperation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14013CC30\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140109640\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5610\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14013C810\",\n      \"target\": \"api_MoveFileEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14013CC30\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140109640\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D5610\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14013C810\",\n      \"target\": \"api_MoveFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__25_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400BE4D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x140004770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400E5550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400B8F10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400CFE80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400BE0F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400CFD90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x140004ED0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400EA6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400BE1E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400D13A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x140004D80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x14017B500\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400E5D50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400DBC10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400CB5B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400BE570\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400CFA70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x140004610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400B3660\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400BE010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400048C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400DC9B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400F0070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__25_matches_\",\n      \"target\": \"func_0x1400C2DC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400BE4D0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004770\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E5550\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B8F10\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CFE80\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE0F0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CFD90\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004ED0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EA6D0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE1E0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D13A0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004D80\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14017B500\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E5D50\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DBC10\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CB5B0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE570\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CFA70\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004610\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B3660\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE010\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400048C0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DC9B0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400F0070\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C2DC0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE4D0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004770\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E5550\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B8F10\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CFE80\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE0F0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CFD90\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004ED0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EA6D0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE1E0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D13A0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004D80\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14017B500\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E5D50\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DBC10\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CB5B0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE570\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CFA70\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004610\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B3660\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE010\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400048C0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DC9B0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400F0070\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C2DC0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400BE4D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140004770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400E5550\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400B8F10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400CFE80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400BE0F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400CFD90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140004ED0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400EA6D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400BE1E0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D13A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140004D80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x14017B500\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400E5D50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400DBC10\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400CB5B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400BE570\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400CFA70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140004610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400B3660\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400BE010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400048C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400DC9B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400F0070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400C2DC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400BE4D0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004770\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E5550\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B8F10\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CFE80\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE0F0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CFD90\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004ED0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EA6D0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE1E0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D13A0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004D80\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14017B500\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E5D50\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DBC10\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CB5B0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE570\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CFA70\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004610\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B3660\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE010\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400048C0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DC9B0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400F0070\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C2DC0\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE4D0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004770\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E5550\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B8F10\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CFE80\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE0F0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CFD90\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004ED0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EA6D0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE1E0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D13A0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004D80\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14017B500\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E5D50\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DBC10\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CB5B0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE570\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CFA70\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140004610\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B3660\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BE010\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400048C0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DC9B0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400F0070\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400C2DC0\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__9_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__9_matches_\",\n      \"target\": \"func_0x1400D54C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__9_matches_\",\n      \"target\": \"func_0x1400B3B20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__9_matches_\",\n      \"target\": \"func_0x1401AC870\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__9_matches_\",\n      \"target\": \"func_0x1400EA560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__9_matches_\",\n      \"target\": \"func_0x1400EE1D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__9_matches_\",\n      \"target\": \"func_0x1401ACAB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__9_matches_\",\n      \"target\": \"func_0x1400EE440\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__9_matches_\",\n      \"target\": \"func_0x1400EE680\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__9_matches_\",\n      \"target\": \"func_0x1400EE370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D54C0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B3B20\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401AC870\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EA560\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EE1D0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401ACAB0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EE440\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EE680\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EE370\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D54C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400B3B20\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1401AC870\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400EA560\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400EE1D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1401ACAB0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400EE440\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400EE680\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400EE370\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D54C0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B3B20\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401AC870\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EA560\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EE1D0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401ACAB0\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EE440\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EE680\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EE370\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_gui_resources\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_gui_resources\",\n      \"target\": \"func_0x1401048B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1401048B0\",\n      \"target\": \"api_EnumWindows\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____johnk3r__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1401048B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1401048B0\",\n      \"target\": \"api_EnumWindows\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_application_hook__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_change_the_wallpaper\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_change_the_wallpaper\",\n      \"target\": \"bb_0x14013D52F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox\",\n      \"target\": \"bb_0x14013D52F\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_find_graphical_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_graphical_window_text__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__7_matches_\",\n      \"target\": \"func_0x1400D96C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__7_matches_\",\n      \"target\": \"func_0x140163B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__7_matches_\",\n      \"target\": \"func_0x1401632A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__7_matches_\",\n      \"target\": \"func_0x140163900\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__7_matches_\",\n      \"target\": \"func_0x1400D9770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__7_matches_\",\n      \"target\": \"func_0x14015CFD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text__7_matches_\",\n      \"target\": \"func_0x140165280\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D96C0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140163B70\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401632A0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140163900\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D9770\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14015CFD0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140165280\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D96C0\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140163B70\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401632A0\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140163900\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D9770\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14015CFD0\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140165280\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400D96C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140163B70\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1401632A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140163900\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400D9770\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x14015CFD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140165280\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D96C0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140163B70\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401632A0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140163900\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D9770\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14015CFD0\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140165280\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D96C0\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140163B70\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401632A0\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140163900\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D9770\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x14015CFD0\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140165280\",\n      \"target\": \"api_SendMessage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hide_graphical_window\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hide_graphical_window\",\n      \"target\": \"bb_0x140102610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x140102610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_keyboard_layout__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_keyboard_layout__2_matches_\",\n      \"target\": \"func_0x1400DC3B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_keyboard_layout__2_matches_\",\n      \"target\": \"func_0x1400CC320\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400DC3B0\",\n      \"target\": \"api_GetKeyboardLayoutList\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CC320\",\n      \"target\": \"api_GetKeyboardLayoutList\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DC3B0\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CC320\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DC3B0\",\n      \"target\": \"api_GetKeyboardLayout\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CC320\",\n      \"target\": \"api_GetKeyboardLayout\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400DC3B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400CC320\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400DC3B0\",\n      \"target\": \"api_GetKeyboardLayoutList\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CC320\",\n      \"target\": \"api_GetKeyboardLayoutList\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DC3B0\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CC320\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DC3B0\",\n      \"target\": \"api_GetKeyboardLayout\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CC320\",\n      \"target\": \"api_GetKeyboardLayout\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x1400DC080\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x1400D2A60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x1400D7010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x1400D8100\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x1400D91B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_disk_information__6_matches_\",\n      \"target\": \"func_0x1400E6E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400DC080\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D2A60\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D7010\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8100\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D91B0\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E6E80\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DC080\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D2A60\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D7010\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8100\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D91B0\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E6E80\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DC080\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D2A60\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D7010\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8100\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D91B0\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E6E80\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400DC080\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D2A60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D7010\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D8100\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D91B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400E6E80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400DC080\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D2A60\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D7010\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8100\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D91B0\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E6E80\",\n      \"target\": \"api_GetVolumeInformation\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DC080\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D2A60\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D7010\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8100\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D91B0\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E6E80\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DC080\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D2A60\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D7010\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D8100\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400D91B0\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E6E80\",\n      \"target\": \"api_QueryDosDevice\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_size\",\n      \"target\": \"func_0x1400D7270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D7270\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D7270\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D7270\",\n      \"target\": \"api_GetDiskFreeSpace\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_volume_information_via_ioctl__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_volume_information_via_ioctl__2_matches_\",\n      \"target\": \"bb_0x1400CFE80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______william_ballenthin_mandiant_com\",\n      \"target\": \"bb_0x1400CFE80\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access_the_windows_event_log\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_access_the_windows_event_log\",\n      \"target\": \"func_0x1400B4190\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400B4190\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400B4190\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400B4190\",\n      \"target\": \"api_ReportEvent\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_mutex_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_mutex_on_windows\",\n      \"target\": \"func_0x1400CE930\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400CE930\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CE930\",\n      \"target\": \"api_CreateMutex\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x1400CE930\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400CE930\",\n      \"target\": \"api_GetLastError\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CE930\",\n      \"target\": \"api_CreateMutex\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_mutex_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_local_ipv4_addresses__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_local_ipv4_addresses__3_matches_\",\n      \"target\": \"func_0x1400B9FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_local_ipv4_addresses__3_matches_\",\n      \"target\": \"func_0x1400B9880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_local_ipv4_addresses__3_matches_\",\n      \"target\": \"func_0x1400BB6C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400B9FD0\",\n      \"target\": \"api_getsockname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B9880\",\n      \"target\": \"api_getsockname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BB6C0\",\n      \"target\": \"api_getsockname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com__mehunhoff_google_com\",\n      \"target\": \"func_0x1400B9FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com__mehunhoff_google_com\",\n      \"target\": \"func_0x1400B9880\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com__mehunhoff_google_com\",\n      \"target\": \"func_0x1400BB6C0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400B9FD0\",\n      \"target\": \"api_getsockname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B9880\",\n      \"target\": \"api_getsockname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400BB6C0\",\n      \"target\": \"api_getsockname\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_hostname\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_hostname\",\n      \"target\": \"func_0x1400D6F40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D6F40\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D6F40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D6F40\",\n      \"target\": \"api_GetComputerName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_system_information_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_system_information_on_windows\",\n      \"target\": \"func_0x1400E4260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400E4260\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x1400E4260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400E4260\",\n      \"target\": \"api_GetSystemInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__2_matches_\",\n      \"target\": \"bb_0x1400E3562\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__2_matches_\",\n      \"target\": \"bb_0x1400D7D15\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1400E3562\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x1400D7D15\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process__7_matches_\",\n      \"target\": \"func_0x1400B4190\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__7_matches_\",\n      \"target\": \"func_0x1401AB3A7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__7_matches_\",\n      \"target\": \"func_0x1400EC810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__7_matches_\",\n      \"target\": \"func_0x1400ECD90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__7_matches_\",\n      \"target\": \"func_0x1401AC760\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__7_matches_\",\n      \"target\": \"func_0x1400CCA90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_terminate_process__7_matches_\",\n      \"target\": \"func_0x1400CD290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400B4190\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401AB3A7\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EC810\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400ECD90\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401AC760\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CCA90\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CD290\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B4190\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401AB3A7\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EC810\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400ECD90\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401AC760\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CCA90\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CD290\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B4190\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401AB3A7\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EC810\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400ECD90\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401AC760\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CCA90\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CD290\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400B4190\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1401AB3A7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400EC810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400ECD90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1401AC760\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400CCA90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400CD290\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400B4190\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401AB3A7\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EC810\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400ECD90\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401AC760\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CCA90\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CD290\",\n      \"target\": \"api_OpenProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B4190\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401AB3A7\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EC810\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400ECD90\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401AC760\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CCA90\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CD290\",\n      \"target\": \"api_TerminateProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400B4190\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401AB3A7\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EC810\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400ECD90\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1401AC760\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CCA90\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400CD290\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"target\": \"func_0x140110070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_key__2_matches_\",\n      \"target\": \"func_0x1400DA6F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140110070\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA6F0\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140110070\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA6F0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x140110070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400DA6F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x140110070\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA6F0\",\n      \"target\": \"api_RegEnumKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140110070\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA6F0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x1400DAB40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x1400DAC60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x1400DCB00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x1400DA9A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_or_enumerate_registry_value__5_matches_\",\n      \"target\": \"func_0x140110070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400DAB40\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DAC60\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DCB00\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA9A0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140110070\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DAB40\",\n      \"target\": \"api_SHRegGetUSValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DAC60\",\n      \"target\": \"api_SHRegGetUSValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DCB00\",\n      \"target\": \"api_SHRegGetUSValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA9A0\",\n      \"target\": \"api_SHRegGetUSValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140110070\",\n      \"target\": \"api_SHRegGetUSValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DAB40\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DAC60\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DCB00\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA9A0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140110070\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DAB40\",\n      \"target\": \"api_RegQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DAC60\",\n      \"target\": \"api_RegQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DCB00\",\n      \"target\": \"api_RegQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA9A0\",\n      \"target\": \"api_RegQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140110070\",\n      \"target\": \"api_RegQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400DAB40\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400DAC60\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400DCB00\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400DA9A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x140110070\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400DAB40\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DAC60\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DCB00\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA9A0\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140110070\",\n      \"target\": \"api_RegQueryValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DAB40\",\n      \"target\": \"api_SHRegGetUSValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DAC60\",\n      \"target\": \"api_SHRegGetUSValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DCB00\",\n      \"target\": \"api_SHRegGetUSValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA9A0\",\n      \"target\": \"api_SHRegGetUSValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140110070\",\n      \"target\": \"api_SHRegGetUSValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DAB40\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DAC60\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DCB00\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA9A0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140110070\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DAB40\",\n      \"target\": \"api_RegQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DAC60\",\n      \"target\": \"api_RegQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DCB00\",\n      \"target\": \"api_RegQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA9A0\",\n      \"target\": \"api_RegQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140110070\",\n      \"target\": \"api_RegQueryValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_registry_value__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__2_matches_\",\n      \"target\": \"func_0x1400E24D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_registry_value__2_matches_\",\n      \"target\": \"func_0x1400E2610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400E24D0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E2610\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E24D0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E2610\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400E24D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x1400E2610\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400E24D0\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E2610\",\n      \"target\": \"api_RegCreateKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E24D0\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E2610\",\n      \"target\": \"api_RegSetValueEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_key__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key__2_matches_\",\n      \"target\": \"func_0x1400DA820\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_registry_key__2_matches_\",\n      \"target\": \"func_0x1400DA6F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400DA820\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA6F0\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA820\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA6F0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x1400DA820\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x1400DA6F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400DA820\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA6F0\",\n      \"target\": \"api_RegDeleteKey\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA820\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400DA6F0\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_registry_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_registry_value\",\n      \"target\": \"func_0x1400E2720\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400E2720\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E2720\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400E2720\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400E2720\",\n      \"target\": \"api_RegDeleteValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400E2720\",\n      \"target\": \"api_RegOpenKeyEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_run_as_service\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_service__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_service__2_matches_\",\n      \"target\": \"func_0x1400ECFE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_service__2_matches_\",\n      \"target\": \"func_0x140005A50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400ECFE0\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005A50\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400ECFE0\",\n      \"target\": \"api_OpenSCManager\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005A50\",\n      \"target\": \"api_OpenSCManager\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400ECFE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140005A50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400ECFE0\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005A50\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400ECFE0\",\n      \"target\": \"api_OpenSCManager\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005A50\",\n      \"target\": \"api_OpenSCManager\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_service__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_service__2_matches_\",\n      \"target\": \"func_0x1400056D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_service__2_matches_\",\n      \"target\": \"func_0x1400EC810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400056D0\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EC810\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400056D0\",\n      \"target\": \"api_DeleteService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EC810\",\n      \"target\": \"api_DeleteService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400056D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400EC810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400056D0\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EC810\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400056D0\",\n      \"target\": \"api_DeleteService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EC810\",\n      \"target\": \"api_DeleteService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_start_service__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_start_service__2_matches_\",\n      \"target\": \"func_0x1400ECAF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_start_service__2_matches_\",\n      \"target\": \"func_0x140005820\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400ECAF0\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005820\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400ECAF0\",\n      \"target\": \"api_StartService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005820\",\n      \"target\": \"api_StartService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400ECAF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140005820\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400ECAF0\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005820\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400ECAF0\",\n      \"target\": \"api_StartService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005820\",\n      \"target\": \"api_StartService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_stop_service__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_stop_service__4_matches_\",\n      \"target\": \"func_0x1400ECD90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_stop_service__4_matches_\",\n      \"target\": \"func_0x1400056D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_stop_service__4_matches_\",\n      \"target\": \"func_0x1400EC810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_stop_service__4_matches_\",\n      \"target\": \"func_0x140005930\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400ECD90\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400056D0\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EC810\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005930\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400ECD90\",\n      \"target\": \"api_ControlService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400056D0\",\n      \"target\": \"api_ControlService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EC810\",\n      \"target\": \"api_ControlService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005930\",\n      \"target\": \"api_ControlService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400ECD90\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400056D0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400EC810\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140005930\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400ECD90\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400056D0\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EC810\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005930\",\n      \"target\": \"api_OpenService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400ECD90\",\n      \"target\": \"api_ControlService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400056D0\",\n      \"target\": \"api_ControlService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x1400EC810\",\n      \"target\": \"api_ControlService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005930\",\n      \"target\": \"api_ControlService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_session_user_name\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_session_user_name\",\n      \"target\": \"func_0x1400D6FA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D6FA0\",\n      \"target\": \"api_GetUserName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x1400D6FA0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400D6FA0\",\n      \"target\": \"api_GetUserName\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread\",\n      \"target\": \"bb_0x1401AAC4D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x1401AAC4D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__98_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_many_functions_at_runtime__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__2_matches_\",\n      \"target\": \"func_0x1401AF3F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_link_many_functions_at_runtime__2_matches_\",\n      \"target\": \"func_0x1400E4260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x1401AF3F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__joakim_intezer_com\",\n      \"target\": \"func_0x1400E4260\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_pe_sections__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__2_matches_\",\n      \"target\": \"func_0x1400D13A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_enumerate_pe_sections__2_matches_\",\n      \"target\": \"func_0x1400D0820\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______ana06___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x1400D13A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_______ana06___mr_tz\",\n      \"target\": \"func_0x1400D0820\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header\",\n      \"target\": \"func_0x1401AB000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1401AB000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports__7_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__7_matches_\",\n      \"target\": \"func_0x140011870\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__7_matches_\",\n      \"target\": \"func_0x140183590\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__7_matches_\",\n      \"target\": \"func_0x14016A420\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__7_matches_\",\n      \"target\": \"func_0x140009FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__7_matches_\",\n      \"target\": \"func_0x140029EE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__7_matches_\",\n      \"target\": \"func_0x1400BF5A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports__7_matches_\",\n      \"target\": \"func_0x1400B18B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x140011870\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x140183590\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x14016A420\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x140009FD0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x140029EE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x1400BF5A0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x1400B18B0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_persist_via_run_registry_key__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_persist_via_run_registry_key__3_matches_\",\n      \"target\": \"func_0x140144390\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_persist_via_run_registry_key__3_matches_\",\n      \"target\": \"func_0x14014D500\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_persist_via_run_registry_key__3_matches_\",\n      \"target\": \"func_0x140149760\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x140144390\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x14014D500\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"target\": \"func_0x140149760\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_persist_via_windows_service__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_persist_via_windows_service__2_matches_\",\n      \"target\": \"func_0x1400ECFE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_persist_via_windows_service__2_matches_\",\n      \"target\": \"func_0x140005A50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400ECFE0\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005A50\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x1400ECFE0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x140005A50\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x1400ECFE0\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x140005A50\",\n      \"target\": \"api_CreateService\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-20 17:03:45.576871\",\n    \"total_functions\": \"2689\",\n    \"total_features\": \"234849\",\n    \"pdb_path\": \"c:\\\\\\\\dev\\\\\\\\Everything-1.4\\\\\\\\x64\\\\\\\\Release\\\\\\\\Everything.pdb\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-20 17:03:53"}
{"_id":{"$oid":"6a5e3f39b3bed57e0e737943"},"sha256":"03e40798b193db7de556657be34522abb0a4bb6f74b2e71bb4b4af44dab6aa40","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_i7z1_uq2/zlib_offset_0x59454_5.bin_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_i7z1_uq2/zlib_offset_0x59454_5.bin_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_i7z1_uq2/zlib_offset_0x59454_5.bin_very_verbose.txt"}},"outputs":{"normal":"┌───────────┬──────────────────────────────────────────────────────────────────┐\n│ md5       │ 862f820c3251e4ca6fc0ac00e4092239                                 │\n│ sha1      │ ef96d84b253041b090c243594f90938e9a487a9a                         │\n│ sha256    │ 36585912e5eaf83ba9fea0631534f690ccdc2d7ba91537166fe53e56c221e153 │\n│ analysis  │ static                                                           │\n│ os        │ windows                                                          │\n│ format    │ pe                                                               │\n│ arch      │ amd64                                                            │\n│ path      │ /tmp/sdm_decoded_nsfochly/zlib_offset_0x59454_5.bin              │\n└───────────┴──────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic                       ┃ ATT&CK Technique                       ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ EXECUTION                           │ Shared Modules [T1129]                 │\n└─────────────────────────────────────┴────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                               ┃ Namespace                         ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ contains PDB path                        │ executable/pe/pdb                 │\n│ parse PE header                          │ load-code/pe                      │\n└──────────────────────────────────────────┴───────────────────────────────────┘\n\n","verbose":"md5                     862f820c3251e4ca6fc0ac00e4092239                        \nsha1                    ef96d84b253041b090c243594f90938e9a487a9a                \nsha256                  36585912e5eaf83ba9fea0631534f690ccdc2d7ba91537166fe53e5…\npath                    /tmp/sdm_decoded_nsfochly/zlib_offset_0x59454_5.bin     \ntimestamp               2026-07-20 21:00:56.916001                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x180000000                                             \nrules                   /tmp/_MEIWgGeyR/rules                                   \nfunction count          141                                                     \nlibrary function count  145                                                     \ntotal feature count     10317                                                   \n\ncontains PDB path\nnamespace  executable/pe/pdb\nscope      file             \n\nparse PE header\nnamespace  load-code/pe\nscope      function    \nmatches    0x180010D30 \n\n\n\n","very_verbose":"md5                     862f820c3251e4ca6fc0ac00e4092239                        \nsha1                    ef96d84b253041b090c243594f90938e9a487a9a                \nsha256                  36585912e5eaf83ba9fea0631534f690ccdc2d7ba91537166fe53e5…\npath                    /tmp/sdm_decoded_nsfochly/zlib_offset_0x59454_5.bin     \ntimestamp               2026-07-20 21:01:04.749700                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x180000000                                             \nrules                   /tmp/_MEIP9czgP/rules                                   \nfunction count          141                                                     \nlibrary function count  145                                                     \ntotal feature count     10317                                                   \n\ncontain loop (59 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x180001230\n  or:\n    characteristic: loop @ 0x180001230\n\ncontains PDB path\nnamespace  executable/pe/pdb        \nauthor     moritz.raabe@mandiant.com\nscope      file                     \nregex: /:\\\\.*\\.pdb/\n  - \"D:\\\\a\\\\_work\\\\1\\\\s\\\\binaries\\\\amd64ret\\\\bin\\\\amd64\\\\\\\\vcruntime140.amd64.pdb\" @ file+0x14EDC\n\nparse PE header\nnamespace  load-code/pe                     \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \natt&ck     Execution::Shared Modules [T1129]\nfunction @ 0x180010D30\n  and:\n    os: windows\n    and:\n      mnemonic: cmp @ 0x180010D35, 0x180010D41, 0x180010D50\n      or:\n        number: 0x4550 = IMAGE_NT_SIGNATURE (PE) @ 0x180010D41\n      or:\n        number: 0x5A4D = IMAGE_DOS_SIGNATURE (MZ) @ 0x180010D30\n\n\n\n"},"hashes":{"md5":"862f820c3251e4ca6fc0ac00e4092239","sha1":"ef96d84b253041b090c243594f90938e9a487a9a","sha256":"36585912e5eaf83ba9fea0631534f690ccdc2d7ba91537166fe53e56c221e153"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 141</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 10317</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"zlib_offset_0x59454_5.bin\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"862f820c3251e4ca6fc0ac00e4092239\",\n        \"sha256\": \"36585912e5eaf83ba9fea0631534f690ccdc2d7ba91537166fe53e5\",\n        \"arch\": \"amd64\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_contain_loop__59_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (59 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x180001230\",\n      \"label\": \"Function 0x180001230\",\n      \"type\": \"function\",\n      \"address\": \"0x180001230\"\n    },\n    {\n      \"id\": \"cap_contains_pdb_path\",\n      \"label\": \"contains PDB path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_parse_pe_header\",\n      \"label\": \"parse PE header\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x180010D30\",\n      \"label\": \"Function 0x180010D30\",\n      \"type\": \"function\",\n      \"address\": \"0x180010D30\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__59_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__59_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x180001230\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contains_pdb_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_parse_pe_header\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_parse_pe_header\",\n      \"target\": \"func_0x180010D30\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x180010D30\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-20 21:01:04.749700\",\n    \"total_functions\": \"141\",\n    \"total_features\": \"10317\",\n    \"pdb_path\": \"D:\\\\\\\\a\\\\\\\\_work\\\\\\\\1\\\\\\\\s\\\\\\\\binaries\\\\\\\\amd64ret\\\\\\\\bin\\\\\\\\amd64\\\\\\\\\\\\\\\\vcruntime140.amd64.pdb\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-20 21:01:05"}
{"_id":{"$oid":"6a5f64dd39c3725e311ebc02"},"sha256":"ca029c447aa12fd5e8e91a5debffcdde4cf78151ee15ee13da69200a3cc1663f","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_hgkexcw_/ca029c447aa12fd5e8e91a5debffcdde4cf78151ee15ee13da69200a3cc1663f-019f84747f8b7b32a1cccc7839305ec1.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_hgkexcw_/ca029c447aa12fd5e8e91a5debffcdde4cf78151ee15ee13da69200a3cc1663f-019f84747f8b7b32a1cccc7839305ec1.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_hgkexcw_/ca029c447aa12fd5e8e91a5debffcdde4cf78151ee15ee13da69200a3cc1663f-019f84747f8b7b32a1cccc7839305ec1.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 861e3af88bf1bcac9caf72bf16fa02b5                                  │\n│ sha1     │ d0e4300ef05b840b0f36e198eb634b54a917761d                          │\n│ sha256   │ ca029c447aa12fd5e8e91a5debffcdde4cf78151ee15ee13da69200a3cc1663f  │\n│ analysis │ static                                                            │\n│ os       │ any                                                               │\n│ format   │ dotnet                                                            │\n│ arch     │ amd64                                                             │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/ca029c447aa12fd5… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION      │ Reflective Code Loading [T1620]                       │\n│                      │ Virtualization/Sandbox Evasion::System Checks         │\n│                      │ [T1497.001]                                           │\n│ DISCOVERY            │ File and Directory Discovery [T1083]                  │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Virtual Machine Detection [B0009]                 │\n│ CRYPTOGRAPHY             │ Generate Pseudo-random Sequence::Use API          │\n│                          │ [C0021.003]                                       │\n│ DISCOVERY                │ Analysis Tool Discovery::Process detection        │\n│                          │ [B0013.001]                                       │\n│                          │ File and Directory Discovery [E1083]              │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                             ┃ Namespace                           ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ reference analysis tools strings       │ anti-analysis                       │\n│ reference anti-VM strings targeting    │ anti-analysis/anti-vm/vm-detection  │\n│ Xen                                    │                                     │\n│ generate random numbers in .NET (4     │ data-manipulation/prng              │\n│ matches)                               │                                     │\n│ access .NET resource                   │ executable/resource                 │\n│ check if file exists                   │ host-interaction/file-system/exists │\n│ load .NET assembly                     │ load-code/dotnet                    │\n│ compiled to the .NET platform          │ runtime/dotnet                      │\n└────────────────────────────────────────┴─────────────────────────────────────┘\n\n","verbose":"md5                     861e3af88bf1bcac9caf72bf16fa02b5                        \nsha1                    d0e4300ef05b840b0f36e198eb634b54a917761d                \nsha256                  ca029c447aa12fd5e8e91a5debffcdde4cf78151ee15ee13da69200…\npath                    /home/apogean/projects/malware/windows/all_runs/ca029c4…\ntimestamp               2026-07-21 17:53:16.376715                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIqXPqIk/rules                                   \nfunction count          79                                                      \nlibrary function count  0                                                       \ntotal feature count     152233                                                  \n\nreference analysis tools strings\nnamespace  anti-analysis\nscope      file         \n\nreference anti-VM strings targeting Xen\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\ngenerate random numbers in .NET (4 matches)\nnamespace  data-manipulation/prng\nscope      function              \nmatches    token(0x6000011)      \n           token(0x6000013)      \n           token(0x6000015)      \n           token(0x6000021)      \n\naccess .NET resource\nnamespace  executable/resource\nscope      function           \nmatches    token(0x600003F)   \n\ncheck if file exists\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    token(0x6000038)                   \n\nload .NET assembly\nnamespace  load-code/dotnet\nscope      function        \nmatches    token(0x600001A)\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet\nscope      file          \n\n\n\n","very_verbose":"md5                     861e3af88bf1bcac9caf72bf16fa02b5                        \nsha1                    d0e4300ef05b840b0f36e198eb634b54a917761d                \nsha256                  ca029c447aa12fd5e8e91a5debffcdde4cf78151ee15ee13da69200…\npath                    /home/apogean/projects/malware/windows/all_runs/ca029c4…\ntimestamp               2026-07-21 17:53:56.922622                              \ncapa version            9.2.1                                                   \nos                      any                                                     \nformat                  dotnet                                                  \narch                    amd64                                                   \nanalysis                static                                                  \nextractor               DnfileFeatureExtractor                                  \nbase address            global                                                  \nrules                   /tmp/_MEIsWrTF6/rules                                   \nfunction count          79                                                      \nlibrary function count  0                                                       \ntotal feature count     152233                                                  \n\nreference analysis tools strings\nnamespace   anti-analysis                                                       \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \nmbc         Discovery::Analysis Tool Discovery::Process detection [B0013.001]   \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /(?<!\\w)ida?(\\.exe)?$/i\n    - \"IDAT\" @ file+0x2A0C9, file+0x5A0C9, file+0x6A0C9, file+0x8A0C9, and 104 more...\n\nreference anti-VM strings targeting Xen\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /^Xen/i\n    - \"XEN~--\" @ file+0x36B977\n    - \"Xen~\" @ file+0x68488A\n    - \"xEn~\" @ file+0x380FAF\n\ngenerate random numbers in .NET (4 matches)\nnamespace  data-manipulation/prng                                            \nauthor     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com     \nscope      function                                                          \nmbc        Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\nfunction @ token(0x6000011)\n  or:\n    api: System.Random::NextDouble @ token(0x6000011)+0x1F, token(0x6000011)+0xF0\nfunction @ token(0x6000013)\n  or:\n    api: System.Random::Next @ token(0x6000013)+0x11\nfunction @ token(0x6000015)\n  or:\n    api: System.Random::NextDouble @ token(0x6000015)+0x1F, token(0x6000015)+0x57\nfunction @ token(0x6000021)\n  or:\n    api: System.Random::NextDouble @ token(0x6000021)+0x90\n\naccess .NET resource\nnamespace  executable/resource\nauthor     @mr-tz             \nscope      function           \nfunction @ token(0x600003F)\n  and:\n    format: dotnet\n    or:\n      api: System.Resources.ResourceManager::ctor @ token(0x600003F)+0x22\n\ncheck if file exists\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ token(0x6000038)\n  or:\n    api: System.IO.File::Exists @ token(0x6000038)+0x7\n\n(internal) .NET file limitation\nnamespace    internal/limitation/dynamic                        \nauthor       @v1bh475u                                          \nscope        file                                               \ndescription  This dynamic analysis trace describes a .NET file. \n                                                                \n             capa rules are not yet tuned for the .NET runtime, \n             so its analysis may be incomplete or misleading.   \n                                                                \nor:\n  format: dotnet\n\nload .NET assembly\nnamespace  load-code/dotnet                                \nauthor     anushka.virgaonkar@mandiant.com                 \nscope      function                                        \natt&ck     Defense Evasion::Reflective Code Loading [T1620]\nfunction @ token(0x600001A)\n  or:\n    api: System.AppDomain::Load @ token(0x600001A)+0x2CD\n\ncompiled to the .NET platform\nnamespace  runtime/dotnet                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nor:\n  format: dotnet\n\n\n\n"},"hashes":{"md5":"861e3af88bf1bcac9caf72bf16fa02b5","sha1":"d0e4300ef05b840b0f36e198eb634b54a917761d","sha256":"ca029c447aa12fd5e8e91a5debffcdde4cf78151ee15ee13da69200a3cc1663f"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 79</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 152233</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"ca029c4\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"861e3af88bf1bcac9caf72bf16fa02b5\",\n        \"sha256\": \"ca029c447aa12fd5e8e91a5debffcdde4cf78151ee15ee13da69200\",\n        \"arch\": \"amd64\",\n        \"os\": \"any\",\n        \"format\": \"dotnet\"\n      }\n    },\n    {\n      \"id\": \"cap_reference_analysis_tools_strings\",\n      \"label\": \"reference analysis tools strings\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Analysis Tool Discovery::Process detection [B0013.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"label\": \"reference anti-VM strings targeting Xen\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_generate_random_numbers_in__net__4_matches_\",\n      \"label\": \"generate random numbers in .NET (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"api_System\",\n      \"label\": \"System\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Cryptography::Generate Pseudo-random Sequence::Use API [C0021.003]\"\n      ]\n    },\n    {\n      \"id\": \"cap_access__net_resource\",\n      \"label\": \"access .NET resource\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz\",\n      \"label\": \"author     @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists\",\n      \"label\": \"check if file exists\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap__internal___net_file_limitation\",\n      \"label\": \"(internal) .NET file limitation\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author________v1bh475u\",\n      \"label\": \"author       @v1bh475u\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_load__net_assembly\",\n      \"label\": \"load .NET assembly\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Reflective Code Loading [T1620]\"\n      ]\n    },\n    {\n      \"id\": \"cap_compiled_to_the__net_platform\",\n      \"label\": \"compiled to the .NET platform\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_analysis_tools_strings\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_generate_random_numbers_in__net__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_access__net_resource\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap__internal___net_file_limitation\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author________v1bh475u\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_load__net_assembly\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_to_the__net_platform\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-21 17:53:56.922622\",\n    \"total_functions\": \"79\",\n    \"total_features\": \"152233\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-21 17:53:57"}
{"_id":{"$oid":"6a5f8f0039c3725e311ebc0c"},"sha256":"115a0313cc91d6bd04289153206752ba9576f08418583e826b546240940731ad","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_g79i0t42/DriverPack-Notifier-019f8543e9bb7843ad162075fdd8babb.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_g79i0t42/DriverPack-Notifier-019f8543e9bb7843ad162075fdd8babb.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_g79i0t42/DriverPack-Notifier-019f8543e9bb7843ad162075fdd8babb.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ 1f2ce8a37d806b8e01e35917c64a3487                                  │\n│ sha1     │ 8b378b0b8e193c50241f588fed6e82ed65e38b31                          │\n│ sha256   │ 115a0313cc91d6bd04289153206752ba9576f08418583e826b546240940731ad  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/DriverPack-Notif… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic        ┃ ATT&CK Technique                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ COLLECTION           │ Input Capture::Keylogging [T1056.001]                 │\n│ DEFENSE EVASION      │ File and Directory Permissions Modification [T1222]   │\n│                      │ Indicator Removal::File Deletion [T1070.004]          │\n│                      │ Obfuscated Files or Information [T1027]               │\n│                      │ Virtualization/Sandbox Evasion::System Checks         │\n│                      │ [T1497.001]                                           │\n│ DISCOVERY            │ File and Directory Discovery [T1083]                  │\n│                      │ System Information Discovery [T1082]                  │\n│                      │ System Location Discovery [T1614]                     │\n│                      │ System Location Discovery::System Language Discovery  │\n│                      │ [T1614.001]                                           │\n│                      │ System Owner/User Discovery [T1033]                   │\n│ EXECUTION            │ Command and Scripting Interpreter [T1059]             │\n│                      │ Shared Modules [T1129]                                │\n│ PERSISTENCE          │ Boot or Logon Autostart Execution::Shortcut           │\n│                      │ Modification [T1547.009]                              │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MAEC Category                                    ┃ MAEC Value                ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ malware-category                                 │ launcher                  │\n└──────────────────────────────────────────────────┴───────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective            ┃ MBC Behavior                                      ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ ANTI-BEHAVIORAL ANALYSIS │ Virtual Machine Detection [B0009]                 │\n│ COLLECTION               │ Keylogging::Application Hook [F0002.001]          │\n│                          │ Keylogging::Polling [F0002.002]                   │\n│ DATA                     │ Checksum::CRC32 [C0032.001]                       │\n│                          │ Encode Data::XOR [C0026.002]                      │\n│ DEFENSE EVASION          │ Obfuscated Files or                               │\n│                          │ Information::Encoding-Standard Algorithm          │\n│                          │ [E1027.m02]                                       │\n│                          │ Self Deletion::COMSPEC Environment Variable       │\n│                          │ [F0007.001]                                       │\n│ DISCOVERY                │ Application Window Discovery [E1010]              │\n│                          │ File and Directory Discovery [E1083]              │\n│                          │ System Information Discovery [E1082]              │\n│ EXECUTION                │ Command and Scripting Interpreter [E1059]         │\n│ FILE SYSTEM              │ Create Directory [C0046]                          │\n│                          │ Delete Directory [C0048]                          │\n│                          │ Delete File [C0047]                               │\n│                          │ Get File Attributes [C0049]                       │\n│                          │ Read File [C0051]                                 │\n│                          │ Set File Attributes [C0050]                       │\n│                          │ Writes File [C0052]                               │\n│ OPERATING SYSTEM         │ Environment Variable::Set Variable [C0034.001]    │\n│ PROCESS                  │ Create Process [C0017]                            │\n│                          │ Create Thread [C0038]                             │\n│                          │ Resume Thread [C0054]                             │\n│                          │ Terminate Process [C0018]                         │\n└──────────────────────────┴───────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ inspect load icon resource            │ anti-analysis                        │\n│ self delete                           │ anti-analysis/anti-forensic/self-de… │\n│ reference anti-VM strings targeting   │ anti-analysis/anti-vm/vm-detection   │\n│ Xen                                   │                                      │\n│ get geographical location             │ collection                           │\n│ log keystrokes via application hook   │ collection/keylog                    │\n│ log keystrokes via polling            │ collection/keylog                    │\n│ hash data with CRC32                  │ data-manipulation/checksum/crc32     │\n│ encode data using XOR (4 matches)     │ data-manipulation/encoding/xor       │\n│ extract resource via kernel32         │ executable/resource                  │\n│ functions                             │                                      │\n│ accept command line arguments (2      │ host-interaction/cli                 │\n│ matches)                              │                                      │\n│ query environment variable (3         │ host-interaction/environment-variab… │\n│ matches)                              │                                      │\n│ set environment variable              │ host-interaction/environment-variab… │\n│ get common file path (4 matches)      │ host-interaction/file-system         │\n│ get file system object information    │ host-interaction/file-system         │\n│ set current directory                 │ host-interaction/file-system         │\n│ create directory                      │ host-interaction/file-system/create  │\n│ delete directory                      │ host-interaction/file-system/delete  │\n│ delete file (2 matches)               │ host-interaction/file-system/delete  │\n│ check if file exists (5 matches)      │ host-interaction/file-system/exists  │\n│ enumerate files recursively           │ host-interaction/file-system/files/… │\n│ get file attributes (6 matches)       │ host-interaction/file-system/meta    │\n│ get file size                         │ host-interaction/file-system/meta    │\n│ set file attributes (4 matches)       │ host-interaction/file-system/meta    │\n│ read file on Windows (2 matches)      │ host-interaction/file-system/read    │\n│ clear file content                    │ host-interaction/file-system/write   │\n│ write file on Windows (3 matches)     │ host-interaction/file-system/write   │\n│ get graphical window text             │ host-interaction/gui/window/get-text │\n│ get memory capacity                   │ host-interaction/hardware/memory     │\n│ get disk information                  │ host-interaction/hardware/storage    │\n│ get disk size                         │ host-interaction/hardware/storage    │\n│ check OS version                      │ host-interaction/os/version          │\n│ create process on Windows (3 matches) │ host-interaction/process/create      │\n│ terminate process                     │ host-interaction/process/terminate   │\n│ get token membership                  │ host-interaction/session             │\n│ create thread (2 matches)             │ host-interaction/thread/create       │\n│ resume thread (2 matches)             │ host-interaction/thread/resume       │\n│ link function at runtime on Windows   │ linking/runtime-linking              │\n│ (6 matches)                           │                                      │\n│ resolve function by parsing PE        │ load-code/pe                         │\n│ exports                               │                                      │\n│ create shortcut via IShellLink        │ persistence                          │\n│ identify system language via API      │ targeting/language                   │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     1f2ce8a37d806b8e01e35917c64a3487                        \nsha1                    8b378b0b8e193c50241f588fed6e82ed65e38b31                \nsha256                  115a0313cc91d6bd04289153206752ba9576f08418583e826b54624…\npath                    /home/apogean/projects/malware/windows/all_runs/DriverP…\ntimestamp               2026-07-21 20:53:32.186870                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIPbhQWR/rules                                   \nfunction count          566                                                     \nlibrary function count  22                                                      \ntotal feature count     34217                                                   \n\ninspect load icon resource\nnamespace  anti-analysis\nscope      basic block  \nmatches    0x4086FC     \n\nself delete\nnamespace  anti-analysis/anti-forensic/self-deletion\nscope      function                                 \nmatches    0x4052FA                                 \n\nreference anti-VM strings targeting Xen\nnamespace  anti-analysis/anti-vm/vm-detection\nscope      file                              \n\nget geographical location\nnamespace  collection\nscope      function  \nmatches    0x402173  \n\nlog keystrokes via application hook\nnamespace  collection/keylog\nscope      basic block      \nmatches    0x40865B         \n\nlog keystrokes via polling\nnamespace  collection/keylog\nscope      function         \nmatches    0x405717         \n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32\nscope      function                        \nmatches    0x416400                        \n\nencode data using XOR (4 matches)\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x416402                      \n           0x4164C0                      \n           0x416AB0                      \n           0x416B90                      \n\nextract resource via kernel32 functions\nnamespace  executable/resource\nscope      function           \nmatches    0x401DB5           \n\naccept command line arguments (2 matches)\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x405034            \n           0x405717            \n\nquery environment variable (3 matches)\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x402173                             \n           0x402B5D                             \n           0x403269                             \n\nset environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x4045DD                             \n\nget common file path (4 matches)\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x40384A                    \n           0x40452E                    \n           0x4048F9                    \n           0x408A0E                    \n\nget file system object information\nnamespace  host-interaction/file-system\nscope      basic block                 \nmatches    0x408A0E                    \n\nset current directory\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x405717                    \n\ncreate directory\nnamespace  host-interaction/file-system/create\nscope      function                           \nmatches    0x401B61                           \n\ndelete directory\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x402ED2                           \n\ndelete file (2 matches)\nnamespace  host-interaction/file-system/delete\nscope      function                           \nmatches    0x402ED2                           \n           0x402FDF                           \n\ncheck if file exists (5 matches)\nnamespace  host-interaction/file-system/exists\nscope      function                           \nmatches    0x401B61                           \n           0x402FDF                           \n           0x403373                           \n           0x40452E                           \n           0x405717                           \n\nenumerate files on Windows\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x402ED2                               \n\nenumerate files recursively\nnamespace  host-interaction/file-system/files/list\nscope      function                               \nmatches    0x402ED2                               \n\nget file attributes (6 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x401B8C                         \n           0x402FEC                         \n           0x403373                         \n           0x40375C                         \n           0x404591                         \n           0x4066BB                         \n\nget file size\nnamespace  host-interaction/file-system/meta\nscope      function                         \nmatches    0x40F93A                         \n\nset file attributes (4 matches)\nnamespace  host-interaction/file-system/meta\nscope      basic block                      \nmatches    0x402F7D                         \n           0x402FAE                         \n           0x403006                         \n           0x40544E                         \n\nread file on Windows (2 matches)\nnamespace  host-interaction/file-system/read\nscope      function                         \nmatches    0x40FA71                         \n           0x40FA9E                         \n\nclear file content\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x40FB66                          \n\nwrite file on Windows (3 matches)\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x401BCB                          \n           0x4052FA                          \n           0x40FB2C                          \n\nset application hook (4 matches)\nnamespace  host-interaction/gui\nscope      instruction         \nmatches    0x406F75            \n           0x406F88            \n           0x40864C            \n           0x408666            \n\nget graphical window text\nnamespace  host-interaction/gui/window/get-text\nscope      function                            \nmatches    0x4030D6                            \n\nget memory capacity\nnamespace  host-interaction/hardware/memory\nscope      function                        \nmatches    0x4026BB                        \n\nget disk information\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x4052FA                         \n\nget disk size\nnamespace  host-interaction/hardware/storage\nscope      function                         \nmatches    0x4011BD                         \n\ncheck OS version\nnamespace  host-interaction/os/version\nscope      function                   \nmatches    0x405717                   \n\ncreate process on Windows (3 matches)\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x404FF0                       \n           0x405034                       \n           0x40544E                       \n\nterminate process\nnamespace  host-interaction/process/terminate\nscope      function                          \nmatches    0x401000                          \n\nget token membership\nnamespace  host-interaction/session\nscope      function                \nmatches    0x40243A                \n\ncreate thread (2 matches)\nnamespace  host-interaction/thread/create\nscope      basic block                   \nmatches    0x4015FD                      \n           0x406DF7                      \n\nresume thread (2 matches)\nnamespace  host-interaction/thread/resume\nscope      basic block                   \nmatches    0x405205                      \n           0x405248                      \n\nlink function at runtime on Windows (6 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x401E4C               \n           0x401E83               \n           0x402372               \n           0x4023BB               \n           0x4023ED               \n           0x407654               \n\nresolve function by parsing PE exports\nnamespace  load-code/pe\nscope      function    \nmatches    0x414F7C    \n\ncreate shortcut via IShellLink\nnamespace  persistence\nscope      function   \nmatches    0x40384A   \n\nidentify system language via API\nnamespace  targeting/language\nscope      function          \nmatches    0x40211D          \n\n\n\n","very_verbose":"md5                     1f2ce8a37d806b8e01e35917c64a3487                        \nsha1                    8b378b0b8e193c50241f588fed6e82ed65e38b31                \nsha256                  115a0313cc91d6bd04289153206752ba9576f08418583e826b54624…\npath                    /home/apogean/projects/malware/windows/all_runs/DriverP…\ntimestamp               2026-07-21 20:53:43.915570                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIGwjCvr/rules                                   \nfunction count          566                                                     \nlibrary function count  22                                                      \ntotal feature count     34217                                                   \n\nallocate memory (library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x402734 in function 0x402725\n  or:\n    api: VirtualAlloc @ 0x402741\n\nallocate or change RW memory (library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x402734 in function 0x402725\n  and:\n    or:\n      match: allocate memory @ 0x402734\n        or:\n          api: VirtualAlloc @ 0x402741\n    or:\n      number: 0x4 = PAGE_READWRITE @ 0x402734\n\ncalculate modulo 256 via x86 assembly (3 matches, only showing first match of \nlibrary rule)\nauthor  moritz.raabe@mandiant.com\nscope   instruction              \nmbc     Data::Modulo [C0058]     \ninstruction @ 0x4164C9\n  and:\n    or:\n      arch: i386\n    mnemonic: and @ 0x4164C9\n    or:\n      number: 0xFF @ 0x4164C9\n\ncontain loop (161 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x401000\n  or:\n    characteristic: tight loop @ 0x401063\n\ncreate or open file (2 matches, only showing first match of library rule)\nauthor  michael.hunhoff@mandiant.com, joakim@intezer.com\nscope   instruction                                     \nmbc     File System::Create File [C0016]                \ninstruction @ 0x405372\n  or:\n    api: CreateFile @ 0x405372\n\ndelay execution (6 matches, only showing first match of library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x4012DA in function 0x4012CF\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x4012DC\n\nget OS version (library rule)\nauthor  @mr-tz  \nscope   function\nfunction @ 0x405717\n  or:\n    api: GetVersionEx @ 0x405747\n\ninspect load icon resource\nnamespace  anti-analysis               \nauthor     michael.hunhoff@mandiant.com\nscope      basic block                 \nbasic block @ 0x4086FC in function 0x4086DD\n  and:\n    api: LoadIcon @ 0x408709\n    number: 0x0 @ 0x408704, 0x408715, 0x408729\n    mnemonic: test @ 0x408736\n    not:\n      or: = predefined icon identifiers\n        number: 0x7F05 = IDI_WINLOGO\n        number: 0x7F06 = IDI_SHIELD\n        number: 0x7F02 = IDI_QUESTION\n        number: 0x7F00 = IDI_APPLICATION\n        number: 0x7F04 = (IDI_ASTERISK | IDI_INFORMATION)\n        number: 0x7F01 = (IDI_ERROR | IDI_HAND)\n        number: 0x7F03 = (IDI_EXCLAMATION | IDI_WARNING)\n\nself delete\nnamespace  anti-analysis/anti-forensic/self-deletion                            \nauthor     michael.hunhoff@mandiant.com, @mr-tz                                 \nscope      function                                                             \natt&ck     Defense Evasion::Indicator Removal::File Deletion [T1070.004]        \nmbc        Defense Evasion::Self Deletion::COMSPEC Environment Variable         \n           [F0007.001]                                                          \nfunction @ 0x4052FA\n  and:\n    or:\n      match: host-interaction/process/create @ 0x40544E\n        or:\n          api: ShellExecute @ 0x405464\n    or:\n      regex: /(^|[\\&;\\|]\\s*)del(\\s.*)?/i\n        - \"del \\\"\" @ 0x40539A\n\nreference anti-VM strings targeting Xen\nnamespace   anti-analysis/anti-vm/vm-detection                                  \nauthor      michael.hunhoff@mandiant.com                                        \nscope       file                                                                \natt&ck      Defense Evasion::Virtualization/Sandbox Evasion::System Checks      \n            [T1497.001]                                                         \nmbc         Anti-Behavioral Analysis::Virtual Machine Detection [B0009]         \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nor:\n  regex: /^Xen/i\n    - \"XenW\" @ file+0x90533\n\nget geographical location\nnamespace  collection                                  \nauthor     moritz.raabe, michael.hunhoff@mandiant.com  \nscope      function                                    \natt&ck     Discovery::System Location Discovery [T1614]\nfunction @ 0x402173\n  or:\n    api: GetLocaleInfo @ 0x4022EF\n\nlog keystrokes via application hook\nnamespace  collection/keylog                                   \nauthor     michael.hunhoff@mandiant.com                        \nscope      basic block                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]   \nmbc        Collection::Keylogging::Application Hook [F0002.001]\nbasic block @ 0x40865B in function 0x40862A\n  and:\n    match: set application hook @ 0x408666\n      or:\n        api: SetWindowsHookEx @ 0x408666\n    or:\n      number: 0x2 = WH_KEYBOARD @ 0x408664\n\nlog keystrokes via polling\nnamespace  collection/keylog                                \nauthor     michael.hunhoff@mandiant.com                     \nscope      function                                         \natt&ck     Collection::Input Capture::Keylogging [T1056.001]\nmbc        Collection::Keylogging::Polling [F0002.002]      \nfunction @ 0x405717\n  or:\n    api: GetKeyState @ 0x4063B0\n\nwrite and execute a file\nnamespace              communication/c2/file-transfer               \nmaec/malware-category  launcher                                     \nauthor                 moritz.raabe@mandiant.com                    \nscope                  function                                     \nmbc                    Execution::Install Additional Program [B0023]\nfunction @ 0x4052FA\n  and:\n    match: host-interaction/file-system/write @ 0x4052FA\n      or:\n        and:\n          os: windows\n          optional:\n            basic block:\n              or:\n                number: 0x40000000 = GENERIC_WRITE @ 0x40536A\n                number: 0x2 = FILE_WRITE_DATA @ 0x405366\n                match: create or open file @ 0x405372\n                  or:\n                    api: CreateFile @ 0x405372\n          or:\n            api: WriteFile @ 0x405427\n    match: host-interaction/process/create @ 0x40544E\n      or:\n        api: ShellExecute @ 0x405464\n\nhash data with CRC32\nnamespace  data-manipulation/checksum/crc32 \nauthor     moritz.raabe@mandiant.com        \nscope      function                         \nmbc        Data::Checksum::CRC32 [C0032.001]\nfunction @ 0x416400\n  or:\n    and:\n      number: 0x1 = bits in a byte @ 0x416404, 0x416407, 0x416413, 0x416419, and 22 more...\n      instruction:\n        and:\n          operand[1].number: 0x1 @ 0x416440\n          or:\n            mnemonic: and @ 0x416440\n        and:\n          operand[1].number: 0x1 @ 0x416404\n          or:\n            mnemonic: and @ 0x416404\n        and:\n          operand[1].number: 0x1 @ 0x416467\n          or:\n            mnemonic: and @ 0x416467\n        and:\n          operand[1].number: 0x1 @ 0x41642D\n          or:\n            mnemonic: and @ 0x41642D\n        and:\n          operand[1].number: 0x1 @ 0x41648E\n          or:\n            mnemonic: and @ 0x41648E\n        and:\n          operand[1].number: 0x1 @ 0x416454\n          or:\n            mnemonic: and @ 0x416454\n        and:\n          operand[1].number: 0x1 @ 0x416419\n          or:\n            mnemonic: and @ 0x416419\n        and:\n          operand[1].number: 0x1 @ 0x41647B\n          or:\n            mnemonic: and @ 0x41647B\n      instruction:\n        and:\n          mnemonic: shr @ 0x416481\n          number: 0x1 @ 0x416481\n        and:\n          mnemonic: shr @ 0x416427\n          number: 0x1 @ 0x416427\n        and:\n          mnemonic: shr @ 0x41644E\n          number: 0x1 @ 0x41644E\n        and:\n          mnemonic: shr @ 0x416433\n          number: 0x1 @ 0x416433\n        and:\n          mnemonic: shr @ 0x416413\n          number: 0x1 @ 0x416413\n        and:\n          mnemonic: shr @ 0x416475\n          number: 0x1 @ 0x416475\n        and:\n          mnemonic: shr @ 0x41645A\n          number: 0x1 @ 0x41645A\n        and:\n          mnemonic: shr @ 0x41649C\n          number: 0x1 @ 0x41649C\n      characteristic: nzxor @ 0x416415, 0x416429, 0x41643C, 0x416450, and 5 more...\n      operand[1].number: 0xEDB88320 @ 0x41640C, 0x416421, 0x416437, 0x416448, and 4 more...\n\nencode data using XOR (4 matches)\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x416402 in function 0x416400\n  and:\n    characteristic: tight loop @ 0x416402\n    characteristic: nzxor @ 0x416415, 0x416429, 0x41643C, 0x416450, and 4 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x4164C0 in function 0x416400\n  and:\n    characteristic: tight loop @ 0x4164C0\n    characteristic: nzxor @ 0x4164D2\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x416AB0 in function 0x416A60\n  and:\n    characteristic: tight loop @ 0x416AB0\n    characteristic: nzxor @ 0x416AB7, 0x416AC1, 0x416AD1, 0x416ADB, and 4 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\nbasic block @ 0x416B90 in function 0x416B40\n  and:\n    characteristic: tight loop @ 0x416B90\n    characteristic: nzxor @ 0x416BA8, 0x416BAC, 0x416BB3, 0x416BB7, and 4 more...\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\nextract resource via kernel32 functions\nnamespace  executable/resource            \nauthor     william.ballenthin@mandiant.com\nscope      function                       \nfunction @ 0x401DB5\n  or:\n    and:\n      or:\n        api: LoadResource @ 0x401E0C\n        api: LockResource @ 0x401E17\n      optional:\n        api: GetModuleHandle @ 0x401DC0\n        or:\n          api: FindResourceEx @ 0x401DDD, 0x401DF1\n        api: SizeofResource @ 0x401E02\n\naccept command line arguments (2 matches)\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x405034\n  or:\n    api: GetCommandLine @ 0x405055\nfunction @ 0x405717\n  or:\n    api: GetCommandLine @ 0x4057D8, 0x406040\n\nquery environment variable (3 matches)\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x402173\n  or:\n    api: GetEnvironmentVariable @ 0x4021E8, 0x40221B\nfunction @ 0x402B5D\n  or:\n    api: ExpandEnvironmentStrings @ 0x402B8E, 0x402BAF\nfunction @ 0x403269\n  or:\n    api: GetEnvironmentVariable @ 0x40327F, 0x4032AB\n\nset environment variable\nnamespace  host-interaction/environment-variable                           \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \nmbc        Operating System::Environment Variable::Set Variable [C0034.001]\nfunction @ 0x4045DD\n  or:\n    api: SetEnvironmentVariable @ 0x404619\n\nget common file path (4 matches)\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x40384A\n  or:\n    api: SHGetSpecialFolderPath @ 0x403911\nfunction @ 0x40452E\n  or:\n    api: GetTempPath @ 0x404551, 0x40456E\nfunction @ 0x4048F9\n  or:\n    api: SHGetSpecialFolderPath @ 0x40498B\nfunction @ 0x408A0E\n  or:\n    api: GetSystemDirectory @ 0x408A56\n\nget file system object information\nnamespace  host-interaction/file-system                   \nauthor     michael.hunhoff@mandiant.com                   \nscope      basic block                                    \natt&ck     Discovery::File and Directory Discovery [T1083]\nbasic block @ 0x408A0E in function 0x408A0E\n  or:\n    api: SHGetFileInfo @ 0x408A76\n\nset current directory\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x405717\n  or:\n    api: SetCurrentDirectory @ 0x406C0F\n\ncreate directory\nnamespace  host-interaction/file-system/create                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Create Directory [C0046]                  \nfunction @ 0x401B61\n  or:\n    api: CreateDirectory @ 0x401B68\n\ndelete directory\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete Directory [C0048]                  \nfunction @ 0x402ED2\n  or:\n    api: RemoveDirectory @ 0x402FBC\n\ndelete file (2 matches)\nnamespace  host-interaction/file-system/delete                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \nmbc        File System::Delete File [C0047]                       \nfunction @ 0x402ED2\n  or:\n    api: DeleteFile @ 0x402F87\nfunction @ 0x402FDF\n  or:\n    api: DeleteFile @ 0x403014\n\ncheck if file exists (5 matches)\nnamespace  host-interaction/file-system/exists                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\nscope      function                                               \natt&ck     Discovery::File and Directory Discovery [T1083]        \nmbc        Discovery::File and Directory Discovery [E1083]        \nfunction @ 0x401B61\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x401B90\n        instruction:\n          and:\n            mnemonic: cmp @ 0x401B96\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x401B96\nfunction @ 0x402FDF\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x402FF2\n        instruction:\n          and:\n            mnemonic: cmp @ 0x402FF8\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x402FF8\nfunction @ 0x403373\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x403381\n        instruction:\n          and:\n            mnemonic: cmp @ 0x403387\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x403387\nfunction @ 0x40452E\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x4045BF\n        instruction:\n          and:\n            mnemonic: cmp @ 0x4045C5\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x4045C5\nfunction @ 0x405717\n  or:\n    basic block:\n      and:\n        api: GetFileAttributes @ 0x406708\n        instruction:\n          and:\n            mnemonic: cmp @ 0x40670E\n            number: 0xFFFFFFFF = INVALID_FILE_ATTRIBUTES @ 0x40670E\n\nenumerate files on Windows\nnamespace   host-interaction/file-system/files/list                             \nauthor      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com          \nscope       function                                                            \natt&ck      Discovery::File and Directory Discovery [T1083]                     \nmbc         Discovery::File and Directory Discovery [E1083]                     \nreferences  https://github.com/hfiref0x/TDL/blob/cc4b46ae1c939b14a22a734a727b16…\nfunction @ 0x402ED2\n  or:\n    and:\n      or:\n        api: FindFirstFile @ 0x402F01\n      or:\n        api: FindNextFile @ 0x402F99\n      optional:\n        api: FindClose @ 0x402FA8\n        match: contain loop @ 0x402ED2\n          or:\n            characteristic: loop @ 0x402ED2\n            characteristic: recursive call @ 0x402ED2\n\nenumerate files recursively\nnamespace  host-interaction/file-system/files/list        \nauthor     @_re_fox, anushka.virgaonkar@mandiant.com      \nscope      function                                       \natt&ck     Discovery::File and Directory Discovery [T1083]\nmbc        Discovery::File and Directory Discovery [E1083]\nfunction @ 0x402ED2\n  and:\n    characteristic: recursive call @ 0x402ED2\n    or:\n      match: enumerate files on Windows @ 0x402ED2\n        or:\n          and:\n            or:\n              api: FindFirstFile @ 0x402F01\n            or:\n              api: FindNextFile @ 0x402F99\n            optional:\n              api: FindClose @ 0x402FA8\n              match: contain loop @ 0x402ED2\n                or:\n                  characteristic: loop @ 0x402ED2\n                  characteristic: recursive call @ 0x402ED2\n\nget file attributes (6 matches)\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      basic block                                                  \nmbc        File System::Get File Attributes [C0049]                     \nbasic block @ 0x401B8C in function 0x401B61\n  or:\n    api: GetFileAttributes @ 0x401B90\nbasic block @ 0x402FEC in function 0x402FDF\n  or:\n    api: GetFileAttributes @ 0x402FF2\nbasic block @ 0x403373 in function 0x403373\n  or:\n    api: GetFileAttributes @ 0x403381\nbasic block @ 0x40375C in function 0x4036DD\n  or:\n    api: GetFileAttributes @ 0x403767\nbasic block @ 0x404591 in function 0x40452E\n  or:\n    api: GetFileAttributes @ 0x4045BF\nbasic block @ 0x4066BB in function 0x405717\n  or:\n    api: GetFileAttributes @ 0x406708\n\nget file size\nnamespace  host-interaction/file-system/meta                            \nauthor     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                     \natt&ck     Discovery::File and Directory Discovery [T1083]              \nmbc        Discovery::File and Directory Discovery [E1083]              \nfunction @ 0x40F93A\n  or:\n    api: GetFileSize @ 0x40F945\n\nset file attributes (4 matches)\nnamespace  host-interaction/file-system/meta                                    \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      basic block                                                          \natt&ck     Defense Evasion::File and Directory Permissions Modification [T1222] \nmbc        File System::Set File Attributes [C0050]                             \nbasic block @ 0x402F7D in function 0x402ED2\n  or:\n    api: SetFileAttributes @ 0x402F80\nbasic block @ 0x402FAE in function 0x402ED2\n  or:\n    api: SetFileAttributes @ 0x402FB3\nbasic block @ 0x403006 in function 0x402FDF\n  or:\n    api: SetFileAttributes @ 0x403009\nbasic block @ 0x40544E in function 0x4052FA\n  or:\n    api: SetFileAttributes @ 0x405452\n\nread file on Windows (2 matches)\nnamespace  host-interaction/file-system/read                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \nmbc        File System::Read File [C0051]                            \nfunction @ 0x40FA71\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x40FA87\nfunction @ 0x40FA9E\n  or:\n    and:\n      os: windows\n      or:\n        api: ReadFile @ 0x40FA87\n\nclear file content\nnamespace  host-interaction/file-system/write\nauthor     jakeperalta7                      \nscope      function                          \nmbc        File System::Writes File [C0052]  \nfunction @ 0x40FB66\n  and:\n    api: SetEndOfFile @ 0x40FB68\n    not:\n      api: SetFilePointer\n\nwrite file on Windows (3 matches)\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x401BCB\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x401BF2\nfunction @ 0x4052FA\n  or:\n    and:\n      os: windows\n      optional:\n        basic block:\n          or:\n            number: 0x40000000 = GENERIC_WRITE @ 0x40536A\n            number: 0x2 = FILE_WRITE_DATA @ 0x405366\n            match: create or open file @ 0x405372\n              or:\n                api: CreateFile @ 0x405372\n      or:\n        api: WriteFile @ 0x405427\nfunction @ 0x40FB2C\n  or:\n    and:\n      os: windows\n      or:\n        api: WriteFile @ 0x40FB4F\n\nset application hook (4 matches)\nnamespace  host-interaction/gui        \nauthor     michael.hunhoff@mandiant.com\nscope      instruction                 \ninstruction @ 0x406F75\n  or:\n    api: UnhookWindowsHookEx @ 0x406F75\ninstruction @ 0x406F88\n  or:\n    api: UnhookWindowsHookEx @ 0x406F88\ninstruction @ 0x40864C\n  or:\n    api: SetWindowsHookEx @ 0x40864C\ninstruction @ 0x408666\n  or:\n    api: SetWindowsHookEx @ 0x408666\n\nget graphical window text\nnamespace  host-interaction/gui/window/get-text           \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \nmbc        Discovery::Application Window Discovery [E1010]\nfunction @ 0x4030D6\n  or:\n    and:\n      api: GetWindowText @ 0x403104\n\nget memory capacity\nnamespace  host-interaction/hardware/memory               \nauthor     moritz.raabe@mandiant.com                      \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nfunction @ 0x4026BB\n  or:\n    api: GlobalMemoryStatusEx @ 0x4026DF\n\nget disk information\nnamespace  host-interaction/hardware/storage                         \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Discovery::System Information Discovery [T1082]           \nmbc        Discovery::System Information Discovery [E1082]           \nfunction @ 0x4052FA\n  or:\n    api: GetDriveType @ 0x405341\n\nget disk size\nnamespace   host-interaction/hardware/storage                                   \nauthor      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com       \nscope       function                                                            \natt&ck      Discovery::System Information Discovery [T1082]                     \nmbc         Discovery::System Information Discovery [E1082]                     \nreferences  https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/A…\nfunction @ 0x4011BD\n  or:\n    api: GetDiskFreeSpaceEx @ 0x4011D9\n\ncheck OS version\nnamespace  host-interaction/os/version                    \nauthor     michael.hunhoff@mandiant.com, johnk3r          \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x405717\n  and:\n    match: get OS version @ 0x405717\n      or:\n        api: GetVersionEx @ 0x405747\n    or:\n      and:\n        instruction:\n          and:\n            mnemonic: cmp @ 0x405762\n            number: 0x5 = Windows 2000 @ 0x405762\n        optional:\n          instruction:\n            and:\n              mnemonic: cmp @ 0x406007\n              or:\n                number: 0x0 @ 0x406007\n            and:\n              mnemonic: cmp @ 0x406C48\n              or:\n                number: 0x0 @ 0x406C48\n            and:\n              mnemonic: cmp @ 0x406809\n              or:\n                number: 0x0 @ 0x406809\n            and:\n              mnemonic: cmp @ 0x40664E\n              or:\n                number: 0x0 @ 0x40664E\n            and:\n              mnemonic: cmp @ 0x406A8F\n              or:\n                number: 0x0 @ 0x406A8F\n            and:\n              mnemonic: cmp @ 0x406392\n              or:\n                number: 0x0 @ 0x406392\n            and:\n              mnemonic: cmp @ 0x4062D3\n              or:\n                number: 0x0 @ 0x4062D3\n            and:\n              mnemonic: cmp @ 0x406654\n              or:\n                number: 0x0 @ 0x406654\n            and:\n              mnemonic: cmp @ 0x405755\n              or:\n                number: 0x2 = Windows XP 64-bit / Windows Server 2003 / Windows Server 2003 R2 @ 0x405755\n            and:\n              mnemonic: cmp @ 0x4063D9\n              or:\n                number: 0x0 @ 0x4063D9\n            and:\n              mnemonic: cmp @ 0x406A99\n              or:\n                number: 0x0 @ 0x406A99\n            and:\n              mnemonic: cmp @ 0x40691E\n              or:\n                number: 0x0 @ 0x40691E\n            and:\n              mnemonic: cmp @ 0x406261\n              or:\n                number: 0x0 @ 0x406261\n            and:\n              mnemonic: cmp @ 0x4064A3\n              or:\n                number: 0x0 @ 0x4064A3\n            and:\n              mnemonic: cmp @ 0x405FE8\n              or:\n                number: 0x1 = Windows XP @ 0x405FE8\n            and:\n              mnemonic: cmp @ 0x4065EA\n              or:\n                number: 0x0 @ 0x4065EA\n            and:\n              mnemonic: cmp @ 0x40666C\n              or:\n                number: 0x0 @ 0x40666C\n            and:\n              mnemonic: cmp @ 0x4064AD\n              or:\n                number: 0x0 @ 0x4064AD\n            and:\n              mnemonic: cmp @ 0x4066AE\n              or:\n                number: 0x0 @ 0x4066AE\n            and:\n              mnemonic: cmp @ 0x406CB7\n              or:\n                number: 0x0 @ 0x406CB7\n            and:\n              mnemonic: cmp @ 0x405ABA\n              or:\n                number: 0x2 = Windows XP 64-bit / Windows Server 2003 / Windows Server 2003 R2 @ 0x405ABA\n            and:\n              mnemonic: cmp @ 0x4069FB\n              or:\n                number: 0x0 @ 0x4069FB\n            and:\n              mnemonic: cmp @ 0x406CBD\n              or:\n                number: 0x0 @ 0x406CBD\n\ncreate process on Windows (3 matches)\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x404FF0 in function 0x404F5D\n  or:\n    api: ShellExecuteEx @ 0x405000\nbasic block @ 0x405034 in function 0x405034\n  or:\n    api: CreateProcess @ 0x4051A0\nbasic block @ 0x40544E in function 0x4052FA\n  or:\n    api: ShellExecute @ 0x405464\n\nterminate process\nnamespace  host-interaction/process/terminate                                   \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \nmbc        Process::Terminate Process [C0018]                                   \nfunction @ 0x401000\n  or:\n    and:\n      or:\n        api: ExitProcess @ 0x4010AC\n\nget token membership\nnamespace  host-interaction/session                      \nauthor     michael.hunhoff@mandiant.com                  \nscope      function                                      \natt&ck     Discovery::System Owner/User Discovery [T1033]\nfunction @ 0x40243A\n  and:\n    api: CheckTokenMembership @ 0x402485\n    optional:\n      api: AllocateAndInitializeSid @ 0x402473\n      api: FreeSid @ 0x40248E\n\ncreate thread (2 matches)\nnamespace  host-interaction/thread/create                                       \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           joakim@intezer.com, anushka.virgaonkar@mandiant.com                  \nscope      basic block                                                          \nmbc        Process::Create Thread [C0038]                                       \nbasic block @ 0x4015FD in function 0x4015FD\n  or:\n    and:\n      os: windows\n      or:\n        api: CreateThread @ 0x401641\nbasic block @ 0x406DF7 in function 0x406DF7\n  or:\n    and:\n      os: windows\n      or:\n        api: _beginthreadex @ 0x406E0A\n\nresume thread (2 matches)\nnamespace  host-interaction/thread/resume                     \nauthor     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\nscope      basic block                                        \nmbc        Process::Resume Thread [C0054]                     \nbasic block @ 0x405205 in function 0x405034\n  or:\n    api: ResumeThread @ 0x405223\nbasic block @ 0x405248 in function 0x405034\n  or:\n    api: ResumeThread @ 0x40524B\n\nlink function at runtime on Windows (6 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x401E4C\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401E4C\ninstruction @ 0x401E83\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401E83\ninstruction @ 0x402372\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x402372\ninstruction @ 0x4023BB\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4023BB\ninstruction @ 0x4023ED\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4023ED\ninstruction @ 0x407654\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x407654\n\nresolve function by parsing PE exports\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x414F7C\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x414F7C\n      mnemonic: movzx @ 0x415111\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x41509B\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x4153D3\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x4150A3\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x414F8C, 0x414FB6, 0x41502F, 0x4150D1, and 8 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x4154B3\n\ncreate shortcut via IShellLink\nnamespace   persistence                                                         \nauthor      matthew.williams@mandiant.com                                       \nscope       function                                                            \natt&ck      Persistence::Boot or Logon Autostart Execution::Shortcut            \n            Modification [T1547.009]                                            \nreferences  https://docs.microsoft.com/en-us/windows/win32/shell/links#creating…\nfunction @ 0x40384A\n  and:\n    offset: 0x50 = psl->SetPath @ 0x403AC1\n    offset: 0x18 = ppf->Save @ 0x403B29\n    api: CoCreateInstance @ 0x403AA9\n    bytes: 0114020000000000c000000000000046 = CLSID_ShellLink @ 0x403AA1\n    bytes: 0b01000000000000c000000000000046 = IID_IPersistFile @ 0x403B12\n    or:\n      bytes: f914020000000000c000000000000046 = IID_IShellLinkW @ 0x403A99\n\nidentify system language via API\nnamespace  targeting/language                                                   \nauthor     william.ballenthin@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::System Location Discovery::System Language Discovery      \n           [T1614.001]                                                          \nfunction @ 0x40211D\n  and:\n    os: windows\n    or:\n      api: GetUserDefaultUILanguage @ 0x402127\n      api: GetSystemDefaultUILanguage @ 0x402148\n\n\n\n"},"hashes":{"md5":"1f2ce8a37d806b8e01e35917c64a3487","sha1":"8b378b0b8e193c50241f588fed6e82ed65e38b31","sha256":"115a0313cc91d6bd04289153206752ba9576f08418583e826b546240940731ad"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 566</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 34217</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"DriverP\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"1f2ce8a37d806b8e01e35917c64a3487\",\n        \"sha256\": \"115a0313cc91d6bd04289153206752ba9576f08418583e826b54624\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_library_rule_\",\n      \"label\": \"library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Modulo [C0058]\"\n      ]\n    },\n    {\n      \"id\": \"cap_contain_loop__161_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (161 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401000\",\n      \"label\": \"Function 0x401000\",\n      \"type\": \"function\",\n      \"address\": \"0x401000\"\n    },\n    {\n      \"id\": \"cap_create_or_open_file__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"create or open file (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create File [C0016]\"\n      ]\n    },\n    {\n      \"id\": \"api_CreateFile\",\n      \"label\": \"CreateFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_delay_execution__6_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"delay execution (6 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed\",\n        \"Execution [B0003.003]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4012DA\",\n      \"label\": \"Block 0x4012DA\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4012DA\"\n    },\n    {\n      \"id\": \"api_Sleep\",\n      \"label\": \"Sleep\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_inspect_load_icon_resource\",\n      \"label\": \"inspect load icon resource\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"bb_0x4086FC\",\n      \"label\": \"Block 0x4086FC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4086FC\"\n    },\n    {\n      \"id\": \"api_LoadIcon\",\n      \"label\": \"LoadIcon\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_self_delete\",\n      \"label\": \"self delete\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4052FA\",\n      \"label\": \"Function 0x4052FA\",\n      \"type\": \"function\",\n      \"address\": \"0x4052FA\"\n    },\n    {\n      \"id\": \"api_ShellExecute\",\n      \"label\": \"ShellExecute\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Defense Evasion::Self Deletion::COMSPEC Environment Variable\",\n        \"[F0007.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"label\": \"reference anti-VM strings targeting Xen\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Anti-Behavioral Analysis::Virtual Machine Detection [B0009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_geographical_location\",\n      \"label\": \"get geographical location\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402173\",\n      \"label\": \"Function 0x402173\",\n      \"type\": \"function\",\n      \"address\": \"0x402173\"\n    },\n    {\n      \"id\": \"api_GetLocaleInfo\",\n      \"label\": \"GetLocaleInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery [T1614]\"\n      ]\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_application_hook\",\n      \"label\": \"log keystrokes via application hook\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Application Hook [F0002.001]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x40865B\",\n      \"label\": \"Block 0x40865B\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40865B\"\n    },\n    {\n      \"id\": \"api_SetWindowsHookEx\",\n      \"label\": \"SetWindowsHookEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_log_keystrokes_via_polling\",\n      \"label\": \"log keystrokes via polling\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Collection::Keylogging::Polling [F0002.002]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405717\",\n      \"label\": \"Function 0x405717\",\n      \"type\": \"function\",\n      \"address\": \"0x405717\"\n    },\n    {\n      \"id\": \"api_GetKeyState\",\n      \"label\": \"GetKeyState\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_write_and_execute_a_file\",\n      \"label\": \"write and execute a file\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"api_WriteFile\",\n      \"label\": \"WriteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_maec_malware_category__launcher\",\n      \"label\": \"maec/malware-category  launcher\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"launcher\",\n      \"mitre\": [\n        \"Execution::Install Additional Program [B0023]\"\n      ]\n    },\n    {\n      \"id\": \"cap_hash_data_with_crc32\",\n      \"label\": \"hash data with CRC32\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x416400\",\n      \"label\": \"Function 0x416400\",\n      \"type\": \"function\",\n      \"address\": \"0x416400\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Data::Checksum::CRC32 [C0032.001]\"\n      ]\n    },\n    {\n      \"id\": \"cap_extract_resource_via_kernel32_functions\",\n      \"label\": \"extract resource via kernel32 functions\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401DB5\",\n      \"label\": \"Function 0x401DB5\",\n      \"type\": \"function\",\n      \"address\": \"0x401DB5\"\n    },\n    {\n      \"id\": \"api_SizeofResource\",\n      \"label\": \"SizeofResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LockResource\",\n      \"label\": \"LockResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindResourceEx\",\n      \"label\": \"FindResourceEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_LoadResource\",\n      \"label\": \"LoadResource\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetModuleHandle\",\n      \"label\": \"GetModuleHandle\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments__2_matches_\",\n      \"label\": \"accept command line arguments (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x405034\",\n      \"label\": \"Function 0x405034\",\n      \"type\": \"function\",\n      \"address\": \"0x405034\"\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable__3_matches_\",\n      \"label\": \"query environment variable (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402B5D\",\n      \"label\": \"Function 0x402B5D\",\n      \"type\": \"function\",\n      \"address\": \"0x402B5D\"\n    },\n    {\n      \"id\": \"func_0x403269\",\n      \"label\": \"Function 0x403269\",\n      \"type\": \"function\",\n      \"address\": \"0x403269\"\n    },\n    {\n      \"id\": \"api_GetEnvironmentVariable\",\n      \"label\": \"GetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_ExpandEnvironmentStrings\",\n      \"label\": \"ExpandEnvironmentStrings\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_environment_variable\",\n      \"label\": \"set environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable::Set Variable [C0034.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4045DD\",\n      \"label\": \"Function 0x4045DD\",\n      \"type\": \"function\",\n      \"address\": \"0x4045DD\"\n    },\n    {\n      \"id\": \"api_SetEnvironmentVariable\",\n      \"label\": \"SetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path__4_matches_\",\n      \"label\": \"get common file path (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40452E\",\n      \"label\": \"Function 0x40452E\",\n      \"type\": \"function\",\n      \"address\": \"0x40452E\"\n    },\n    {\n      \"id\": \"func_0x408A0E\",\n      \"label\": \"Function 0x408A0E\",\n      \"type\": \"function\",\n      \"address\": \"0x408A0E\"\n    },\n    {\n      \"id\": \"func_0x40384A\",\n      \"label\": \"Function 0x40384A\",\n      \"type\": \"function\",\n      \"address\": \"0x40384A\"\n    },\n    {\n      \"id\": \"func_0x4048F9\",\n      \"label\": \"Function 0x4048F9\",\n      \"type\": \"function\",\n      \"address\": \"0x4048F9\"\n    },\n    {\n      \"id\": \"api_GetTempPath\",\n      \"label\": \"GetTempPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SHGetSpecialFolderPath\",\n      \"label\": \"SHGetSpecialFolderPath\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetSystemDirectory\",\n      \"label\": \"GetSystemDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_system_object_information\",\n      \"label\": \"get file system object information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [T1083]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x408A0E\",\n      \"label\": \"Block 0x408A0E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x408A0E\"\n    },\n    {\n      \"id\": \"api_SHGetFileInfo\",\n      \"label\": \"SHGetFileInfo\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_current_directory\",\n      \"label\": \"set current directory\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_SetCurrentDirectory\",\n      \"label\": \"SetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_directory\",\n      \"label\": \"create directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401B61\",\n      \"label\": \"Function 0x401B61\",\n      \"type\": \"function\",\n      \"address\": \"0x401B61\"\n    },\n    {\n      \"id\": \"api_CreateDirectory\",\n      \"label\": \"CreateDirectory\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Create Directory [C0046]\"\n      ]\n    },\n    {\n      \"id\": \"cap_delete_directory\",\n      \"label\": \"delete directory\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete Directory [C0048]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402ED2\",\n      \"label\": \"Function 0x402ED2\",\n      \"type\": \"function\",\n      \"address\": \"0x402ED2\"\n    },\n    {\n      \"id\": \"api_RemoveDirectory\",\n      \"label\": \"RemoveDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_delete_file__2_matches_\",\n      \"label\": \"delete file (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Delete File [C0047]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x402FDF\",\n      \"label\": \"Function 0x402FDF\",\n      \"type\": \"function\",\n      \"address\": \"0x402FDF\"\n    },\n    {\n      \"id\": \"api_DeleteFile\",\n      \"label\": \"DeleteFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_check_if_file_exists__5_matches_\",\n      \"label\": \"check if file exists (5 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x403373\",\n      \"label\": \"Function 0x403373\",\n      \"type\": \"function\",\n      \"address\": \"0x403373\"\n    },\n    {\n      \"id\": \"api_GetFileAttributes\",\n      \"label\": \"GetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_enumerate_files_on_windows\",\n      \"label\": \"enumerate files on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_FindNextFile\",\n      \"label\": \"FindNextFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindFirstFile\",\n      \"label\": \"FindFirstFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FindClose\",\n      \"label\": \"FindClose\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_enumerate_files_recursively\",\n      \"label\": \"enumerate files recursively\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     @_re_fox, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_attributes__6_matches_\",\n      \"label\": \"get file attributes (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x402FEC\",\n      \"label\": \"Block 0x402FEC\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x402FEC\"\n    },\n    {\n      \"id\": \"bb_0x404591\",\n      \"label\": \"Block 0x404591\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x404591\"\n    },\n    {\n      \"id\": \"bb_0x403373\",\n      \"label\": \"Block 0x403373\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x403373\"\n    },\n    {\n      \"id\": \"bb_0x401B8C\",\n      \"label\": \"Block 0x401B8C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401B8C\"\n    },\n    {\n      \"id\": \"bb_0x40375C\",\n      \"label\": \"Block 0x40375C\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40375C\"\n    },\n    {\n      \"id\": \"bb_0x4066BB\",\n      \"label\": \"Block 0x4066BB\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4066BB\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Get File Attributes [C0049]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_file_size\",\n      \"label\": \"get file size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40F93A\",\n      \"label\": \"Function 0x40F93A\",\n      \"type\": \"function\",\n      \"address\": \"0x40F93A\"\n    },\n    {\n      \"id\": \"api_GetFileSize\",\n      \"label\": \"GetFileSize\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_set_file_attributes__4_matches_\",\n      \"label\": \"set file attributes (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Set File Attributes [C0050]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x402F7D\",\n      \"label\": \"Block 0x402F7D\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x402F7D\"\n    },\n    {\n      \"id\": \"bb_0x40544E\",\n      \"label\": \"Block 0x40544E\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x40544E\"\n    },\n    {\n      \"id\": \"bb_0x403006\",\n      \"label\": \"Block 0x403006\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x403006\"\n    },\n    {\n      \"id\": \"bb_0x402FAE\",\n      \"label\": \"Block 0x402FAE\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x402FAE\"\n    },\n    {\n      \"id\": \"api_SetFileAttributes\",\n      \"label\": \"SetFileAttributes\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_read_file_on_windows__2_matches_\",\n      \"label\": \"read file on Windows (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Read File [C0051]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40FA9E\",\n      \"label\": \"Function 0x40FA9E\",\n      \"type\": \"function\",\n      \"address\": \"0x40FA9E\"\n    },\n    {\n      \"id\": \"func_0x40FA71\",\n      \"label\": \"Function 0x40FA71\",\n      \"type\": \"function\",\n      \"address\": \"0x40FA71\"\n    },\n    {\n      \"id\": \"api_ReadFile\",\n      \"label\": \"ReadFile\",\n      \"type\": \"api\",\n      \"category\": \"file_system\"\n    },\n    {\n      \"id\": \"cap_clear_file_content\",\n      \"label\": \"clear file content\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40FB66\",\n      \"label\": \"Function 0x40FB66\",\n      \"type\": \"function\",\n      \"address\": \"0x40FB66\"\n    },\n    {\n      \"id\": \"api_SetFilePointer\",\n      \"label\": \"SetFilePointer\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_SetEndOfFile\",\n      \"label\": \"SetEndOfFile\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____jakeperalta7\",\n      \"label\": \"author     jakeperalta7\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_write_file_on_windows__3_matches_\",\n      \"label\": \"write file on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401BCB\",\n      \"label\": \"Function 0x401BCB\",\n      \"type\": \"function\",\n      \"address\": \"0x401BCB\"\n    },\n    {\n      \"id\": \"func_0x40FB2C\",\n      \"label\": \"Function 0x40FB2C\",\n      \"type\": \"function\",\n      \"address\": \"0x40FB2C\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_application_hook__4_matches_\",\n      \"label\": \"set application hook (4 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_UnhookWindowsHookEx\",\n      \"label\": \"UnhookWindowsHookEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_graphical_window_text\",\n      \"label\": \"get graphical window text\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::Application Window Discovery [E1010]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4030D6\",\n      \"label\": \"Function 0x4030D6\",\n      \"type\": \"function\",\n      \"address\": \"0x4030D6\"\n    },\n    {\n      \"id\": \"api_GetWindowText\",\n      \"label\": \"GetWindowText\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_memory_capacity\",\n      \"label\": \"get memory capacity\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [T1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4026BB\",\n      \"label\": \"Function 0x4026BB\",\n      \"type\": \"function\",\n      \"address\": \"0x4026BB\"\n    },\n    {\n      \"id\": \"api_GlobalMemoryStatusEx\",\n      \"label\": \"GlobalMemoryStatusEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_information\",\n      \"label\": \"get disk information\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetDriveType\",\n      \"label\": \"GetDriveType\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_disk_size\",\n      \"label\": \"get disk size\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x4011BD\",\n      \"label\": \"Function 0x4011BD\",\n      \"type\": \"function\",\n      \"address\": \"0x4011BD\"\n    },\n    {\n      \"id\": \"api_GetDiskFreeSpaceEx\",\n      \"label\": \"GetDiskFreeSpaceEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author      michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_check_os_version\",\n      \"label\": \"check OS version\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetVersionEx\",\n      \"label\": \"GetVersionEx\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, johnk3r\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_create_process_on_windows__3_matches_\",\n      \"label\": \"create process on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x405034\",\n      \"label\": \"Block 0x405034\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x405034\"\n    },\n    {\n      \"id\": \"bb_0x404FF0\",\n      \"label\": \"Block 0x404FF0\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x404FF0\"\n    },\n    {\n      \"id\": \"api_CreateProcess\",\n      \"label\": \"CreateProcess\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"api_ShellExecuteEx\",\n      \"label\": \"ShellExecuteEx\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_terminate_process\",\n      \"label\": \"terminate process\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Terminate Process [C0018]\"\n      ]\n    },\n    {\n      \"id\": \"api_ExitProcess\",\n      \"label\": \"ExitProcess\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_token_membership\",\n      \"label\": \"get token membership\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Owner/User Discovery [T1033]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40243A\",\n      \"label\": \"Function 0x40243A\",\n      \"type\": \"function\",\n      \"address\": \"0x40243A\"\n    },\n    {\n      \"id\": \"api_AllocateAndInitializeSid\",\n      \"label\": \"AllocateAndInitializeSid\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_FreeSid\",\n      \"label\": \"FreeSid\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CheckTokenMembership\",\n      \"label\": \"CheckTokenMembership\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_thread__2_matches_\",\n      \"label\": \"create thread (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x406DF7\",\n      \"label\": \"Block 0x406DF7\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x406DF7\"\n    },\n    {\n      \"id\": \"bb_0x4015FD\",\n      \"label\": \"Block 0x4015FD\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4015FD\"\n    },\n    {\n      \"id\": \"api__beginthreadex\",\n      \"label\": \"_beginthreadex\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CreateThread\",\n      \"label\": \"CreateThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"joakim@intezer.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Thread [C0038]\"\n      ]\n    },\n    {\n      \"id\": \"cap_resume_thread__2_matches_\",\n      \"label\": \"resume thread (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Resume Thread [C0054]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x405248\",\n      \"label\": \"Block 0x405248\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x405248\"\n    },\n    {\n      \"id\": \"bb_0x405205\",\n      \"label\": \"Block 0x405205\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x405205\"\n    },\n    {\n      \"id\": \"api_ResumeThread\",\n      \"label\": \"ResumeThread\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     0x534a@mailbox.org, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Resume Thread [C0054]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__6_matches_\",\n      \"label\": \"link function at runtime on Windows (6 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"label\": \"resolve function by parsing PE exports\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x414F7C\",\n      \"label\": \"Function 0x414F7C\",\n      \"type\": \"function\",\n      \"address\": \"0x414F7C\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_create_shortcut_via_ishelllink\",\n      \"label\": \"create shortcut via IShellLink\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    },\n    {\n      \"id\": \"api_CoCreateInstance\",\n      \"label\": \"CoCreateInstance\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______matthew_williams_mandiant_com\",\n      \"label\": \"author      matthew.williams@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Persistence::Boot or Logon Autostart Execution::Shortcut\",\n        \"Modification [T1547.009]\"\n      ]\n    },\n    {\n      \"id\": \"cap_identify_system_language_via_api\",\n      \"label\": \"identify system language via API\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Location Discovery::System Language Discovery\",\n        \"[T1614.001]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x40211D\",\n      \"label\": \"Function 0x40211D\",\n      \"type\": \"function\",\n      \"address\": \"0x40211D\"\n    },\n    {\n      \"id\": \"api_GetSystemDefaultUILanguage\",\n      \"label\": \"GetSystemDefaultUILanguage\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_GetUserDefaultUILanguage\",\n      \"label\": \"GetUserDefaultUILanguage\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__161_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__161_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_or_open_file__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delay_execution__6_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delay_execution__6_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x4012DA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_inspect_load_icon_resource\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_inspect_load_icon_resource\",\n      \"target\": \"bb_0x4086FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x4086FC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_self_delete\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_self_delete\",\n      \"target\": \"func_0x4052FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4052FA\",\n      \"target\": \"api_ShellExecute\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com___mr_tz\",\n      \"target\": \"func_0x4052FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4052FA\",\n      \"target\": \"api_ShellExecute\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_reference_anti_vm_strings_targeting_xen\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_geographical_location\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_geographical_location\",\n      \"target\": \"func_0x402173\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402173\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x402173\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402173\",\n      \"target\": \"api_GetLocaleInfo\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_application_hook\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_application_hook\",\n      \"target\": \"bb_0x40865B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x40865B\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_log_keystrokes_via_polling\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_log_keystrokes_via_polling\",\n      \"target\": \"func_0x405717\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405717\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405717\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405717\",\n      \"target\": \"api_GetKeyState\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_and_execute_a_file\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_and_execute_a_file\",\n      \"target\": \"func_0x4052FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4052FA\",\n      \"target\": \"api_ShellExecute\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4052FA\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4052FA\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_maec_malware_category__launcher\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_maec_malware_category__launcher\",\n      \"target\": \"func_0x4052FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4052FA\",\n      \"target\": \"api_ShellExecute\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4052FA\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4052FA\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_hash_data_with_crc32\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_hash_data_with_crc32\",\n      \"target\": \"func_0x416400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x416400\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_extract_resource_via_kernel32_functions\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_extract_resource_via_kernel32_functions\",\n      \"target\": \"func_0x401DB5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401DB5\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401DB5\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401DB5\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401DB5\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401DB5\",\n      \"target\": \"api_GetModuleHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x401DB5\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401DB5\",\n      \"target\": \"api_SizeofResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401DB5\",\n      \"target\": \"api_LockResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401DB5\",\n      \"target\": \"api_FindResourceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401DB5\",\n      \"target\": \"api_LoadResource\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401DB5\",\n      \"target\": \"api_GetModuleHandle\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__2_matches_\",\n      \"target\": \"func_0x405034\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__2_matches_\",\n      \"target\": \"func_0x405717\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405034\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405717\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405034\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x405717\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405034\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405717\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__3_matches_\",\n      \"target\": \"func_0x402B5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__3_matches_\",\n      \"target\": \"func_0x403269\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable__3_matches_\",\n      \"target\": \"func_0x402173\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402B5D\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403269\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402173\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402B5D\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403269\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402173\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x402B5D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x403269\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x402173\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402B5D\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403269\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402173\",\n      \"target\": \"api_GetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402B5D\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403269\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402173\",\n      \"target\": \"api_ExpandEnvironmentStrings\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_environment_variable\",\n      \"target\": \"func_0x4045DD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4045DD\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x4045DD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4045DD\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__4_matches_\",\n      \"target\": \"func_0x40452E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__4_matches_\",\n      \"target\": \"func_0x408A0E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__4_matches_\",\n      \"target\": \"func_0x40384A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path__4_matches_\",\n      \"target\": \"func_0x4048F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40452E\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408A0E\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40384A\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4048F9\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40452E\",\n      \"target\": \"api_SHGetSpecialFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408A0E\",\n      \"target\": \"api_SHGetSpecialFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40384A\",\n      \"target\": \"api_SHGetSpecialFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4048F9\",\n      \"target\": \"api_SHGetSpecialFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40452E\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408A0E\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40384A\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4048F9\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40452E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x408A0E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40384A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4048F9\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40452E\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408A0E\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40384A\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4048F9\",\n      \"target\": \"api_GetTempPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40452E\",\n      \"target\": \"api_SHGetSpecialFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408A0E\",\n      \"target\": \"api_SHGetSpecialFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40384A\",\n      \"target\": \"api_SHGetSpecialFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4048F9\",\n      \"target\": \"api_SHGetSpecialFolderPath\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40452E\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408A0E\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40384A\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4048F9\",\n      \"target\": \"api_GetSystemDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_system_object_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_system_object_information\",\n      \"target\": \"bb_0x408A0E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"bb_0x408A0E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_current_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_current_directory\",\n      \"target\": \"func_0x405717\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405717\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405717\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405717\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_directory\",\n      \"target\": \"func_0x401B61\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401B61\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401B61\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401B61\",\n      \"target\": \"api_CreateDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_directory\",\n      \"target\": \"func_0x402ED2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402ED2\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x402ED2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402ED2\",\n      \"target\": \"api_RemoveDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_delete_file__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_delete_file__2_matches_\",\n      \"target\": \"func_0x402ED2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_delete_file__2_matches_\",\n      \"target\": \"func_0x402FDF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402ED2\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402FDF\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x402ED2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x402FDF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402ED2\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402FDF\",\n      \"target\": \"api_DeleteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_if_file_exists__5_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__5_matches_\",\n      \"target\": \"func_0x402FDF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__5_matches_\",\n      \"target\": \"func_0x401B61\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__5_matches_\",\n      \"target\": \"func_0x403373\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__5_matches_\",\n      \"target\": \"func_0x40452E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_check_if_file_exists__5_matches_\",\n      \"target\": \"func_0x405717\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402FDF\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B61\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403373\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40452E\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405717\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x402FDF\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401B61\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x403373\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40452E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x405717\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402FDF\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401B61\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x403373\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40452E\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x405717\",\n      \"target\": \"api_GetFileAttributes\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_on_windows\",\n      \"target\": \"func_0x402ED2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402ED2\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402ED2\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402ED2\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402ED2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402ED2\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402ED2\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402ED2\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_enumerate_files_recursively\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_enumerate_files_recursively\",\n      \"target\": \"func_0x402ED2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402ED2\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402ED2\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402ED2\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_______re_fox__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x402ED2\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x402ED2\",\n      \"target\": \"api_FindNextFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402ED2\",\n      \"target\": \"api_FindFirstFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x402ED2\",\n      \"target\": \"api_FindClose\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_attributes__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x402FEC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x404591\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x403373\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x401B8C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x40375C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_get_file_attributes__6_matches_\",\n      \"target\": \"bb_0x4066BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x402FEC\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x404591\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x403373\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x401B8C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40375C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4066BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_file_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_file_size\",\n      \"target\": \"func_0x40F93A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40F93A\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40F93A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40F93A\",\n      \"target\": \"api_GetFileSize\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_file_attributes__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__4_matches_\",\n      \"target\": \"bb_0x402F7D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__4_matches_\",\n      \"target\": \"bb_0x40544E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__4_matches_\",\n      \"target\": \"bb_0x403006\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_set_file_attributes__4_matches_\",\n      \"target\": \"bb_0x402FAE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x402F7D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x40544E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x403006\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x402FAE\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_read_file_on_windows__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__2_matches_\",\n      \"target\": \"func_0x40FA9E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_read_file_on_windows__2_matches_\",\n      \"target\": \"func_0x40FA71\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40FA9E\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40FA71\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40FA9E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40FA71\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40FA9E\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40FA71\",\n      \"target\": \"api_ReadFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_clear_file_content\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_clear_file_content\",\n      \"target\": \"func_0x40FB66\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40FB66\",\n      \"target\": \"api_SetFilePointer\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40FB66\",\n      \"target\": \"api_SetEndOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____jakeperalta7\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____jakeperalta7\",\n      \"target\": \"func_0x40FB66\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40FB66\",\n      \"target\": \"api_SetFilePointer\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40FB66\",\n      \"target\": \"api_SetEndOfFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__3_matches_\",\n      \"target\": \"func_0x401BCB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__3_matches_\",\n      \"target\": \"func_0x40FB2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows__3_matches_\",\n      \"target\": \"func_0x4052FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401BCB\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40FB2C\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4052FA\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401BCB\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40FB2C\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4052FA\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401BCB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x40FB2C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4052FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401BCB\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40FB2C\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4052FA\",\n      \"target\": \"api_CreateFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x401BCB\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40FB2C\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4052FA\",\n      \"target\": \"api_WriteFile\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_application_hook__4_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_graphical_window_text\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_graphical_window_text\",\n      \"target\": \"func_0x4030D6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4030D6\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4030D6\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4030D6\",\n      \"target\": \"api_GetWindowText\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_memory_capacity\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_memory_capacity\",\n      \"target\": \"func_0x4026BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4026BB\",\n      \"target\": \"api_GlobalMemoryStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"func_0x4026BB\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4026BB\",\n      \"target\": \"api_GlobalMemoryStatusEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_information\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_information\",\n      \"target\": \"func_0x4052FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4052FA\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4052FA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4052FA\",\n      \"target\": \"api_GetDriveType\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_disk_size\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_disk_size\",\n      \"target\": \"func_0x4011BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4011BD\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______michael_hunhoff_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4011BD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x4011BD\",\n      \"target\": \"api_GetDiskFreeSpaceEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_check_os_version\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_check_os_version\",\n      \"target\": \"func_0x405717\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405717\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com__johnk3r\",\n      \"target\": \"func_0x405717\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x405717\",\n      \"target\": \"api_GetVersionEx\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__3_matches_\",\n      \"target\": \"bb_0x405034\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__3_matches_\",\n      \"target\": \"bb_0x404FF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows__3_matches_\",\n      \"target\": \"bb_0x40544E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x405034\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x404FF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x40544E\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_terminate_process\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_terminate_process\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401000\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401000\",\n      \"target\": \"api_ExitProcess\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_token_membership\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_token_membership\",\n      \"target\": \"func_0x40243A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40243A\",\n      \"target\": \"api_AllocateAndInitializeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40243A\",\n      \"target\": \"api_FreeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40243A\",\n      \"target\": \"api_CheckTokenMembership\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x40243A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40243A\",\n      \"target\": \"api_AllocateAndInitializeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40243A\",\n      \"target\": \"api_FreeSid\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40243A\",\n      \"target\": \"api_CheckTokenMembership\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_thread__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_thread__2_matches_\",\n      \"target\": \"bb_0x406DF7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_create_thread__2_matches_\",\n      \"target\": \"bb_0x4015FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x406DF7\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_joakim_intezer_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x4015FD\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resume_thread__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resume_thread__2_matches_\",\n      \"target\": \"bb_0x405248\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_resume_thread__2_matches_\",\n      \"target\": \"bb_0x405205\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x405248\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____0x534a_mailbox_org__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"bb_0x405205\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__6_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"target\": \"func_0x414F7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x414F7C\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_shortcut_via_ishelllink\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_shortcut_via_ishelllink\",\n      \"target\": \"func_0x40384A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40384A\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______matthew_williams_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______matthew_williams_mandiant_com\",\n      \"target\": \"func_0x40384A\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40384A\",\n      \"target\": \"api_CoCreateInstance\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_identify_system_language_via_api\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_identify_system_language_via_api\",\n      \"target\": \"func_0x40211D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40211D\",\n      \"target\": \"api_GetSystemDefaultUILanguage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40211D\",\n      \"target\": \"api_GetUserDefaultUILanguage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"target\": \"func_0x40211D\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x40211D\",\n      \"target\": \"api_GetSystemDefaultUILanguage\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x40211D\",\n      \"target\": \"api_GetUserDefaultUILanguage\",\n      \"relationship\": \"calls\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-21 20:53:43.915570\",\n    \"total_functions\": \"566\",\n    \"total_features\": \"34217\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-21 20:53:44"}
{"_id":{"$oid":"6a5f9e2b39c3725e311ebc0e"},"sha256":"0659388dba26d26eada6d82ed38f22fb2b0a264d1cc4667cce7f4523c72d59be","analysis_data":{"success":true,"results":{"normal":{"success":true,"path":"/tmp/sdm_capa_28f3wrpk/DriverPackNotifier-019f85807f6c7773b42d4974124ffe3f.exe_normal.txt"},"verbose":{"success":true,"path":"/tmp/sdm_capa_28f3wrpk/DriverPackNotifier-019f85807f6c7773b42d4974124ffe3f.exe_verbose.txt"},"very_verbose":{"success":true,"path":"/tmp/sdm_capa_28f3wrpk/DriverPackNotifier-019f85807f6c7773b42d4974124ffe3f.exe_very_verbose.txt"}},"outputs":{"normal":"┌──────────┬───────────────────────────────────────────────────────────────────┐\n│ md5      │ d663176b9297a432309140315169274c                                  │\n│ sha1     │ 0f49833354b2b172491d8a32fd70c2bb35ae0535                          │\n│ sha256   │ 0659388dba26d26eada6d82ed38f22fb2b0a264d1cc4667cce7f4523c72d59be  │\n│ analysis │ static                                                            │\n│ os       │ windows                                                           │\n│ format   │ pe                                                                │\n│ arch     │ i386                                                              │\n│ path     │ /home/apogean/projects/malware/windows/all_runs/DriverPackNotifi… │\n└──────────┴───────────────────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ ATT&CK Tactic             ┃ ATT&CK Technique                                 ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DEFENSE EVASION           │ Obfuscated Files or Information [T1027]          │\n│ DISCOVERY                 │ File and Directory Discovery [T1083]             │\n│                           │ System Information Discovery [T1082]             │\n│ EXECUTION                 │ Command and Scripting Interpreter [T1059]        │\n│                           │ Shared Modules [T1129]                           │\n└───────────────────────────┴──────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ MBC Objective        ┃ MBC Behavior                                          ┃\n┡━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ DATA                 │ Encode Data::XOR [C0026.002]                          │\n│ DEFENSE EVASION      │ Obfuscated Files or Information::Encoding-Standard    │\n│                      │ Algorithm [E1027.m02]                                 │\n│ DISCOVERY            │ File and Directory Discovery [E1083]                  │\n│                      │ System Information Discovery [E1082]                  │\n│ EXECUTION            │ Command and Scripting Interpreter [E1059]             │\n│ FILE SYSTEM          │ Writes File [C0052]                                   │\n│ MEMORY               │ Allocate Memory [C0007]                               │\n│ OPERATING SYSTEM     │ Environment Variable::Set Variable [C0034.001]        │\n│ PROCESS              │ Create Process [C0017]                                │\n└──────────────────────┴───────────────────────────────────────────────────────┘\n┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓\n┃ Capability                            ┃ Namespace                            ┃\n┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩\n│ compiled with MinGW for Windows       │ compiler/mingw                       │\n│ encode data using XOR                 │ data-manipulation/encoding/xor       │\n│ contain a thread local storage (.tls) │ executable/pe/section/tls            │\n│ section                               │                                      │\n│ accept command line arguments (2      │ host-interaction/cli                 │\n│ matches)                              │                                      │\n│ query environment variable            │ host-interaction/environment-variab… │\n│ set environment variable              │ host-interaction/environment-variab… │\n│ get common file path                  │ host-interaction/file-system         │\n│ set current directory                 │ host-interaction/file-system         │\n│ write file on Windows                 │ host-interaction/file-system/write   │\n│ get thread local storage value        │ host-interaction/process             │\n│ create process on Windows             │ host-interaction/process/create      │\n│ execute command                       │ host-interaction/process/create      │\n│ allocate or change RWX memory         │ host-interaction/process/inject      │\n│ link function at runtime on Windows   │ linking/runtime-linking              │\n│ (3 matches)                           │                                      │\n│ resolve function by parsing PE        │ load-code/pe                         │\n│ exports                               │                                      │\n└───────────────────────────────────────┴──────────────────────────────────────┘\n\n","verbose":"md5                     d663176b9297a432309140315169274c                        \nsha1                    0f49833354b2b172491d8a32fd70c2bb35ae0535                \nsha256                  0659388dba26d26eada6d82ed38f22fb2b0a264d1cc4667cce7f452…\npath                    /home/apogean/projects/malware/windows/all_runs/DriverP…\ntimestamp               2026-07-21 21:58:20.405527                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEI1abTGu/rules                                   \nfunction count          146                                                     \nlibrary function count  0                                                       \ntotal feature count     6721                                                    \n\ncompiled with MinGW for Windows\nnamespace  compiler/mingw\nscope      file          \n\nencode data using XOR\nnamespace  data-manipulation/encoding/xor\nscope      basic block                   \nmatches    0x404658                      \n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls\nscope      file                     \n\naccept command line arguments (2 matches)\nnamespace  host-interaction/cli\nscope      function            \nmatches    0x4013F0            \n           0x408340            \n\nquery environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x404AF0                             \n\nset environment variable\nnamespace  host-interaction/environment-variable\nscope      function                             \nmatches    0x408340                             \n\nget common file path\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x408340                    \n\nset current directory\nnamespace  host-interaction/file-system\nscope      function                    \nmatches    0x408340                    \n\nwrite file on Windows\nnamespace  host-interaction/file-system/write\nscope      function                          \nmatches    0x401BC0                          \n\nget thread local storage value\nnamespace  host-interaction/process\nscope      function                \nmatches    0x401980                \n\ncreate process on Windows\nnamespace  host-interaction/process/create\nscope      basic block                    \nmatches    0x4085BA                       \n\nexecute command\nnamespace  host-interaction/process/create\nscope      function                       \nmatches    0x408340                       \n\nallocate or change RWX memory\nnamespace  host-interaction/process/inject\nscope      basic block                    \nmatches    0x401C66                       \n\nlink function at runtime on Windows (3 matches)\nnamespace  linking/runtime-linking\nscope      instruction            \nmatches    0x401329               \n           0x401374               \n           0x4013B9               \n\nresolve function by parsing PE exports\nnamespace  load-code/pe\nscope      function    \nmatches    0x404AF0    \n\n\n\n","very_verbose":"md5                     d663176b9297a432309140315169274c                        \nsha1                    0f49833354b2b172491d8a32fd70c2bb35ae0535                \nsha256                  0659388dba26d26eada6d82ed38f22fb2b0a264d1cc4667cce7f452…\npath                    /home/apogean/projects/malware/windows/all_runs/DriverP…\ntimestamp               2026-07-21 21:58:26.824058                              \ncapa version            9.2.1                                                   \nos                      windows                                                 \nformat                  pe                                                      \narch                    i386                                                    \nanalysis                static                                                  \nextractor               VivisectFeatureExtractor                                \nbase address            0x400000                                                \nrules                   /tmp/_MEIc801iW/rules                                   \nfunction count          146                                                     \nlibrary function count  0                                                       \ntotal feature count     6721                                                    \n\nallocate or change RW memory (library rule)\nauthor  0x534a@mailbox.org, @mr-tz     \nscope   basic block                    \nmbc     Memory::Allocate Memory [C0007]\nbasic block @ 0x401C66 in function 0x401C10\n  and:\n    or:\n      match: change memory protection @ 0x401C66\n        or:\n          api: VirtualProtect @ 0x401C85\n    or:\n      number: 0x4 = PAGE_READWRITE @ 0x401CA6\n\nchange memory protection (2 matches, only showing first match of library rule)\nauthor  @mr-tz                                  \nscope   basic block                             \nmbc     Memory::Change Memory Protection [C0008]\nbasic block @ 0x401C66 in function 0x401C10\n  or:\n    api: VirtualProtect @ 0x401C85\n\ncontain loop (42 matches, only showing first match of library rule)\nauthor  moritz.raabe@mandiant.com\nscope   function                 \nfunction @ 0x4013F0\n  or:\n    characteristic: loop @ 0x4013F0\n    characteristic: tight loop @ 0x4014B0, 0x401500, 0x4015A8, 0x4015E5, and 1 more...\n\ndelay execution (library rule)\nauthor      michael.hunhoff@mandiant.com, @ramen0x3f                            \nscope       basic block                                                         \nmbc         Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed         \n            Execution [B0003.003]                                               \nreferences  https://docs.microsoft.com/en-us/windows/win32/sync/wait-functions, \n            https://github.com/LordNoteworthy/al-khaser/blob/master/al-khaser/T…\nbasic block @ 0x4073B0 in function 0x407390\n  or:\n    and:\n      os: windows\n      or:\n        api: Sleep @ 0x4073B7\n\ncompiled with MinGW for Windows\nnamespace  compiler/mingw                 \nauthor     william.ballenthin@mandiant.com\nscope      file                           \nand:\n  string: \"Mingw runtime failure:\" @ file+0x8140\n  string: \"_Jv_RegisterClasses\" = from GCC @ file+0x7E37\n\nencode data using XOR\nnamespace  data-manipulation/encoding/xor                                       \nauthor     moritz.raabe@mandiant.com                                            \nscope      basic block                                                          \natt&ck     Defense Evasion::Obfuscated Files or Information [T1027]             \nmbc        Defense Evasion::Obfuscated Files or Information::Encoding-Standard  \n           Algorithm [E1027.m02], Data::Encode Data::XOR [C0026.002]            \nbasic block @ 0x404658 in function 0x404520\n  and:\n    characteristic: tight loop @ 0x404658\n    characteristic: nzxor @ 0x404662\n    not: = filter for potential false positives\n      or:\n        or: = unsigned bitwise negation operation (~i)\n          number: 0xFFFFFFFF = bitwise negation for unsigned 32 bits\n          number: 0xFFFFFFFFFFFFFFFF = bitwise negation for unsigned 64 bits\n        or: = signed bitwise negation operation (~i)\n          number: 0xFFFFFFF = bitwise negation for signed 32 bits\n          number: 0xFFFFFFFFFFFFFFF = bitwise negation for signed 64 bits\n        or: = Magic constants used in the implementation of strings functions.\n          number: 0x7EFEFEFF = optimized string constant for 32 bits\n          number: 0x81010101 = -0x81010101 = 0x7EFEFEFF\n          number: 0x81010100 = 0x81010100 = ~0x7EFEFEFF\n          number: 0x7EFEFEFEFEFEFEFF = optimized string constant for 64 bits\n          number: 0x8101010101010101 = -0x8101010101010101 = 0x7EFEFEFEFEFEFEFF\n          number: 0x8101010101010100 = 0x8101010101010100 = ~0x7EFEFEFEFEFEFEFF\n\ncontain a thread local storage (.tls) section\nnamespace  executable/pe/section/tls   \nauthor     michael.hunhoff@mandiant.com\nscope      file                        \nsection: .tls @ 0x410000\n\naccept command line arguments (2 matches)\nnamespace  host-interaction/cli                                      \nauthor     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                  \natt&ck     Execution::Command and Scripting Interpreter [T1059]      \nmbc        Execution::Command and Scripting Interpreter [E1059]      \nfunction @ 0x4013F0\n  or:\n    api: GetCommandLine @ 0x401406\nfunction @ 0x408340\n  or:\n    api: GetCommandLine @ 0x408382\n    api: CommandLineToArgv @ 0x408394\n\nquery environment variable\nnamespace  host-interaction/environment-variable          \nauthor     michael.hunhoff@mandiant.com, @_re_fox         \nscope      function                                       \natt&ck     Discovery::System Information Discovery [T1082]\nmbc        Discovery::System Information Discovery [E1082]\nfunction @ 0x404AF0\n  or:\n    api: getenv @ 0x404B50\n\nset environment variable\nnamespace  host-interaction/environment-variable                           \nauthor     michael.hunhoff@mandiant.com                                    \nscope      function                                                        \nmbc        Operating System::Environment Variable::Set Variable [C0034.001]\nfunction @ 0x408340\n  or:\n    api: SetEnvironmentVariable @ 0x4083B6\n\nget common file path\nnamespace  host-interaction/file-system                                         \nauthor     moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com,             \n           anushka.virgaonkar@mandiant.com                                      \nscope      function                                                             \natt&ck     Discovery::File and Directory Discovery [T1083]                      \nmbc        Discovery::File and Directory Discovery [E1083]                      \nfunction @ 0x408340\n  or:\n    api: GetWindowsDirectory @ 0x4083CE\n\nset current directory\nnamespace  host-interaction/file-system\nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x408340\n  or:\n    api: SetCurrentDirectory @ 0x4084AE, 0x408569, 0x4085B4\n\nwrite file on Windows\nnamespace  host-interaction/file-system/write                              \nauthor     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\nscope      function                                                        \nmbc        File System::Writes File [C0052]                                \nfunction @ 0x401BC0\n  or:\n    and:\n      os: windows\n      or:\n        api: fwrite @ 0x401BEC\n\nget thread local storage value\nnamespace  host-interaction/process    \nauthor     michael.hunhoff@mandiant.com\nscope      function                    \nfunction @ 0x401980\n  and:\n    api: TlsGetValue @ 0x4019A6\n\ncreate process on Windows\nnamespace  host-interaction/process/create\nauthor     moritz.raabe@mandiant.com      \nscope      basic block                    \nmbc        Process::Create Process [C0017]\nbasic block @ 0x4085BA in function 0x408340\n  or:\n    api: ShellExecute @ 0x4085E1\n\nexecute command\nnamespace  host-interaction/process/create\nauthor     @mr-tz                         \nscope      function                       \nmbc        Process::Create Process [C0017]\nfunction @ 0x408340\n  or:\n    api: _wsystem @ 0x408576, 0x4085A8\n\nallocate or change RWX memory\nnamespace  host-interaction/process/inject\nauthor     @mr-tz, mehunhoff@google.com   \nscope      basic block                    \nmbc        Memory::Allocate Memory [C0007]\nbasic block @ 0x401C66 in function 0x401C10\n  or:\n    basic block:\n      and:\n        or:\n          match: change memory protection @ 0x401C66\n            or:\n              api: VirtualProtect @ 0x401C85\n        or:\n          number: 0x40 = PAGE_EXECUTE_READWRITE @ 0x401C70\n\nlink function at runtime on Windows (3 matches)\nnamespace  linking/runtime-linking                        \nauthor     moritz.raabe@mandiant.com, mehunhoff@google.com\nscope      instruction                                    \natt&ck     Execution::Shared Modules [T1129]              \ninstruction @ 0x401329\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401329\ninstruction @ 0x401374\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x401374\ninstruction @ 0x4013B9\n  and:\n    os: windows\n    or:\n      api: GetProcAddress @ 0x4013B9\n\nresolve function by parsing PE exports\nnamespace  load-code/pe\nauthor     sara-rn     \nscope      function    \nfunction @ 0x404AF0\n  and:\n    os: windows\n    or:\n      characteristic: loop @ 0x404AF0\n      mnemonic: movzx @ 0x404BB9, 0x404BE2, 0x404BF0, 0x404C67, and 20 more...\n    and:\n      offset: 0x3C = IMAGE_DOS_HEADER.PE.e_lfanew @ 0x404B2D\n      or:\n        and:\n          arch: i386\n          offset: 0x78 = offset to IMAGE_DATA_DIRECTORY[IMAGE_DIRECTORY_ENTRY_EXPORT] @ 0x404B40\n      3 or more:\n        offset: 0x14 = IMAGE_EXPORT_DIRECTORY.NumberOfFunctions @ 0x404BAD, 0x404BF6, 0x404C4B, 0x404C58, and 22 more...\n        offset: 0x24 = IMAGE_EXPORT_DIRECTORY.AddressOfNameOrdinals @ 0x404DA0, 0x404DA8, 0x404E23, 0x404E53, and 10 more...\n        offset: 0x20 = IMAGE_EXPORT_DIRECTORY.AddressOfNames @ 0x404CE8, 0x404CEC, 0x404DAE, 0x404DB2, and 18 more...\n        offset: 0x18 = IMAGE_EXPORT_DIRECTORY.NumberOfNames @ 0x404BC1, 0x40507C, 0x405084, 0x405099, and 7 more...\n        offset: 0x1C = IMAGE_EXPORT_DIRECTORY.AddressOfFunctions @ 0x404B7C, 0x40533E\n\n\n\n"},"hashes":{"md5":"d663176b9297a432309140315169274c","sha1":"0f49833354b2b172491d8a32fd70c2bb35ae0535","sha256":"0659388dba26d26eada6d82ed38f22fb2b0a264d1cc4667cce7f4523c72d59be"},"interactive_graph":"<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Malware Analysis Network Graph</title>\n    <script src=\"https://cdnjs.cloudflare.com/ajax/libs/d3/7.8.5/d3.min.js\"></script>\n    <style>\n        * {\n            margin: 0;\n            padding: 0;\n            box-sizing: border-box;\n        }\n\n        body {\n            font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;\n            background: linear-gradient(135deg, #1a1a2e 0%, #0f0f1e 100%);\n            color: #fff;\n            overflow: hidden;\n        }\n\n        #container {\n            display: flex;\n            height: 100vh;\n        }\n\n        #graph {\n            flex: 1;\n            position: relative;\n        }\n\n        #sidebar {\n            width: 350px;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 20px;\n            overflow-y: auto;\n            border-left: 2px solid rgba(100, 100, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        h1 {\n            font-size: 20px;\n            margin-bottom: 10px;\n            color: #6c63ff;\n            text-shadow: 0 0 10px rgba(108, 99, 255, 0.5);\n        }\n\n        h2 {\n            font-size: 16px;\n            margin-top: 20px;\n            margin-bottom: 10px;\n            color: #00d9ff;\n        }\n\n        .info-section {\n            background: rgba(50, 50, 80, 0.5);\n            padding: 12px;\n            border-radius: 8px;\n            margin-bottom: 15px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n        }\n\n        .info-item {\n            margin: 8px 0;\n            font-size: 13px;\n            line-height: 1.6;\n            word-break: break-all;\n        }\n\n        .label {\n            color: #00d9ff;\n            font-weight: bold;\n        }\n\n        .legend {\n            margin-top: 20px;\n        }\n\n        .legend-item {\n            display: flex;\n            align-items: center;\n            margin: 8px 0;\n            font-size: 13px;\n        }\n\n        .legend-color {\n            width: 20px;\n            height: 20px;\n            border-radius: 50%;\n            margin-right: 10px;\n            border: 2px solid rgba(255, 255, 255, 0.3);\n        }\n\n        .controls {\n            position: absolute;\n            top: 20px;\n            left: 20px;\n            z-index: 1000;\n            background: rgba(30, 30, 50, 0.95);\n            padding: 15px;\n            border-radius: 10px;\n            border: 1px solid rgba(108, 99, 255, 0.3);\n            backdrop-filter: blur(10px);\n        }\n\n        button {\n            background: linear-gradient(135deg, #6c63ff 0%, #5848ff 100%);\n            color: white;\n            border: none;\n            padding: 8px 16px;\n            margin: 5px;\n            border-radius: 5px;\n            cursor: pointer;\n            font-size: 12px;\n            transition: all 0.3s;\n        }\n\n        button:hover {\n            transform: translateY(-2px);\n            box-shadow: 0 5px 15px rgba(108, 99, 255, 0.5);\n        }\n\n        .node {\n            cursor: pointer;\n            transition: all 0.3s;\n        }\n\n        .node:hover {\n            filter: brightness(1.5);\n        }\n\n        .link {\n            stroke-opacity: 0.6;\n            transition: all 0.3s;\n        }\n\n        .link:hover {\n            stroke-opacity: 1;\n            stroke-width: 3px;\n        }\n\n        text {\n            font-size: 11px;\n            pointer-events: none;\n            text-shadow: 0 0 3px rgba(0, 0, 0, 0.8);\n        }\n\n        .severity-high {\n            animation: pulse 2s infinite;\n        }\n\n        @keyframes pulse {\n            0%, 100% { opacity: 1; }\n            50% { opacity: 0.6; }\n        }\n\n        ::-webkit-scrollbar {\n            width: 8px;\n        }\n\n        ::-webkit-scrollbar-track {\n            background: rgba(30, 30, 50, 0.5);\n        }\n\n        ::-webkit-scrollbar-thumb {\n            background: rgba(108, 99, 255, 0.5);\n            border-radius: 4px;\n        }\n\n        ::-webkit-scrollbar-thumb:hover {\n            background: rgba(108, 99, 255, 0.8);\n        }\n    </style>\n</head>\n<body>\n    <div id=\"container\">\n        <div id=\"graph\">\n            <div class=\"controls\">\n                <button onclick=\"resetZoom()\">Reset View</button>\n                <button onclick=\"toggleLabels()\">Toggle Labels</button>\n                <button onclick=\"togglePhysics()\">Toggle Physics</button>\n            </div>\n        </div>\n        <div id=\"sidebar\">\n            <h1>🔍 Malware Analysis</h1>\n            <div id=\"node-info\" class=\"info-section\">\n                <p style=\"color: #888;\">Click on a node to see details</p>\n            </div>\n            \n            <div class=\"legend\">\n                <h2>Legend</h2>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff4757;\"></div>\n                    <span>File</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ff6348;\"></div>\n                    <span>Capability (High)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #ffa502;\"></div>\n                    <span>Capability (Medium)</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #5f27cd;\"></div>\n                    <span>Function</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #00d2d3;\"></div>\n                    <span>API Call</span>\n                </div>\n                <div class=\"legend-item\">\n                    <div class=\"legend-color\" style=\"background: #1dd1a1;\"></div>\n                    <span>Basic Block</span>\n                </div>\n            </div>\n\n            <div class=\"info-section\">\n                <h2>Analysis Info</h2>\n                <div class=\"info-item\"><span class=\"label\">Type:</span> static</div>\n                <div class=\"info-item\"><span class=\"label\">Functions:</span> 146</div>\n                <div class=\"info-item\"><span class=\"label\">Features:</span> 6721</div>\n            </div>\n        </div>\n    </div>\n\n    <script>\n        const graphData = {\n  \"nodes\": [\n    {\n      \"id\": \"malware_file\",\n      \"label\": \"DriverP\\u2026\",\n      \"type\": \"file\",\n      \"properties\": {\n        \"md5\": \"d663176b9297a432309140315169274c\",\n        \"sha256\": \"0659388dba26d26eada6d82ed38f22fb2b0a264d1cc4667cce7f452\",\n        \"arch\": \"i386\",\n        \"os\": \"windows\",\n        \"format\": \"pe\"\n      }\n    },\n    {\n      \"id\": \"cap_change_memory_protection__2_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"change memory protection (2 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Change Memory Protection [C0008]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x401C66\",\n      \"label\": \"Block 0x401C66\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x401C66\"\n    },\n    {\n      \"id\": \"api_VirtualProtect\",\n      \"label\": \"VirtualProtect\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_contain_loop__42_matches__only_showing_first_match_of_library_rule_\",\n      \"label\": \"contain loop (42 matches, only showing first match of library rule)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x4013F0\",\n      \"label\": \"Function 0x4013F0\",\n      \"type\": \"function\",\n      \"address\": \"0x4013F0\"\n    },\n    {\n      \"id\": \"cap_compiled_with_mingw_for_windows\",\n      \"label\": \"compiled with MinGW for Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"label\": \"contain a thread local storage (.tls) section\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"label\": \"author     michael.hunhoff@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_accept_command_line_arguments__2_matches_\",\n      \"label\": \"accept command line arguments (2 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x408340\",\n      \"label\": \"Function 0x408340\",\n      \"type\": \"function\",\n      \"address\": \"0x408340\"\n    },\n    {\n      \"id\": \"api_GetCommandLine\",\n      \"label\": \"GetCommandLine\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"api_CommandLineToArgv\",\n      \"label\": \"CommandLineToArgv\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Command and Scripting Interpreter [E1059]\"\n      ]\n    },\n    {\n      \"id\": \"cap_query_environment_variable\",\n      \"label\": \"query environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x404AF0\",\n      \"label\": \"Function 0x404AF0\",\n      \"type\": \"function\",\n      \"address\": \"0x404AF0\"\n    },\n    {\n      \"id\": \"api_getenv\",\n      \"label\": \"getenv\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"label\": \"author     michael.hunhoff@mandiant.com, @_re_fox\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::System Information Discovery [E1082]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_environment_variable\",\n      \"label\": \"set environment variable\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Operating System::Environment Variable::Set Variable [C0034.001]\"\n      ]\n    },\n    {\n      \"id\": \"api_SetEnvironmentVariable\",\n      \"label\": \"SetEnvironmentVariable\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_get_common_file_path\",\n      \"label\": \"get common file path\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetWindowsDirectory\",\n      \"label\": \"GetWindowsDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"label\": \"anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Discovery::File and Directory Discovery [E1083]\"\n      ]\n    },\n    {\n      \"id\": \"cap_set_current_directory\",\n      \"label\": \"set current directory\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"api_SetCurrentDirectory\",\n      \"label\": \"SetCurrentDirectory\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_write_file_on_windows\",\n      \"label\": \"write file on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"func_0x401BC0\",\n      \"label\": \"Function 0x401BC0\",\n      \"type\": \"function\",\n      \"address\": \"0x401BC0\"\n    },\n    {\n      \"id\": \"api_fwrite\",\n      \"label\": \"fwrite\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"label\": \"author     william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"File System::Writes File [C0052]\"\n      ]\n    },\n    {\n      \"id\": \"cap_get_thread_local_storage_value\",\n      \"label\": \"get thread local storage value\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"func_0x401980\",\n      \"label\": \"Function 0x401980\",\n      \"type\": \"function\",\n      \"address\": \"0x401980\"\n    },\n    {\n      \"id\": \"api_TlsGetValue\",\n      \"label\": \"TlsGetValue\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_create_process_on_windows\",\n      \"label\": \"create process on Windows\",\n      \"type\": \"capability\",\n      \"severity\": \"medium\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"bb_0x4085BA\",\n      \"label\": \"Block 0x4085BA\",\n      \"type\": \"basic_block\",\n      \"address\": \"0x4085BA\"\n    },\n    {\n      \"id\": \"api_ShellExecute\",\n      \"label\": \"ShellExecute\",\n      \"type\": \"api\",\n      \"category\": \"process\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_execute_command\",\n      \"label\": \"execute command\",\n      \"type\": \"capability\",\n      \"severity\": \"high\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"api__wsystem\",\n      \"label\": \"_wsystem\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author______mr_tz\",\n      \"label\": \"author     @mr-tz\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Process::Create Process [C0017]\"\n      ]\n    },\n    {\n      \"id\": \"cap_allocate_or_change_rwx_memory\",\n      \"label\": \"allocate or change RWX memory\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"label\": \"author     @mr-tz, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Memory::Allocate Memory [C0007]\"\n      ]\n    },\n    {\n      \"id\": \"cap_link_function_at_runtime_on_windows__3_matches_\",\n      \"label\": \"link function at runtime on Windows (3 matches)\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"api_GetProcAddress\",\n      \"label\": \"GetProcAddress\",\n      \"type\": \"api\",\n      \"category\": \"other\"\n    },\n    {\n      \"id\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"label\": \"author     moritz.raabe@mandiant.com, mehunhoff@google.com\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\",\n      \"mitre\": [\n        \"Execution::Shared Modules [T1129]\"\n      ]\n    },\n    {\n      \"id\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"label\": \"resolve function by parsing PE exports\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    },\n    {\n      \"id\": \"cap_author_____sara_rn\",\n      \"label\": \"author     sara-rn\",\n      \"type\": \"capability\",\n      \"severity\": \"low\",\n      \"category\": \"\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_change_memory_protection__2_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_change_memory_protection__2_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"bb_0x401C66\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_loop__42_matches__only_showing_first_match_of_library_rule_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_contain_loop__42_matches__only_showing_first_match_of_library_rule_\",\n      \"target\": \"func_0x4013F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_compiled_with_mingw_for_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_contain_a_thread_local_storage___tls__section\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_accept_command_line_arguments__2_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__2_matches_\",\n      \"target\": \"func_0x408340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_accept_command_line_arguments__2_matches_\",\n      \"target\": \"func_0x4013F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408340\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4013F0\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408340\",\n      \"target\": \"api_CommandLineToArgv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4013F0\",\n      \"target\": \"api_CommandLineToArgv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x408340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x4013F0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408340\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4013F0\",\n      \"target\": \"api_GetCommandLine\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x408340\",\n      \"target\": \"api_CommandLineToArgv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"func_0x4013F0\",\n      \"target\": \"api_CommandLineToArgv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_query_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_query_environment_variable\",\n      \"target\": \"func_0x404AF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404AF0\",\n      \"target\": \"api_getenv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com____re_fox\",\n      \"target\": \"func_0x404AF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x404AF0\",\n      \"target\": \"api_getenv\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_environment_variable\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_environment_variable\",\n      \"target\": \"func_0x408340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408340\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408340\",\n      \"target\": \"api_SetEnvironmentVariable\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_common_file_path\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_common_file_path\",\n      \"target\": \"func_0x408340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408340\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x408340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408340\",\n      \"target\": \"api_GetWindowsDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_set_current_directory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_set_current_directory\",\n      \"target\": \"func_0x408340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408340\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x408340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408340\",\n      \"target\": \"api_SetCurrentDirectory\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_write_file_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_write_file_on_windows\",\n      \"target\": \"func_0x401BC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401BC0\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____william_ballenthin_mandiant_com__anushka_virgaonkar_mandiant_com\",\n      \"target\": \"func_0x401BC0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401BC0\",\n      \"target\": \"api_fwrite\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_get_thread_local_storage_value\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_get_thread_local_storage_value\",\n      \"target\": \"func_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"cap_author_____michael_hunhoff_mandiant_com\",\n      \"target\": \"func_0x401980\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x401980\",\n      \"target\": \"api_TlsGetValue\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_create_process_on_windows\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_create_process_on_windows\",\n      \"target\": \"bb_0x4085BA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____moritz_raabe_mandiant_com\",\n      \"target\": \"bb_0x4085BA\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_execute_command\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_execute_command\",\n      \"target\": \"func_0x408340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408340\",\n      \"target\": \"api__wsystem\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz\",\n      \"target\": \"func_0x408340\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"func_0x408340\",\n      \"target\": \"api__wsystem\",\n      \"relationship\": \"calls\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_allocate_or_change_rwx_memory\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_allocate_or_change_rwx_memory\",\n      \"target\": \"bb_0x401C66\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author______mr_tz__mehunhoff_google_com\",\n      \"target\": \"bb_0x401C66\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_link_function_at_runtime_on_windows__3_matches_\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____moritz_raabe_mandiant_com__mehunhoff_google_com\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_resolve_function_by_parsing_pe_exports\",\n      \"target\": \"func_0x404AF0\",\n      \"relationship\": \"implemented_by\"\n    },\n    {\n      \"source\": \"malware_file\",\n      \"target\": \"cap_author_____sara_rn\",\n      \"relationship\": \"exhibits\"\n    },\n    {\n      \"source\": \"cap_author_____sara_rn\",\n      \"target\": \"func_0x404AF0\",\n      \"relationship\": \"implemented_by\"\n    }\n  ],\n  \"metadata\": {\n    \"analysis_type\": \"static\",\n    \"version\": \"9.2.1\",\n    \"timestamp\": \"2026-07-21 21:58:26.824058\",\n    \"total_functions\": \"146\",\n    \"total_features\": \"6721\",\n    \"pdb_path\": \"\"\n  }\n};\n\n        const width = window.innerWidth - 350;\n        const height = window.innerHeight;\n\n        const svg = d3.select(\"#graph\")\n            .append(\"svg\")\n            .attr(\"width\", width)\n            .attr(\"height\", height);\n\n        const g = svg.append(\"g\");\n\n        const zoom = d3.zoom()\n            .scaleExtent([0.1, 4])\n            .on(\"zoom\", (event) => {\n                g.attr(\"transform\", event.transform);\n            });\n\n        svg.call(zoom);\n\n        const colorMap = {\n            \"file\": \"#ff4757\",\n            \"capability\": \"#ff6348\",\n            \"function\": \"#5f27cd\",\n            \"api\": \"#00d2d3\",\n            \"basic_block\": \"#1dd1a1\"\n        };\n\n        const simulation = d3.forceSimulation(graphData.nodes)\n            .force(\"link\", d3.forceLink(graphData.edges).id(d => d.id).distance(100))\n            .force(\"charge\", d3.forceManyBody().strength(-300))\n            .force(\"center\", d3.forceCenter(width / 2, height / 2))\n            .force(\"collision\", d3.forceCollide().radius(40));\n\n        const linkColorMap = {\n            \"exhibits\": \"#ff6b6b\",\n            \"implemented_by\": \"#4ecdc4\",\n            \"calls\": \"#45b7d1\",\n            \"part_of\": \"#96ceb4\",\n            \"depends_on\": \"#ffeaa7\"\n        };\n\n        const link = g.append(\"g\")\n            .selectAll(\"line\")\n            .data(graphData.edges)\n            .enter()\n            .append(\"line\")\n            .attr(\"class\", \"link\")\n            .attr(\"stroke\", d => linkColorMap[d.relationship] || \"#999\")\n            .attr(\"stroke-width\", 2);\n\n        const node = g.append(\"g\")\n            .selectAll(\"circle\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"circle\")\n            .attr(\"class\", d => `node ${d.severity === \"high\" ? \"severity-high\" : \"\"}`)\n            .attr(\"r\", d => {\n                if (d.type === \"file\") return 20;\n                if (d.type === \"capability\") return d.severity === \"high\" ? 15 : 12;\n                if (d.type === \"function\") return 10;\n                return 8;\n            })\n            .attr(\"fill\", d => {\n                if (d.type === \"capability\" && d.severity === \"medium\") return \"#ffa502\";\n                if (d.type === \"capability\" && d.severity === \"low\") return \"#48dbfb\";\n                return colorMap[d.type] || \"#666\";\n            })\n            .attr(\"stroke\", \"#fff\")\n            .attr(\"stroke-width\", 2)\n            .on(\"click\", (event, d) => showNodeInfo(d))\n            .call(d3.drag()\n                .on(\"start\", dragstarted)\n                .on(\"drag\", dragged)\n                .on(\"end\", dragended));\n\n        let labelsVisible = true;\n        const labels = g.append(\"g\")\n            .selectAll(\"text\")\n            .data(graphData.nodes)\n            .enter()\n            .append(\"text\")\n            .text(d => d.label)\n            .attr(\"fill\", \"#fff\")\n            .attr(\"dx\", 15)\n            .attr(\"dy\", 4);\n\n        simulation.on(\"tick\", () => {\n            link\n                .attr(\"x1\", d => d.source.x)\n                .attr(\"y1\", d => d.source.y)\n                .attr(\"x2\", d => d.target.x)\n                .attr(\"y2\", d => d.target.y);\n\n            node\n                .attr(\"cx\", d => d.x)\n                .attr(\"cy\", d => d.y);\n\n            labels\n                .attr(\"x\", d => d.x)\n                .attr(\"y\", d => d.y);\n        });\n\n        function dragstarted(event, d) {\n            if (!event.active) simulation.alphaTarget(0.3).restart();\n            d.fx = d.x;\n            d.fy = d.y;\n        }\n\n        function dragged(event, d) {\n            d.fx = event.x;\n            d.fy = event.y;\n        }\n\n        function dragended(event, d) {\n            if (!event.active) simulation.alphaTarget(0);\n            d.fx = null;\n            d.fy = null;\n        }\n\n        function showNodeInfo(node) {\n            let html = `<h2>${node.label}</h2>`;\n            html += `<div class=\"info-item\"><span class=\"label\">Type:</span> ${node.type}</div>`;\n            \n            if (node.severity) {\n                html += `<div class=\"info-item\"><span class=\"label\">Severity:</span> ${node.severity.toUpperCase()}</div>`;\n            }\n            \n            if (node.category) {\n                html += `<div class=\"info-item\"><span class=\"label\">Category:</span> ${node.category}</div>`;\n            }\n            \n            if (node.mitre) {\n                html += `<div class=\"info-item\"><span class=\"label\">MITRE:</span> ${node.mitre.join(\", \")}</div>`;\n            }\n            \n            if (node.operations) {\n                html += `<div class=\"info-item\"><span class=\"label\">Operations:</span><br>${node.operations.join(\"<br>\")}</div>`;\n            }\n            \n            if (node.properties) {\n                html += `<div class=\"info-item\"><span class=\"label\">MD5:</span><br>${node.properties.md5}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">SHA256:</span><br>${node.properties.sha256}</div>`;\n                html += `<div class=\"info-item\"><span class=\"label\">Arch:</span> ${node.properties.arch}</div>`;\n            }\n            \n            if (node.address) {\n                html += `<div class=\"info-item\"><span class=\"label\">Address:</span> ${node.address}</div>`;\n            }\n            \n            document.getElementById(\"node-info\").innerHTML = html;\n        }\n\n        function resetZoom() {\n            svg.transition().duration(750).call(zoom.transform, d3.zoomIdentity);\n        }\n\n        function toggleLabels() {\n            labelsVisible = !labelsVisible;\n            labels.style(\"display\", labelsVisible ? \"block\" : \"none\");\n        }\n\n        let physicsEnabled = true;\n        function togglePhysics() {\n            physicsEnabled = !physicsEnabled;\n            if (physicsEnabled) {\n                simulation.alphaTarget(0.3).restart();\n                setTimeout(() => simulation.alphaTarget(0), 1000);\n            } else {\n                simulation.stop();\n            }\n        }\n\n        window.addEventListener(\"resize\", () => {\n            const w = window.innerWidth - 350;\n            const h = window.innerHeight;\n            svg.attr(\"width\", w).attr(\"height\", h);\n            simulation.force(\"center\", d3.forceCenter(w / 2, h / 2));\n            simulation.alpha(0.3).restart();\n        });\n    </script>\n</body>\n</html>"},"timestamp":"2026-07-21 21:58:27"}
